An Interpretable Federated Learning-based Network Intrusion Detection Framework

01/10/2022
by   Tian Dong, et al.
0

Learning-based Network Intrusion Detection Systems (NIDSs) are widely deployed for defending various cyberattacks. Existing learning-based NIDS mainly uses Neural Network (NN) as a classifier that relies on the quality and quantity of cyberattack data. Such NN-based approaches are also hard to interpret for improving efficiency and scalability. In this paper, we design a new local-global computation paradigm, FEDFOREST, a novel learning-based NIDS by combining the interpretable Gradient Boosting Decision Tree (GBDT) and Federated Learning (FL) framework. Specifically, FEDFOREST is composed of multiple clients that extract local cyberattack data features for the server to train models and detect intrusions. A privacy-enhanced technology is also proposed in FEDFOREST to further defeat the privacy of the FL systems. Extensive experiments on 4 cyberattack datasets of different tasks demonstrate that FEDFOREST is effective, efficient, interpretable, and extendable. FEDFOREST ranks first in the collaborative learning and cybersecurity competition 2021 for Chinese college students.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
10/08/2022

FedDef: Robust Federated Learning-based Network Intrusion Detection Systems Against Gradient Leakage

Deep learning methods have been widely applied to anomaly-based network ...
research
07/02/2021

Segmented Federated Learning for Adaptive Intrusion Detection System

Cyberattacks are a major issues and it causes organizations great financ...
research
12/02/2021

Deep Transfer Learning: A Novel Collaborative Learning Model for Cyberattack Detection Systems in IoT Networks

Federated Learning (FL) has recently become an effective approach for cy...
research
09/01/2022

Generalizing intrusion detection for heterogeneous networks: A stacked-unsupervised federated learning approach

The constantly evolving digital transformation imposes new requirements ...
research
05/23/2022

FedSA: Accelerating Intrusion Detection in Collaborative Environments with Federated Simulated Annealing

Fast identification of new network attack patterns is crucial for improv...
research
11/05/2020

Collaborative City Digital Twin For Covid-19 Pandemic: A Federated Learning Solution

In this work, we propose a collaborative city digital twin based on FL, ...
research
04/26/2022

A review of Federated Learning in Intrusion Detection Systems for IoT

Intrusion detection systems are evolving into intelligent systems that p...

Please sign up or login with your details

Forgot password? Click here to reset