Skip to main content

Research Repository

Advanced Search

Federated Learning for IoT Intrusion Detection

Lazzarini, Riccardo; Tianfield, Huaglory; Charissis, Vassilis

Authors

Riccardo Lazzarini

Huaglory Tianfield



Abstract

The number of Internet of Things (IoT) devices has increased considerably in the past few years, resulting in a large growth of cyber attacks on IoT infrastructure. As part of a defense in depth approach to cybersecurity, intrusion detection systems (IDSs) have acquired a key role in attempting to detect malicious activities efficiently. Most modern approaches to IDS in IoT are based on machine learning (ML) techniques. The majority of these are centralized, which implies the sharing of data from source devices to a central server for classification. This presents potentially crucial issues related to privacy of user data as well as challenges in data transfers due to their volumes. In this article, we evaluate the use of federated learning (FL) as a method to implement intrusion detection in IoT environments. FL is an alternative, distributed method to centralized ML models, which has seen a surge of interest in IoT intrusion detection recently. In our implementation, we evaluate FL using a shallow artificial neural network (ANN) as the shared model and federated averaging (FedAvg) as the aggregation algorithm. The experiments are completed on the ToN_IoT and CICIDS2017 datasets in binary and multiclass classification. Classification is performed by the distributed devices using their own data. No sharing of data occurs among participants, maintaining data privacy. When compared against a centralized approach, results have shown that a collaborative FL IDS can be an efficient alternative, in terms of accuracy, precision, recall and F1-score, making it a viable option as an IoT IDS. Additionally, with these results as baseline, we have evaluated alternative aggregation algorithms, namely FedAvgM, FedAdam and FedAdagrad, in the same setting by using the Flower FL framework. The results from the evaluation show that, in our scenario, FedAvg and FedAvgM tend to perform better compared to the two adaptive algorithms, FedAdam and FedAdagrad.

Citation

Lazzarini, R., Tianfield, H., & Charissis, V. (2023). Federated Learning for IoT Intrusion Detection. Artificial Intelligence, 4(3), 509-530. https://doi.org/10.3390/ai4030028

Journal Article Type Article
Acceptance Date Jul 11, 2023
Online Publication Date Jul 24, 2023
Publication Date 2023-09
Deposit Date Jul 24, 2023
Publicly Available Date Jul 24, 2023
Print ISSN 0004-3702
Electronic ISSN 2673-2688
Publisher MDPI
Peer Reviewed Peer Reviewed
Volume 4
Issue 3
Pages 509-530
DOI https://doi.org/10.3390/ai4030028
Keywords Internet of Things, intrusion detection systems, federated learning, deep learning
Publisher URL https://www.mdpi.com/2673-2688/4/3/28

Files






You might also like



Downloadable Citations