Skip to content
Open access

Privacy-Preserving Intrusion Detection in Smart Traffic Networks

Woh Xiang Huai, Lin Peng, Sarah Diong Yu Jie Su-Bo-Yu-Zhang-Liang Yu Zainab Hana, Tan Min Hong
Jul 2026 · International Journal of Emerging Multidisciplinaries: Computer Science & Artificial Intelligence · 0 citations · 65 references

TL;DR

Findings indicate that FL-IDS is better at performance compared to Cloud-IDS and traditional ML-IDS, with a high detection rate of 95% and a false-positive rate of 1.8 percent, proving to be highly resilient with secure aggregation and differential privacy.

Abstract

Smart transportation and associated systems are becoming more susceptible as they also apply to cyber threats such as Distributed Denial-of-Service (DDoS), model poisoning, node impersonation, and ransomware lateral movement using more interconnected IoT products (traffic controllers, sensors, cameras, etc.). The current centralized Intrusion Detection Systems (IDS) have structural disadvantages, namely, high latency, bandwidth overhead, privacy exposure, and single-point collision, which limit their applicability in real and safety-critical urban settings. In order to handle these gaps, this research will suggest a Federated Learning Multi-layer Intrusion Detection System (FL-IDS) that is specifically crafted to intelligent traffic infrastructures. The architecture incorporates edge-based anomaly detection, federated collaborative learning, secure aggregation, differential privacy, encrypted communication (TLS 1.3, MQTT-S, SNMPv3), and devices-integrity (Secure Boot and firmware signing). Every intersection does its local detection and transmits the encrypted model updates, which allows them to learn globally and capture the local traffic features. Detection performance, latency, and bandwidth consumption coupled with resistance to poisoning attacks were tested within a conceptual experimental framework comprising of the CICIoT2023 dataset and trafficking simulated variations in the real world. Findings indicate that FL-IDS is better at performance compared to Cloud-IDS and traditional ML-IDS, with a high detection rate of 95% and a false-positive rate of 1.8 percent along with a detection latency of 80 ms and bandwidth consumption of 2.3 MB. With the conditions of model-poisoning, the reduction in accuracy is only as high as 8 percent, proving to be highly resilient with secure aggregation and differential privacy.

Read PDF

Similar papers

Conference Open access 2026

An Intelligent Intrusion Detection and Privacy-Preserving Architecture for the Internet of Medical Things (IoMT)

This work proposes an intelligent, lightweight Tiny LSTM–GRU hybrid IDS on the edge to monitor device-generated behavioral patterns in real time, with minimal computational and energy overhead, and proposes an adaptive FedProx-based weighted federated learning framework.

Emmanuel Udok, B. Stephen, U. Luke et al. · 0 citations
Open access Jul 2026

Latency aware trust weighted federated intrusion detection for secure 6G vehicular IoT

This paper proposes a federated intrusion-detection framework for autonomous-vehicle Internet of Things (IoT) networks in future 6G transport systems. Here, IoT refers to the connected sensors, vehicles, roadside units, and control platforms that continuously exchange operational data. The framework, FL-AIID-AV, allows vehicles to train a shared detection model without sending raw traffic or sensor data to a central server. Its secure aggregation mechanism for autonomous vehicle (SecAggAV), combines anomaly screening of model updates, history-based trust weighting, client-side differential privacy, encrypted update transport, and latency-aware round control. In the current implementation, the aggregation server is trusted for decryption, anomaly scoring, and trust computation, while encryption protects updates in transit. This trusted-server assumption is intended as a pragmatic transitional design choice for near-term edge-cloud 6G deployments rather than as the end-state of a fully decentralised 6G architecture; the same trust-weighting logic can later be migrated to server-opaque or multi-coordinator secure aggregation. On the CICIoV2024 benchmark, the method reaches 98.2% accuracy in benign settings and 95.4% under 20% poisoning, with edge inference latency below 50 ms. We additionally evaluate the method on TON-IoT, Edge-IIoTset, and a strict de-duplicated CICIoV2024 split. Under this complementary evaluation track, SecAggAV attains 97.42% accuracy on TON-IoT, 95.84% on Edge-IIoTset, and a macro-F1 score, that is, the unweighted average F1 across classes, of 0.712 on the de-duplicated CICIoV2024 corpus. Overall, the results show that the proposed framework remains robust under heterogeneous data, adversarial updates, and latency constraints while providing better visibility into minority-attack detection.

Q. Mamun, Md. Mujibur Rahman, Mehedi Hasan et al. · 0 citations
Open access Aug 2026

Automated Network Intrusion Detection for Internet of Things Security Enhancements

As interconnected devices increasingly transmit personal and sensitive data, security attacks are becoming more sophisticated and prevalent, highlighting the critical need for effective security solutions in Internet of Things (IoT) environments. An automated Network Intrusion Detection (NID) system plays a vital role in notifying system administrators of security breaches, acting as an efficient tool for protecting IoT networks from various threats. This study utilizes the UNSW-NB 15 dataset to enhance intrusion detection accuracy by addressing performance challenges and class imbalances within the data. We employ a combination of feature selection techniques, including Filter Method, Wrapper Method, and an Embedded approach using Lasso and Random Forest with Recursive Feature Elimination (RFE), alongside Pearson Correlation Coefficient (PCC). To tackle class imbalance, we apply the Synthetic Minority Over-sampling Technique (SOMTE). Various algorithms are implemented, including Random Forest, Decision Tree, AdaBoost, Bernoulli Naive Bayes, K-Nearest Neighbors, and Logistic Regression. Notably, the Stacking Classifier, which combines Boosted Decision Trees, Bagging with Random Forest, and LightGBM, demonstrates high performance in accurately detecting intrusions, significantly improving detection rates and reducing false alarms.

