Skip to main page content
U.S. flag

An official website of the United States government

Dot gov

The .gov means it’s official.
Federal government websites often end in .gov or .mil. Before sharing sensitive information, make sure you’re on a federal government site.

Https

The site is secure.
The https:// ensures that you are connecting to the official website and that any information you provide is encrypted and transmitted securely.

Access keys NCBI Homepage MyNCBI Homepage Main Content Main Navigation
. 2024 Oct 24;19(10):e0308639.
doi: 10.1371/journal.pone.0308639. eCollection 2024.

NIDS-FGPA: A federated learning network intrusion detection algorithm based on secure aggregation of gradient similarity models

Affiliations

NIDS-FGPA: A federated learning network intrusion detection algorithm based on secure aggregation of gradient similarity models

JiaMing Wang et al. PLoS One. .

Abstract

With the rapid development of Industrial Internet of Things (IIoT), network security issues have become increasingly severe, making intrusion detection one of the key technologies for ensuring IIoT security. However, existing intrusion detection systems face challenges such as incomplete data features, missing labels, parameter leakage, and high communication overhead. To address these challenges, this paper proposes a federated learning-based intrusion detection algorithm (NIDS-FGPA) that utilizes gradient similarity model aggregation. This algorithm leverages a federated learning architecture and combines it with Paillier homomorphic encryption technology to ensure the security of the training process. Additionally, the paper introduces the Gradient Similarity Model Aggregation (GSA) algorithm, which dynamically selects and weights updates from different models to reduce communication overhead. Finally, the paper designs a deep learning model based on two-dimensional convolutional neural networks and bidirectional gated recurrent units (2DCNN-BIGRU) to handle incomplete data features and missing labels in network traffic data. Experimental validation on the Edge-IIoTset and CIC IoT 2023 datasets achieves accuracies of 94.5% and 99.2%, respectively. The results demonstrate that the NIDS-FGPA model possesses the ability to identify and capture complex network attacks, significantly enhancing the overall security of the network.

PubMed Disclaimer

Conflict of interest statement

The authors have declared that no competing interests exist.

Figures

Fig 1
Fig 1. Federated learning framework diagram.
Fig 2
Fig 2. Federated learning classification.
Fig 3
Fig 3. Overall model framework.
Fig 4
Fig 4. Transformed grayscale image.
Fig 5
Fig 5. 2DCNN-BIGRU framework.
Fig 6
Fig 6. Network resource consumption comparison for three methods in learning process under C = 3 scenario.
Fig 7
Fig 7. Paillier homomorphic encryption and decryption.
Fig 8
Fig 8. Communication overhead under different key lengths.
Fig 9
Fig 9. Accuracy and loss variation of the NIDS-FGPA model.
Fig 10
Fig 10. Classification report for the nids-fgpa model.

Similar articles

References

    1. Bukhari SMS, Zafar MH, Houran MA, Moosavi SKR, Mansoor M, Muaaz M, et al.. Secure and privacy-preserving intrusion detection in wireless sensor networks: Federated learning with SCNN-Bi-LSTM for enhanced reliability. Ad Hoc Networks. 2024;155. doi: 10.1016/j.adhoc.2024.103407 - DOI
    1. Rashid MM, Khan SU, Eusufzai F, Redwan MA, Sabuj SR, Elsharief M. A Federated Learning-Based Approach for Improving Intrusion Detection in Industrial Internet of Things Networks. Network. 2023;3(1):158–179. doi: 10.3390/network3010008 - DOI
    1. Sarhan M, Layeghy S, Moustafa N, Portmann M. Cyber Threat Intelligence Sharing Scheme Based on Federated Learning for Network Intrusion Detection. Journal of Network and Systems Management. 2022;31(1). doi: 10.1007/s10922-022-09691-3 - DOI
    1. Lai YC, Lin JY, Lin YD, Hwang RH, Lin PC, Wu HK, et al.. Two-phase Defense Against Poisoning Attacks on Federated Learning-based Intrusion Detection. Computers & Security. 2023;129. doi: 10.1016/j.cose.2023.103205 - DOI
    1. Doriguzzi-Corin R, Siracusa D. FLAD: Adaptive Federated Learning for DDoS attack detection. Computers & Security. 2024;137. doi: 10.1016/j.cose.2023.103597 - DOI

LinkOut - more resources