A distributed Internet of Things intrusion detection method and system

By adopting federated learning distributed intrusion detection methods in industrial IoT systems, the security challenges of IIoT system resource constraints and data sensitivity are solved, and high-performance intrusion detection and protection are achieved.

CN114548222BActive Publication Date: 2025-05-02CHENGDU YALIAN TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210054882.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-18
Publication Date
2025-05-02
Estimated Expiration
2042-01-18

AI Technical Summary

Technical Problem

Industrial Internet of Things (IIoT) systems face severe security challenges, resource-constrained sensor systems are vulnerable to cyber attacks, and the sensitivity and high value of IIoT data hinder data sharing of high-performance intrusion detection models.

Method used

A distributed IoT intrusion detection method based on federated learning is adopted, and a lightweight machine learning model is initialized through a secure cloud server, and local classification training is performed on the client. FedAvg is used for model aggregation, and a weighted voting algorithm is proposed to generate the final output.

Benefits of technology

Without violating data privacy, high-performance intrusion detection is achieved, solving the problems of IIoT system resource limitation and data sensitivity, and improving detection performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114548222B_ABST
    Figure CN114548222B_ABST
Patent Text Reader

Abstract

The present invention belongs to the technical field of intrusion detection of the Internet of Things, and discloses a distributed intrusion detection method and system of the Internet of Things. A secure cloud server initializes a lightweight machine learning model using public data of an IDS, and the server distributes public data and models to all clients; in instance-based transfer learning, each client uses the model as a basic classifier and performs local classification training; the client sends the updated classifier back to the server; when the server receives all updates from the client, FedAvg is used for model aggregation, and a weighted voting algorithm for generating the final output is proposed; the server distributes the final output back to the client, and the client starts a localized intrusion detection system IDS according to the updated model. The present invention uses a rank aggregation algorithm to improve the FedAvg method, improves detection performance, and solves the key problem of using non-independent and identically distributed data to train local models in federated learning.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of Internet of Things intrusion detection, and in particular to a distributed Internet of Things intrusion detection method and system. Background Art

[0002] Currently, Industrial Internet of Things (IIoT) systems face severe security challenges, mainly because their resource-constrained sensor systems are vulnerable to attacks from the network and intrusions from botnets (such as Mirai Botnet). The sensitivity, privacy, and high-value nature of IIoT data also hinder the sharing of internal data for training high-performance intrusion detection machine learning models. Therefore, it is urgent to design a new distributed IoT intrusion detection method and system to make up for the shortcomings of existing technologies.

[0003] Through the above analysis, the problems and defects of the prior art are as follows:

[0004] (1) Existing resource-constrained sensor systems are vulnerable to network attacks and intrusions from botnets (e.g., Mirai Botnet).

[0005] (2) The sensitivity, privacy, and high-value nature of existing IIoT data hinders the sharing of internal data for training high-performance intrusion detection machine learning models.

[0006] The difficulty of solving the above problems and defects is:

[0007] Industrial Internet of Things (IIoT) systems are facing severe security challenges as they connect low-cost and resource-limited sensors that may be vulnerable to increasing intrusion attacks such as the Mirai botnet. The sensitivity, privacy, and high value of IIoT data also hinder data sharing for training high-performance intrusion detection models.

[0008] The significance of solving the above problems and defects is:

[0009] This patent's instance-based transfer learning ensures the effect of local training, and also proposes a ranking method for privatized model aggregation and a weighted voting method for the final model output, which can achieve intrusion detection without violating data privacy and maintaining device independence. Summary of the invention

[0010] In view of the problems existing in the prior art, the present invention provides a distributed Internet of Things intrusion detection method and system, and more particularly, relates to a distributed Internet of Things intrusion detection method and system based on federated learning.

