TY - JOUR
T1 - Semi-Supervised Federated Learning Based Intrusion Detection Method for Internet of Things
AU - Zhao, Ruijie
AU - Wang, Yijun
AU - Xue, Zhi
AU - Ohtsuki, Tomoaki
AU - Adebisi, Bamidele
AU - Gui, Guan
N1 - Publisher Copyright:
IEEE
PY - 2022
Y1 - 2022
N2 - Federated learning (FL) has become an increasingly popular solution for intrusion detection to avoid data privacy leakage in Internet of Things (IoT) edge devices. Existing FL-based intrusion detection methods, however, suffer from three limitations: (1) model parameters transmitted in each round may be used to recover private data, which leads to security risks, (2) not independent and identically distributed (non-IID) private data seriously adversely affects the training of FL (especially distillation-based FL), and (3) high communication overhead caused by the large model size greatly hinders the actual deployment of the solution. To address these problems, this paper develops an intrusion detection method based on semi-supervised FL scheme via knowledge distillation. First, our proposed method leverages unlabeled data via distillation method to enhance the classifier performance. Second, we build a model based on convolutional neural networks (CNN) for extracting deep features of the traffic packets, and take this model as both the classifier network and discriminator network. Third, the discriminator is designed to improve the quality of each client’s predicted labels, to avoid the failure of distillation training caused by a large number of incorrect predictions under private non-IID data. Moreover, the combination of hard-label strategy and voting mechanism further reduces communication overhead. Experiments on the real-world traffic dataset with three non-IID scenarios show that our proposed method can achieve better detection performance as well as lower communication overhead than state-of-the-art methods.
AB - Federated learning (FL) has become an increasingly popular solution for intrusion detection to avoid data privacy leakage in Internet of Things (IoT) edge devices. Existing FL-based intrusion detection methods, however, suffer from three limitations: (1) model parameters transmitted in each round may be used to recover private data, which leads to security risks, (2) not independent and identically distributed (non-IID) private data seriously adversely affects the training of FL (especially distillation-based FL), and (3) high communication overhead caused by the large model size greatly hinders the actual deployment of the solution. To address these problems, this paper develops an intrusion detection method based on semi-supervised FL scheme via knowledge distillation. First, our proposed method leverages unlabeled data via distillation method to enhance the classifier performance. Second, we build a model based on convolutional neural networks (CNN) for extracting deep features of the traffic packets, and take this model as both the classifier network and discriminator network. Third, the discriminator is designed to improve the quality of each client’s predicted labels, to avoid the failure of distillation training caused by a large number of incorrect predictions under private non-IID data. Moreover, the combination of hard-label strategy and voting mechanism further reduces communication overhead. Experiments on the real-world traffic dataset with three non-IID scenarios show that our proposed method can achieve better detection performance as well as lower communication overhead than state-of-the-art methods.
KW - Data models
KW - Distributed databases
KW - Feature extraction
KW - federated learning
KW - Internet of Things
KW - Intrusion detection
KW - Intrusion detection
KW - knowledge distillation.
KW - semi-supervised learning
KW - Servers
KW - Training
UR - http://www.scopus.com/inward/record.url?scp=85130469624&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=85130469624&partnerID=8YFLogxK
U2 - 10.1109/JIOT.2022.3175918
DO - 10.1109/JIOT.2022.3175918
M3 - Article
AN - SCOPUS:85130469624
SN - 2327-4662
SP - 1
JO - IEEE Internet of Things Journal
JF - IEEE Internet of Things Journal
ER -