Federated transfer learning-based intrusion detection system in 5G networks

The development of Intrusion Detection Systems (IDS) for the Internet of Things (IoT) and 5G networks is rapidly advancing. This study investigates the application of federated architectures to train detection models while preserving data privacy by eliminating the need for data sharing among device...

Descripción completa

Detalles Bibliográficos
Autores: Bellmunt, Andrea, Otero Calviño, Beatriz|||0000-0002-9194-559X, Rodríguez Luna, Eva|||0000-0001-5904-7039, Masip Bruin, Xavier|||0000-0002-4755-556X
Tipo de recurso: artículo
Fecha de publicación:2025
País:España
Institución:Universitat Politècnica de Catalunya (UPC)
Repositorio:UPCommons. Portal del coneixement obert de la UPC
Idioma:inglés
OAI Identifier:oai:upcommons.upc.edu:2117/451974
Acceso en línea:https://hdl.handle.net/2117/451974
https://dx.doi.org/10.1016/j.eswa.2025.130868
Access Level:acceso abierto
Palabra clave:Intrusion detection system
Federated learning
Federated transfer learning
Convolutional neural network
Internet of things
UNSW-NB15 dataset
Bot-IoT dataset
Weight sharing
Robust aggregation functions
Geometric median
Descripción
Sumario:The development of Intrusion Detection Systems (IDS) for the Internet of Things (IoT) and 5G networks is rapidly advancing. This study investigates the application of federated architectures to train detection models while preserving data privacy by eliminating the need for data sharing among devices. We propose a Federated Transfer Learning (FTL) model tailored for scenarios with unbalanced nodes, enhancing the detection capabilities for unknown attacks compared to conventional Federated Learning (FL) approaches. Utilizing the Bot-IoT dataset as the source domain and the UNSW-NB15 dataset as the target domain, our experiments reveal significant improvements in detection performance. Specifically, nodes characterized by lower proportions of malicious traffic demonstrate up to a 62.614% enhancement in detecting unknown attacks, increasing detection rates from 19.090% to 81.704%. Moreover, our findings indicate that FTL not only improves the identification of unknown threats but also maintains robust performance in detecting both attacks and benign traffic. Notably, the minimum accuracy achieved by the most imbalanced node reaches 0.912, in contrast to 0.741 with standard FL models. These results highlight the potential of FTL to train robust models across distributed nodes while ensuring privacy, thereby contributing to improved security measures in IoT and 5G networks.