[0011] The present invention is implemented as follows: a distributed Internet of Things intrusion detection method, the distributed Internet of Things intrusion detection method comprising the following steps:

[0012] Step 1: The secure cloud server initializes a lightweight machine learning model using the public data of the IDS. The secure cloud server distributes the public data and model to all clients.

[0013] Step 2: In instance-based transfer learning, each client uses the model as a basic classifier and constructs a local classification training algorithm to perform local classification training;

[0014] Step 3, after completing the entire localized training process, the client sends the updated classifier back to the secure cloud server instead of its transmission learning strategy;

[0015] Step 4: When the server receives all updates from the client, it uses FedAvg to aggregate the model and proposes a weighted voting algorithm to generate the final output;

[0016] Step 5: The security cloud server distributes the final output back to the client, and the client starts the localized intrusion detection system IDS based on the updated model.

[0017] Furthermore, in step 2, instances from a public dataset are transmitted as source domains, and each client sets its own instance reuse strategy to adapt to the detection task, but all clients share the same base classifier and follow instance-based transfer learning.

[0018] Furthermore, the local classification training algorithm in step 2 includes:

[0019] Use data from the public to assist in training, from target instances and examples Initialize the instance weight factor, x is the feature, y is the true label; use D S and D T To train and return the predicted label as H k , weighted error rate ε k for:

[0020]

[0021]

[0022] Among them, β S and β T Update after obtaining the predicted label; β T is the same as ε k The weight factor of this iteration is related to S is the static factor of the source domain.

[0023]

[0024]

[0025] According to the results H k and the iterative error rate ε k , the weight factor ω for the training data S and ω T Update; start the next iteration of the training process, with β T Returns the predicted label as a weight factor.

[0026]

[0027]

[0028] Furthermore, the training strategy includes:

[0029] Preparation:

[0030] Public Dataset D S , private dataset Test dataset D test , initialize model f0;

[0031] Goal: predict label pred;

[0032] (1) Local training algorithm:

[0033] 1) Initialize the source dataset D S The sample weight ω S and the target dataset D T The sample weight ω T ;

[0034] 2) for k = 1, 2, 3...K execute:

[0035] 3) Use D S and Training model f k Get the sample weight ω S and ω T , returns the predicted value p k ;

[0036] 4) Use formula (2) to calculate the error rate ε k and calculated using formula (3) and formula (4)

[0037] 5) Update the sample weight ω according to formula (5) and formula (6) S and ω T ;

[0038] 6) end for;

[0039] 7) Integration results k and

[0040] 8) Return the updated model f i .

[0041] (2) Federal Averaging Algorithm:

[0042] 1) Get the updated model f i , i=1,2,3...r;

[0043] 2) Return the overall model f0.

[0044] (3) Weighted voting method

[0045] 1) Sorting integration:

[0046] 2) Use the updated model f i According to different attack A j , a binary data set with j=1, 2, 3, ..., p;

[0047] 3) Aggregate attack classifier F on j .

[0048] (4) Weighted voting:

[0049] 1) Use formula (7) to calculate the MMD distance MMD[D test , A j ] and use formula (8) to calculate the weight wts[D test , A j ], j = 1, 2, 3, ... p;

[0050] 2) Set weights for attack classification F j And generate the predicted label D test ;

[0051] 3) Return pred.

[0052] Furthermore, the weighted voting method in step 4 includes:

[0053] The model training part consists of two steps: cloud model initialization and localized model training; the secure cloud platform initializes the model based on public data and sends the model to the client; the client uses the data to train the model; after the secure cloud platform receives all updates from the client, the secure cloud executes the algorithm and averages all aggregated parameters; the adaptive boosting algorithm AdaBoost based on the decision tree as the basic classifier is used to obtain the final prediction result by combining the outputs; wherein, the adaptive boosting algorithm AdaBoost is an enhancement algorithm that uses multiple machine learning models to implement a basic estimator.

