<p>The rapid evolution of cyber threats, particularly zero-day attacks, presents a major challenge to modern network security. Traditional Network Intrusion Detection Systems (NIDS) rely on centralized data collection, which raises privacy concerns, limits scalability, and hampers adaptability to unseen attacks. To overcome these limitations, this paper proposes a Federated Learning-based One-Shot Intrusion Detection System (FLOIDS), a privacy-preserving and distributed framework that integrates federated learning with a one-shot Siamese neural network architecture. FLOIDS learns discriminative similarity-based embeddings from limited attack samples and identifies anomalous traffic patterns that deviate from known classes as potential zero-day attacks. Federated learning enables decentralized training across multiple clients without exposing raw network data, thereby ensuring data confidentiality and reducing communication overhead. The proposed model was evaluated on two benchmark datasets, NSL-KDD and CICIDS2017, under one-shot conditions where U2R and Heartbleed attacks were excluded during training. FLOIDS achieved precision and recall scores of 69% and 83% on NSL-KDD, and 100% and 67% on CICIDS2017, respectively, with overall accuracies of 98% and 92% under an Independent and Identically Distributed federated environment. These results demonstrate that combining one-shot and federated learning enables effective detection of previously unseen (zero-day) threats while maintaining data privacy and scalability, making FLOIDS a promising and robust solution for next-generation NIDS deployments.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

FLOIDS: a federated learning based one-shot intrusion detection system using siamese neural networks for detecting zero-day attacks

  • B. Selvakumar,
  • B. Lakshmanan,
  • P. Kaviya,
  • A. R. Akash,
  • I. Akash Xavier

摘要

The rapid evolution of cyber threats, particularly zero-day attacks, presents a major challenge to modern network security. Traditional Network Intrusion Detection Systems (NIDS) rely on centralized data collection, which raises privacy concerns, limits scalability, and hampers adaptability to unseen attacks. To overcome these limitations, this paper proposes a Federated Learning-based One-Shot Intrusion Detection System (FLOIDS), a privacy-preserving and distributed framework that integrates federated learning with a one-shot Siamese neural network architecture. FLOIDS learns discriminative similarity-based embeddings from limited attack samples and identifies anomalous traffic patterns that deviate from known classes as potential zero-day attacks. Federated learning enables decentralized training across multiple clients without exposing raw network data, thereby ensuring data confidentiality and reducing communication overhead. The proposed model was evaluated on two benchmark datasets, NSL-KDD and CICIDS2017, under one-shot conditions where U2R and Heartbleed attacks were excluded during training. FLOIDS achieved precision and recall scores of 69% and 83% on NSL-KDD, and 100% and 67% on CICIDS2017, respectively, with overall accuracies of 98% and 92% under an Independent and Identically Distributed federated environment. These results demonstrate that combining one-shot and federated learning enables effective detection of previously unseen (zero-day) threats while maintaining data privacy and scalability, making FLOIDS a promising and robust solution for next-generation NIDS deployments.