Recently the threat has escalated, and it has become an important security concern that threatens to undermine the stability of the Internet. The classic supervised and unsupervised learning techniques and deep learning methods encounter many problems if one tries to train models using data from different clients. Compounding this issue is the reluctance of various traffic collection devices in real-world scenarios to share their data due to the sensitive nature and strategic value of attack traffic analysis. This lack of data sharing severely restricts model accuracy to address these challenging issues, the current study has developed a novel federated learning-based threat detection model. This strategy allows each client's local model to learn from its own set of data without transferring data between devices. This technique utilizes multiple clients’ pooled knowledge to increase model accuracy and resilience while maintaining data privacy. Furthermore, the study presents two novel approaches to detecting imbalanced attack detection dataset distribution, which lead to relatively few assault instances. Firstly, this work presents a hierarchical aggregation scheme based on K-Means that optimizes model updates for fast convergence without long communication cycles. Secondly, unusual attack patterns can be recognized better by creating new examples through the approach of data resampling using SMOTEENN. This method also distributes data between RNN, CNN, and MLP models differently based on Dirichlet Distribution to improve learning abilities. Results from experiments show that the proposed methodology enhances accuracy by 4% concerning conventional methods while reducing communication rounds by an outstanding 40%. This improves security and operational efficacy in network security measures and showcases a fascinating advancement in safeguarding against several threats including DDOS, MITM, and ARP spoofing. Cognitive computing with HUAI improves Decision-making and threat identification via simulating human cognitive processes. In addition, it ensures AI outputs that can be made sense of and used by people, thus bridging the knowledge divide between intricate AI models and practical uses. This combination approach increases cyber security by fortifying network defenses and increasing technological usability/accessibility to be used by security experts.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Federated Threat Detection with Dirichlet Distribution

  • Saswati Chatterjee,
  • Lalmohan Pattnaik,
  • Suneeta Satpathy,
  • Pabitra Kumar Tripathy

摘要

Recently the threat has escalated, and it has become an important security concern that threatens to undermine the stability of the Internet. The classic supervised and unsupervised learning techniques and deep learning methods encounter many problems if one tries to train models using data from different clients. Compounding this issue is the reluctance of various traffic collection devices in real-world scenarios to share their data due to the sensitive nature and strategic value of attack traffic analysis. This lack of data sharing severely restricts model accuracy to address these challenging issues, the current study has developed a novel federated learning-based threat detection model. This strategy allows each client's local model to learn from its own set of data without transferring data between devices. This technique utilizes multiple clients’ pooled knowledge to increase model accuracy and resilience while maintaining data privacy. Furthermore, the study presents two novel approaches to detecting imbalanced attack detection dataset distribution, which lead to relatively few assault instances. Firstly, this work presents a hierarchical aggregation scheme based on K-Means that optimizes model updates for fast convergence without long communication cycles. Secondly, unusual attack patterns can be recognized better by creating new examples through the approach of data resampling using SMOTEENN. This method also distributes data between RNN, CNN, and MLP models differently based on Dirichlet Distribution to improve learning abilities. Results from experiments show that the proposed methodology enhances accuracy by 4% concerning conventional methods while reducing communication rounds by an outstanding 40%. This improves security and operational efficacy in network security measures and showcases a fascinating advancement in safeguarding against several threats including DDOS, MITM, and ARP spoofing. Cognitive computing with HUAI improves Decision-making and threat identification via simulating human cognitive processes. In addition, it ensures AI outputs that can be made sense of and used by people, thus bridging the knowledge divide between intricate AI models and practical uses. This combination approach increases cyber security by fortifying network defenses and increasing technological usability/accessibility to be used by security experts.