[0054] The aggregation method is implemented using public data, the accuracy score is evaluated, and all base estimators are ranked; the estimators with high strength are selected for ranking and a new AdaBoost classifier is formed; the secure cloud server returns the updated model to the client for another iteration.

[0055] Further, a weighted voting algorithm is used to generate the final output; the server creates a binary dataset Y for each attack from the public data i (i=1, 2, ...p); train the classifier with different data; the server evaluates the difference in feature distribution between the test data and the binary attack dataset as the weight of the vote; calculates the statistical distance between the two datasets in the kernel Hilbert space using the maximum mean difference (MMD):

[0056]

[0057] wts(X,Y i )=-log(2*MMD[F,X,Y i ])(i=1,2,…p) (8)

[0058] in, represents the upper limit of the expected difference between the two datasets; f(·) is the mapping function for the feature space; M and n are the number of samples in the source domain and the target domain; MMD is used as a loss function to quantify the difference between the transmitted source domain and the target domain; the voting weight wts(X, Y) is the negative logarithm of the corresponding MMD distance.

[0059] Another object of the present invention is to provide a distributed Internet of Things intrusion detection system that applies the distributed Internet of Things intrusion detection method, and the distributed Internet of Things intrusion detection system includes a secure cloud server and a client.

[0060] The secure cloud server has a large amount of public data and high-performance hardware for model initialization and aggregation; the server is used to connect and manage all IoT clients, distribute initialized models to clients, and collect updates from clients and process model aggregation;

[0061] The clients are various independent IoT endpoints connected to a secure cloud, and each client is not allowed to share information with other IoT endpoints; the machine learning model in the secure cloud is a lightweight model suitable for low-cost IoT devices.

[0062] Another object of the present invention is to provide a computer device, the computer device comprising a memory and a processor, the memory storing a computer program, and when the computer program is executed by the processor, the processor performs the following steps:

[0063] The secure cloud server uses the public data of the IDS to initialize a lightweight machine learning model, and the server distributes the public data and model to all clients. In instance-based transfer learning, each client uses the model as a basic classifier and builds a local classification training algorithm for local classification training.

[0064] After completing the entire localized training process, the client sends the updated classifier back to the server instead of its transfer learning strategy; when the secure cloud server receives all updates from the client, it uses FedAvg for model aggregation and proposes a weighted voting algorithm to generate the final output; the secure cloud server distributes the final output back to the client, and the client starts the localized intrusion detection system IDS based on the updated model.

[0065] Another object of the present invention is to provide a computer-readable storage medium storing a computer program, wherein when the computer program is executed by a processor, the processor executes the following steps:

[0066] The secure cloud server uses the public data of the IDS to initialize a lightweight machine learning model, and the server distributes the public data and model to all clients. In instance-based transfer learning, each client uses the model as a basic classifier and builds a local classification training algorithm for local classification training.

[0067] After completing the entire localized training process, the client sends the updated classifier back to the secure cloud server instead of its transfer learning strategy; when the server receives all updates from the client, it uses FedAvg for model aggregation and proposes a weighted voting algorithm to generate the final output; the secure cloud server distributes the final output back to the client, and the client starts the localized intrusion detection system IDS based on the updated model.

[0068] Another object of the present invention is to provide an information data processing terminal, which is used to implement the distributed Internet of Things intrusion detection system.

[0069] Combining all the above technical solutions, the advantages and positive effects of the present invention are as follows: The distributed Internet of Things intrusion detection method provided by the present invention specifically relates to a machine learning model training and network intrusion detection framework based on federated learning, which is suitable for network intrusion detection and protection based on data privacy protection in the future industrial Internet of Things. The present invention adopts a rank aggregation algorithm of a weighted voting method to further improve the FedAvg method, improve the detection performance, and solve the key problem of using non-independent and identically distributed (IID) data to train local models in federated learning.

