Federated Learning Based Intelligent Network Intrusion Detection in Power Plant Information Systems
摘要
The cyberspace security is considered important for reliable and safe operation of power plants. To this end, this work develops a federated learning based intelligent network intrusion detection method for the power plant information systems. Facing the increasing and diverse forms of threats from the cyberspace, the conventional centralized intrusion detection systems can no longer be efficient to timely and accurately identify the new forms of cyberspace attacks and preserve the data privacy. To overcome these limitations, this work proposes a federated anomaly detection framework based on Deep Autoencoding Gaussian Mixture Model (DAGMM). The proposed algorithmic solution leverages the distributed nature of federated learning to cope with the non-independent and identically distributed (i.e. non-IID) network data traffic across various sensors and terminal devices in the power plant information systems. Extensive evaluations through simulation experiments demonstrates that the proposed solution can effectively enhance the model generalization capability, improve the detection efficiency as well as guarantee the data privacy. The technical contributions include the integration of FedPer (Federated Learning with Personalized Layers) as a federated aggregation framework to address data heterogeneity and the development of a robust anomaly detection model.