[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-123484-en":3,"doc-seo-123484-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},123484,687197207919,"Theodora","https://ap-avatar.wpscdn.com/avatar/a000253d6f5f7c60be?x-image-process=image/resize,m_fixed,w_180,h_180&k=1779446848396160552",8,"Research & Report","Collaborative Machine Learning for Detecting Network Anomalies on the Edge - Thesis Abstract","Massive adoption of IoT and mobile terminals increases the need for secure edge networks while creating constraints in resources, connectivity, and data management. Edge environments are highly diverse and distribute traffic data across terminals, making centralized intrusion detection unsuitable due to scalability and data privacy risks. Federated learning enables local training and privacy-preserving model updates, yet edge anomaly detection remains difficult under non-IID data, class imbalance, limited storage and compute, and unreliable connectivity. This thesis proposes clustering-enhanced aggregation, a federated transfer learning scheme using public data, and a decentralized FL architecture to detect wireless intrusions under mobility and uncertainty.","University of Exeter  \nFaculty of Environment, Science and Economy  \nCollaborative Machine Learning for Detecting Network Anomalies on  \nthe Edge  \nJIAZHEN ZHANG  \nSubmitted by JIAZHEN ZHANG, to the University of Exeter as a thesis for the degree of Doctor of Philosophy in Computer Science, May 2024 .  \nThis thesis is available for Library use on the understanding that it is copyright material and that no quotation from the thesis may be published without proper acknowledgement.  \nI certify that all material in this thesis which is not my own work has been identified and that any material that has previously been submitted and approved for the award of a degree by this or any other University has been acknowledged.  \nSigned:    \nAbstract  \nMassive uses of the Internet of Things (IoT) and mobile terminals have brought revolutionary changes to existing network applications and raised the importance of edge networks to a new level. Edge network environments can exhibit extreme diversity and flexibility, calling novel network security and data privacy requirements for resource-constrained edge terminals. Therefore, Machine Learning (ML) and Deep Learning (DL) based network intrusion detection could be one feasible solution to analyse network traffic and protect them from attacks. The existing approaches require central entities to collect, store, and analyse client network traffic flows. This approach can bring severe data privacy concerns and lack flexibility or scalability to fulfil security requirements on edge networks. Moreover, edge network traffic flows present higher heterogeneity compared to traditional network environments, and data are scattered on massive edge terminals. These features merge challenges and call for novel designs for network intrusion detection in a more distributed manner.  \nIn recent years, Federated Learning (FL) has emerged as a promising technique for deploying ML in distributed systems. Instead of forwarding data to central nodes, FL clients can train their models locally and share model updates with other participants, enabling knowledge exchange while preserving data privacy. This collaborative machine learning approach allows clients to contribute to a model that delivers more comprehensive performance.  \nHowever, applying FL for edge network anomaly detection can still face significant challenges that need to be addressed. For example, edge network endpoints  \nsuch as IoT devices are often designed for specific tasks with various embedded applications. The patterns of their network traffic flows can vary, and the training samples on these clients may exhibit class imbalance and non-Independent and Identically Distributed (non-IID) characteristics. Furthermore, deploying ML models for network anomaly detection on IoTs is often constrained by the availability of local resources. Including restricted samples for training, limited computing power, and insufficient storage capacity. Edge devices may be unable to support the cost of training and deploying sophisticated ML models, such as Deep Neural Network (DNN) . Moreover, traditional FL structures are centralized, assuming clients can connect to a central server for model exchanges. However, edge networks, which often involve multiple wireless communication techniques, present higher complexity and mobility. The flexibility and unpredictability of edge network connectivity necessitate innovative FL designs tailored to these challenges.  \nThis thesis aims to address the aforementioned challenges and research gapsin collaborative machine learning for anomaly detection on edge network terminals. To coordinate model training among heterogeneous edge terminals with non-IID training samples, a novel FL framework is introduced, which incorporates clustering approaches during the model aggregation phase to enhance the performance of the aggregated model. Meanwhile, this thesis also introduces a hardware test platform to simulate real-world IoT environmen","cbCaieTLZWBHqYNE","https://ap.wps.com/l/cbCaieTLZWBHqYNE","pdf",15306637,1,123,"English","en",105,"# Abstract\n## Problem context: edge networks and intrusion detection\n## Federated learning motivation and challenges\n## Thesis contributions and proposed approaches","[{\"question\":\"Why are centralized intrusion detection approaches not ideal for edge networks?\",\"answer\":\"Centralized approaches require collecting and analyzing client traffic in a central entity, which creates strong data privacy concerns and can lack flexibility or scalability for edge environments.\"},{\"question\":\"What makes federated learning challenging for edge anomaly detection?\",\"answer\":\"Edge clients often have class-imbalanced and non-IID traffic samples, limited local resources, and connectivity uncertainty that breaks traditional centralized FL assumptions.\"},{\"question\":\"What solutions does the thesis propose to improve edge anomaly detection?\",\"answer\":\"It introduces a clustering-based FL framework for aggregation, a federated transfer learning approach using public datasets to support local training, and a decentralized FL architecture for wireless intrusion detection under high flexibility and uncertainty.\"}]","Collaborative Machine Learning for Detecting Network Anomalies on the Edge - Thesis Abstract | PDF",1785816781,310,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"collaborative-machine-learning-for-detecting-network-anomalies-on-the-edge-thesis-abstract","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/collaborative-machine-learning-for-detecting-network-anomalies-on-the-edge-thesis-abstract/123484/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why are centralized intrusion detection approaches not ideal for edge networks?","Question",{"text":75,"@type":76},"Centralized approaches require collecting and analyzing client traffic in a central entity, which creates strong data privacy concerns and can lack flexibility or scalability for edge environments.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What makes federated learning challenging for edge anomaly detection?",{"text":80,"@type":76},"Edge clients often have class-imbalanced and non-IID traffic samples, limited local resources, and connectivity uncertainty that breaks traditional centralized FL assumptions.",{"name":82,"@type":73,"acceptedAnswer":83},"What solutions does the thesis propose to improve edge anomaly detection?",{"text":84,"@type":76},"It introduces a clustering-based FL framework for aggregation, a federated transfer learning approach using public datasets to support local training, and a decentralized FL architecture for wireless intrusion detection under high flexibility and uncertainty.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]