[0070] In order to evaluate the performance of the model, the present invention established a physical test platform to simulate the IoT network intrusion detection system. The present invention selected two datasets, CIC-IDS20171 and CIC-IDS20182, as attack databases. In the experiment, the present invention implemented the federated learning model training process on multiple Raspberry Pi chips to simulate the industrial IoT setting.

[0071] The present invention simulates the scenario of customers connecting from different industrial environments, such as smart factories and smart grids supported by microcontrollers. The intrusion samples collected locally are different due to different hardware and operating systems. Here, the present invention uses 5 Raspberry Pis (3 Pi3BTM and 2 Pi4BTM) to present different IIoT hardware. All Raspberry Pis use Cortex-ATM series microprocessors, the present invention limits the size of available memory for localized training process to 100MB. The present invention uses two Debian-based and three Archc-based Linux operating systems. The high-performance desktop runs Ubuntu Linux 20.04 and uses CoreTMi9-9900KCPU@3.60GHz and 64GB memory, which can act as a central server to connect all clients and perform model aggregation.

[0072] The present invention simulates the scenario where the localized dataset maintains privacy and the dataset size is limited. At the same time, these datasets are likely to be incomplete and only contain specific attacks. The present invention uses the CIC-IDS network traffic dataset, a real network dataset collected when the intrusion occurs. The CIC-IDS dataset records data packets with 79 features and is marked with a specific type. The present invention selects the three most common attack types in 2017 (DDoS, Botnet, and PortScan) and four attack types in 2018 (DDoS, Botnet, Brute Force, and Infiltration) for model training and evaluation; the central server and 5 client machines have different data configurations, among which the public data (D S ) and 5 client datasets with non-iid settings (D T ) data configuration. The present invention sets 5 different mini datasets as the target domain for local storage; the source domain (D S ) consists of the CIC-IDS2017 dataset. When tested on a hardware test system, the federated learning strategy of the present invention achieved an accuracy of 91.57%. BRIEF DESCRIPTION OF THE DRAWINGS

[0073] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments of the present invention. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0074] Figure 1 It is a flow chart of a distributed Internet of Things intrusion detection method provided by an embodiment of the present invention.

[0075] Figure 2 It is a schematic diagram of a distributed Internet of Things intrusion detection method provided by an embodiment of the present invention.

[0076] Figure 3 It is a structural block diagram of a distributed Internet of Things intrusion detection system provided by an embodiment of the present invention;

[0077] Figure 4 It is a flowchart of the algorithm training provided by an embodiment of the present invention.

[0078] Figure 5 When tested on a hardware testing system provided by an embodiment of the present invention, the federated learning strategy of the present invention achieved an accuracy rate of 91.57%. DETAILED DESCRIPTION

[0079] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0080] In view of the problems existing in the prior art, the present invention provides a distributed Internet of Things intrusion detection method and system, which is described in detail below in conjunction with the accompanying drawings.

[0081] like Figure 1 As shown, the distributed Internet of Things intrusion detection method provided by the embodiment of the present invention includes the following steps:

[0082] S101, the secure cloud server initializes a lightweight machine learning model using the public data of the IDS, and the secure cloud server distributes the public data and model to all clients;

[0083] S102, in instance-based transfer learning, each client uses the model as a basic classifier and performs local classification training by constructing a local classification training algorithm;

[0084] S103, after completing the entire localized training process, the client sends the updated classifier back to the secure cloud server instead of its transmission learning strategy;

[0085] S104, when the secure cloud server receives all updates from the client, it uses FedAvg to perform model aggregation and proposes a weighted voting algorithm to generate the final output;

[0086] S105, the security cloud server distributes the final output back to the client, and the client starts the localized intrusion detection system IDS according to the updated model.

[0087] The principle diagram of the distributed Internet of Things intrusion detection method provided by the embodiment of the present invention is as follows Figure 2 shown.

[0088] like Figure 3 As shown, the distributed Internet of Things intrusion detection system provided by the embodiment of the present invention includes a secure cloud server and a client.

