Evaluation of Centralized, Distributed and Federated Learning for IoT Intrusion Detection Systems
Omar Elnakib, Eman Shaaban, Mohamed M. E. A. Mahmoud, Karim Emara · 2023
Introducing smart intrusion detection systems (IDSs) in the IoT system was a crucial requirement in the last decades to secure these systems due to the high sensitivity of the sensed data. Smart IDS has often been built based on a machine/deep learning model trained at a centralized node in the cloud. However, the centralized learning approach violates data privacy since IoT nodes are required to share their data to the cloud to train the model. Distributed and federated learning approaches were introduced to solve this issue by keeping data within the local network and letting the edge devices train the model. In this paper, a comparative study among centralized, distributed, and federated learning approaches is presented. First, a deep learning model is proposed to identify traffic behavior using CICIDS2017 dataset. The three learning approaches are then applied with the proposed model to evaluate the effect of each approach on the model accuracy. In the centralized learning approach, an F-Score of 98% can be achieved. Moreover, the dataset is split over ten simulated nodes with various data distribution and entropies to evaluate the distributed and federated learning approaches. In distributed learning, the F-Score ranges between 63% to 93% with an average of 78% over the ten nodes. In the federated learning, the F-Score ranges between 73% to 98% with an average of 89% over the ten nodes. This result confirms that IDSs based on federated learning are a promising solution for both accuracy and preserving data privacy.