TY - CHAP
T1 - Intrusion Detection at the IoT Edge Using Federated Learning
AU - Pope, James
AU - Spyridopoulos, Theodoros
AU - Kumar, Vijay
AU - Raimondo, Francesco
AU - Gunner, Sam D
AU - Oikonomou, George
AU - Pasquier, Thomas
AU - McConville, Ryan
AU - Carnelli, Pietro
AU - Sanchez-Mompo, Adrian
AU - Mavrommatis, Ioannis
AU - Khan, Aftab
N1 - Publisher Copyright:
© The Author(s), under exclusive license to Springer Nature Switzerland AG 2025.
PY - 2024/10/29
Y1 - 2024/10/29
N2 - With the proliferation of Internet of Things (IoT) technologies in urban environments, cities are increasingly deploying Edge processing nodes for urban sensing. This large-scale integration of Edge nodes and sensing endpoints raises significant security concerns. For instance, existing Intrusion Detection methods cannot scale well and do not consider the privacy and energy consumption implications that emerge when applied to those systems. In addition, the use of containerised applications managed by container orchestration platforms in these environments, while enabling diverse applications and allowing scanning of the container images, can still introduce vulnerabilities. This Chapter addresses the challenge of effectively detecting malicious activities in large-scale resource-constrained IoT systems. We introduce an unsupervised distributed learning solution employing Federated Learning (FL) for real-time anomaly detection across the IoT infrastructure. Our approach involves analysing Linux system call data through a Federated Learning Framework, significantly reducing the need for central data processing. The Chapter presents a comprehensive architectural overview of the system, its core components, and the methodology for deploying and updating anomaly detection models. It also provides the performance evaluation of our approach. Our results demonstrate that the size of the clients’ datasets and the use of pre-trained models play a significant role in the performance of FL models. The work presented in this chapter was supported by UK Research and Innovation, Innovate UK [grant number 53707].
AB - With the proliferation of Internet of Things (IoT) technologies in urban environments, cities are increasingly deploying Edge processing nodes for urban sensing. This large-scale integration of Edge nodes and sensing endpoints raises significant security concerns. For instance, existing Intrusion Detection methods cannot scale well and do not consider the privacy and energy consumption implications that emerge when applied to those systems. In addition, the use of containerised applications managed by container orchestration platforms in these environments, while enabling diverse applications and allowing scanning of the container images, can still introduce vulnerabilities. This Chapter addresses the challenge of effectively detecting malicious activities in large-scale resource-constrained IoT systems. We introduce an unsupervised distributed learning solution employing Federated Learning (FL) for real-time anomaly detection across the IoT infrastructure. Our approach involves analysing Linux system call data through a Federated Learning Framework, significantly reducing the need for central data processing. The Chapter presents a comprehensive architectural overview of the system, its core components, and the methodology for deploying and updating anomaly detection models. It also provides the performance evaluation of our approach. Our results demonstrate that the size of the clients’ datasets and the use of pre-trained models play a significant role in the performance of FL models. The work presented in this chapter was supported by UK Research and Innovation, Innovate UK [grant number 53707].
KW - Anomaly Detection
KW - Internet of Things
KW - Federated Learning
U2 - 10.1007/978-3-031-66708-4_5
DO - 10.1007/978-3-031-66708-4_5
M3 - Chapter in a book
SN - 9783031667077
VL - 14800
T3 - Lecture Notes in Computer Science
SP - 98
EP - 119
BT - Security and Privacy in Smart Environments
A2 - Pitropakis, Nikolaos
A2 - Katsikas, Sokratis
PB - Springer Nature Switzerland
ER -