Industry 4.0 has brought numerous advantages, such as increasing productivity through automation. However, it also presents major cybersecurity issues such as cyberattacks affecting industrial processes. Federated Learning (FL) combined with time-series analysis is a promising cyberattack detection mechanism proposed in the literature. However, the fact of having a single point of failure and network bottleneck are critical challenges that need to be tackled. Thus, this article explores the benefits of the Decentralized Federated Learning (DFL) in terms of cyberattack detection and resource consumption. The work presents TemporalFED, a software module for detecting anomalies in industrial environments using FL paradigms and time series. TemporalFED incorporates three components: Time Series Conversion, Feature Engineering, and Time Series Stationary Conversion. To evaluate TemporalFED, it was deployed on Fedstellar, a DFL framework. Then, a pool of experiments measured the detection performance and resource consumption in a chemical gas industrial environment with different time-series configurations, FL paradigms, and topologies. The results showcase the superiority of the configuration utilizing DFL and Semi-Decentralized Federated Learning (SDFL) paradigms, along with a fully connected topology, which achieved the best performance in anomaly detection. Regarding resource consumption, the configuration without feature engineering employed less bandwidth, CPU, and RAM than other configurations.
翻译:工业4.0带来了诸多优势,例如通过自动化提升生产力,但也引发了重大网络安全问题,如影响工业流程的网络攻击。联邦学习(FL)与时序分析的结合是文献中提出的极具前景的网络攻击检测机制。然而,单点故障和网络瓶颈是亟需解决的关键挑战。为此,本文探讨了去中心化联邦学习(DFL)在网络攻击检测与资源消耗方面的优势。研究提出了TemporalFED——一种利用联邦学习范式与时间序列检测工业环境异常的软件模块。TemporalFED包含三个组件:时间序列转换、特征工程及时间序列平稳化转换。为评估TemporalFED,将其部署于去中心化联邦学习框架Fedstellar。随后,通过一组实验在化工气体工业环境中测量了不同时间序列配置、联邦学习范式和拓扑结构下的检测性能与资源消耗。结果表明,采用DFL和半去中心化联邦学习(SDFL)范式并配合全连接拓扑的配置取得了最佳异常检测性能。在资源消耗方面,未采用特征工程的配置相较于其他配置占用了更少的带宽、CPU和内存。