Federated Payload-based Anomaly Detection: An Investigation for Different Aggregation Algorithms

Chong Chen, Peng Chao Zhou · 2022

Payload-based anomaly detection (PAD) has been proven as a very effective solution to protect the Internet for a long period of time, but unfortunately rely on a big data of normal payload samples for model training, which potentially induces the privacy concerns for the data owners who usually hold their network payloads locally and are not willing to share in the public. To tackle the privacy issue, some pioneer research advocates the use of federated learning to build the PAD model (we call it federated PAD) by aggregating the local model's parameters rather than the local data directly, hence preserving the data privacy for PAD. We understand the federated PAD may sacrifice the detection performance to gain privacy benefits, while the trade-offs may vary quite largely in different federated aggregation algorithms. For this reason, we investigate the effectiveness of federated PAD with typical aggregation algorithms in this paper, which includes the weighted mean, trimmed mean, median, absolute mean, and Krum. We implement all of these algorithms in the condition of a typical PAD application, and also run extensive experiments on the real-world Internet payload datasets for comparison. Our results have successfully revealed the best practice for the use of federated aggregation for training the PAD.

Read the paper · More papers on PaperTik