Traditional vs Federated Learning with Deep Autoencoders: a Study in IoT Intrusion Detection
Marta Catillo, Antonio Pecchia, Umberto Villano · 2023
Security of Internet of Things (IoT) devices and networks is a primary concern. Many intrusion detection systems (IDS) proposals in the IoT leverage machine and deep learning algorithms to learn models that can be used to discriminate normal behaviors from intrusions. Due to the dynamicity and scale of modern IoT networks, it is hard to learn and maintain one separate IDS model per device; on the other hand, the Cloud-Edge-IoT architecture allows learning a single IDS model (instead of many separate models). This paper compares two paradigms, i.e., traditional and federated, to learn a single IDS model atop the traffic of different IoT devices. The former assumes the availability of an all-in-one training dataset at a unique learning node; the latter aggregates the outcomes of independent learning procedures executed on individual training datasets hosted by different nodes. The experiments are done with a well-established public benchmark of nine IoT devices and the use of deep autoencoders. In the experiment and dataset at hand, federated learning lead to an increase of the false positive rate of six devices compared to the traditional scenario. Such an increase was balanced by a narrower variability of the false positive rate across all the devices and a mitigation of potential overfitting.