[0089] The secure cloud server has a large amount of public data and high-performance hardware for model initialization and aggregation; the secure cloud server is used to connect and manage all IoT clients, distribute initialized models to clients, and collect updates from clients and process model aggregation;

[0090] The clients are various independent IoT endpoints connected to a secure cloud, and each client is not allowed to share information with other IoT endpoints; the machine learning model in the secure cloud is a lightweight model suitable for low-cost IoT devices.

[0091] The technical solution of the present invention is further described below in conjunction with specific embodiments.

[0092] The present invention proposes a machine learning model training and network intrusion detection framework based on federated learning, which is suitable for network intrusion detection and protection based on data privacy protection in the future industrial Internet of Things.

[0093] The present invention aims to solve the key problem of using non-independent and identically distributed (IID) data to train local models in federated learning. The present invention proposes a rank aggregation algorithm using a weighted voting method, further improves the FedAvg method, and improves the detection performance.

[0094] 1. System Framework

[0095] Figure 3It is shown that the architecture consists of two main components: secure cloud server and clients. The secure cloud server has a large amount of public data and high-performance hardware for model initialization and aggregation. The server has three tasks: (1) it connects and manages all IoT clients; (2) it distributes initialized models to clients; (3) it collects updates from clients and processes model aggregation. Clients are various independent IoT endpoints connected to the secure cloud. Each client is not allowed to share information with other IoT endpoints. The machine learning model in the secure cloud should be a lightweight model that is suitable for low-cost IoT devices.

[0096] The training process has six main steps, such as Figure 3 As shown. The details of each step are as follows: (1) The security cloud server initializes a lightweight machine learning model using the public data of the IDS; (2) The server distributes the public data and model to all clients; (3) In instance-based transfer learning, each client uses this model as the base classifier. It transfers instances from the public dataset as the source domain to overcome the class imbalance or limited training data problems. This method is equivalent to the binary transfer learning algorithm TrAdaBoost, but can be extended to multi-class classification. Each client can set its own instance reuse strategy to adapt to the detection task, but all clients share the same base classifier and follow instance-based transfer learning; (4) After completing the entire localized training process, the client sends the updated classifier back to the server instead of its transfer learning strategy; (5) When the server receives all updates from the clients, it can process model aggregation. The present invention adopts FedAvg for model aggregation and proposes a weighted voting algorithm to generate the final output; (6) The server distributes the final output back to the client, and the client can start the localized intrusion detection system (IDS) based on the updated model.

[0097] 2. Weighted voting method

[0098] The framework uses federated learning to solve data privacy issues. The model training part consists of two key steps: cloud model initialization and localized model training. The secure cloud platform initializes the model based on public data and sends the model to the client. The client uses its data to train the model. After the secure cloud platform receives all updates from the client, the secure cloud can execute the algorithm and average all aggregated parameters. Here, the present invention uses the adaptive boosting algorithm AdaBoost based on the decision tree as the basic classifier, which is an enhancement algorithm that uses multiple machine learning models to implement the basic estimator, and obtains the final prediction result by combining their outputs.

[0099] Considering that the AdaBoost classifier is composed of multiple different base estimators, the present invention implements another aggregation method using public data, evaluates the accuracy score using public data, and ranks all these base estimators. The method selects the estimator with high strength to rank and form a new AdaBoost classifier. The secure cloud server can return the updated model to the client for another iteration.

