Аналитический обзор подходов к обнаружению вторжений, основанных на федеративном обучении: преимущества использования и открытые задачи

Author:

Novikova EvgeniaORCID,Fedorchenko ElenaORCID,Kotenko IgorORCID,Kholod Ivan

Abstract

To provide an accurate and timely response to different types of attacks, intrusion detection systems collect and analyze a large amount of data, which may include information with limited access, such as personal data or trade secrets. Consequently, such systems can be seen as an additional source of risks associated with handling sensitive information and breaching its security. Applying the federated learning paradigm to build analytical models for attack and anomaly detection can significantly reduce such risks because locally generated data is not transmitted to any third party, and model training is done locally - on the data sources. Using federated training for intrusion detection solves the problem of training on data that belongs to different organizations, and which, due to the need to protect commercial or other secrets, cannot be placed in the public domain. Thus, this approach also allows us to expand and diversify the set of data on which machine learning models are trained, thereby increasing the level of detectability of heterogeneous attacks. Due to the fact that this approach can overcome the aforementioned problems, it is actively used to design new approaches for intrusion and anomaly detection. The authors systematically explore existing solutions for intrusion and anomaly detection based on federated learning, study their advantages, and formulate open challenges associated with its application in practice. Particular attention is paid to the architecture of the proposed systems, the intrusion detection methods and models used, and approaches for modeling interactions between multiple system users and distributing data among them are discussed. The authors conclude by formulating open problems that need to be solved in order to apply federated learning-based intrusion detection systems in practice.

Publisher

SPIIRAS

Subject

Artificial Intelligence,Applied Mathematics,Computational Theory and Mathematics,Computational Mathematics,Computer Networks and Communications,Information Systems

Reference111 articles.

1. McMahan B., Moore E., Ramage D., Hampson S., Arcas B.A. Communication-Efficient Learning of Deep Networks from Decentralized Data // Artificial intelligence and statistics. 2017. pp. 1273–1282.

2. Lwakatare L.E., Raj A., Bosch J., Olsson H.H., Crnkovic I.A Taxonomy of Software Engineering Challenges for Machine Learning Systems: An Empirical Investigation (Eds.: Kruchten P., Fraser S., Coallier F.) // Agile Processes in Software Engineering and Extreme Programming: Proceedings of 20th International Conference. 2019. pp. 227–243.

3. Antonakakis M., April T., Bailey M., Bernhard M., Bursztein E., Cochran J., Durumeric Z., Halderman J.A., Invernizzi L., Kallitsis M., Kumar D., Lever C., Ma Z., Mason J., Menscher D., Seaman C., Thomas K., Zhou Y. Understanding the Mirai Botnet // 26th USENIX Security Symposium (USENIX Security 17). 2017. pp. 1093–1110.

4. Novikova E., Doynikova E., Golubev S. Federated Learning for Intrusion Detection in the Critical Infrastructures: Vertically Partitioned Data Use Case // Algorithms. 2022. vol. 15(4). no. 104. DOI: 10.3390/a15040104.

5. Ludwig H, et al. IBM Federated Learning: an Enterprise Framework White Paper V0.1. ArXiv preprint arXiv:2007.10987. 2020.

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3