The results demonstrate that lightweight distribution-aware aggregation offers an effective, robust, and practically deployable solution for mitigating aggregation bias under simultaneous non-IID heterogeneity and severe multi-class imbalance in FL-based IoT botnet detection.
Abstract
Federated learning (FL) is a promising paradigm for privacy-preserving IoT intrusion detection, but its effectiveness can be substantially degraded by the combination of heterogeneous non-IID client distributions and severe multi-class imbalance. Under such conditions, conventional size-based aggregation may overemphasize large yet highly skewed clients, limiting the representation of minority attack classes in the global model. To address this issue, we propose Mean/Std, a lightweight distribution-aware aggregation strategy that combines a client-size proxy with two complementary statistics of local label distributions, namely the standard deviation and the dominance gap of class proportions, while preserving a communication footprint comparable to FedAvg. Experiments on the N-BaIoT benchmark, comprising seven heterogeneous IoT clients and eleven traffic classes, are conducted under a privacy-oriented update-perturbation setting inspired by secure aggregation workflows. The results show that Mean/Std consistently provides the strongest imbalance-aware performance among the evaluated FL baselines, achieving a Macro-F1 score of 0.8418 and a Balanced Accuracy of 0.8722 while improving the representation of minority attack classes. Additional experiments across five independent random seeds and a comprehensive hyperparameter sensitivity analysis further confirm the robustness and stability of the proposed aggregation mechanism. Overall, the results demonstrate that lightweight distribution-aware aggregation offers an effective, robust, and practically deployable solution for mitigating aggregation bias under simultaneous non-IID heterogeneity and severe multi-class imbalance in FL-based IoT botnet detection.
Experimental results demonstrate that the federated LLM-based models consistently outperform a multilayer perceptron baseline, with the LLaMA model achieving up to 99.9% accuracy and F1-score while generalising effectively to previously unseen device types.
Chloe Nazaruk, Rahim Taheri, Gelayol Golcarenarenji et al.· Journal of Supercomputing· 0 citations
Federated Bandit Intrusion Detection (FBID), a novel adaptive PFL framework to address this limitation through server-side personalization control, employs a contextual multi-armed bandit at the server to dynamically regulate each client's local training intensity according to its observed behavior and update quality.
A. Bui, C. T. Nguyen, Hoang-Anh Pham et al.· 0 citations
AF-BKM is presented, an Adaptive Federated Baseline K-Means that repairs the federated mechanism with two label-free, statistics-only enhancements, and identifies merge-induced precision decay under non-IID workers as an open gap.
Internet of Things (IoT) botnet detection requires high predictive performance, low client-side resource demands, and limited exposure of raw traffic data. This paper presents a traffic-constrained multi-client split-learning (TC-SL) intrusion-detection system evaluated on BoT-IoT, N-BaIoT, and CIC-IDS2017 using eight clients and one edge server. TC-SL is positioned as a resource-constrained engineering adaptation of standard split learning: it profiles candidate cut layers, selects the highest-performing feasible cut under an explicit communication budget, and trains by exchanging cut-layer activations and gradients while raw records remain local. Centralized, federated, split-learning, and SplitFed-v1 models were compared with matched partitions and optimization budgets. Split learning achieved macro F1 scores of 98.88%, 98.42%, and 97.51% on the three datasets, respectively, with a mean macro F1 of 98.27%, compared with 98.52% for centralized learning, 97.84% for federated learning, and 98.39% for SplitFed. Its pooled ROC-AUC and average precision were 0.985 and 0.980. Within the fixed 10-epoch systems workload, the selected L4 cut logged 95 MB of bidirectional communication per epoch and 0.95 GB in total, versus 405 MB per epoch and 4.05 GB for the configured federated-learning baseline; these byte totals are fixed-workload measurements rather than communication-to-target-accuracy claims. The early split minimized cumulative client energy at 248 J, whereas the middle split minimized total-system energy at 780 J. Across L1–L6, reconstruction NRMSE increased from 0.18 to 0.71, membership-inference AUC decreased from 0.71 to 0.53, label- and attribute-inference success decreased from 0.84 and 0.76 to 0.55 and 0.54, inversion success decreased from 75% to 20%, and poisoning-induced macro-F1 degradation decreased from 6.8 to 3.9 percentage points. The results identify a practical accuracy–communication–energy–privacy operating point for constrained IoT clients.
Mohammad Alja’afreh, Ali Karime, Aziz Oukaira· IoT· 0 citations
Accurate IoT device identification is critical to network forensics, access control, and anomaly detection in large-scale, security-sensitive environments. Federated learning (FL) provides a decentralized and privacy-enhancing approach well suited to IoT, but FL-based identification remains hampered by cross-client data heterogeneity, i.e., Non-IID distributions, and intra-client class imbalance, which jointly degrade global model performance and stability. To address these challenges, we propose MsaaDI, a novel federated device identification framework featuring Multi-Scale Adaptive Aggregation (MSAA) on the server side and a lightweight device fingerprinting pipeline with an enhanced local training strategy on the client side. The MSAA mechanism employs a three-stage aggregation scheme with real-time monitoring that robustly reweights heterogeneous client updates and refines global parameters to mitigate cross-client distribution skew, while the client design produces compact grayscale-image representations and alleviates intra-client imbalance and improves cross-client model consistency during local optimization. Extensive experiments on the UNSW and Aalto IoT device datasets show that, under extreme label-skewed Non-IID conditions with only 20% training data, MsaaDI achieves accuracies of 94.35% and 87.72%, respectively. It delivers up to 14.33% absolute improvement over the best-performing baseline, DA-PFL, and exhibits faster convergence and higher robustness. These results demonstrate MsaaDI’s effectiveness and adaptability for reliable IoT device identification in realistic deployments.
Tong Sun, Qian Lu, Hanlin Zhang et al.· IEEE Transactions on Informa...· 0 citations
Simulation of a Federated Learning framework for privacy-preserving anomaly detection tailored to heterogeneous IoT networks characterised by non-independent and identically distributed data, variable computational capacities, and intermittent connectivity indicates that the proposed method offers a practical, scalable, and regulation-compliant pathway toward trustworthy intrusion and anomaly detection in large-scale, heterogeneous IoT deployments.
Raushan Raj, B. L. Pal, Saurab Singh· International journal of com...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.