A DDoS attack detection method combining federated learning and hybrid deep learning in software-defined networking

Qi Zhou, Xuechun Mao, Ying Chen · The Computer Journal · 2025

Abstract Software-defined networking (SDN) improves network flexibility by separating the control plane and data plane, but centralized control architecture also increases the risk of distributed denial of service (DDoS) attacks. Traditional detection methods often face performance bottlenecks when dealing with large-scale data. Deep learning, with its powerful automatic feature extraction capabilities, can significantly improve detection accuracy. However, single models typically focus on a specific dimension of network traffic features, neglecting the comprehensive processing of spatial and temporal features. In addition, most existing deep learning methods rely on centralized training, leading to issues such as data transmission delays and privacy breaches. To address these issues, this paper proposes a hybrid model named 1DCNN-TransBiLSTM. The model consists of a spatial feature extraction module based on a 1DCNN and a temporal feature extraction module based on Transformer and BiLSTM. By processing spatial and temporal features in parallel, the model effectively enhances the ability to identify complex attack patterns. Additionally, federated learning is employed to enable multiple SDN controllers to collaborate in training without sharing raw data, and multi-key homomorphic encryption is used to protect the privacy of model gradients. The experimental results show that the model achieves an accuracy of 99.925% and an F1 score of 99.962% on the CICDDoS2019 dataset, outperforming existing machine learning and deep learning methods, demonstrating outstanding performance in DDoS detection in SDN environments.

Read the paper · More papers on PaperTik