Rangu Shashidhar, M. Raju · 1 citation
Open access Sep 2026

Edge Computing-Enabled Secure Federated Learning for Anomaly Detection in Industrial IoT Sensor Streams

The rise of the Industrial IoT (IIoT) will result in a surge of IIoT devices with high-velocity data streams requiring rapid, real-time analysis of these data streams to power predictive maintenance and assure cybersecurity. Centralized cloud-based approaches to anomaly detection are hindered by their inherent latency and privacy issues while independent or stand-alone approaches to edge-based anomaly detection do not have enough data to effectively detect anomalies. This paper presents a federated learning framework to collaboratively develop an anomaly detection model from multiple edge nodes, without sharing the raw sensor data, so that data sovereignty is preserved. Two major contributions of this research include a lightweight hybrid secure aggregation method that utilizes pairwise additive masking and differential privacy, which mitigates the threat of inversion attacks achieved via a reconstruction SSIM < 0.05, and successfully detects >90% of model poisoning attempts, where as traditional homomorphic encryption solutions incur excessively high computational costs (approximately 68 ms/node) and 70 KB of communication overhead/round). Our architecture was validated using a synthetic IIoT data set containing 600,000 rows of data correlated across 12 edge nodes and 10 different types of sensors, and further validated using the real-world SWaT data set. The experimental results demonstrated the effectiveness of the framework, achieving an F1 score of 0.944 for anomaly detection, an F2 from centralized training of only 2.3%, and a 60-70% reduction in communication costs compared to the use of homomorphic encryption. The experimental results also demonstrate that local edge inference latency is <50 ms, meeting the real-time requirements of IIoT systems. Overall, the framework demonstrates that practical, deployable security for federated learning in IIoT is achievable without sacrificing accuracy or responsiveness, and open-source implementations are provided to ensure full reproducibility.

Wijdan Noaman Marzoog Al Mukhtar · 0 citations
Open access Sep 2026

A Privacy-Preserving Intrusion Detection System for IoT Networks Using Federated Learning

With the increasing presence of IoT devices in the real world, this widespread presence leads to serious security challenges related to the privacy of these devices' data. Despite the important role of intrusion detection system (IDS) and its ability to identify malicious security activities in traditional centralized learning solutions that rely on collecting raw data from devices and sharing it directly to a central server, these solutions may raise concerns regarding data privacy and an increase in communication overhead. To address these challenges, this study proposes a privacy-preserving intrusion detection system using federated learning (FL) that enables distributed IoT devices to engage in collaborative learning, without share the raw data, only updates, with taking into account the preservation of data privacy, all existing IoT clients independently train the Multilayer Perceptron (MLP) models on their own data only, and then share only the models updates with the central server, the Federated Averaging (FedAvg) algorithm is used within the central server to aggregate the updates and create a global model. The proposed framework was evaluated using the NF-BoT-IoT dataset. The experimental results demonstrate that the proposed lightweight IDS achieves an accuracy of 83.21% and an F1-score of 81.78 %, with performance comparable to the centralized learning approach while preserving client data privacy. In addition, the proposed hybrid feature selection approach reduces the feature space from eight to five features, resulting in measurable computational benefits. In particular, leading to a 15.21% reduction in inference time, a 4.59% reduction in training time, and a 2.78% reduction in memory usage. These results demonstrate that the proposed framework not only maintains competitive detection performance and data privacy but also reduces computational and memory requirements, supporting its suitability as an effective and lightweight IDS for resource-constrained IoT environments.

Ali Abd Alraheem, Ali Obeid, Bassam Noori Shaker · 0 citations
Conference Jul 2026

A Lightweight Intrusion Detection System for Constrained IoT Devices

Traditional Internet of Things (IoT) security solutions often rely on heavy cloud-based or gateway-class infrastructure, which is frequently unsuitable for resource-limited hardware due to latency, power, and memory constraints. This paper proposed a resource-aware behavioral Intrusion Detection System (IDS) designed for highly constrained IoT devices. To address these challenges, the proposed system implements real-time application-layer monitoring on an ESP32 Microcontroller Unit (MCU) and utilizes an offline-trained logistic regression model for autonomous, on-device inference. The detection mechanism extracts behavioral features, such as request rates, failed authentication attempts, and invalid resource access within sliding time windows to estimate attack probabilities. Experimental evaluations under controlled scenarios involving flood, brute force, and scan attacks demonstrate that the system achieves high accuracy, precision, and recall. These findings indicate that effective cyber intrusion detection and local mitigation can be successfully executed directly on a single MCU while preserving stable runtime performance and minimal memory usage. Finally, this paper highlights the need for further optimizations to improve robustness and scalability.

Sofyan Bisher, Anas Fawaza, Tarek Mawed et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.