A federated learning method for network intrusion detection

IF 1.5 4区 计算机科学 Q3 COMPUTER SCIENCE, SOFTWARE ENGINEERING Concurrency and Computation-Practice & Experience Pub Date : 2021-12-24 DOI:10.1002/cpe.6812
Zhongyun Tang, Haiyang Hu, Chonghuan Xu
{"title":"A federated learning method for network intrusion detection","authors":"Zhongyun Tang,&nbsp;Haiyang Hu,&nbsp;Chonghuan Xu","doi":"10.1002/cpe.6812","DOIUrl":null,"url":null,"abstract":"<p>Intrusion detection is a common network security defense technology. At present, there are many research using deep learning to realize network intrusion detection. This method has been proved to have high detection accuracy. However, deep learning requires large-scale data sets for training. The network intrusion detection data set of some institution is lacking. If the network traffic data set is uploaded for centralized deep learning training, it will face privacy problems. Combined with the characteristics of network traffic, this article proposes a network intrusion detection method based on federated learning. This method allows multiple ISPs or other institutions to conduct joint deep learning training on the premise of retaining local data. It not only improves the detection accuracy of the model but also protects privacy in network traffic. This article conducts experiments on the CICIDS2017 network intrusion detection data set. Experimental results show that worker participating in federated learning have higher detection accuracy. The accuracy and other performance of federated learning are almost equal to those of centralized deep learning models.</p>","PeriodicalId":55214,"journal":{"name":"Concurrency and Computation-Practice & Experience","volume":"34 10","pages":""},"PeriodicalIF":1.5000,"publicationDate":"2021-12-24","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"25","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Concurrency and Computation-Practice & Experience","FirstCategoryId":"94","ListUrlMain":"https://onlinelibrary.wiley.com/doi/10.1002/cpe.6812","RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"COMPUTER SCIENCE, SOFTWARE ENGINEERING","Score":null,"Total":0}
引用次数: 25

Abstract

Intrusion detection is a common network security defense technology. At present, there are many research using deep learning to realize network intrusion detection. This method has been proved to have high detection accuracy. However, deep learning requires large-scale data sets for training. The network intrusion detection data set of some institution is lacking. If the network traffic data set is uploaded for centralized deep learning training, it will face privacy problems. Combined with the characteristics of network traffic, this article proposes a network intrusion detection method based on federated learning. This method allows multiple ISPs or other institutions to conduct joint deep learning training on the premise of retaining local data. It not only improves the detection accuracy of the model but also protects privacy in network traffic. This article conducts experiments on the CICIDS2017 network intrusion detection data set. Experimental results show that worker participating in federated learning have higher detection accuracy. The accuracy and other performance of federated learning are almost equal to those of centralized deep learning models.

查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
一种网络入侵检测的联邦学习方法
入侵检测是一种常用的网络安全防御技术。目前,利用深度学习实现网络入侵检测的研究有很多。实践证明,该方法具有较高的检测精度。然而,深度学习需要大规模的数据集进行训练。缺乏某机构的网络入侵检测数据集。如果上传网络流量数据集进行集中深度学习训练,将会面临隐私问题。结合网络流量的特点,提出了一种基于联邦学习的网络入侵检测方法。该方法允许多个isp或其他机构在保留本地数据的前提下进行联合深度学习训练。既提高了模型的检测精度,又保护了网络流量中的隐私。本文在CICIDS2017网络入侵检测数据集上进行实验。实验结果表明,参与联邦学习的工作人员具有较高的检测准确率。联邦学习的精度和其他性能几乎与集中式深度学习模型相当。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
Concurrency and Computation-Practice & Experience
Concurrency and Computation-Practice & Experience 工程技术-计算机:理论方法
CiteScore
5.00
自引率
10.00%
发文量
664
审稿时长
9.6 months
期刊介绍: Concurrency and Computation: Practice and Experience (CCPE) publishes high-quality, original research papers, and authoritative research review papers, in the overlapping fields of: Parallel and distributed computing; High-performance computing; Computational and data science; Artificial intelligence and machine learning; Big data applications, algorithms, and systems; Network science; Ontologies and semantics; Security and privacy; Cloud/edge/fog computing; Green computing; and Quantum computing.
期刊最新文献
Issue Information A Multi-Workflow Scheduling Approach With Explicit Evolutionary Multi-Objective Multi-Task Optimization Algorithm in Cloud Environment Measuring Thread Timing to Assess the Feasibility of Early-Bird Message Delivery Across Systems and Scales Issue Information Analysis and Fuzzy Neural Networks-Based Inertia Coefficient Adjustment Strategy of Power Converters
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1