[0100] In order to make full use of the models returned by all clients in federated learning, this paper proposes a weighted voting algorithm to generate the final output, whose structure is as follows: Figure 4 First, the server creates a binary dataset Y for each attack from the public data i (i=1, 2, ...p). Then the classifier is trained accordingly with different data. Finally, the server evaluates the difference in feature distribution between the test data and the binary attack dataset as the weight of the vote. Here, the present invention uses the maximum mean difference (MMD) to calculate the statistical distance between the two datasets in the kernel Hilbert space:

[0101]

[0102] wts(X,Y i )=-log(2*MMD[F,X,Y i ])(i=1,2,…p) (2)

[0103] in, represents the upper limit of the expected difference between the two datasets. f(·) is a mapping function for the feature space. M and n are the number of samples in the source domain and the target domain. MMD is used as a loss function to quantify the difference between the source domain and the target domain. The voting weight wts(X, Y) is the negative logarithm of the corresponding MMD distance.

[0104] 3. Local classification training algorithm

[0105] Federated learning implements a privacy-preserving machine learning framework, which means that the secure cloud server does not need and cannot access the data stored locally. However, this local model may not perform well because the distribution between public and private data for non-IID federated learning may be different. The size of the local preprocessed and labeled dataset may also be limited and cannot support the training process. Therefore, it is necessary to use data from the public to assist in training. The following algorithm is used in this method:

[0106] The main steps are as follows: First, from the target instance and examples Initialize the instance weight factor, x is the feature, y is the true label. Then use D S and DT To train and return the predicted label as H k . Weighted error rate ε k for:

[0107]

[0108]

[0109] β S and β T Can be updated after obtaining the predicted label. T is the same as ε k The weight factor of this iteration is related to S is the static factor of the source domain.

[0110]

[0111]

[0112] According to the results H k and the iterative error rate ε k , the weight factor ω of the training data can be S and ω T Finally, the next iteration of the training process begins with β T Returns the predicted label as a weight factor.

[0113]

[0114]

[0115] 4. Training strategy:

[0116] Preparation:

[0117] Public Dataset D S , private dataset Test dataset D test , initialize the model f0

[0118] Goal: predict label pred

[0119] 1. Local training algorithm:

[0120] 2. Initialize the source dataset D S The sample weight ω S and the target dataset D T The sample weight ω T

[0121] 3. for k = 1, 2, 3...K execute:

[0122] 4. Use DS and Training model f k Get the sample weight ω S and ω T , returns the predicted value p k

[0123] 5. Use formula (4) to calculate the error rate ε k and calculated using formula (5) and formula (6)

[0124] 6. Update the sample weight ω according to formula (7) and formula (8) S and ω T

[0125] 7. end for

[0126] 8. Integrate the results k and

[0127] 9. Return the updated model f i 10.

[0129] 11. Federal Average Algorithm:

[0130] 12. Get the updated model f i , i=1,2,3...r

[0131] 13. Return the overall model f0 14.

[0133] 15. Weighted Voting Method

[0134] 16. Sorting Integration:

[0135] 17. Use updated model f i According to different attack A j , j = 1, 2, 3...p binary data set

[0136] 18. Aggregate attack classifier F on j 19.

[0138] 20. Weighted voting:

[0139] 21. Use formula (1) to calculate the MMD distance MMD[D test , A j ] and use formula (2) to calculate the weight wts[D test , A j ], j = 1, 2, 3 ... p

[0140] 22. Set weights for attack classification F j And generate the predicted label D test

[0141] 23. Return pred

[0142] Flowchart as Figure 2 shown.

[0143] In order to evaluate the performance of the model, the present invention established a physical test platform to simulate the IoT network intrusion detection system. The present invention selected two datasets, CIC-IDS20171 and CIC-IDS20182, as attack databases. In the experiment, the present invention implemented the federated learning model training process on multiple Raspberry Pi chips to simulate the industrial IoT setting.

[0144] The present invention simulates the scenario of customers connecting from different industrial environments, such as smart factories and smart grids supported by microcontrollers. The intrusion samples collected locally are different due to different hardware and operating systems. Here, the present invention uses 5 Raspberry Pis (3 Pi3BTM and 2 Pi4BTM) to present different IIoT hardware. All Raspberry Pis use Cortex-ATM series microprocessors, the present invention limits the size of available memory for localized training process to 100MB. The present invention uses two Debian-based and three Archc-based Linux operating systems. The high-performance desktop runs Ubuntu Linux 20.04 and uses CoreTMi9-9900KCPU@3.60GHz and 64GB memory, which can act as a central server to connect all clients and perform model aggregation.

