A Federated Learning-POMDP Approach for Network Intrusion Detection
Curtis Rookard, Anahita Khojandi · 2024
Due to the increasing expanse of the internet, cyber attacks have become more prevalent, thus necessitating the need for robust security controls, especially with respect to machine learning-assisted intrusion detection. A recent method for intrusion detection involves federated learning, which ensures the confidentiality of data as opposed to traditional, centralized machine learning. In this study, we propose a novel framework involving the formulation of a federated learning network intrusion detection system as a partially observable Markov decision process (POMDP). We then solve this POMDP by applying a reinforcement learning algorithm, specifically the asynchronous advantage actor critic algorithm. Our results indicate that our A3C statistically performs better compared with our benchmark federated learning models and obtains a higher recall score while maintaining a high precision score. Henceforth, our proposed model decreases the number of false negatives while maintaining high overall performance. Our novel, unique framework is a promising approach for federated network intrusion detection.