Federated Multi-Discriminator BiWGAN-GP based Collaborative Anomaly Detection for Virtualized Network Slicing

Federated Multi-Discriminator BiWGAN-GP based Collaborative Anomaly Detection for Virtualized Network Slicing
复制标题

DOI:
10.1109/tmc.2022.3200059
复制
发表时间:
2022-08
影响因子:
7.9
通讯作者:
Weili Wang;C. Liang;Lun Tang;H. Yanikomeroglu;Qianbin Chen
Weili Wang;C. Liang;Lun Tang;H. Yanikomeroglu;Qianbin Chen
中科院分区:
计算机科学2区
文献类型:
--
作者:
Weili Wang;C. Liang;Lun Tang;H. Yanikomeroglu;Qianbin Chen

文献摘要

相似文献

虚拟化网络切片允许在公共底层基础设施上创建多个逻辑网络以支持不同的服务。虚拟化网络切片是多个虚拟网络功能的逻辑组合,通过虚拟化技术作为软件应用程序运行在虚拟机(VM)上。由于网络切片的性能取决于虚拟机的正常运行,因此检测和分析虚拟机的异常情况至关重要。基于虚拟化网络切片的三层管理框架,我们首先开发了基于联邦学习(FL)的三层分布式虚拟机异常检测框架,该框架使分布式网络切片管理者能够协作训练全局虚拟机异常检测模型,同时在本地保存指标数据。虚拟化网络切片场景中的高维、不平衡、分布式数据特征使得现有的异常检测模型失效。考虑到生成对抗网络(GAN)在捕获复杂数据分布方面的强大能力,我们设计了一种新的带有梯度惩罚的多判别器双向 Wasserstein GAN(BiWGAN-GP)模型,从分布在多个虚拟机监视器上的高维资源指标数据集中学习正态数据分布。多判别器BiWGAN-GP模型可以在分布式数据源上进行训练,避免了本地数据的集中收集和处理带来的高通信和计算开销。我们将异常分数定义为判别标准,用于量化新指标数据与学习到的正态分布的偏差,以检测虚拟机中出现的异常行为。通过对真实数据集进行广泛的实验评估,验证了所提出的协作异常检测算法的效率和有效性。
Virtualized network slicing allows a multitude of logical networks to be created on a common substrate infrastructure to support diverse services. A virtualized network slice is a logical combination of multiple virtual network functions, which run on virtual machines (VMs) as software applications by virtualization techniques. As the performance of network slices hinges on the normal running of VMs, detecting and analyzing anomalies in VMs are critical. Based on the three-tier management framework of virtualized network slicing, we first develop a federated learning (FL) based three-tier distributed VM anomaly detection framework, which enables distributed network slice managers to collaboratively train a global VM anomaly detection model while keeping metrics data locally. The high-dimensional, imbalanced, and distributed data features in virtualized network slicing scenarios invalidate the existing anomaly detection models. Considering the powerful ability of generative adversarial network (GAN) in capturing the distribution from complex data, we design a new multi-discriminator Bidirectional Wasserstein GAN with Gradient Penalty (BiWGAN-GP) model to learn the normal data distribution from high-dimensional resource metrics datasets that are spread on multiple VM monitors. The multi-discriminator BiWGAN-GP model can be trained over distributed data sources, which avoids high communication and computation overhead caused by the centralized collection and processing of local data. We define an anomaly score as the discriminant criterion to quantify the deviation of new metrics data from the learned normal distribution to detect abnormal behaviors arising in VMs. The efficiency and effectiveness of the proposed collaborative anomaly detection algorithm are validated through extensive experimental evaluation on a real-world dataset.