FLAD: Adaptive Federated Learning for DDoS attack detection

被引:6
|
作者
Doriguzzi-Corin, Roberto [1 ]
Siracusa, Domenico [1 ]
机构
[1] Fdn Bruno Kessler, Cybersecur Ctr, Trento, Italy
关键词
Network security; Intrusion detection; Distributed denial of service; Federated Learning; Heterogeneous data;
D O I
10.1016/j.cose.2023.103597
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Federated Learning (FL) has been recently receiving increasing consideration from the cybersecurity community as a way to collaboratively train deep learning models with distributed profiles of cyber threats, with no disclosure of training data. Nevertheless, the adoption of FL in cybersecurity is still in its infancy, and a range of practical aspects have not been properly addressed yet. Indeed, the Federated Averaging algorithm at the core of the FL concept requires the availability of test data to control the FL process. Although this might be feasible in some domains, test network traffic of newly discovered attacks cannot be always shared without disclosing sensitive information. In this paper, we address the convergence of the FL process in dynamic cybersecurity scenarios, where the trained model must be frequently updated with new recent attack profiles to empower all members of the federation with the latest detection features. To this aim, we propose FLAD (adaptive Federated Learning Approach to DDoS attack detection), an FL solution for cybersecurity applications based on an adaptive mechanism that orchestrates the FL process by dynamically assigning more computation to those members whose attacks profiles are harder to learn, without the need of sharing any test data to monitor the performance of the trained model. Using a recent dataset of DDoS attacks, we demonstrate that FLAD outperforms state-of-the-art FL algorithms in terms of convergence time and accuracy across a range of unbalanced datasets of heterogeneous DDoS attacks. We also show the robustness of our approach in a realistic scenario, where we retrain the deep learning model multiple times to introduce the profiles of new attacks on a pre-trained model.
引用
收藏
页数:13
相关论文
共 50 条
  • [1] FLDDoS: DDoS Attack Detection Model based on Federated Learning
    Zhang, Jiachao
    Yu, Peiran
    Qi, Le
    Liu, Song
    Zhang, Haiyu
    Zhang, Jianzhong
    [J]. 2021 IEEE 20TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2021), 2021, : 635 - 642
  • [2] Federated Learning for Decentralized DDoS Attack Detection in IoT Networks
    Alhasawi, Yaser
    Alghamdi, Salem
    [J]. IEEE ACCESS, 2024, 12 : 42357 - 42368
  • [3] Robust DDoS attack detection with adaptive transfer learning
    Anley, Mulualem Bitew
    Genovese, Angelo
    Agostinello, Davide
    Piuri, Vincenzo
    [J]. COMPUTERS & SECURITY, 2024, 144
  • [4] FedDB: A Federated Learning Approach Using DBSCAN for DDoS Attack Detection
    Lee, Yi-Chen
    Chien, Wei-Che
    Chang, Yao-Chung
    [J]. Applied Sciences (Switzerland), 2024, 14 (22):
  • [5] Federated Incremental Learning Based DDoS Attack Detection Model in SDN Environment
    Liu, Yan-Hua
    Fang, Wen-Yu
    Guo, Wen-Zhong
    Zhao, Bao-Kang
    Huang, Wei
    [J]. Jisuanji Xuebao/Chinese Journal of Computers, 2024, 47 (12): : 2852 - 2866
  • [6] PoAh-Enabled Federated Learning Architecture for DDoS Attack Detection in IoT Networks
    Park, Jin Ho
    Yotxay, Sangthong
    Singh, Sushil Kumar
    Park, Jong Hyuk
    [J]. HUMAN-CENTRIC COMPUTING AND INFORMATION SCIENCES, 2024, 14 : 1 - 24
  • [7] An Asynchronous Federated Learning Arbitration Model for Low-Rate DDoS Attack Detection
    Liu, Zengguang
    Guo, Cuiyun
    Liu, Deyong
    Yin, Xiaochun
    [J]. IEEE ACCESS, 2023, 11 : 18448 - 18460
  • [8] DDoS Attack Detection in a Real Urban IoT Environment using Federated Deep Learning
    Ahmadi, Khatereh
    Javidan, Reza
    [J]. 2023 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE, CSR, 2023, : 117 - 122
  • [9] DDoS attack detection using unsupervised federated learning for 5G networks and beyond
    Sheikhi, Saeid
    Kostakos, Panos
    [J]. 2023 JOINT EUROPEAN CONFERENCE ON NETWORKS AND COMMUNICATIONS & 6G SUMMIT, EUCNC/6G SUMMIT, 2023, : 442 - 447
  • [10] Adaptive DDoS Attack Detection Method Based on Multiple-Kernel Learning
    Cheng, Jieren
    Zhang, Chen
    Tang, Xiangyan
    Sheng, Victor S.
    Dong, Zhe
    Li, Junqi
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2018,