CoolFace
Apppublic

eswar0474/FL_IDS

sourceHugging Faceupdated 6mo agoView on Hugging Face
0likes
App README

FL Enterprise - Federated Learning Intrusion Detection System

πŸš€ Enterprise-Grade FL-IDS Platform v3.1.0

AgisFL Enterprise is a cutting-edge Federated Learning Intrusion Detection System designed for enterprise-level cybersecurity operations. This platform combines the power of distributed machine learning with advanced security monitoring to provide robust, privacy-preserving threat detection across distributed networks.

✨ Key Features

πŸ”’ Federated Learning Core

  • β€”Distributed Model Training: Train ML models across multiple clients without sharing raw data
  • β€”Privacy-Preserving: Differential privacy and secure aggregation protocols
  • β€”Multi-Algorithm Support: FedAvg, FedProx, FedNova, and custom algorithms
  • β€”Client Management: Geographic distribution, role-based access, and performance monitoring

πŸ›‘οΈ Advanced Security Engine

  • β€”Real-time Threat Detection: Network packet analysis, behavioral monitoring, and anomaly detection
  • β€”Multi-Source Intelligence: Integration with CrowdStrike, FireEye, and Recorded Future
  • β€”Automated Response: Intelligent threat response and incident management
  • β€”Compliance Ready: GDPR, HIPAA, SOX, and PCI-DSS compliance features

πŸ§ͺ Research & Development Lab

  • β€”Advanced FL Research: Cutting-edge federated learning algorithms and methodologies
  • β€”Experimental Framework: A/B testing, model versioning, and rollback capabilities
  • β€”Academic Integration: Publication tracking, patent management, and research collaboration
  • β€”Multi-Modal Learning: Combining network traffic, logs, and behavioral data

πŸ“Š Enterprise Dashboard

  • β€”Real-time Monitoring: System health, performance metrics, and security status
  • β€”Advanced Analytics: ML predictions, anomaly detection, and performance trends
  • β€”Client Insights: Geographic distribution, training progress, and model performance
  • β€”Compliance Reporting: Automated compliance checks and audit trails

πŸ–₯️ Desktop Application

  • β€”Pure Desktop Experience: Native Electron-based desktop application
  • β€”Cross-Platform Support: Windows, macOS, and Linux compatibility
  • β€”Offline Capability: Works without internet connection
  • β€”Native Performance: Optimized for desktop usage

πŸ†• Latest Updates (v3.1.0)

πŸ› Bug Fixes & Improvements

  • β€”Fixed 100+ Critical Bugs: Resolved import errors, missing dependencies, and API inconsistencies
  • β€”Enhanced Error Handling: Comprehensive error handling with fallback data
  • β€”Improved Type Safety: Fixed TypeScript compilation issues and type mismatches
  • β€”API Consistency: Standardized response formats across all endpoints

πŸš€ New Features

  • β€”Real-time Data Integration: Live system metrics, network monitoring, and security alerts
  • β€”Enhanced Dashboard: Comprehensive overview with real-time updates
  • β€”Dataset Management: Upload, manage, and analyze datasets for FL training
  • β€”Network Monitoring: Real-time packet analysis and threat detection
  • β€”Security Center: Advanced threat management and response system
  • β€”System Metrics: Detailed performance monitoring and optimization
  • β€”Settings Management: Configurable application preferences

🎨 UI/UX Improvements

  • β€”Dark Mode Support: Modern dark theme with light mode toggle
  • β€”Responsive Design: Mobile-friendly interface with adaptive layouts
  • β€”Real-time Updates: Live data refresh and status indicators
  • β€”Professional Interface: Enterprise-grade design for production use

πŸ”§ Technical Enhancements

  • β€”Electron Integration: Full desktop application support
  • β€”Real-time Monitoring: Integration with existing monitoring services
  • β€”College Project Mode: Special environment for academic presentations
  • β€”Performance Optimization: Improved response times and resource usage

πŸ—οΈ Architecture

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚   Frontend      β”‚    β”‚   Backend       β”‚    β”‚   FL Clients    β”‚
β”‚   (React +      │◄──►│   (FastAPI)     │◄──►│   (Distributed) β”‚
β”‚    Electron)    β”‚    β”‚                 β”‚    β”‚                 β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
         β”‚                       β”‚                       β”‚
         β”‚                       β”‚                       β”‚
         β–Ό                       β–Ό                       β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚   WebSocket     β”‚    β”‚   FL Engine     β”‚    β”‚   Local Models  β”‚
β”‚   Real-time     β”‚    β”‚   Core          β”‚    β”‚   Training      β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

