Comprehensive Evaluation of Federated Learning Configurations for Intrusion Detection in IoT Contexts

Abderahmane Hamdouchi, Ali Idri · 2024

The Internet of Things (IoT) encompasses billions of internet-connected devices that function with little human intervention. The reliance on user data for automation exposes IoT networks to cyber threats, including theft and manipulation of personally identifiable information. As a result, there is a growing focus on utilizing deep learning (DL) methods to develop intrusion detection systems (IDS). Many DL-based IDS rely on centralized methods, requiring IoT devices to send data to data centers for analysis. To address privacy issues linked to these centralized methods, the adoption of Federated Learning (FL) has gained considerable attention across various sectors in recent years. This research meticulously evaluates FL configurations that utilize a dense neural network (DNN) as the base model, incorporating two types of aggregation servers (FedAVG and FedSGD), across three different device counts (5, 15, and 30), and with two data setups (raw and balanced). The analysis was performed on the NF-ToN-IoT-v2 dataset employing the Scott-Knott test and Borda Count method. In this research, we evaluated 12 FL setups. Our findings revealed that the FedAVG method excels at aggregating models to detect attacks within FL environments. Notably, combining FedAVG with raw data from five devices significantly enhances FL model efficiency, outperforming all other configurations tested.

Read the paper · More papers on PaperTik