Automated federated learning for intrusion detection of industrial control systems based on evolutionary neural architecture search

Jun-Min Shao,Guo-Qiang Zeng,Kang-Di Lu,Guang-Gang Geng,Jian Weng
DOI: https://doi.org/10.1016/j.cose.2024.103910
IF: 5.105
2024-05-29
Computers & Security
Abstract:In recent years, federated learning has been applied to the security of the Internet of Things and Industrial Control Systems (ICS) due to its advantages in communication cost and privacy preserving. However, the existing deep learning models used in federated learning-based intrusion detection systems (IDS) are manually designed by relying on the extensive experiences of designers and are not applicable in different scenarios flexibly. In this paper, we make the first attempt to automatically design a lightweight federated learning model termed as Fed-GA-CNN-IDS for the IDS issue in ICS by evolutionary neural architecture search (NAS). Five lightweight neural architectures of Convolutional Neural Network (CNN) are considered as the basic blocks to be combined and optimized in federated NAS for ICS intrusion detection. An efficient discrete encoding strategy is developed to describe the combination of five basic lightweight blocks and the specific discrete evolutionary operations under the framework of genetic algorithm (GA) are designed elaborately to guide the evolutionary process of an automated federated learning model. The experimental results on three widely-used intrusion detection datasets in ICSs such as Gas Pipeline, SWaT and WADI, demonstrate that the proposed Fed-GA-CNN-IDS method can obtain more lightweight models and better or at least competitive intrusion detection performance than three state-of-the-art manually-designed federated learning-based IDS methods, two federated NAS methods originally developed for traditional image classification tasks, and four lightweight IDS methods.
computer science, information systems
What problem does this paper attempt to address?