Skip to content
Open access

Edge- Federated Graph Anomaly Detection With Self-Supervised Representation Learning for IoT Networks

2026 · IEEE Access · Vol 14, pp. 102184-102202 · 0 citations · 61 references
Computer Science

TL;DR

This paper presents an Edge Federated Graph Anomaly Detection (E-FGAD) framework for IoT environments that combines centralized self-supervised pre-training with distributed supervised learning over edge embeddings that outperforms centralized and federated baselines in detecting attacks while preserving privacy.

Abstract

The Internet of Things (IoT) plays a vital role in the digital age by interconnecting numerous heterogeneous devices. This complexity and ubiquity expose IoT networks to diverse and sophisticated cyber threats. IoT environments require rigorous collaborative intrusion detection system (IDS) that operates in distributed environments and heterogeneous data traffic. While federated learning offers a promising, privacy-conscious training model, most traditional approaches to IDS fail to detect the structural relationships between connected entities. On the other hand, Graph Neural Networks (GNNs) have attracted significant attention in Network Intrusion Detection Systems (NIDS) for their effectiveness in modeling complex network traffic flows in real-world environments. However, existing GAD methods are generally designed for centralized training, thereby posing privacy leakage risks. Despite progress, current mainstream Federated Graph anomaly detection (FGAD) methods still face challenges. A key limitation is that most existing approaches focus on node-level analysis while disregarding inter-node relationships making them ineffective against sophisticated attacks. To tackle this problem, this paper presents an Edge Federated Graph Anomaly Detection (E-FGAD) framework for IoT environments that combines centralized self-supervised pre-training with distributed supervised learning over edge embeddings. During the supervised phase, parameters are optimized in a federated manner using FedAvg with FedProx and server momentum. Our framework operates on graphs, where nodes represent IP endpoints and edges represent NetFlow records with traffic statistics as features, aiming to capture the flow of interactions between entities. We evaluate experiments on two real-world datasets, NF-BoT-IoT-v3 and NF-ToN-IoT-v3, in both binary and multi-class settings. E-FGAD achieves a maximum detection accuracy of 99.32%, a Macro-F1 of 89.73%, and a Weighted-F1 of 99.2%. Our framework outperforms centralized and federated baselines, demonstrating its effectiveness in detecting attacks while preserving privacy.

Read PDF

Similar papers

#federated learning Open access Aug 2026

Privacy-Enhancing Federated Learning Models for Cybersecurity in IoT Networks

The rapid expansion of the Internet of Things (IoT) has intensified cybersecurity risks by exposing distributed connected devices to increasingly complex and pervasive threats. Conventional centralized security mechanisms often struggle to accommodate the heterogeneous and decentralized structure of IoT networks. This study investigates Federated Learning (FL) as a decentralized approach to intrusion detection that enables local model training on IoT edge devices while transmitting only encrypted model updates to a central server, thereby preserving data privacy and reducing communication overhead. A novel FL-based Intrusion Detection System (IDS) architecture was developed using Convolutional Neural Networks (CNNs) for anomaly detection and the Federated Averaging (FedAvg) algorithm for aggregating local model updates. The framework was evaluated on standard IoT datasets under non-independent and identically distributed (non-IID) data conditions to simulate heterogeneous real-world environments. Experimental results demonstrate that the proposed system achieved a detection accuracy of 94.6%, an F1-score of 93.8%, and a recall of 92.7%, outperforming centralized and standalone local learning methods. The framework also reduced communication overhead by 35% and achieved convergence 28% faster than conventional approaches. These findings demonstrate that FL can provide a scalable, privacy-preserving, and computationally efficient foundation for strengthening IoT cybersecurity. This study contributes a decentralized machine-learning architecture for real-time, adaptive, and privacy-conscious intrusion detection in large-scale IoT environments.

Mohammed Ajuji, Y. M. Malgwi, A. Ahmadu et al. · 0 citations
Conference Open access 2026

Enhanced Intrusion Detection in IoT Networks using Federated Learning

The results show a success in implementing a real time, scalable, privacy-preserving, and adaptive IDS in large-scale IoT deployments through intelligent workload distribution between edge and cloud layers.

