Federated learning has emerged as a powerful solution in network intrusion detection, proving highly effective in countering sophisticated attacks. This work delves into the intricate workings of a federated system, exploring its capabilities through a structured, three-stage workflow. The first stage involved data exploration, followed by model construction and testing, where critical parameters such as training epochs, data partitioning, and data proportions were adjusted to evaluate their impact on the model’s performance. In the final stage, feature exploration, an explainable AI framework was employed to assess feature contributions, with the premise that models utilizing the same dataset should assign similar importance to key features. A comparison between the centralized and federated models was conducted, revealing that both approaches aligned closely in their feature interpretations. Explainable AI brought enhanced transparency, ensuring that the model’s decision-making was consistent with practical, real-world reasoning. In conclusion, this study highlights the robustness of federated models in intrusion detection, offering valuable insights into their parameter optimization and confirming their potential as a reliable alternative to centralized systems. We have utilized CICIDS 2017 dataset to evaluate and demonstrate the results.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

EXPLAINABLE AI for Applied Federated Learning in Network Intrusion Detection

  • Jesmine Akhter,
  • Y. Annie Jerusha,
  • S. P. Syed Ibrahim,
  • Vijay Varadharajan

摘要

Federated learning has emerged as a powerful solution in network intrusion detection, proving highly effective in countering sophisticated attacks. This work delves into the intricate workings of a federated system, exploring its capabilities through a structured, three-stage workflow. The first stage involved data exploration, followed by model construction and testing, where critical parameters such as training epochs, data partitioning, and data proportions were adjusted to evaluate their impact on the model’s performance. In the final stage, feature exploration, an explainable AI framework was employed to assess feature contributions, with the premise that models utilizing the same dataset should assign similar importance to key features. A comparison between the centralized and federated models was conducted, revealing that both approaches aligned closely in their feature interpretations. Explainable AI brought enhanced transparency, ensuring that the model’s decision-making was consistent with practical, real-world reasoning. In conclusion, this study highlights the robustness of federated models in intrusion detection, offering valuable insights into their parameter optimization and confirming their potential as a reliable alternative to centralized systems. We have utilized CICIDS 2017 dataset to evaluate and demonstrate the results.