FL-CGF: An Edge-Federated Learning-Based Intelligent Intrusion Detection Framework for Heterogenous Maritime Internet of Things

Jialong Li, Jin Liu, Zhongdai Wu, Junxiang Wang · 2024

Maritime Internet of Things (MIoT) consists of maritime devices such as ships, consoles and base stations for information sharing at sea. However, as the quantity of devices accessed through MIoT continues to increase, the likelihood of breaches in data privacy escalates considerably. Current Intrusion Detection Systems (IDSs) for MIoT face three main challenges: data privacy regulations, maritime information silos, and highly mobile and decentralized network topologies. Therefore, there is an urgent need for an intrusion detection solution that protects data privacy, securely shares information and adapts to heterogeneous MIoT and Non-Independent and Identically Distributed (Non-IID). To this end, this study proposes an innovative framework for intrusion detection based on an edge Federated Learning (FL) architecture for dynamic and efficient cyber threat event identification in the presence of low communication resources among nodes of distributed maritime vessels, FL-CGF. In this model, the network traffic data is first converted into images in a specific way, and then the proposed hybrid model of CGF, which combines Convolutional Neural Network (CNN) and Gated Recurrent Unit (GRU), is employed to effectively extract features across both spatial and temporal dimensions. Co-training between various clients is achieved by FL algorithm, which enables FL-CGF to obtain a high degree of generalization capability while being able to be deployed on resource-constrained end-devices. The intrusion detection accuracies of FL-CGF on the well-known public dataset utilized in intrusion detection NSL-KDD and on the highly unbalanced network message stream dataset CTI, which is collected during the voyage of a real ship, are respectively 96.71% and 96.04%. Especially for U2R and Slowloris, which account for a relatively small number of cyber threat events, FL-CGF also shows good performance. Our proposed FL-CGF demonstrates the capability to somewhat mitigate the issue of data silos. The effective application of FL-CGF presents a novel, privacy-protecting, and efficient approach to intrusion detection in MIoT security.

Read the paper · More papers on PaperTik