ENSURE-6G Event #8 Highlights: Privacy-Preserving Federated Learning for Network Intrusion Detection by Dr. Tijana Markovic

We are delighted to share the presentation recording from Talk #2 of our ENSURE-6G Event 8: Workshop on AI for 6G Security, hosted at the University of Sri Jayewardenepura (USJ), Sri Lanka.

In this session, Dr. Tijana Markovic, Researcher at the University of Portsmouth, United Kingdom, and Visiting Professor at the University Mediterranean, Montenegro, presents her cutting-edge research on “Privacy-Preserving Federated Learning for Network Intrusion Detection”.

About the Speaker & The Research

Dr. Tijana Markovic brings over a decade of computer science teaching and research experience. Her expertise spans applied artificial intelligence, cyber security, and privacy-preserving collaborative machine learning. This featured research was conducted during her ENSURE-6G secondment in Barcelona with Telefonica Innovación Digital, resulting in a jointly published paper accepted at the ACML-PDD conference.

Key Takeaways from the Talk

  • The Privacy Imperative in Intrusion Detection: Modern Network Intrusion Detection Systems (NIDS) utilize machine learning to differentiate normal traffic from malicious anomalies. However, traditional centralized learning—where all network nodes send raw data to a single server—raises severe data privacy and security concerns.
  • Leveraging Horizontal Federated Learning: To completely bypass the need for raw data sharing, Dr. Markovic’s framework utilizes horizontal federated learning combined with Random Forest models. Because Random Forest remains incredibly effective for tabular NIDS datasets, local nodes can train their own local models and securely share only the model updates (decision trees) rather than private network data.
  • Removing the Server via One-Shot Decentralization: Taking security a step further, the research introduces a fully decentralized, peer-to-peer one-shot model aggregation scheme. By passing the model sequentially from client to client, each node ranks, filters, and propagates only the top-performing decision trees. This eliminates the need for a centralized aggregator server entirely.
  • Benchmarking Against Leading Datasets: The proposed approach was rigorously evaluated against multiple industry benchmark datasets (including KDD 99, NSL-KDD, UNSW-NB15, and CIC-IDS2017), alongside recent real-world traffic data such as the 2023 Western Network Traffic dataset and a 2022 5G NIDS dataset.
  • High Performance Without Prior Coordination: Experimental results show that the decentralized federated model significantly outperforms individual client models and achieves an accuracy closely matching an ideal, fully centralized dataset. Remarkably, the final model accuracy converges regardless of the peer ordering strategy (whether sorted by training size, malicious traffic ratio, or randomly). This ensures that clients do not even need to coordinate or reveal details about their local dataset sizes to participate.
  • Future Horizons: Moving forward, the research team aims to test this framework on real hardware utilizing ENSURE-6G testbeds (in collaboration with Telefonica and Montimage), alongside exploring iterative communication adjustments and personalized federated learning settings.

Watch the full presentation video below:

Previous Article

ENSURE-6G Event #8 Highlights: Trustworthy AI for Autonomous 6G Networks by Dr. Shen Wang

Next Article

ENSURE-6G Event #8 Highlights: Research Methods and Dissemination: Navigating Uncharted Waters by Dr. Gürkan Gür

Write a Comment

Leave a Comment

Your email address will not be published. Required fields are marked *