用联邦学习在物联网边缘设备上实现低通信开销的实时攻击检测
In-network Attack Detection with Federated Deep Learning in IoT Networks: Real Implementation and Analysis
- 在边缘设备部署轻量级自编码器,结合联邦学习协同训练
- 实测通信开销显著降低,性能接近中心化方法
- 适合资源受限的物联网场景,兼顾隐私与实时性
物联网(IoT)的快速扩展及其与骨干网络的融合,加剧了安全风险。传统的集中式异常检测方法需将大量数据传输至中心服务器,面临隐私泄露、可扩展性差和延迟高等问题。本文提出一种面向资源受限边缘设备的轻量级自编码器异常检测框架,支持实时检测并最小化数据传输,同时保护隐私。采用联邦学习,在分布式设备上进行本地训练,仅聚合模型参数至中心服务器。构建基于树莓派传感器节点的真实物联网测试平台,采集正常与攻击流量数据。在该平台上实现并评估所提出的联邦异常检测系统,结果表明其能有效识别网络攻击,在显著降低通信开销的同时,达到与集中式方法相当的性能。
原文摘要 · Abstract (English)
The rapid expansion of the Internet of Things (IoT) and its integration with backbone networks have heightened the risk of security breaches. Traditional centralized approaches to anomaly detection, which require transferring large volumes of data to central servers, suffer from privacy, scalability, and latency limitations. This paper proposes a lightweight autoencoder-based anomaly detection framework designed for deployment on resource-constrained edge devices, enabling real-time detection while minimizing data transfer and preserving privacy. Federated learning is employed to train models collaboratively across distributed devices, where local training occurs on edge nodes and only model weights are aggregated at a central server. A real-world IoT testbed using Raspberry Pi sensor nodes was developed to collect normal and attack traffic data. The proposed federated anomaly detection system, implemented and evaluated on the testbed, demonstrates its effectiveness in accurately identifying network attacks. The communication overhead was reduced significantly while achieving comparable performance to the centralized method.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。