Federated transfer learning for rare attack class detection in network intrusion detection systems
Abstract
Abstract Federated learning (FL) offers a promising approach for training machine learning models with minimal data sharing, enhancing privacy and performance. However, building effective FL-based network intrusion detection systems (NIDS) remains challenging due to the need for large, diverse training datasets. Identifying rare attack types with limited instances is a persistent obstacle, and their detection is critical in cybersecurity. This research introduces a novel FL framework to address these challenges. By incorporating adaptive, personalized layers at the client level, the model reduces false alarm rates for zero-day attack types and improves the detection of rare classes. The model also leverages Transfer Learning (TL) to identify zero-day attacks, where client-specific gradients are collected and used to update a global model on the server side after multiple rounds of exposure to new data. The proposed sustainable framework aims to disseminate knowledge about rare attack types across clients through a server-based global model within the FL ecosystem. This study achieves two main objectives: (i) improving the detection of rare attack classes and (ii) identifying zero-day attacks in a NIDS context. Evaluations on the CSE-CICIDS-2018, Edge IIoT, and UNSW-NB 15 datasets, which encompass diverse class distributions, demonstrate that the proposed approach outperforms existing models in detecting and handling rare and novel attack types. The proposed model achieves 98.90% accuracy on CICIDS 2018, 98.70% on UNSW-NB 15, and 97.92% on Edge-IIoT, surpassing the FL-TL-CNN model by 2.78%, 1.51%, and 2.03%, respectively. These results highlight the effectiveness, robustness, and adaptability of the proposed approach in enhancing intrusion detection across heterogeneous network environments.
Article Details
Authors (4)
Chunduru Sri Abhijit
Y. Annie Jerusha
S. P. Syed Ibrahim
Vijay Varadharajan