The framework is presented as a bounded, server-assisted robustness-oriented training strategy for heterogeneous IoT/edge intrusion detection, and shows competitive primary performance and stronger robustness in several severe label-skew settings.
Abstract
Internet of Things(IoT)/edge intrusion-detection systems operate on distributed traffic and system-state data whose distributions vary across gateways, services, and attack conditions. We study a server-assisted federated setting in which a teacher reference is fitted from a permitted server-accessible training pool and explicitly distinguish this simulation assumption from fully decentralized deployment. The proposed framework evaluates progressive local training through boundary stabilization, confidence-weighted decision distillation, representation alignment, and validation-quality-aware aggregation. The evaluation uses a leakage-controlled protocol: server and client validation subsets are held out before federated training, update quality and early stopping use validation data only, and the final-test split is evaluated once. Results on NSL-KDD, CIC-IDS2017, Edge-IIoTset, and the ToN-IoT network dataset show competitive primary performance and stronger robustness in several severe label-skew settings. On the Telemetry of Things(ToN-IoT) with Dirichlet alpha = 0.1, the proposed method achieves 91.46 ± 5.54 F1, compared with 53.73 ± 49.00 for FedAvg and 53.77 ± 48.92 for FedProx. The results do not establish universal superiority or a universally optimal stage order: competing methods remain stronger in selected stable and attack-shift settings. The framework is therefore presented as a bounded, server-assisted robustness-oriented training strategy for heterogeneous IoT/edge intrusion detection.
The results show a success in implementing a real time, scalable, privacy-preserving, and adaptive IDS in large-scale IoT deployments through intelligent workload distribution between edge and cloud layers.
Chidera Winifred John, Eduediuyai Ekerete Dan, P. Asuquo et al.· E3S Web of Conferences· 0 citations
AF-BKM is presented, an Adaptive Federated Baseline K-Means that repairs the federated mechanism with two label-free, statistics-only enhancements, and identifies merge-induced precision decay under non-IID workers as an open gap.
Introduction: The rapid expansion of Internet of Things (IoT) deployments has increased the cyber-attack surface and introduced heterogeneous traffic behaviour across devices, gateways, edge services, and network environments. Although many IoT intrusion detection studies report high performance under independent and identically distributed test conditions, such results often provide limited evidence of real deployment reliability, particularly for unseen hosts, cross-dataset transfers, and calibration drifts.
Methodology: This study presents a deployment-aware evaluation and calibration framework for IoT intrusion detection using a Denoising Autoencoder-Based Deep Feature Extraction (DAE-DFE) backbone. Rather than proposing a new neural architecture, this study focuses on robustness-oriented evaluation protocols and calibration-aware decision-making under domain shifts. The framework was evaluated using conventional IID splits, identifier-removed testing, and source-IP-based GroupSplit evaluation on NF-ToN-IoT-v2 to reduce the memorisation of the host. Cross-dataset robustness was assessed by converting Edge-IIoTset packet/protocol logs into pseudo-flows and testing Edge→NF and NF→Edge transfer using unsupervised threshold adaptation based on positive rate matching.
Results: On the NF-ToN-IoT-v2 GroupSplit, the framework achieved an F1 score of 0.9919 and ROC-AUC of 0.9997. In the Edge→NF cross-dataset setting, the model retained a meaningful ranking performance with ROC-AUC = 0.7962, while unsupervised threshold adaptation improved the target-domain accuracy from 0.4959 to 0.8878 and F1 score from 0.6630 to 0.8981.
Conclusion: The findings show that calibration-aware thresholding and deployment-realistic evaluation are essential for assessing IoT IDS reliability beyond the conventional IID accuracy.
Ola Madi Mohammed Al Mari· Majestic International Journ...· 0 citations
The findings support federated learning as a viable and communication-efficient direction for privacy-aware intrusion detection in distributed edge-security settings, while also highlighting the need for cautious interpretation, native V2X validation, and future robustness analysis against compromised federated clients.
Gateway-resident intrusion detection can act before IoT traffic reaches cloud services, but early decisions are based on incomplete flow prefixes. This paper presents a reliability-aware edge–cloud framework that treats early detection as a sequential routing problem. At each checkpoint, a lightweight gated recurrent unit (GRU) maps causal packet-prefix features to a malicious-probability estimate. Temperature scaling, asymmetric benign and malicious thresholds, and an eight-packet minimum-evidence gate determine whether a flow exits locally, remains under observation, or is sent for cloud refinement. Short and unresolved flows are classified by regularized logistic regression using a compact 97-feature causal representation. The edge model contains 19,777 parameters, and each cloud submission carries 388 bytes of float32 features. The principal evaluation uses all 309 CIC-IoT-2023 PCAP files under four outer PCAP-disjoint folds, with separate edge-training, calibration, cloud-development, and final-test roles. Across 2,286,754 pooled out-of-fold flows with 88.54% malicious prevalence, the framework resolves 422,190 flows at the edge and routes 1,864,564 for cloud refinement, reducing cloud submissions by 18.46%. The final policy attains 4.47% FPR, 1.89% FNR, 96.82% balanced accuracy, and 98.76% F1 score. Observation-budget analysis identifies 32 packets as a corpus-specific compromise, whereas controlled delays in post-eight-packet information expose the limits of short-prefix detection. On the balanced CICIDS2017 test set, in-domain development attains 97.03% balanced accuracy; zero-shot transfer falls to 86.30%, and target-calibration-only adaptation improves it to 91.65%. Ablation results identify the minimum-evidence gate and cloud-refinement stage as the main reliability controls. Benign false alarms, delayed post-eight-packet information, cross-dataset shift, and scenario/file-level labels remain the principal limitations.
Siraj Azam, Farheen Naaz, Mikail Mohammed Salim· Electronics· 0 citations
Federated Learning has become a practical approach for training intrusion detection models across distributed Internet of Things devices, but it remains exposed to poisoning attacks, non-IID data heterogeneity, and free-rider exploitation. This paper presents DT-Guard, a defense framework that leverages a server-side Digital Twin as a controlled testing environment for actively verifying client model behavior. Each submitted update is deployed in the Digital Twin and evaluated on synthetic challenge data through a four-layer pipeline that examines detection capability, backdoor resistance, parameter deviation, and cross-round stability. A complementary aggregation scheme called DT-Driven Performance Weighting compares client predictions against the current global model, exposing free-riders whose outputs are nearly indistinguishable from the global baseline. We validate DT-Guard on CIC-IoT-2023 under five poisoning strategies. DT-Guard generally outperforms nine existing defenses in accuracy, false positive rate, and contribution fairness.
H. Pham, Duy The Phan, Van-Hau Pham· IEEE International Conferenc...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.