This invention discloses a
distributed intrusion detection method and
system based on flexible, secure, and trusted
federated learning, belonging to the field of
network data security and sharing. The method includes: dividing nodes into training nodes and aggregation nodes; training nodes collecting network traffic, training a local network
traffic classification model, and sending it to an edge network device; the edge network device detecting the uploaded local model and updating the
list of trusted and malicious nodes; aggregation nodes aggregating qualified local models and returning the generated
global model to the
edge device; the
edge device receiving the
global model, verifying it, and
broadcasting it; all training nodes receiving and using the latest
global model to obtain the final intrusion detection model, and using the final intrusion detection model to detect intrusions. This invention effectively improves the
system's security and robustness while ensuring data privacy and the
trustworthiness of sharing.