Privacy-preserving Network Anomaly Detection on Homomorphically Encrypted Data
Tatjana Wingarz, Richard August See, Florian Gondesen, Mathias Fischer · 2024
With the increasing reliance on cloud computing for managed security services, sensitive data, such as network or host data, is increasingly not processed on-premise anymore. To protect the privacy of this sensitive data while processed in the cloud we propose a framework that combines homomorphic encryption (HE) with privacy-preserving machine learning (PPML) techniques, to run Intrusion Detection Systems (IDS) in the cloud, without exposing sensitive data to cloud providers. Our work evaluates the applicability of two HE schemes for network traffic anomaly detection, focusing on computational efficiency and compatibility with PPML. We adopt optimization strategies, namely quantization and feature vector reduction, to enhance computational efficiency and ensure the scalability of anomaly detection tasks in cloud-based environments. Furthermore, we conduct a runtime analysis to evaluate the practical feasibility of integrating HE with PPML for IDS. Our findings indicate that while incorporating HE introduces a computational overhead, there are realistic scenarios where the proposed system can be effectively applied, offering a balance between privacy preservation and operational requirements.