It is demonstrated that the proposed method is more effective, in terms of the detection, stability, and convergence behavior, than the existing centralized and federated IDS models, and can effectively deal with non-IID data distribution and the extensibility of the approach to different types of distributed network environment.
Abstract
The rising rate of interconnected systems, cloud infrastructures, edge environments, and distributed network architectures have greatly exposed the vulnerability of the current digital infrastructures. This has exposed them to more advanced cybercrimes like denial-of-service attacks, malware injections, and data leaks. Also, there are sophisticated persistent threats that add more security burdens to such systems. The traditional Intrusion Detection Systems (IDS) are conventionally designed around central data collection and model training which result in the loss of privacy, a severely limited scale, a huge load on communications and a single point of failure. These constraints are even more deplorable in large and heterogeneous networks. To solve these issues, federated learning-based IDS models are suggested, but the existing practices fail to converge quickly, do not scale to non-IID data distributions and have an increased computation and communication cost which restricts its application. To overcome these issues, this paper proposes a Federated Enhanced Transformer-based Intrusion Detection System (FET-FIDS), a privacy-preserving and decentralized system of security, where federated learning is combined with Transformer-based self-attention. In the proposed architecture, a group of clients are introduced, each client is responsible for being trained on local network traffic data using FET-FIDS model. This method will help the system to learn intrusion patterns that are usually complicated to be learnt only in collaborative training. The locally trained model updates are then securely combined in a centralized server using adaptive federated averaging without having access to the raw data and, therefore, preserving their confidentiality of the data. The proposed architecture is effective in distributed and heterogeneous environments where under the experimental conditions taken into account in this study, its scalability, robustness and communication performance are improved. Using the provided means of wide-scale experimental analysis, the proposed FET-FIDS gives accuracy of 97.82%. It demonstrated that the proposed method is more effective, in terms of the detection, stability, and convergence behavior, than the existing centralized and federated IDS models. Further, it is shown that the framework can effectively deal with non-IID data distribution and the extensibility of the approach to different types of distributed network environment.
FedSE-1DSqueezeNet is proposed, a lightweight federated IDS tailored for resource-constrained IoT environments, designed to optimize feature extraction efficiency under strict resource constraints and achieves detection accuracy exceeding that of state-of-the-art models.
High-speed, low-latency and massive connectivity have emerged as a result of the rapid development of 5G networks, but so have security threats. Current intrusion detection tools are poorly adapted to the distributed, heterogeneous, and dynamic 5G environment where a flood of real-time information is generated over a spectrum of devices at the edges and network layers. Federated learning has been suggested in response to these threats as a new paradigm to aid in the training of intrusion detection systems without having to aggregate the information. This review provides a detailed study of intrusion detection systems in 5G networks that are federated learning-based, and how the federated learning-based intrusion detection systems can address the challenges mentioned above. The paper will also entail the discussion of the basic ideas and principles of federated learning, the importance of robust federated optimization techniques to enhance the robustness of models, and architectural design of distributed intrusion detection systems. Moreover, accuracy, efficiency, and resilience to adversarial attacks are also used as indicators of performance, which emphasizes the potential and strength of federated learning when used in complex network conditions. The key challenges and the difficulties, including the heterogeneity, communication, and security, are also discussed and analyzed. Lastly, the new trends and possible directions of research, such as the combination of AI explanations, adaptive learning, and federated learning with other emerging technologies, such as edge computing and blockchain, are also presented. In general, the paper provides a detailed and extensive perspective on the design and development of scalable and privacy-conserving and smart intrusion detection mechanisms on next-generation 5G networks.
The rapid expansion of the Internet of Things (IoT) has intensified cybersecurity risks by exposing distributed connected devices to increasingly complex and pervasive threats. Conventional centralized security mechanisms often struggle to accommodate the heterogeneous and decentralized structure of IoT networks. This study investigates Federated Learning (FL) as a decentralized approach to intrusion detection that enables local model training on IoT edge devices while transmitting only encrypted model updates to a central server, thereby preserving data privacy and reducing communication overhead. A novel FL-based Intrusion Detection System (IDS) architecture was developed using Convolutional Neural Networks (CNNs) for anomaly detection and the Federated Averaging (FedAvg) algorithm for aggregating local model updates. The framework was evaluated on standard IoT datasets under non-independent and identically distributed (non-IID) data conditions to simulate heterogeneous real-world environments. Experimental results demonstrate that the proposed system achieved a detection accuracy of 94.6%, an F1-score of 93.8%, and a recall of 92.7%, outperforming centralized and standalone local learning methods. The framework also reduced communication overhead by 35% and achieved convergence 28% faster than conventional approaches. These findings demonstrate that FL can provide a scalable, privacy-preserving, and computationally efficient foundation for strengthening IoT cybersecurity. This study contributes a decentralized machine-learning architecture for real-time, adaptive, and privacy-conscious intrusion detection in large-scale IoT environments.
Mohammed Ajuji, Y. M. Malgwi, A. Ahmadu et al.· International Journal of Edu...· 0 citations
This work proposes an intelligent, lightweight Tiny LSTM–GRU hybrid IDS on the edge to monitor device-generated behavioral patterns in real time, with minimal computational and energy overhead, and proposes an adaptive FedProx-based weighted federated learning framework.
Emmanuel Udok, B. Stephen, U. Luke et al.· E3S Web of Conferences· 0 citations
The rise of the Industrial IoT (IIoT) will result in a surge of IIoT devices with high-velocity data streams requiring rapid, real-time analysis of these data streams to power predictive maintenance and assure cybersecurity. Centralized cloud-based approaches to anomaly detection are hindered by their inherent latency and privacy issues while independent or stand-alone approaches to edge-based anomaly detection do not have enough data to effectively detect anomalies. This paper presents a federated learning framework to collaboratively develop an anomaly detection model from multiple edge nodes, without sharing the raw sensor data, so that data sovereignty is preserved. Two major contributions of this research include a lightweight hybrid secure aggregation method that utilizes pairwise additive masking and differential privacy, which mitigates the threat of inversion attacks achieved via a reconstruction SSIM < 0.05, and successfully detects >90% of model poisoning attempts, where as traditional homomorphic encryption solutions incur excessively high computational costs (approximately 68 ms/node) and 70 KB of communication overhead/round). Our architecture was validated using a synthetic IIoT data set containing 600,000 rows of data correlated across 12 edge nodes and 10 different types of sensors, and further validated using the real-world SWaT data set. The experimental results demonstrated the effectiveness of the framework, achieving an F1 score of 0.944 for anomaly detection, an F2 from centralized training of only 2.3%, and a 60-70% reduction in communication costs compared to the use of homomorphic encryption. The experimental results also demonstrate that local edge inference latency is <50 ms, meeting the real-time requirements of IIoT systems. Overall, the framework demonstrates that practical, deployable security for federated learning in IIoT is achievable without sacrificing accuracy or responsiveness, and open-source implementations are provided to ensure full reproducibility.
This work shows that production‐grade, privacy‐preserving intrusion detection is feasible in IoT networks at the edge, and addresses the concerns of data privacy and non‐IID data distribution inherent to distributed IoT networks.
Vaibhav Joshi, Abishi Chowdhury, Amrit Pal et al.· Software, Practice & Experie...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.