SECURE FEDERATED INTRUSION DETECTION USING HOMOMORPHIC ENCRYPTION: A COMPARATIVE STUDY WITH ENSEMBLE LEARNING
The rapid growth of the Internet of Things (IoT) has also resulted in the increase of the demand in the intrusion detection systems, which can detect suspicious activity and keep the information confidential. The traditional centralized machine learning systems involve attaching the data of the distributed devices to a centralized server thus placing them at a risk of being stolen. Federated Learning (FL) may help overcome this difficulty and assist in a distributed model training process without sharing raw client data. Nevertheless, updated versions of models that are transferred in the process of training are susceptible to poisoning or inference attacks at communication and aggregation. This paper proposed a federated intrusion detection system that is secure and involves implementation of Homomorphic Encryption (HE), in this case CKKS scheme, to provide model updates protection in aggregation process. The CICIoT2023 dataset was used in extensive experimentation of the proposed framework in terms of comparing with the classical machine learning baselines and experiences in using ensembles. Our findings show that the centralized Random Forest model with optimal accuracy of 98.57% worked best and the proposed Federated Learning models worked well with the standard FL performance of 79.54% and the encrypted FL+HE model performed with an accuracy of 79.39%. These are some results that demonstrate how Homomorphic Encryption enables the security and confidentiality of model aggregation a significant effect to model detection (reducing by only 0.15 percent), which provides a strong privacy-preserving security solution to decentralized IoT networks.