<p>In the Cloud, intrusion detection is vital for analyzing and monitoring system activities and network traffic within cloud environments for detecting malicious behavior. Nonetheless, the prevailing detection of cloud intrusion models faces challenges like detecting sophisticated attacks, handling large-scale data, and ensuring low false positives. Accordingly, a new approach, namely, Convolutional Neural Network-based Transfer Learning with Ablation Frigate-Fairy Hybrid Optimization (CNN_TL_AFFHO), is presented for detecting cloud intrusion in Federated Learning (FL). FL protects privacy by storing all local logs on individual client devices and transmitting only model updates to the central server, allowing multiple parties to train a model together without revealing private data. The FL framework has a server and several local models. In the local model, Weitendorf’s Linear (WL) normalization is applied to normalize the log data. This method is applied to standardize log features at local clients. Then, key features are selected utilizing AFFHO, which is designed by combining Superb Fairy-wren Optimization Algorithm (SFOA) and Frigate Ablation Optimization Algorithm (FAOA). N4.1.2.4ext, the Synthetic Minority Over-sampling Technique (SMOTE) is used to achieve data augmentation. The SMOTE is used to augment minority attack samples and address class imbalance. Finally, intrusion detection is performed using CNN_TL, which utilizes hyperparameters derived from the trained Deep Xception convolutional Forward Harmonic Network (DXcov-FH Net). The DXcov-FH Net is developed by DSA, harmonic analysis, and XCovNet. The DXcov-FH Net is used to extract rich hierarchical features for intrusion detection. Lastly, local aggregation and updating at the server are established by averaging. The proposed model enables improved privacy, efficient feature selection for reduced false positives, and scalable deployment across distributed cloud nodes. Here, the Bot-IoT dataset and Network Intrusion Detection dataset are used for the evaluation of the devised model. Moreover, proposed CNN_TL_AFFHO achieves a better accuracy of 97.89%, True Positive Rate (TPR) of 98.48%, True Negative Rate (TNR) of 97.69%, precision of 97.01%, F1-score is 97.74%, and FPR is 2.31%. The devised model provides strong privacy preservation while improving reliability in intrusion detection and reducing false alarm rates. It supports scalable deployment across distributed cloud environments while maintaining robustness against evolving threats. Additionally, it enables efficient learning from heterogeneous and imbalanced data in cloud systems.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Federated learning-driven cloud intrusion detection using transfer learning and ablation frigate-fairy hybrid optimization

  • P. Senthil Raja,
  • J. Sathiamoorthy

摘要

In the Cloud, intrusion detection is vital for analyzing and monitoring system activities and network traffic within cloud environments for detecting malicious behavior. Nonetheless, the prevailing detection of cloud intrusion models faces challenges like detecting sophisticated attacks, handling large-scale data, and ensuring low false positives. Accordingly, a new approach, namely, Convolutional Neural Network-based Transfer Learning with Ablation Frigate-Fairy Hybrid Optimization (CNN_TL_AFFHO), is presented for detecting cloud intrusion in Federated Learning (FL). FL protects privacy by storing all local logs on individual client devices and transmitting only model updates to the central server, allowing multiple parties to train a model together without revealing private data. The FL framework has a server and several local models. In the local model, Weitendorf’s Linear (WL) normalization is applied to normalize the log data. This method is applied to standardize log features at local clients. Then, key features are selected utilizing AFFHO, which is designed by combining Superb Fairy-wren Optimization Algorithm (SFOA) and Frigate Ablation Optimization Algorithm (FAOA). N4.1.2.4ext, the Synthetic Minority Over-sampling Technique (SMOTE) is used to achieve data augmentation. The SMOTE is used to augment minority attack samples and address class imbalance. Finally, intrusion detection is performed using CNN_TL, which utilizes hyperparameters derived from the trained Deep Xception convolutional Forward Harmonic Network (DXcov-FH Net). The DXcov-FH Net is developed by DSA, harmonic analysis, and XCovNet. The DXcov-FH Net is used to extract rich hierarchical features for intrusion detection. Lastly, local aggregation and updating at the server are established by averaging. The proposed model enables improved privacy, efficient feature selection for reduced false positives, and scalable deployment across distributed cloud nodes. Here, the Bot-IoT dataset and Network Intrusion Detection dataset are used for the evaluation of the devised model. Moreover, proposed CNN_TL_AFFHO achieves a better accuracy of 97.89%, True Positive Rate (TPR) of 98.48%, True Negative Rate (TNR) of 97.69%, precision of 97.01%, F1-score is 97.74%, and FPR is 2.31%. The devised model provides strong privacy preservation while improving reliability in intrusion detection and reducing false alarm rates. It supports scalable deployment across distributed cloud environments while maintaining robustness against evolving threats. Additionally, it enables efficient learning from heterogeneous and imbalanced data in cloud systems.