A lightweight federated learning-based IDS that combines Random Forest for feature selection and Temporal Convolutional Network (TCN) for deep learning classification is presented that achieves superior attack-detection performance.
The rapid expansion of the Internet of Things (IoT) has intensified cybersecurity risks by exposing distributed connected devices to increasingly complex and pervasive threats. Conventional centralized security mechanisms often struggle to accommodate the heterogeneous and decentralized structure of IoT networks. This study investigates Federated Learning (FL) as a decentralized approach to intrusion detection that enables local model training on IoT edge devices while transmitting only encrypted model updates to a central server, thereby preserving data privacy and reducing communication overhead. A novel FL-based Intrusion Detection System (IDS) architecture was developed using Convolutional Neural Networks (CNNs) for anomaly detection and the Federated Averaging (FedAvg) algorithm for aggregating local model updates. The framework was evaluated on standard IoT datasets under non-independent and identically distributed (non-IID) data conditions to simulate heterogeneous real-world environments. Experimental results demonstrate that the proposed system achieved a detection accuracy of 94.6%, an F1-score of 93.8%, and a recall of 92.7%, outperforming centralized and standalone local learning methods. The framework also reduced communication overhead by 35% and achieved convergence 28% faster than conventional approaches. These findings demonstrate that FL can provide a scalable, privacy-preserving, and computationally efficient foundation for strengthening IoT cybersecurity. This study contributes a decentralized machine-learning architecture for real-time, adaptive, and privacy-conscious intrusion detection in large-scale IoT environments.
Mohammed Ajuji, Y. M. Malgwi, A. Ahmadu et al.· International Journal of Edu...· 0 citations
The results show a success in implementing a real time, scalable, privacy-preserving, and adaptive IDS in large-scale IoT deployments through intelligent workload distribution between edge and cloud layers.
Chidera Winifred John, Eduediuyai Ekerete Dan, P. Asuquo et al.· E3S Web of Conferences· 0 citations
The proliferation of Internet of Things (IoT) devices in smart home environments has dramatically expanded the attack surface for cyber threats, particularly botnet-driven Distributed Denial of Service (DDoS) attacks. Centralized Intrusion Detection Systems (IDS) are ill-suited to this domain because they violate user privacy, introduce single points of failure, and incur prohibitive communication overhead. Federated Learning (FL) offers a compelling privacy-preserving alternative, yet existing FL-based IDS solutions either deploy convolutional or recurrent models in isolation, lack human-interpretable outputs, or neglect real-world deployability constraints. This paper proposes FedShield-IDS, a novel federated intrusion detection framework that integrates a hybrid one-dimensional Convolutional Neural Network with Long Short-Term Memory units to simultaneously capture spatial traffic fingerprints and long-range temporal attack dynamics across IoT edge devices. Model interpretability is addressed through the integration of SHapley Additive exPlanations (SHAP), enabling administrators to receive human-readable justifications for every detected anomaly. The system is trained and evaluated on the large-scale CICIoT2023 dataset, comprising 712,311 flow records spanning eight attack families including DDoS, DoS, Mirai, Reconnaissance, Spoofing, Injection, and Malware. A multi-stage preprocessing pipeline combining infinite-value imputation, logarithmic feature scaling, Min-Max normalization, temporal windowing, and localized SMOTE oversampling is applied within each federated client to address non-IID data and extreme class imbalance. Federated Averaging aggregates encrypted model updates across seven virtual IoT client nodes over five communication rounds without exchanging raw traffic data, under a formal threat model characterizing the system’s adversarial assumptions and data-confidentiality guarantees. Experimental results demonstrate a Mirai F1-score of 0.99, a DDoS precision of 0.97, and a global weighted F1-score of 0.76 across all eight classes. Comprehensive kernel-size, architecture, and preprocessing ablations confirm the necessity of each design choice, and independent cross-dataset evaluation on the Edge-IIoTset benchmark achieves 98.58% accuracy, demonstrating strong generalization beyond CICIoT2023. The framework achieves sub-500 ms threat mitigation, empirically confirmed via a mitigation-gate threshold sensitivity analysis, and generates SHAP-gated explanations for every alert, bridging the gap between high-accuracy detection and the transparency required for trustworthy smart-home security.
Ghada Abdelhady, Karim Wael Hussein, Islam Anwar Ali Gad· Scientific Reports· 0 citations
The rapid growth of IoT-enabled technologies and interconnected smart devices has significantly increased security risks associated with poorly protected and resource-constrained IoT environments. Efficient anomaly detection mechanisms can help mitigate these threats by analyzing network traffic and identifying abnormal activities. However, such mechanisms must also preserve user privacy and maintain scalability for deployment on low-power edge devices. This paper presents
XP-IDS
: a hybrid deep gradient boosting framework for intrusion detection in IoT networks. Using the
CIC IoT-DIAD 2024
dataset,
XP-IDS
learns from three categories of handcrafted features: (i) strategic-based features that capture high-level protocol semantics and flow behavior, (ii) time-based features that represent sequential relationships and traffic evolution over time, and (iii) IP-based features that characterize packet-flow communication among IoT endpoints. Feature representations extracted through stacked Convolutional Neural Networks are subsequently forwarded to an Extreme Gradient Boosting classifier for final prediction. In addition, SHapley Additive exPlanation (SHAP) is utilized to provide interpretability for model decisions and to identify overall feature importance, thereby enhancing transparency and privacy-aware analysis. Extensive experimental evaluation demonstrates that the proposed framework achieves strong detection accuracy across several common attack categories while outperforming multiple baseline approaches. The proposed accurate and interpretable framework shows strong potential as an edge-deployable security solution for safeguarding IoT devices and improving cyber resilience.
Prabhav Jain, Aashima Sharma, A. Noonia et al.· Scientific Reports· 0 citations
A hierarchical privacy protection and poisoning-robust defense framework for industrial federated learning is proposed and can effectively suppress global-model degradation under multiple poisoning attacks and achieves a favorable balance among privacy protection strength, robustness, and training efficiency.
Huan Yin, Cong Chen, Jing-Yi Zhang et al.· Italian National Conference...· 0 citations
An Internet of Things-based, privacy-preserving Federated Learning (FL) framework for predicting machine failures in Industry 5.0 is proposed, addressing the frequently neglected concerns of data privacy and decentralized operational settings.
Shriya Seth, Harshpreet Singh, Suhasini Monga et al.· Journal of Quality in Mainte...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.