<p>With integration of IoT technologies, the power grid is getting more connected with external networks. This exposes its <i>supervisory control and data acquisition</i> (SCADA) system, the enabler component of smart grids, to severe cyberattacks. To secure smart grids, early identification of anomalies and threats is of utmost importance. Machine learning based <i>intrusion detection systems</i> (IDS) have shown reliable and efficient performance. Most of the proposed IDS are based on centralized learning where data is collected from remote smart devices and transferred to central server for training. Such centralized-based IDS brought up data security and user privacy concerns. To preserve user privacy, <i>federated learning</i> (FL)-based IDS have recently been suggested. FL keeps training data at the client’s side and distributes an aggregated global model which will be trained locally. However, distributed datasets are usually <i>non Independently and Identically Distributed</i> (non-IID) which can decrease the performance of machine learning models. In this paper, we investigate the efficiency and performance of federated-based IDS under non-IID data settings. We, in this study, investigate a different case of label skew where class distributions are significantly skewed within the same client (as when attacks are recently identified and hence only found in the test dataset). Experimental results show that the efficiency of federated-based IDS is reduced significantly when compared to regular scenarios where attacks in the training and testing datasets are the same. The findings also suggest that missing classes not only affect the performance of the related client but also propagate to other clients.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Investigating the Efficiency of a Federated Learning-Based Intrusion Detection System for Smart Grid

  • Najet Hamdi

摘要

With integration of IoT technologies, the power grid is getting more connected with external networks. This exposes its supervisory control and data acquisition (SCADA) system, the enabler component of smart grids, to severe cyberattacks. To secure smart grids, early identification of anomalies and threats is of utmost importance. Machine learning based intrusion detection systems (IDS) have shown reliable and efficient performance. Most of the proposed IDS are based on centralized learning where data is collected from remote smart devices and transferred to central server for training. Such centralized-based IDS brought up data security and user privacy concerns. To preserve user privacy, federated learning (FL)-based IDS have recently been suggested. FL keeps training data at the client’s side and distributes an aggregated global model which will be trained locally. However, distributed datasets are usually non Independently and Identically Distributed (non-IID) which can decrease the performance of machine learning models. In this paper, we investigate the efficiency and performance of federated-based IDS under non-IID data settings. We, in this study, investigate a different case of label skew where class distributions are significantly skewed within the same client (as when attacks are recently identified and hence only found in the test dataset). Experimental results show that the efficiency of federated-based IDS is reduced significantly when compared to regular scenarios where attacks in the training and testing datasets are the same. The findings also suggest that missing classes not only affect the performance of the related client but also propagate to other clients.