[0145] The present invention simulates the scenario where the localized dataset maintains privacy and the dataset size is limited. At the same time, these datasets are likely to be incomplete and only contain specific attacks. The present invention uses the CIC-IDS network traffic dataset, a real network dataset collected from when the intrusion occurs. The CIC-IDS dataset records data packets with 79 features and is marked with a specific type. The present invention selected the three most common attack types in 2017 (DDoS, Botnet, and PortScan) and four attack types in 2018 (DDoS, Botnet, Brute Force, and Infiltration) for model training and evaluation. The central server and 5 client machines have different data configurations, among which the public data (D S ) and 5 client datasets with non-iid settings (D T ) data configuration. The present invention sets 5 different mini datasets as the target domains for local storage. S) consists of the CIC-IDS2017 dataset.

[0146] like Figure 5 As shown, when tested on a hardware test system, the federated learning strategy of the present invention achieved an accuracy of 91.57%.

[0147] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When the use is implemented in whole or in part in the form of a computer program product, the computer program product includes one or more computer instructions. When the computer program instructions are loaded or executed on a computer, the process or function described in the embodiment of the present invention is generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from one website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL) or wireless (e.g., infrared, wireless, microwave, etc.) mode) to another website site, computer, server or data center. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state hard disk Solid State Disk (SSD)), etc.

[0148] The above description is only a specific implementation mode of the present invention, but the protection scope of the present invention is not limited thereto. Any modifications, equivalent substitutions and improvements made by any technician familiar with the technical field within the technical scope disclosed by the present invention and within the spirit and principle of the present invention should be covered by the protection scope of the present invention.

Claims

1. A distributed Internet of Things intrusion detection method, characterized in that: The distributed Internet of Things intrusion detection method comprises the following steps: Step 1: The secure cloud server initializes a lightweight machine learning model using the public data of the IDS and distributes the public data and model to all clients; Step 2: Each client uses the model as a basic classifier to construct a local classification training algorithm for local classification training; Step 3: After completing the entire localized training process, the client sends the updated classifier back to the secure cloud server; Step 4: When the secure cloud server receives all updates from the client, it uses FedAvg to aggregate the model and generate the weighted voting algorithm for the final output; Step 5: The security cloud server distributes the final output back to the client, and the client starts the localized intrusion detection system IDS based on the updated model; The weighted voting method in step 4 includes: The model training part consists of two steps: cloud model initialization and localized model training; the secure cloud platform initializes the model based on public data and sends the model to the client; the client uses the data to train the model; after the secure cloud platform receives all updates from the client, the secure cloud executes the algorithm and averages all aggregated parameters; the adaptive boosting algorithm AdaBoost based on the decision tree as the basic classifier is used to obtain the final prediction result by combining the output; wherein, the adaptive boosting algorithm AdaBoost is an enhancement algorithm that uses multiple machine learning models to implement the basic estimator; Implement aggregation methods using public data, evaluate accuracy scores, and rank all base estimators; select estimators with high strength for ranking and form new AdaBoost classifiers; secure cloud server returns the updated model to the client for another iteration; The final output is generated using a weighted voting algorithm; the server creates a binary dataset Y for each attack from the public data i (i=1, 2, ...p); train the classifier with different data; the server evaluates the difference in feature distribution between the test data and the binary attack dataset as the weight of the vote; calculates the statistical distance between the two datasets in the kernel Hilbert space using the maximum mean difference (MMD): wts(X,Y i )=-log(2*MMD[F,X,Y i ])(i=1,2,…p) (8) in, represents the upper limit of the expected difference between the two datasets; f(·) is the mapping function for the feature space; M and n are the number of samples in the source domain and the target domain; MMD is used as a loss function to quantify the difference between the transmission source domain and the target domain; the voting weight wts(X,Y) is the negative logarithm of the corresponding MMD distance.

