Sep 2026· IEEE Internet of Things Journal· Vol 13, pp. 43319-43332· 0 citations· 31 references
Abstract
The increasing deployment of Edge–Internet of Things (IoT) networks intensifies the need for robust and privacy-preserving malware detection solutions. However, such environments are characterized by highly heterogeneous and nonindependent and identically distributed (non-IID) data distributions, limited computational resources, and strict privacy constraints, which collectively hinder the effectiveness of conventional centralized and federated learning (FL) approaches. Although transformer models and FL have independently shown promise for intrusion detection, their joint potential under statistical heterogeneity remains insufficiently explored. This work proposes a personalized transformer-based federated transfer learning (PTFTL) framework designed for efficient and adaptable malware detection in Edge–IoT environments. The proposed model introduces a lightweight projection layer that enables effective attention over raw traffic data while reducing computational burden. Personalization is achieved by keeping selected model components local to each device, thereby improving robustness under heterogeneous data distributions. Experimental results demonstrate that PTFTL substantially improves stability and detection performance under severe non-IID conditions. In particular, the inclusion of the projection layer enhances resilience to model collapse by up to 38%, whereas replacing it with a traditional embedding reduces stability by at least 10%, highlighting the critical role of the projection design in federated transformer models.
Overall, the proposed framework addresses three critical research gaps: preserving data privacy without centralized data aggregation, handling non-IID data distributions in IoT networks, and enabling efficient computation for resource-limited devices.
Baraa I. Farhan· Al-Noor Journal of Engineeri...· 0 citations
Federated learning (FL) enables multiple devices to collaboratively train machine learning models without sharing raw data, making it well-suited for Internet of Things (IoT) applications. However, this approach is not fully secure, as the exchanged gradients can still leak sensitive information. Attacks such as Deep L...
Federated Learning is investigated as a decentralized approach to intrusion detection that enables local model training on IoT edge devices while transmitting only encrypted model updates to a central server, thereby preserving data privacy and reducing communication overhead.
Mohammed Ajuji, Y. M. Malgwi, A. Ahmadu et al.· International Journal of Edu...· 0 citations
HAF-BiTrans is presented as a compact, edge-oriented federated architecture whose robustness under difficult non-IID conditions still requires further optimization and its practical strength is efficiency.
Tareef S. Alkellezli, Nariman A. Khalil· Sustainable Machine Intellig...· 0 citations
A decentralised federated learning (FL)-based IoT malware detection framework, evaluated using the recent IoT-23 dataset and systematically assessed in terms of robustness and scalability, highlighting the feasibility of robust and scalable FL-based security systems in real-world IoT deployments.
Saba Nayab, Sana Qadir, Madiha Khalid et al.· Journal of Computer Virology...· 0 citations
The rapid proliferation of Internet of Things (IoT) systems has significantly increased the attack surface of modern cyber-physical infrastructures, creating the need for scalable, intelligent, and privacy-preserving security solutions. Traditional centralized intrusion detection approaches are limited by high communic...
Afef Slimani, K. Karoui· International Symposium on N...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.