Network Traffic Anomaly Detection Based on Federated Learning
Yi Luan · 2024
Combating increasingly complex cybersecurity assaults requires an effective and efficient detection procedure, which may be achieved by integrating Machine Learning (ML) methods with well-known Intrusion Detection Systems (IDS). The majority of ML-enabled IDS uses a centralized approach inside the Internet of Things (IoT), wherein IoT devices exchange data with data centers for further analysis. In recent years, a number of industries, notably healthcare and transportation systems, have shown a great deal of interest in using Federated Learning (FL) to reduce the privacy issues associated with centralized techniques. Still, research from other domains is required to determine the primary obstacles to application in real-world settings since FL-based IDS for IoT is still in its early stages of development. Specifically, this study notes that most of the existing IDSs are centralized, which may not be scalable and, more importantly, may be difficult to protect data privacy. To address this issue, this paper works as follows: utilizing CNN and BiGRU, we develop a novel IDS model that incorporates an attention method to improve the concentration on pertinent data. Additionally, we examine an FL system that comprises scattered IoT persons and federated servers, where different users from the IoT don't have to upload data but can share the model for better detection without losing privacy.