Co-Design of Decision Trees for Network Intrusion Detection at the Edge on Digital vs. Analog Hardware
Joseph Riem, Lei Zhang, Jingdi Chen, Henry Mackay, Tian Lan, Nathaniel D. Bastian, Gina C. Adam · 2024
Enabling cybersecurity at the network edge requires energy-efficient and lightweight implementations of explainable network intrusion detection in constrained environments, such as the Internet of Battlefield Things (IoBT). Hardware solutions can support the efficient operation of algorithms for network intrusion detection, but these algorithms must consider the limited resources available at the network edge. To this end, we show two possible hardware implementations, one digital on an FPGA and one analog on a memristor/130nm CMOS design, of 9-node decision trees for three relevant datasets, the UNSW-NB15, the CIC-IDS 2017, and the ACI-IoT 2023. The decision tree boundaries are digitally implemented using LUTs with quantized 6-bit values on the FPGA. For the analog implementation, each leaf unit in the decision trees is naturally mapped to a chiplet, where the boundaries have a physical value stored in the programmable 6-bit resistance of a memristor device. Quantization in such novel computing architectures is necessary due to the limited bit precision of emerging nanoscale memristor devices. The corresponding boundaries are obtained by training the decision tree on respective datasets. The obtained accuracy on the digital implementation on the FPGA is 84%, 93%, and 79%, respectively, for the three datasets. The accuracy of the analog implementation is 79%, 83%, and 73%, respectively, impacted by the memristor non-idealities. Analog non-idealities can be mitigated by developing better devices in the future or by additional circuitry. The power consumption of these implemented trees shows 101mW for the FPGA implementation and 3.4mW for the analog chiplet approach. The 30x reduction in energy consumption shows the potential for analog hardware co-designed with explainable algorithms to provide efficient inference for network intrusion detection at the edge.