Coordinated Attacks Detection Simulation With Deep Neural Network Algorithm and Federated Learning
Retno Fauziah Istiqomah, Parman Sukarno, Aulia Arif Wardana · 2024
This research is focused on comparing the performance of Deep Neural Network (DNN) in Centralized Learning (CL) and Federated Learning (FL) concepts on simulating coordinated attack detection, such as Benign (normal activity), PortScan, DDoS, and Bot using the cicids2017 dataset for model training. The data preprocessing used is the Adaptive Synthetic Sampling (ADASYN) method for unbalanced data balancing. This research aims to advance the concept of network attack detection in an effort to keep each device’s data safe, without the need to send datasets to a central device to update the attack classification model, i.e. the data is trained in a decentralized way using the FL concept. In the simulation of coordinated attack detection, the result of FL is higher than that of CL. To achieve good attack classification results, the FL concept only required 20.45 seconds per epoch, which is shorter than the time required by the CL concept to train the attack classification model. Some of the advantages of the FL concept allow for smarter modeling, low latency, and less power consumption, while ensuring the privacy of each device’s data.