paper-with-me

홈 › Papers

A Cyber Threat Intelligence Sharing Scheme based on Federated Learning for Network Intrusion Detection

2021-11-04 · Mohanad Sarhan, Siamak Layeghy, Nour Moustafa, Marius Portmann

The uses of Machine Learning (ML) in detection of network attacks have been effective when designed and evaluated in a single organisation. However, it has been very challenging to design an ML-based detection system by utilising heterogeneous network data samples originating from several sources. This is mainly due to privacy concerns and the lack of a universal format of datasets. In this paper, we propose a collaborative federated learning scheme to address these issues. The proposed framework allows multiple organisations to join forces in the design, training, and evaluation of a robust ML-based network intrusion detection system. The threat intelligence scheme utilises two critical aspects for its application; the availability of network data traffic in a common format to allow for the extraction of meaningful patterns across data sources. Secondly, the adoption of a federated learning mechanism to avoid the necessity of sharing sensitive users' information between organisations. As a result, each organisation benefits from other organisations cyber threat intelligence while maintaining the privacy of its data internally. The model is trained locally and only the updated weights are shared with the remaining participants in the federated averaging process. The framework has been designed and evaluated in this paper by using two key datasets in a NetFlow format known as NF-UNSW-NB15-v2 and NF-BoT-IoT-v2. Two other common scenarios are considered in the evaluation process; a centralised training method where the local data samples are shared with other organisations and a localised training method where no threat intelligence is shared. The results demonstrate the efficiency and effectiveness of the proposed framework by designing a universal ML model effectively classifying benign and intrusive traffic originating from multiple organisations without the need for local data exchange.

📄 PDF Abstract BibTeX arXiv:2111.02791

Code (0)

등록된 구현이 없습니다.

Tasks

Federated LearningIntrusion DetectionNetwork Intrusion Detection

Similar Papers 제목 키워드 기반

Orchestrating Collaborative Cybersecurity: A Secure Framework for Distributed Privacy-Preserving Threat Intelligence Sharing

2022-09-06 · Juan R. Trocoso-Pastoriza, Alain Mermoud, Romain Bouyé, Francesco Marino 외

Cyber Threat Intelligence (CTI) sharing is an important activity to reduce information asymmetries between attackers and defenders. However, this activity presents challenges due to the tension between data sharing and c…

Privacy Preserving

Cognitive Threat Intelligence and Explainable Federated Security Analytics for distributed Infrastructure Systems

2026-06-04 · Md. Arifur Rahman, B. M. Taslimul Haque, Md. Iqbal Hossan, Md. Serajul Kabir Chowdhury Rubel arxiv

The increasing adoption of distributed infrastructure systems, cloud computing, Internet of Things (IoT) technologies, and edge-based architectures has significantly expanded the cybersecurity attack surface and introduc…

Intrusion DetectionFederated Learning

Byzantine-Robust Federated Learning Framework with Post-Quantum Secure Aggregation for Real-Time Threat Intelligence Sharing in Critical IoT Infrastructure

2026-01-03 · Milad Rahmati, Nima Rahmati arxiv

The proliferation of Internet of Things devices in critical infrastructure has created unprecedented cybersecurity challenges, necessitating collaborative threat detection mechanisms that preserve data privacy while main…

Intrusion DetectionFederated Learning

Federated Graph AGI for Cross-Border Insider Threat Intelligence in Government Financial Schemes

2026-02-18 · Srikumar Nayak, James Walmesley arxiv

Cross-border insider threats pose a critical challenge to government financial schemes, particularly when dealing with distributed, privacy-sensitive data across multiple jurisdictions. Existing approaches face fundament…

Federated LearningCausal InferenceGraph Learning

Adaptive Cybersecurity Architecture for Digital Product Ecosystems Using Agentic AI

2025-09-25 · Oluwakemi T. Olayinka, Sumeet Jeswani, Divine Iloh arxiv

Traditional static cybersecurity models often struggle with scalability, real-time detection, and contextual responsiveness in the current digital product ecosystems which include cloud services, application programming …

Anomaly DetectionDecision Making