πŸš€ Quick Start

Prerequisites

  • β€”Python 3.10+
  • β€”Node.js 16+
  • β€”PostgreSQL (optional, SQLite for development)

Option 1: Universal Startup Script (Recommended)

bash
# Run the universal startup script
START_AGISFL.bat

# Choose from available modes:
# 1. Quick Start (Core features, fastest startup)
# 2. Production Mode (Full enterprise features)
# 3. Development Mode (Hot reload enabled)
# 4. Test Mode (Run comprehensive tests)
# 5. Desktop Application (Pure desktop app with Electron)

Option 2: Manual Setup

Backend Setup
bash
cd backend
python -m venv venv
source venv/bin/activate  # On Windows: venv\Scripts\activate
pip install -r requirements.txt
python main.py
Frontend Setup
bash
cd frontend
npm install
npm run build
npm start
Desktop Application
bash
cd frontend
npm run electron:dev      # Development mode
npm run electron:build    # Build for distribution
npm run electron:pack     # Package for distribution

Production Deployment

bash
# Build frontend
cd frontend && npm run build

# Build desktop application
npm run electron:build

# Start backend with production settings
cd backend
export ENVIRONMENT=production
export JWT_SECRET=your-secure-secret
python main.py

πŸ“‘ API Endpoints

Core Endpoints

  • β€”GET /api/dashboard - Comprehensive dashboard data with real-time metrics
  • β€”GET /api/health - Health check and system status
  • β€”GET /api/system/metrics - System performance metrics
  • β€”GET /api/threats - Security threats and alerts
  • β€”GET /api/security/metrics - Security performance metrics
  • β€”GET /api/security/threats - Detailed threat information

FL-IDS Engine

  • β€”GET /api/fl/strategies - Available FL strategies
  • β€”GET /api/experiments - ML experiments and results
  • β€”GET /api/research/enterprise/research-algorithms - Research algorithms
  • β€”GET /api/fl/status - Federated Learning subsystem mode & metrics (simulation/full, rounds)

Network & Security

  • β€”GET /api/network/stats - Network statistics and performance
  • β€”GET /api/network/packets - Network packet analysis
  • β€”GET /api/integrations/overview - System integrations status

Dataset Management

  • β€”GET /api/datasets - Available datasets for training
  • β€”POST /api/datasets/upload - Upload new datasets
  • β€”DELETE /api/datasets/{id} - Remove datasets

πŸ“‚ Datasets Overview

The datasets/ directory contains curated sample datasets to demonstrate federated intrusion detection workflows. For full details (schema guidance, quality scoring, privacy), see datasets/README.md.

DatasetFileApprox SizeSamplesFeaturesPrimary Use
Network Trafficnetwork_traffic_dataset.csv~150MB50k25Network intrusion detection
Malware Detectionmalware_detection_dataset.csv~89MB30k30Malware classification
Behavioral Analysisbehavioral_analysis_dataset.csv~200MB75k40User/session anomaly detection

Guidelines when adding new data:

  1. 1.No raw PII (anonymize or aggregate first)
  2. 2.Provide a concise schema & feature description
  3. 3.Update (or create) datasets_metadata.json so the platform can index it
  4. 4.Prefer columnar formats (Parquet) for large internal benchmarking to reduce load latency

Planned metrics (future enhancement):

  • β€”agisfl_datasets_index_total – Index passes executed
  • β€”agisfl_datasets_detected_total – Datasets discovered during scan
  • β€”agisfl_dataset_load_seconds – Histogram of dataset load durations

Example minimal metadata entry (JSON):

json
{
    "name": "network_traffic_dataset",
    "file": "network_traffic_dataset.csv",
    "samples": 50000,
    "features": 25,
    "task": "intrusion_detection",
    "updated": "2025-08-15"
}

Settings & Configuration

  • β€”GET /api/settings - Application settings
  • β€”POST /api/settings - Update application settings

πŸ§ͺ Testing

Run All Tests

bash
# Comprehensive testing
python -m pytest tests/ -v

# Specific test categories
python -m pytest tests/test_app.py -v
python -m pytest tests/test_comprehensive.py -v
python -m pytest tests/test_production_ready.py -v

Test Coverage

  • β€”Backend API: 100% endpoint coverage
  • β€”Frontend Components: All pages and components tested
  • β€”Integration: End-to-end functionality verification
  • β€”Performance: Response time and resource usage validation

πŸ”§ Configuration

Environment Variables

bash
# College Project Mode
COLLEGE_PROJECT=true

# JWT Security
JWT_SECRET=your-secure-secret-key

# Environment
ENVIRONMENT=production|development|testing

College Project Mode

When COLLEGE_PROJECT=true, the system:

  • β€”Enables enhanced real-time monitoring
  • β€”Provides detailed FL training progress
  • β€”Shows comprehensive security metrics
  • β€”Optimizes for presentation and demonstration

🧾 Structured Logging

The backend emits newline-delimited JSON (NDJSON) log entries for key events (rate limiting, auth failures, dashboard generation, WebSocket lifecycle).

