Federated Learning Ensemble Voting-Based Methods to Deal with Non-IID and Imbalanced Data in Cybersecurity

  • Bruno H. Meyer
    Department of Informatics (UFPR), Curitiba, Brazil bruno.meyer[at]ufpr.br
  • Michele Nogueira
    Department of Computer Science (UFMG)
  • Wagner M. Nunan Zola
    Department of Informatics (UFPR), Curitiba, Brazil
  • Aurora Pozo
    Department of Informatics (UFPR), Curitiba, Brazil

Abstract

Cybersecurity is an essential topic in society due to the increasing application of technology across different application industries that are connected to the Internet. There are several methods to address cybersecurity challenges, such as Intrusion Detection Systems (IDS). This article presents new methods based on Federated Learning that can be applied to IDS to improve cybersecurity attack detection. Researchers use different approaches to create IDS solutions, including machine learning algorithms and techniques such as Federated Learning (FL) to classify network traffic as normal or malicious. FL is an emerging technology and is expected to benefit cybersecurity by improving attack detection and threat identification. It consists of a set of clients, each one with local data, whose goal is to collaboratively train one or more global models without centralizing the data, through several iterations known as rounds. An important characteristic to consider in cybersecurity data for machine learning algorithms is the presence of non-Independent and Identically Distributed (non-IID) and imbalanced data. Non-IID data describes FL datasets in which data is not evenly distributed between clients. Unlike previously proposed methods in other works, this article proposes approaches that focus on non-IID data while using FL to create models without requiring multiple training rounds. The FLENV and FLEWNV methods are proposed, implementing a federated learning framework that uses a single training round and aggregates clients through ensemble learning with normalized and weighted voting, focusing on non-IID and imbalanced data. The well-known Ton-IoT and Bot-IoT datasets were analyzed to evaluate the proposed methods and other possibilities commonly used in the state of the art. The approaches outperformed other methods from the literature in the experiments, indicating that leveraging knowledge of non-IID and imbalanced data in cybersecurity can lead to improved attack classification frameworks.
  • Referencias
  • Cómo citar
  • Del mismo autor
  • Métricas
Abdullahi, M., Baashar, Y., Alhussian, H., Alwadain, A., Aziz, N., Capretz, L. F., & Abdulkadir, S. J. (2022). Detecting cybersecurity attacks in internet of things using artificial intelligence methods: A systematic literature review. Electronics, 11(2), 198. https://doi.org/10.3390/electronics11020198

Alazab, M., Rm, S. P., Maddikunta, P. K. R., Gadekallu, T. R., & Pham, Q. V. (2021). Federated learning for cybersecurity: Concepts, challenges, and future directions. IEEE Transactions on Industrial Informatics, 18(5), 3501-3509. https://doi.org/10.1109/TII.2021.3119038

Aliyu, I., Feliciano, M. C., Van Engelenburg, S., Kim, D. O., & Lim, C. G. (2021). A blockchain-based federated forest for SDN-enabled in-vehicle network intrusion detection system. IEEE Access, 9, 102593-102608. https://doi.org/10.1109/ACCESS.2021.3094365

Attota, D. C., Mothukuri, V., Parizi, R. M., & Pouriyeh, S. (2021). An ensemble multi-view federated learning intrusion detection for IoT. IEEE Access, 9, 117734-117745. https://doi.org/10.1109/ACCESS.2021.3107337

Campos, E. M., Saura, P. F., González-Vidal, A., Hernández-Ramos, J. L., Bernabe, J. B., Baldini, G., & Skarmeta, A. (2022). Evaluating Federated Learning for intrusion detection in Internet of Things: Review and challenges. Computer Networks, 203, 108661. https://doi.org/10.1016/j.comnet.2021.108661

Dai, R., Zhang, Y., Li, A., Liu, T., Yang, X., & Han, B. (2024). Enhancing one-shot federated learning through data and ensemble co-boosting. arXiv. https://doi.org/10.48550/arXiv.2402.15070

Farid, F., Elkhodr, M., Sabrina, F., Ahamed, F., & Gide, E. (2021). A smart biometric identity management framework for personalised IoT and cloud computing-based healthcare services. Sensors, 21(2), 552. https://doi.org/10.3390/s21020552

