<p>The challenges of data heterogeneity and the complexity of cybersecurity attacks, specifically Distributed Denial of Service (DDoS) attacks on the Internet of Things (IoT), require advanced solutions beyond the conventional federated learning (FL)-based DDoS attack detection. This paper introduces a novel Dynamic Weighted Clustered Federated Learning (FedDWC) framework that addresses the limitation of traditional FL methods such as non-independent and identically distributed (non-IID) nature of data and equal share of influence inherited from conventional averaging. FedDWC integrate model personalization and knowledge sharing by clustering similar clients to learn shared models and formulating bi-level optimization of the learning process across distributed Internet of Things (IoT) environments. Moreover, the framework dynamically adjusts the weight based on the performance of the local model for each IoT device. This approach preserve data privacy, improves detection accuracy and reduces convergence time in the face of evolving DDoS attacks. Our study presents a theoretical analysis to demonstrate the convergence property of the proposed framework. The experimental results show that the proposed FedDWC framework outperforms other state-of-the-art methods: FedAvg, FedProx, and IFCA in terms of convergence and DDoS attack detection accuracy under non-IID data conditions. In terms of accuracy, FedDWC achieved improvements of 1.9%, 1.31%, and 1.01% over FedAvg, FedProx, and IFCA, respectively, when using the IoTID20 non-IID dataset of 10 clusters and 200 IoT devices.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Dynamic weight clustered federated learning for IoT DDoS attack detection

  • Yonas Kibret Beshah,
  • Surafel Lemma Abebe,
  • Henock Mulugela Melaku

摘要

The challenges of data heterogeneity and the complexity of cybersecurity attacks, specifically Distributed Denial of Service (DDoS) attacks on the Internet of Things (IoT), require advanced solutions beyond the conventional federated learning (FL)-based DDoS attack detection. This paper introduces a novel Dynamic Weighted Clustered Federated Learning (FedDWC) framework that addresses the limitation of traditional FL methods such as non-independent and identically distributed (non-IID) nature of data and equal share of influence inherited from conventional averaging. FedDWC integrate model personalization and knowledge sharing by clustering similar clients to learn shared models and formulating bi-level optimization of the learning process across distributed Internet of Things (IoT) environments. Moreover, the framework dynamically adjusts the weight based on the performance of the local model for each IoT device. This approach preserve data privacy, improves detection accuracy and reduces convergence time in the face of evolving DDoS attacks. Our study presents a theoretical analysis to demonstrate the convergence property of the proposed framework. The experimental results show that the proposed FedDWC framework outperforms other state-of-the-art methods: FedAvg, FedProx, and IFCA in terms of convergence and DDoS attack detection accuracy under non-IID data conditions. In terms of accuracy, FedDWC achieved improvements of 1.9%, 1.31%, and 1.01% over FedAvg, FedProx, and IFCA, respectively, when using the IoTID20 non-IID dataset of 10 clusters and 200 IoT devices.