Jul 2026· IEEE International Conference on Consumer Electronics· pp. 107-112· 0 citations· 22 references
Abstract
Federated Learning has become a practical approach for training intrusion detection models across distributed Internet of Things devices, but it remains exposed to poisoning attacks, non-IID data heterogeneity, and free-rider exploitation. This paper presents DT-Guard, a defense framework that leverages a server-side Digital Twin as a controlled testing environment for actively verifying client model behavior. Each submitted update is deployed in the Digital Twin and evaluated on synthetic challenge data through a four-layer pipeline that examines detection capability, backdoor resistance, parameter deviation, and cross-round stability. A complementary aggregation scheme called DT-Driven Performance Weighting compares client predictions against the current global model, exposing free-riders whose outputs are nearly indistinguishable from the global baseline. We validate DT-Guard on CIC-IoT-2023 under five poisoning strategies. DT-Guard generally outperforms nine existing defenses in accuracy, false positive rate, and contribution fairness.
The results show a success in implementing a real time, scalable, privacy-preserving, and adaptive IDS in large-scale IoT deployments through intelligent workload distribution between edge and cloud layers.
Chidera Winifred John, Eduediuyai Ekerete Dan, P. Asuquo et al.· E3S Web of Conferences· 0 citations
The framework is presented as a bounded, server-assisted robustness-oriented training strategy for heterogeneous IoT/edge intrusion detection, and shows competitive primary performance and stronger robustness in several severe label-skew settings.
Xudong Yang, Zikui Lin, Qiuyan Li et al.· Electronics· 0 citations
SplittingFed-DP relocates the Gaussian DP mechanism from the high-dimensional gradient to the low-dimensional activation space at the cut layer, audited under Rényi differential privacy and proves that this same Gaussian release coincides with the randomised-smoothing operator of Cohen et al. at the cut layer.
Rguibi Arjdal, Y. Asimi, Ahmed Asimi et al.· EPJ Web of Conferences· 0 citations
Federated Bandit Intrusion Detection (FBID), a novel adaptive PFL framework to address this limitation through server-side personalization control, employs a contextual multi-armed bandit at the server to dynamically regulate each client's local training intensity according to its observed behavior and update quality.
A. Bui, C. T. Nguyen, Hoang-Anh Pham et al.· 0 citations
The rapid expansion of the Internet of Things (IoT) has intensified cybersecurity risks by exposing distributed connected devices to increasingly complex and pervasive threats. Conventional centralized security mechanisms often struggle to accommodate the heterogeneous and decentralized structure of IoT networks. This study investigates Federated Learning (FL) as a decentralized approach to intrusion detection that enables local model training on IoT edge devices while transmitting only encrypted model updates to a central server, thereby preserving data privacy and reducing communication overhead. A novel FL-based Intrusion Detection System (IDS) architecture was developed using Convolutional Neural Networks (CNNs) for anomaly detection and the Federated Averaging (FedAvg) algorithm for aggregating local model updates. The framework was evaluated on standard IoT datasets under non-independent and identically distributed (non-IID) data conditions to simulate heterogeneous real-world environments. Experimental results demonstrate that the proposed system achieved a detection accuracy of 94.6%, an F1-score of 93.8%, and a recall of 92.7%, outperforming centralized and standalone local learning methods. The framework also reduced communication overhead by 35% and achieved convergence 28% faster than conventional approaches. These findings demonstrate that FL can provide a scalable, privacy-preserving, and computationally efficient foundation for strengthening IoT cybersecurity. This study contributes a decentralized machine-learning architecture for real-time, adaptive, and privacy-conscious intrusion detection in large-scale IoT environments.
Mohammed Ajuji, Y. M. Malgwi, A. Ahmadu et al.· International Journal of Edu...· 0 citations
Healthcare Internet of Things (HIoT) deployments generate sensitive patient telemetry data on resource-constrained edge devices, which are prime targets for network intrusions. Centralizing raw telemetry for training intrusion detection system (IDS) models violates patient privacy and contravenes data-protection regulations such as HIPAA and GDPR. This paper proposes PPFL-IDS, a Privacy-Preserving Federated Learning framework for intrusion detection in HIoT environments. PPFL-IDS combines federated model aggregation with differential privacy noise injection and secure aggregation protocols to train a lightweight gradient-boosted ensemble IDS without exposing local device data. A heterogeneity-aware client selection mechanism addresses the challenge of non-independent and identically distributed (non-IID) data inherent in multi-site HIoT deployments. Evaluated on the UNSW-NB15 and a synthetic HIoT dataset spanning five attack categories, PPFL-IDS achieves a weighted F1-score of 0.938 and a mean detection latency of 20.3 ms, outperforming FedAvg, FedProx, and SCAFFOLD baselines while satisfying an ε-differential privacy budget of 1.2. Results demonstrate that strong privacy guarantees and high detection accuracy can be achieved simultaneously in federated HIoT security architectures.
Nutan Gusain, J. Alzubi· International Journal on Com...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.