用半监督联邦学习提升物联网入侵检测准确率
FedMSE: Semi-supervised federated learning approach for IoT network intrusion detection
- 结合自编码器与中心点分类器,建模正常流量特征
- 检测准确率从93.98%提升至97.30%,仅需50%网关参与训练
- 适合资源受限、隐私要求高的大规模物联网场景
针对物联网设备激增带来的网络攻击面扩大问题,传统集中式机器学习因数据可用性、计算资源、传输成本及隐私保护顾虑而难以应用。本文提出一种新型半监督联邦学习方法FedMSE,融合收缩自编码器与中心点一类分类器(SAE-CEN),在去中心化策略下有效表征正常网络数据并精准识别异常。同时引入基于均方误差的聚合算法(MSEAvg),优先集成更优的本地模型以提升全局性能。实验基于N-BaIoT数据集与狄利克雷分布,在多种设置下验证:检测准确率从93.98±2.90%提升至97.30±0.49%,训练仅需50%网关参与,且在大规模异构网络中表现鲁棒。
原文摘要 · Abstract (English)
This paper proposes a novel federated learning approach for improving IoT network intrusion detection. The rise of IoT has expanded the cyber attack surface, making traditional centralized machine learning methods insufficient due to concerns about data availability, computational resources, transfer costs, and especially privacy preservation. A semi-supervised federated learning model was developed to overcome these issues, combining the Shrink Autoencoder and Centroid one-class classifier (SAE-CEN). This approach enhances the performance of intrusion detection by effectively representing normal network data and accurately identifying anomalies in the decentralized strategy. Additionally, a mean square error-based aggregation algorithm (MSEAvg) was introduced to improve global model performance by prioritizing more accurate local models. The results obtained in our experimental setup, which uses various settings relying on the N-BaIoT dataset and Dirichlet distribution, demonstrate significant improvements in real-world heterogeneous IoT networks in detection accuracy from 93.98$\pm$2.90 to 97.30$\pm$0.49, reduced learning costs when requiring only 50\% of gateways participating in the training process, and robustness in large-scale networks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。