A Federated Learning based Botnet Detection Method for Industrial Internet of Things

Hao Zhou, Zhiwei Sheng · 2023

Botnets in the Industrial Internet of Things (IIoT) significantly threaten system security. Currently, mainstream machine learning-based botnet detection techniques rely on centralized large-scale data training; however, this approach neglects privacy protection and data security issues. In addition, the complexity and heterogeneity of IIoT make the detection model unable to adapt to different industrial enterprises. In this paper, we propose a federated learning-based botnet detection approach for IIoT, where multiple heterogeneous industrial enterprises can train models using local data under the remote coordination of a centralized server, and then upload the model parameters to the central server to complete the aggregation. This approach allows the botnet detection model to better adapt to the local environment while avoiding sharing raw data. Meanwhile, the method is robust to federated learning poisoning attacks. In this paper, we have conducted tests using the N-BaIoT dataset. Our method achieves 99.63% of the F1 value and 99.26% of the MCC value on a new device that is not involved in the training. The detection performance is almost comparable to that of the centrally trained method, and outperforms other similar methods.

Read the paper · More papers on PaperTik