Ferrag, M. A., Friha, O., Hamouda, D., Maglaras, L., & Janicke, H. (2022). Edge-IIoTset: A new comprehensive realistic cyber security dataset of IoT and IIoT applications for centralized and federated learning. IEEE Access, 10, 40281-40306. https://doi.org/10.1109/ACCESS.2022.3165809

Ferrag, M. A., Friha, O., Maglaras, L., Janicke, H., & Shu, L. (2021). Federated deep learning for cyber security in the internet of things: Concepts, applications, and experimental analysis. IEEE Access, 9, 138509-138542. https://doi.org/10.1109/ACCESS.2021.3118642

Ghimire, B., & Rawat, D. B. (2022). Recent advances on federated learning for cybersecurity and cybersecurity for federated learning for internet of things. IEEE Internet of Things Journal, 9(11), 8229-8249. https://doi.org/10.1109/JIOT.2022.3150363

Guha, N., Talwalkar, A., & Smith, V. (2019). One-shot federated learning. arXiv. https://doi.org/10.48550/arXiv.1902.11175

Hsu, T. M. H., Qi, H., & Brown, M. (2019). Measuring the effects of non-identical data distribution for federated visual classification. arXiv. https://doi.org/10.48550/arXiv.1909.06335

Jurek, A., Bi, Y., Wu, S., & Nugent, C. (2014). A survey of commonly used ensemble-based classification techniques. The Knowledge Engineering Review, 29(5), 551-581. https://doi.org/10.1017/S0269888913000155

Khoa, T. V., Saputra, Y. M., Hoang, D. T., Trung, N. L., Nguyen, D., Ha, N. V., & Dutkiewicz, E. (2020). Collaborative learning model for cyberattack detection systems in iot industry 4.0. In Proceedings of the 2020 IEEE Wireless Communications and Networking Conference (pp. 1-6). IEEE. https://doi.org/10.1109/WCNC45663.2020.9120761

Koroniotis, N., Moustafa, N., Sitnikova, E., & Turnbull, B. (2019). Towards the development of realistic botnet dataset in the internet of things for network forensic analytics: Bot-IoT dataset. Future Generation Computer Systems, 100, 779-796. https://doi.org/10.1016/j.future.2019.05.041

Leon, F., Floria, S. A., & Bădică, C. (2017). Evaluating the effect of voting methods on ensemble-based classification. In Proceedings of the 2017 IEEE International Conference on Innovations in Intelligent Systems and Applications (pp. 1-6). IEEE. https://doi.org/10.1109/INISTA.2017.8001122

Li, J., Lyu, L., Liu, X., Zhang, X., & Lyu, X. (2021a). FLEAM: A federated learning empowered architecture to mitigate DDoS in industrial IoT. IEEE Transactions on Industrial Informatics, 18(6), 4059-4068. https://doi.org/10.1109/TII.2021.3088938

Li, Q., He, B., & Song, D. (2021b). Model-contrastive federated learning. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (pp. 10713-10722). https://doi.org/10.1109/CVPR46437.2021.01057

Li, X., Huang, K., Yang, W., Wang, S., & Zhang, Z. (2019). On the convergence of FedAvg on non-IID data. arXiv. https://doi.org/10.48550/arXiv.1907.02189

Lin, J. (2002). Divergence measures based on the Shannon entropy. IEEE Transactions on Information Theory, 37(1), 145-151. https://doi.org/10.1109/18.61115

Lin, J. (2016). On the dirichlet distribution. Department of Mathematics and Statistics, Queens University, 40.

Lin, T., Kong, L., Stich, S. U., & Jaggi, M. (2020). Ensemble distillation for robust model fusion in federated learning. Advances in Neural Information Processing Systems, 33, 2351-2363.

Liu, Y., Liu, Y., Liu, Z., Liang, Y., Meng, C., Zhang, J., & Zheng, Y. (2020). Federated forest. IEEE Transactions on Big Data, 8(3), 843-854. https://doi.org/10.1109/TBDATA.2020.2992755

McMahan, B., Moore, E., Ramage, D., Hampson, S., & y Arcas, B. A. (2017). Communication-efficient learning of deep networks from decentralized data. In Artificial Intelligence and Statistics (pp. 1273-1282). PMLR.

