FI-IDS: A Federated Incremental Learning Approach for Intrusion Detection System

Nguyen Huu Quyen, Nguyen Viet Hoang, Phan The Duy, Van-Hau Pham · 2024

Internet of Things (IoT) networks offer significant comfort and convenience, but they also heighten security risks by exposing system vulnerabilities and private data to network intruders. Therefore, creating an efficient intrusion detection system (IDS) model is essential. Federated Learning (FL)-based IDS has garnered attention due to its ability to train collaboratively on decentralized devices while preserving data privacy. However, most existing methods rely on one-time learning, assuming that object classes within the framework remain constant over time. This leads to significant catastrophic forgetting (CF) in the global model in real-world scenarios, where local devices frequently collect new classes and have limited memory to store old classes. Additionally, new devices with unseen classes may join the FL training, further exacerbating CF in the global model. In this research, we propose a federated incremental learning IDS framework (FI-IDS) based on the Elastic Weight Consolidation (EWC) method. This framework can quickly and continuously learn and train class-incremental models on new data, mitigating CF. Our approach also addresses the issue of non-independent and identically distributed (Non-IID) class imbalance across collaborators. Our FI-IDS approach is validated using the Kitsune dataset, and simulation results indicate that FI-IDS achieves higher efficiency and accuracy compared to existing FL-based IDS model, FedIDS by over 23% and federated incremental learning (FIL) model, GLFC by over 2%.

Read the paper · More papers on PaperTik