PofoliaPofolia ile paylaşıldı

Scientific Reports· 2026Q1

DDoS Tespiti İçin Birleşik Öğrenme ve Otomatik Kodlayıcı Tabanlı Hibrit Çerçeve

Federated learning and autoencoder-based hybrid framework for DDoS detection

G. Srujana, K. S. Harshita, Harshitha Shetty, N. Jhansi ve diğerleri

Kısa özet

Birleşik Ortalama (FedAvg) MLP ve bir otomatik kodlayıcıyı birleştiren hibrit bir birleşik öğrenme çerçevesi, ham trafik verilerini paylaşmadan DDoS saldırılarını tespit eder ve düşük güvenilirlikteki tahminleri yeniden değerlendirerek doğruluğu artırır.

Yapay zekâ ile başlık ve abstract'tan üretildi; tam metin okunmaz.

Ana noktalar

  • Hibrit bir birleşik çerçeve, DDoS tespiti için FedAvg MLP ve bir otomatik kodlayıcıyı birleştirir.
  • Otomatik kodlayıcı, MLP'nin düşük güvenilirlikteki tahminlerini yeniden değerlendirmek için güvenliğe dayalı bir mekanizma aracılığıyla etkinleştirilir.
  • Ham ağ trafiği verileri, veri gizliliğini sağlayarak katılımcı istemcilerde kalır.
  • Çerçeve, standart tespit metrikleri kullanılarak merkezi bir MLP taban çizgisine karşı değerlendirilmiştir.

Yapay zekâ ile başlık ve abstract'tan üretildi; tam metin okunmaz.

Özet (abstract)

Abstract Distributed Denial-of-Service (DDoS) attacks can overwhelm network resources and disrupt the availability of cloud services, enterprise systems, and critical infrastructure. Machine-learning-based intrusion detection can help identify malicious traffic from network-flow characteristics. However, conventional centralized training requires data from multiple environments to be collected and stored in a central location, which can be challenging when organizations face confidentiality and data-sharing restrictions. This study presents a hybrid federated framework for DDoS detection that combines a Federated Averaging (FedAvg) multilayer perceptron (MLP) with an autoencoder trained on benign traffic. Traffic from the CICIDS2017 and CICDDoS2019 datasets is cleaned, deduplicated, and aligned using common flow-level features before being distributed across federated clients. The FedAvg MLP acts as the primary classifier, while the autoencoder provides additional anomaly information through reconstruction error. A confidence-gated cascading mechanism activates the autoencoder only when the MLP predicts benign traffic with low confidence, particularly for samples close to the decision boundary. This enables potentially missed attacks to be reassessed without unnecessarily altering confident predictions. The proposed framework is evaluated against a centralized MLP baseline using standard detection metrics, along with an analysis of recovered attacks and additional false positives. Because raw traffic remains on the participating clients, the framework supports collaborative DDoS detection across distributed network environments without requiring organizations to directly share their underlying traffic data.

Yazarların özeti; kaynağından alınmıştır. Scientific Reports, 2026 · DOI ↗

ÇıkarımlarPremium
Makaleye SorÜcretsiz hesapla

Ücretsiz hesapla devam et

Makaleye Sor ile bu makaleye günde 3 soru ücretsiz; makaleyi kaydet, kaynakçasını al, ilgi alanına göre her gün yeni özetler. Çıkarımlar Premium.

Web'de ücretsiz devam et

Google ya da Apple hesabınla giriş; kart istemez. Bu makaleye geri dönersin.

Telefonda:

Alan: Bilgisayar Ağları ve İletişim

Computer Networks and CommunicationsComputer Science