











Abstract:Machine Learning (ML) techniques have shown strong potential for network traffic analysis; however, their effectiveness depends on access to representative, up-to-date datasets, which is limited in cybersecurity due to privacy and data-sharing restrictions. To address this challenge, Federated Learning (FL) has recently emerged as a novel paradigm that enables collaborative training of ML models across multiple clients while ensuring that sensitive data remains local. Nevertheless, Federated Averaging (FedAvg), the canonical FL algorithm, has shown poor convergence in heterogeneous environments characterised by non-independent and identically distributed (i.i.d.) data distributions and unbalanced dataset sizes across clients, conditions frequently observed in cybersecurity contexts. To overcome these challenges, several alternative FL algorithms have been developed, yet their applicability to network intrusion detection remains insufficiently explored. This study systematically evaluates a range of FL algorithms in the context of network intrusion detection for DDoS attacks. Using a dataset of recent network attacks, the evaluation considers detection performance, training time, and communication overhead under non-i.i.d. settings, providing practical insights into the selection of FL solutions for network intrusion detection.
From: Roberto Doriguzzi Corin Dr. [view email]
[v1]
Mon, 22 Sep 2025 14:25:32 UTC (148 KB)
[v2]
Fri, 11 Sep 2026 14:35:14 UTC (140 KB)
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。