Sample log line:

{"ts":"2025-08-15T12:00:00.000000Z","level":"info","event":"dashboard_generated","version":"3.1.0","cache_ttl":1.0,"size":2489,"request_id":"6f12e52d"}

Fields:

  • β€”ts: UTC timestamp
  • β€”level: info|warning|error|debug
  • β€”event: Event identifier (e.g. dashboardgenerated, wsconnected)
  • β€”version: Application version
  • β€”request_id: Correlates HTTP request lifecycle (added by middleware)
  • β€”Additional dynamic fields (cachettl, size, clientip, etc.)

Enable pretty console output (optional):

SET PRETTY_LOGS=true   # Windows PowerShell: $Env:PRETTY_LOGS="true"

Forward logs to a file:

python main.py > logs/app.ndjson 2>&1

Integrating with tools:

  • β€”Elastic / OpenSearch: Use filebeat to harvest NDJSON
  • β€”Loki: promtail scrapeconfig with pipelinestages: json
  • β€”jq filtering: jq 'select(.event=="ws_broadcast_failure")' logs/app.ndjson

Key events currently instrumented:

  • β€”dashboardcachehit, dashboard_generated
  • β€”ratelimitblocked, unauthorized_access (middleware)
  • β€”wsconnected, wsdisconnected, wsbroadcastfailure, wsbroadcastsuppressed

Additional events:

  • β€”ratelimitexceeded (per-request limiter)
  • β€”ratelimitereviction (global limiter key eviction)
  • β€”wsbackpressuredisconnect (WS dropped due to queued backlog)
  • β€”wsinactivedisconnect (WS closed after inactivity timeout)
  • β€”psutilsampletimeout (system metrics sampling exceeded 1s budget)

πŸ“ˆ Metrics (/metrics Endpoint)

Prometheus-style plaintext exposed at GET /metrics (guarded by ENABLEPROMMETRICS env flag). Each metric includes HELP/TYPE lines for automatic scraping.

Exported metrics:

  • β€”agisflrequeststotal (counter) – Total HTTP requests processed
  • β€”agisflrequestsinflight (gauge) – Current in‑flight requests
  • β€”agisflratelimited_total (counter) – Requests rejected by rate limiter
  • β€”agisflwsconnections_total (counter) – Cumulative accepted WebSocket connections
  • β€”agisflwsactive (gauge) – Active WebSocket connections right now
  • β€”agisfldashboardcache_hits (counter) – Cache hits for /api/dashboard 1‑second TTL cache
  • β€”agisflflrounds_total (counter) – Federated learning rounds completed
  • β€”agisflflsimulation_mode (gauge) – 1 when FL runs in simulation (no TF / forced), 0 in full mode

Example output:

# HELP agisfl_requests_total Total HTTP requests processed
# TYPE agisfl_requests_total counter
agisfl_requests_total 42
# HELP agisfl_requests_inflight Current in-flight HTTP requests
# TYPE agisfl_requests_inflight gauge
agisfl_requests_inflight 0
# HELP agisfl_rate_limited_total Requests rejected due to rate limiting
# TYPE agisfl_rate_limited_total counter
agisfl_rate_limited_total 3
# HELP agisfl_ws_connections_total Total WebSocket connections accepted
# TYPE agisfl_ws_connections_total counter
agisfl_ws_connections_total 5
# HELP agisfl_ws_active Active WebSocket connections
# TYPE agisfl_ws_active gauge
agisfl_ws_active 2
# HELP agisfl_dashboard_cache_hits Number of /api/dashboard cache hits
# TYPE agisfl_dashboard_cache_hits counter
agisfl_dashboard_cache_hits 18
# HELP agisfl_fl_rounds_total Total federated learning rounds completed
# TYPE agisfl_fl_rounds_total counter
agisfl_fl_rounds_total 4
# HELP agisfl_fl_simulation_mode 1 if FL running in simulation mode else 0
# TYPE agisfl_fl_simulation_mode gauge
agisfl_fl_simulation_mode 1

