Distributed Privacy-Preserving Collaborative Intrusion Detection Systems for VANETs

Distributed Privacy-Preserving Collaborative Intrusion Detection Systems for VANETs
复制标题

DOI:
10.1109/tsipn.2018.2801622
复制
发表时间:
2018-02
影响因子:
3.2
通讯作者:
Tao Zhang;Quanyan Zhu
Tao Zhang;Quanyan Zhu
中科院分区:
计算机科学2区
文献类型:
--
作者:
Tao Zhang;Quanyan Zhu

文献摘要

被引文献

相似文献

车辆自组织网络(VANET)是现代交通系统中提供安全和有价值信息的使能技术,但容易受到从被动窃听到主动干扰的一系列攻击。入侵检测系统(ids)是通过检测恶意行为来减轻威胁的重要设备。此外,VANETs中车辆之间的协作可以通过节点之间的经验交流来提高检测精度。为此,分布式机器学习是在VANETs上设计可扩展和可实现的协作检测算法的合适框架。协作学习的一个基本障碍是节点之间交换数据时的隐私问题。恶意节点可以通过对观察到的数据进行推断,获取其他节点的敏感信息。在本文中,我们提出了一种基于隐私保护机器学习的vanet协同IDS (PML-CIDS)。该算法采用乘数交替方向法求解一类经验风险最小化问题,并训练分类器检测VANETs中的入侵。我们利用差分隐私来捕获PML-CIDS的隐私符号,并提出一种双变量摄动方法来提供动态差分隐私。我们分析了理论性能,并描述了PML-CIDS的安全性和隐私性之间的基本权衡。我们还使用网络安全实验室-知识发现和数据挖掘(NSL-KDD)数据集进行了数值实验,以证实检测准确性,安全-隐私权衡和设计方面的结果。
Vehicular ad hoc network (VANET) is an enabling technology in modern transportation systems for providing safety and valuable information, and yet vulnerable to a number of attacks from passive eavesdropping to active interfering. Intrusion detection systems (IDSs) are important devices that can mitigate the threats by detecting malicious behaviors. Furthermore, the collaborations among vehicles in VANETs can improve the detection accuracy by communicating their experiences between nodes. To this end, distributed machine learning is a suitable framework for the design of scalable and implementable collaborative detection algorithms over VANETs. One fundamental barrier to collaborative learning is the privacy concern as nodes exchange data among them. A malicious node can obtain sensitive information of other nodes by inferring from the observed data. In this paper, we propose a privacy-preserving machine-learning-based collaborative IDS (PML-CIDS) for VANETs. The proposed algorithm employs the alternating direction method of multipliers to a class of empirical risk minimization problems and trains a classifier to detect the intrusions in the VANETs. We use the differential privacy to capture the privacy notation of the PML-CIDS and propose a method of dual-variable perturbation to provide dynamic differential privacy. We analyze theoretical performance and characterize the fundamental tradeoff between the security and privacy of the PML-CIDS. We also conduct numerical experiments using the network security laboratory-knowledge discovery and data mining (NSL-KDD) dataset to corroborate the results on the detection accuracy, security-privacy tradeoffs, and design.