2. The distributed Internet of Things intrusion detection method according to claim 1, characterized in that: In the step 2, instances from a public dataset are transmitted as source domains, and each client sets its own instance reuse strategy to adapt to the detection task, but all clients share the same base classifier and follow instance-based transfer learning.

3. The distributed Internet of Things intrusion detection method according to claim 1, characterized in that: The local classification training algorithm in step 2 includes: Use data from the public to assist in training, from target instances and examples Initialize the instance weight factor, x is the feature, y is the true label; use D S and D T To train and return the predicted label as H k , weighted error rate ε k for: Among them, β S and β T Update after obtaining the predicted label; β T is the same as ε k The weight factor of this iteration is related to S is the static factor of the source domain; According to the results H k and the iterative error rate ε k , the weight factor ω for the training data S and ω T Update; start the next iteration of the training process, with β T Returns the predicted label as a weight factor; 4. The distributed Internet of Things intrusion detection method according to claim 3, characterized in that: The training strategy includes: Preparation: Public Dataset D S , private dataset Test dataset D test , initialize model f0; Goal: predict label pred; (1) Local training algorithm: 1) Initialize the source dataset D S The sample weight ω S and the target dataset D T The sample weight ω T ; 2) for k = 1, 2, 3 ... K execute: 3) Use D S and Training model f k Get the sample weight ω S and ω T , returns the predicted value p k ; 4) Use formula (2) to calculate the error rate ε k and calculated using formula (3) and formula (4) 5) Update the sample weight ω according to formula (5) and formula (6) S and ω T ; 6) end for; 7) Integration results k and 8) Return the updated model f i ; (2) Federal Averaging Algorithm: 1) Get the updated model f i ,i=1,2,3...r; 2) Return the overall model f0; (3) Weighted voting method 1) Sorting integration: 2) Use the updated model f i According to different attack A j , a binary data set with j=1, 2, 3, ..., p; 3) Aggregate attack classifier F on j ; (4) Weighted voting: 1) Use formula (7) to calculate the MMD distance MMD[D test , A j ] and use formula (8) to calculate the weight wts[D test , A j ], j = 1, 2, 3, ... p; 2) Set weights for attack classification F j And generate the predicted label D test ; 3) Return pred.

5. A distributed Internet of Things intrusion detection system using the distributed Internet of Things intrusion detection method according to any one of claims 1 to 4, characterized in that: The distributed Internet of Things intrusion detection system includes a secure cloud server and a client; The secure cloud server has a large amount of public data and high-performance hardware for model initialization and aggregation; the secure cloud server is used to connect and manage all IoT clients, distribute initialized models to clients, and collect updates from clients and process model aggregation; The clients are various independent IoT endpoints connected to a secure cloud, and each client is not allowed to share information with other IoT endpoints; the machine learning model in the secure cloud is a lightweight model suitable for low-cost IoT devices.

6. A computer device, characterized in that: The computer device includes a memory and a processor, the memory stores a computer program, and when the computer program is executed by the processor, the processor executes the distributed Internet of Things intrusion detection method according to any one of claims 1 to 4.

7. A computer-readable storage medium storing a computer program, wherein when the computer program is executed by a processor, the processor executes the distributed Internet of Things intrusion detection method according to any one of claims 1 to 4.

8. An information data processing terminal, characterized in that: The information data processing terminal is used to implement the functions of the distributed Internet of Things intrusion detection system as described in claim 5.

Citation Information

Patent Citations

  • Intrusion detection method and intrusion detection system based on sustainable ensemble learning

    CN108023876A

  • Method and system for constructing network intrusion detection model based on transfer learning

    CN110224987A