Sep 2026· 2026 IEEE 1st International Conference on Artificial Intelligence Implementation & Applications (ICAIIA)· pp. 321-326· 0 citations· 23 references
Abstract
Federated learning (FL) is a promising approach for IoT intrusion detection because it enables distributed clients to collaboratively train models without pooling raw network-flow records. However, IoT traffic is often heterogeneous across monitoring sites, devices, and attack scenarios, which can degrade federated model performance. This paper evaluates scenariobased FL for privacy-aware IoT botnet intrusion detection using IoT-23. Instead of randomly partitioning data into artificial clients, real IoT-23 capture scenarios are treated as federated clients to simulate non-IID IoT gateways. A compact multilayer perceptron, SmallMLP, is evaluated on binary benign/malicious detection and seven-class attack-family classification under centralized learning, local-only training, FedAvg, and personalized FedAvg. The final experiment uses a balanced 35,000-record IoT-23 flow-level subset with five scenario-based clients. Results show that FedAvg performs strongly for binary intrusion detection, achieving 0.9721 accuracy and 0.9382 macro-F1, improving over local-only training by 0.4307 macro-F1. In contrast, multiclass FedAvg reaches 0.6901 accuracy and 0.5979 macro-F1, improving over local-only training by 0.4870 but remaining sensitive to scenario-level non-IID partitions. The findings suggest that FedAvg can support raw-data-minimizing IoT IDS training for binary detection, but more advanced federated and personalization methods are needed for robust multiclass botnet classification.
The results show a success in implementing a real time, scalable, privacy-preserving, and adaptive IDS in large-scale IoT deployments through intelligent workload distribution between edge and cloud layers.
Chidera Winifred John, Eduediuyai Ekerete Dan, P. Asuquo et al.· E3S Web of Conferences· 0 citations
PPFL-IDS combines federated model aggregation with differential privacy noise injection and secure aggregation protocols to train a lightweight gradient-boosted ensemble IDS without exposing local device data, demonstrating that strong privacy guarantees and high detection accuracy can be achieved simultaneously in fed...
Nutan Gusain, J. Alzubi· International Journal on Com...· 0 citations
This work investigates combining Federated Learning with TinyML-based model compression for intrusion detection in IoT environments and preliminary results show that training stability plays a critical role in federated TinyML systems.
Younsoo Park, Seokhyoen Bae, Shasi Kumar Ramachandran Prabhu et al.· 1 citation
The proposed framework introduces several innovative features, such as federated learning with momentum-based optimization, adaptive differential privacy, trust verification via blockchain, and Byzantine-resilient aggregation, to enhance the security, scalability, and robustness of the system compared with traditional...
The framework is presented as a bounded, server-assisted robustness-oriented training strategy for heterogeneous IoT/edge intrusion detection, and shows competitive primary performance and stronger robustness in several severe label-skew settings.
Xu-Dong Yang, Zikui Lin, Qiu-Yan Li et al.· Electronics· 0 citations
This paper proposes FedCAMP-IDS, a Federated Cluster-Aware Memory-Augmented Prototypical Network for privacy-preserving intrusion detection in distributed network environments, and integrates Cluster-Aware Contrastive Pretraining, memory-augmented few-shot prototypical learning, adaptive prototype mixing, and Extreme V...
A. Yadav, V. Pawar, Roshni Yadav· Cluster Computing· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.