The evolution of cybersecurity is undoubtedly associated and intertwined with the development and improvement of artificial intelligence (AI). As a key tool for realizing more cybersecure ecosystems, Intrusion Detection Systems (IDSs) have evolved tremendously in recent years by integrating machine learning (ML) techniques for the detection of increasingly sophisticated cybersecurity attacks hidden in big data. However, these approaches have traditionally been based on centralized learning architectures, in which data from end nodes are shared with data centers for analysis. Recently, the application of federated learning (FL) in this context has attracted great interest to come up with collaborative intrusion detection approaches where data does not need to be shared. Due to the recent rise of this field, this work presents a complete, contemporary taxonomy for FL-enabled IDS approaches that stems from a comprehensive survey of the literature in the time span from 2018 to 2022. Precisely, our discussion includes an analysis of the main ML models, datasets, aggregation functions, as well as implementation libraries, which are employed by the proposed FL-enabled IDS approaches. On top of everything else, we provide a critical view of the current state of the research around this topic, and describe the main challenges and future directions based on the analysis of the literature and our own experience in this area.
翻译:网络安全的演进无疑与人工智能(AI)的发展和完善紧密相连、相互交织。作为实现更安全网络生态系统的关键工具,入侵检测系统(IDSs)近年来通过集成机器学习(ML)技术,在检测隐藏在大量数据中的日益复杂的网络安全攻击方面取得了巨大进展。然而,这些方法传统上基于集中式学习架构,其中终端节点的数据需要共享至数据中心进行分析。近年来,联邦学习(FL)在此领域的应用引起了广泛关注,旨在提出无需数据共享的协作入侵检测方法。鉴于该领域的快速兴起,本文基于对2018年至2022年间文献的全面调研,提出了一套完整且具有时代性的针对FL赋能IDS方法的分类体系。具体而言,我们的讨论涵盖了所提出的FL赋能IDS方法中采用的主要机器学习模型、数据集、聚合函数以及实现库。尤为重要的是,我们对这一主题的当前研究现状提供了批判性视角,并结合文献分析及本领域经验,阐述了主要挑战和未来发展方向。