Scraping configuration snippet (Prometheus):

yaml
scrape_configs:
    - job_name: agisfl
        static_configs:
            - targets: ['localhost:8000']
        metrics_path: /metrics
        scheme: http

Disable metrics endpoint:

SET ENABLE_PROM_METRICS=false   # PowerShell: $Env:ENABLE_PROM_METRICS="false"

βš™οΈ Configuration (Pydantic)

Runtime config now powered by Pydantic BaseSettings (backend/config/app_config.py). Environment variables map automatically:

Env VarDescriptionDefault
LOG_LEVELRoot logging levelINFO
PRETTY_LOGSPretty console logsfalse
JWT_SECRETJWT signing secret(empty)
ENVIRONMENTEnvironment namedevelopment
ENABLEPROMMETRICSExpose /metricstrue
RATELIMITMAXPer-IP+path req/min60
FORCEFLSIMForce FL simulation mode even if TF present(unset)

Backward compatibility: legacy inline dataclass removed in favor of config.app_config singleton.

Planned (extend as needed): datasetupload, modeltrainstart, modeltrain_complete Additional FL events/metrics added:

  • β€”/api/fl/status endpoint for real-time FL mode & round metrics
  • β€”agisflflrounds_total counter
  • β€”agisflflsimulation_mode gauge

🌐 Network Capture Dependencies

Some advanced network monitoring features require packet capture libraries.

Windows:

  1. 1.Install Npcap (https://nmap.org/npcap/) with support for WinPcap API compatibility
  2. 2.Ensure "Install Npcap in WinPcap API-compatible Mode" is checked
  3. 3.Restart the backend after installation

Linux (Debian/Ubuntu):

sudo apt update
sudo apt install -y libpcap-dev tcpdump

macOS:

brew install libpcap

Python packages (only if packet capture modules are enabled):

pip install scapy

Troubleshooting:

  • β€”Permission denied capturing packets: run with elevated privileges or grant CAPNETRAW
  • β€”No interfaces found: verify driver (Npcap/libpcap) installed
  • β€”High CPU: reduce capture filter breadth or sampling frequency

πŸ“± Desktop Application Features

Cross-Platform Support

  • β€”Windows: Native Windows application with installer
  • β€”macOS: macOS app bundle with proper signing
  • β€”Linux: AppImage and package formats

Desktop-Specific Features

  • β€”Native Menus: File, Edit, View, Window, Help menus
  • β€”System Integration: Proper window management and notifications
  • β€”Offline Operation: Works without internet connection
  • β€”Performance: Optimized for desktop hardware

πŸš€ Deployment Options

1. Web Application

  • β€”Traditional web-based interface
  • β€”Accessible from any browser
  • β€”Real-time updates via WebSocket
  • β€”Mobile-responsive design

2. Desktop Application

  • β€”Native desktop experience
  • β€”Offline capability
  • β€”System integration
  • β€”Professional presentation

3. Hybrid Mode

  • β€”Run both web and desktop simultaneously
  • β€”Shared backend services
  • β€”Consistent data across platforms

πŸ”’ Security Features

Authentication & Authorization

  • β€”JWT-based authentication
  • β€”Role-based access control (RBAC)
  • β€”Session management
  • β€”Secure password policies

Data Protection

  • β€”End-to-end encryption
  • β€”Privacy-preserving FL algorithms
  • β€”Secure data transmission
  • β€”Compliance with security standards

πŸ“Š Performance Metrics

System Requirements

  • β€”Minimum: 4GB RAM, 2 CPU cores, 10GB storage
  • β€”Recommended: 8GB RAM, 4 CPU cores, 50GB storage
  • β€”Production: 16GB RAM, 8 CPU cores, 100GB storage

Performance Benchmarks

  • β€”API Response: <100ms average
  • β€”Real-time Updates: <1 second latency
  • β€”FL Training: Scalable to 100+ clients
  • β€”Threat Detection: <50ms analysis time

🀝 Contributing

Development Setup

  1. 1.Fork the repository
  2. 2.Create a feature branch
  3. 3.Make your changes
  4. 4.Run tests to ensure quality
  5. 5.Submit a pull request

Code Standards

  • β€”Follow PEP 8 for Python code
  • β€”Use TypeScript for frontend
  • β€”Maintain test coverage above 90%
  • β€”Document all public APIs

πŸ™ Acknowledgments

  • β€”Federated Learning Community: For research and algorithms
  • β€”Open Source Contributors: For various libraries and tools
  • β€”Academic Partners: For research collaboration and validation

πŸ›‘οΈInstustion Detection System Using Federated Learning

Check out the configuration reference at https://huggingface.co/docs/hub/spaces-config-reference