Skip to content
#federated learning Open access

A resource-aware framework for energy and bandwidth efficient IoT intrusion detection using lightweight federated learning over SDN

Oct 2026 · Scientific Reports
Network Security and Intrusion Detection

Abstract

The rapid growth of Internet of Things (IoT) deployments has widened the network attack surface while increasing the cost of centralised intrusion detection, particularly when raw traffic must be moved to remote servers. We propose HFL-SDN-IDS, a hierarchical, resource-aware framework that combines a lightweight federated intrusion-detection model, two-tier aggregation, and an SDN-assisted enforcement layer. The contribution is a system-level co-design rather than a new federated aggregation rule. Experiments use five benchmark datasets-CICIDS-2017, N-BaIoT, TON_IoT, Edge-IIoTset, and UNSW-NB15. Under the default CICIDS-2017 configuration ( \(N=100\) , \(K=10\) , \(\alpha =0.5\) ), the retained aggregate comparison reports 98.93% detection accuracy, 18.4 MB/round of model-based communication accounting, and 3.87 J/round of model-based energy consumption, compared with 38.6 MB/round and 9.82 J/round for FedAvg. In the fixed 10,000-sample six-family classification evaluation used for class-wise reporting, HFL-SDN-IDS achieves 98.6% accuracy, 98.6% weighted F1, and 96.9% Macro-F1. These values correspond to 52.3% lower reported bandwidth and 60.6% lower reported energy, while convergence is reached in 31.3% fewer communication rounds. In the scalability study, the reported HFL-SDN-IDS bandwidth increases from 18.4 MB/round at \(N=100\) to 41.6 MB/round at \(N=1{,}000\) ; the corresponding FedAvg reference at \(N=1{,}000\) is 389.7 MB/round. The SDN control channel has an analytical worst-case reporting overhead of approximately 1.28 KB/round under the default participation setting, and the Mininet enforcement measurements show a median latency of 4.3 ms and a 99th-percentile latency of 11.7 ms. Controlled ablation separates the contributions of the lightweight model, hierarchical topology, and SDN-assisted configuration. Overall, the results support a resource-aware, data-local approach to large-scale IoT intrusion detection while also highlighting the limitations of simulation-based resource accounting and the absence of formal privacy or Byzantine-robustness guarantees in the proposed method.

Read PDF

Similar papers

#machine learning Review Open access Oct 2014

Software development in startup companies: A systematic mapping study

The results indicate that software engineering work practices are chosen opportunistically, adapted and configured to provide value under the constrains imposed by the startup context.

Nicolò Paternoster, Carmine Giardino, M. Unterkalmsteiner et al. · 394 citations · ⚡54
#machine learning Review Open access Jun 2014

Why Early-Stage Software Startups Fail: A Behavioral Framework

This state-of-practice investigation was performed using a literature review followed by a multiple-case study approach and presents how inconsistency between managerial strategies and execution can lead to failure by means of a behavioral framework.

Carmine Giardino, Xiaofeng Wang, P. Abrahamsson · 175 citations · ⚡19
#machine learning Review Open access Oct 2016

“Failures” to be celebrated: an analysis of major pivots of software startups

This study conducts a case survey study based on the secondary data of the major pivots happened in 49 software startups, and demonstrates that customer need pivot is the most common among all pivot types.

Sohaib Shahid Bajwa, Xiaofeng Wang, Anh Nguyen-Duc et al. · 127 citations · ⚡15
#machine learning Review Open access May 2016

Key Challenges in Software Startups Across Life Cycle Stages

It is found that what perceived as biggest challenges by software startups do vary across different life cycle stages, even though its significance decreases when the learning focuses of the startups move from problem to solution and their products mature.

Xiaofeng Wang, Henry Edison, Sohaib Shahid Bajwa et al. · 62 citations · ⚡6

Related blog posts

MIT News · Artificial Intelligence Oct 7, 2026

Discovering the value of humanistic inquiry

Students in MIT’s Concourse program delve deeply into the human condition, debate challenging questions, and learn to develop judgment about issues that can’t be quantified.

Microsoft Research Blog Oct 7, 2026

Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses

Training AI agents with reinforcement learning can be challenging because their tools, context, and decision-making are managed by complex frameworks. Agent Lightning connects existing agents to RL training, making it easier to improve them without rebuilding them. The post Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses appeared first on Microsoft Research.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.