A Clustering Strategy for Enhanced FL-Based Intrusion Detection in IoT Networks

Jacopo Talpini, Fabio Sartori, Marco Savi

2023

Abstract

The Internet of Things (IoT) is growing rapidly and so the need of ensuring protection against cybersecurity attacks to IoT devices. In this scenario, Intrusion Detection Systems (IDSs) play a crucial role and data-driven IDSs based on machine learning (ML) have recently attracted more and more interest by the research community. While conventional ML-based IDSs are based on a centralized architecture where IoT devices share their data with a central server for model training, we propose a novel approach that is based on federated learning (FL). However, conventional FL is ineffective in the considered scenario, due to the high statistical heterogeneity of data collected by IoT devices. To overcome this limitation, we propose a three-tier FL-based architecture where IoT devices are clustered together based on their statistical properties. Clustering decisions are taken by means of a novel entropy-based strategy, which helps improve model training performance. We tested our solution on the CIC-ToN-IoT dataset: our clustering strategy increases intrusion detection performance with respect to a conventional FL approach up to +17% in terms of F1-score, along with a significant reduction of the number of training rounds.

Download


Paper Citation


in Harvard Style

Talpini J., Sartori F. and Savi M. (2023). A Clustering Strategy for Enhanced FL-Based Intrusion Detection in IoT Networks. In Proceedings of the 15th International Conference on Agents and Artificial Intelligence - Volume 3: ICAART, ISBN 978-989-758-623-1, pages 152-160. DOI: 10.5220/0011627500003393


in Bibtex Style

@conference{icaart23,
author={Jacopo Talpini and Fabio Sartori and Marco Savi},
title={A Clustering Strategy for Enhanced FL-Based Intrusion Detection in IoT Networks},
booktitle={Proceedings of the 15th International Conference on Agents and Artificial Intelligence - Volume 3: ICAART,},
year={2023},
pages={152-160},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0011627500003393},
isbn={978-989-758-623-1},
}


in EndNote Style

TY - CONF

JO - Proceedings of the 15th International Conference on Agents and Artificial Intelligence - Volume 3: ICAART,
TI - A Clustering Strategy for Enhanced FL-Based Intrusion Detection in IoT Networks
SN - 978-989-758-623-1
AU - Talpini J.
AU - Sartori F.
AU - Savi M.
PY - 2023
SP - 152
EP - 160
DO - 10.5220/0011627500003393