Chidera Winifred John, Eduediuyai Ekerete Dan, P. Asuquo et al. · 0 citations
Open access 2026

The Method of Malicious Traffic Detection for Internet of Things Based on Lightweight Graph Neural Networks

: With the sustained expansion of complex Internet of Things (IoT) ecosystems, malicious traffic detection has become critical for maintaining both cyber security and operational continuity. Modern IoT deployments contain heterogeneous devices, ubiquitous sensing layers, edge services, and autonomous assets, so abnormal communication may affect not only data confidentiality but also physical operations. To address the limitations of independent flow-level detection and heavy graph propagation, this paper proposes a Lightweight Graph-Attentive Network for Traffic Detection (LGNT). LGNT constructs a directed traffic-interaction graph from NetFlow records, where communication entities are represented as nodes and traffic sessions are represented as edges. Communication-strength-based auxiliary node supervision provides an activity-aware structural signal, while a compact backbone combining topology adaptive graph convolution (TAGConv) and graph attention v2 convolution (GATv2Conv) captures local topological dependencies and key communication relations. A structure-significance pruning strategy is further introduced to reduce the message-passing edge set and graph computation overhead. Experiments on NetFlow BoT-IoT (NF-BoT-IoT) and NetFlow ToN-IoT (NF-ToN-IoT) show that LGNT obtains effective results in both binary and multi-class detection tasks. Specifically, it achieves 94.28% accuracy, 97.36% area under the curve (AUC), and 86.88% F1 on NF-BoT-IoT, and 99.93% accuracy, 99.95% AUC, and 69.05% weighted F1 on NF-ToN-IoT. The per-class analysis further shows that long-tailed minority categories remain challenging in fine-grained NF-ToN-IoT recognition. Overall, LGNT improves the balance between traffic-interaction modeling, detection performance, and deployment efficiency while keeping the parameter scale at 0.236 million.

Unknown authors · 0 citations
Open access 2026

Hardening the IoT Edge: A TRADES-Based Approach for Robust Network Intrusion Detection

Deep-learning-based Network Intrusion Detection Systems (NIDS) play a vital role in protecting Internet of Things (IoT) environments; however, they remain vulnerable to adversarial examples, in which small input perturbations can cause misclassification. Previous research has considered that there exists a trade-off between model accuracy and robustness; however, this work seeks to prove that TRADES, which uses KL divergence regularization, does not exhibit this trade-off on IoT tabular data. It has been shown that TRADES enables aligning the decision boundaries of the DNN with causal traffic feature spaces rather than vulnerable anomalies. For the Bot-IoT dataset, TRADES has achieved almost full robustness (~100%) against three different attacks including PGD, FGSM, and C&W in a bounded threat model ( $\epsilon $ =0.1). In addition, the TRADES framework has improved the robustness of models in case of data brittleness through using SMOTE method on NSL-KDD imbalanced dataset, leading to an increase of 55 points in robustness. Furthermore, cross-dataset evaluation on UNSW-NB15 and CICIDS2017 datasets has demonstrated good generalization properties (86.10% and 93.20% PGD robustness). Apart from theoretical findings, we provide practical validation for edge deployment within sub-millisecond latency (0.03 ms/packet) based on a quantized 150 KB TensorFlow Lite model, demonstrating promising potential for deployment in IoT devices using latency measurements.

Aqeel S. Azez, Maytham S Jabor, Alberto Bonastre et al. · 0 citations
Conference Aug 2026

Probabilistic Graph Learning Based Anomaly Detection Framework for Internet of Things Security

The blistering growth of the Internet of Things (IoT) networks has posed considerable issues of security because of the growing number of connected devices and the susceptibility of them to cyberattacks. Conventional anomaly detectors usually cannot reflect complicated communication association and dynamic behavioral trends that exist in the IoT context. This paper suggests a Probabilistic Graph Learning Based Anomaly Detection (PGL-AD) model on the CICIoT2023 data. The suggested method models IoT devices as the nodes of a probabilistic graph, with the communication relationships included as weighted edges with the probabilities of interactions. Learning through graph representation is used to learn probabilistic embeddings that incorporate structural and behavioral network traffic attributes. Probabilistic inference is carried out to calculate anomaly scores to determine abnormal communication patterns. Experimental performance shows that the proposed framework has reached $99.08 \%, 98.86 \%, 98.91 \%$, and $98.86\%$ detection accuracy, precision, recall, and F1-score respectively, and is superior to the traditional machine learning and deep learning models. The probabilistic graph learning algorithm is a good algorithm with the capability to learn network dependencies and uncertainty, to be able to detect anomalies accurately and at scale. The proposed framework is a dependable and effective measure of increasing the security of IoT and ensuring that connected devices are not affected by developing cyber threats.

T. H. Vidhya, K. Nithya, K. Alqawasmi et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.