Moustafa, N. (2021). A new distributed architecture for evaluating AI-based security systems at the edge: Network TON_IoT datasets. Sustainable Cities and Society, 72, 102994. https://doi.org/10.1016/j.scs.2021.102994

Nguyen, N. H., Nguyen, P. L., Nguyen, T. D., Nguyen, T. T., Nguyen, D. L., Nguyen, T. H., ... & Truong, T. N. (2022). FedDRL: Deep reinforcement learning-based adaptive aggregation for non-IID data in federated learning. In Proceedings of the 51st International Conference on Parallel Processing (pp. 1-11). https://doi.org/10.1145/3545008.3545085

Papernot, N., Abadi, M., Erlingsson, U., Goodfellow, I., & Talwar, K. (2016). Semi-supervised knowledge transfer for deep learning from private training data. arXiv. https://doi.org/10.48550/arXiv.1610.05755

Schneible, J., & Lu, A. (2017). Anomaly detection on the edge. In MILCOM 2017-2017 IEEE Military Communications Conference (pp. 678-682). IEEE. https://doi.org/10.1109/MILCOM.2017.8170817

Sewak, M., Sahay, S. K., & Rathore, H. (2018). Comparison of deep learning and the classical machine learning algorithm for the malware detection. In Proceedings of the 2018 19th IEEE/ACIS International Conference on Software Engineering, Artificial Intelligence, Networking and Parallel/Distributed Computing (pp. 293-296). IEEE. https://doi.org/10.1109/SNPD.2018.8441123

Vinyals, O., Blundell, C., Lillicrap, T., & Wierstra, D. (2016). Matching networks for one shot learning. Advances in Neural Information Processing Systems, 29.

Wang, C., Xia, H., Xu, S., Chi, H., Zhang, R., & Hu, C. (2024). FedBnR: Mitigating federated learning non-IID problem by breaking the skewed task and reconstructing representation. Future Generation Computer Systems, 153, 1-11. https://doi.org/10.1016/j.future.2023.11.020

Yue, K., Jin, R., Wong, C. W., & Dai, H. (2022). Federated learning via plurality vote. IEEE Transactions on Neural Networks and Learning Systems, 35(6), 8215-8228. https://doi.org/10.1109/TNNLS.2022.3225715

Yurochkin, M., Agarwal, M., Ghosh, S., Greenewald, K., Hoang, N., & Khazaeni, Y. (2019). Bayesian nonparametric federated learning of neural networks. In Proceedings of the International Conference on Machine Learning (pp. 7252-7261). PMLR.

Zhao, R., Yin, Y., Shi, Y., & Xue, Z. (2020). Intelligent intrusion detection based on federated learning aided long short-term memory. Physical Communication, 42, 101157. https://doi.org/10.1016/j.phycom.2020.101157

Zhao, S., Liao, T., Fu, L., Chen, C., Bian, J., & Zheng, Z. (2024). Data-free knowledge distillation via generator-free data generation for non-IID federated learning. Neural Networks, 179, 106627. https://doi.org/10.1016/j.neunet.2024.106627

Zhou, Y., Pu, G., Ma, X., Li, X., & Wu, D. (2020). Distilled one-shot federated learning. arXiv. https://doi.org/10.48550/arXiv.2009.07999

Zhu, H., Xu, J., Liu, S., & Jin, Y. (2021). Federated learning on non-IID data: A survey. Neurocomputing, 465, 371-390. https://doi.org/10.1016/j.neucom.2021.07.098
Meyer, B. H., Nogueira, M., Nunan Zola, W. M., & Pozo, A. (2026). Federated Learning Ensemble Voting-Based Methods to Deal with Non-IID and Imbalanced Data in Cybersecurity. ADCAIJ: Advances in Distributed Computing and Artificial Intelligence Journal, 14, e32905. https://doi.org/10.14201/adcaij.32905

Downloads

Download data is not yet available.
+ −