Skip to content
Conference

Scenario-Based Federated Learning for Privacy-Aware IoT Botnet Intrusion Detection

Sep 2026 · 2026 IEEE 1st International Conference on Artificial Intelligence Implementation & Applications (ICAIIA) · pp. 321-326 · 0 citations · 23 references

Abstract

Federated learning (FL) is a promising approach for IoT intrusion detection because it enables distributed clients to collaboratively train models without pooling raw network-flow records. However, IoT traffic is often heterogeneous across monitoring sites, devices, and attack scenarios, which can degrade federated model performance. This paper evaluates scenariobased FL for privacy-aware IoT botnet intrusion detection using IoT-23. Instead of randomly partitioning data into artificial clients, real IoT-23 capture scenarios are treated as federated clients to simulate non-IID IoT gateways. A compact multilayer perceptron, SmallMLP, is evaluated on binary benign/malicious detection and seven-class attack-family classification under centralized learning, local-only training, FedAvg, and personalized FedAvg. The final experiment uses a balanced 35,000-record IoT-23 flow-level subset with five scenario-based clients. Results show that FedAvg performs strongly for binary intrusion detection, achieving 0.9721 accuracy and 0.9382 macro-F1, improving over local-only training by 0.4307 macro-F1. In contrast, multiclass FedAvg reaches 0.6901 accuracy and 0.5979 macro-F1, improving over local-only training by 0.4870 but remaining sensitive to scenario-level non-IID partitions. The findings suggest that FedAvg can support raw-data-minimizing IoT IDS training for binary detection, but more advanced federated and personalization methods are needed for robust multiclass botnet classification.

View source

Similar papers

Conference Open access 2026

Enhanced Intrusion Detection in IoT Networks using Federated Learning

The results show a success in implementing a real time, scalable, privacy-preserving, and adaptive IDS in large-scale IoT deployments through intelligent workload distribution between edge and cloud layers.

Chidera Winifred John, Eduediuyai Ekerete Dan, P. Asuquo et al. · 0 citations
Open access Aug 2026

A Privacy-Preserving Federated Learning Framework for Intrusion Detection in Healthcare IoT Environments

PPFL-IDS combines federated model aggregation with differential privacy noise injection and secure aggregation protocols to train a lightweight gradient-boosted ensemble IDS without exposing local device data, demonstrating that strong privacy guarantees and high detection accuracy can be achieved simultaneously in fed...

Nutan Gusain, J. Alzubi · 0 citations
#machine learning Preprint Sep 2026

Reliable Federated TinyML Deployment for IoT Security

This work investigates combining Federated Learning with TinyML-based model compression for intrusion detection in IoT environments and preliminary results show that training stability plays a critical role in federated TinyML systems.

Younsoo Park, Seokhyoen Bae, Shasi Kumar Ramachandran Prabhu et al. · 1 citation
Open access 2026

Federated Learning for Privacy-preserving Internet of Things (IoT) Security: A Decentralized Intrusion Detection Framework

The proposed framework introduces several innovative features, such as federated learning with momentum-based optimization, adaptive differential privacy, trust verification via blockchain, and Byzantine-resilient aggregation, to enhance the security, scalability, and robustness of the system compared with traditional...

M. Ramzan · 0 citations
Open access Aug 2026

A Three-Stage Federated Distillation Framework for Robust Intrusion Detection in Heterogeneous IoT/Edge Networks

The framework is presented as a bounded, server-assisted robustness-oriented training strategy for heterogeneous IoT/edge intrusion detection, and shows competitive primary performance and stronger robustness in several severe label-skew settings.

Xu-Dong Yang, Zikui Lin, Qiu-Yan Li et al. · 0 citations

FedCAMP-IDS: a federated cluster-aware memory-augmented prototypical network for intrusion detection in heterogeneous IoT environments

This paper proposes FedCAMP-IDS, a Federated Cluster-Aware Memory-Augmented Prototypical Network for privacy-preserving intrusion detection in distributed network environments, and integrates Cluster-Aware Contrastive Pretraining, memory-augmented few-shot prototypical learning, adaptive prototype mixing, and Extreme V...

A. Yadav, V. Pawar, Roshni Yadav · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.