Intelligent defense at the edge: a comprehensive survey of federated learning, TinyML and explainable AI for intrusion detection in IoT and IIoT ecosystems
Abstract
The proliferation of Internet of Things (IoT) and Industrial Internet of Things (IIoT) technologies has fundamentally transformed contemporary computing infrastructures by interconnecting large heterogeneous devices, sensors, embedded systems, and cyber-physical platforms. These ecosystems support diverse applications including smart cities, intelligent transportation, industrial automation, medical surveillance, precision agriculture and home automation. Despite their operational advantages, the vast connectivity and inherent resource constraints of IoT devices significantly expand the cyberattack surface. Limited processing power, limited memory and restricted energy budgets render conventional cybersecurity solutions infeasible for IoT environments. Consequently, IoT systems have become prime targets for advanced threats, including malware, botnets, Distributed Denial of Service (DDoS) attacks, ransomware, insider attacks and data manipulation. Traditional Intrusion Detection Systems (IDS), designed for enterprise networks, rely on centralized data collection and computationally intensive machine learning models that are unsuitable for IoT deployments due to scalability limitations, communication overhead, latency constraints and privacy concerns. Recent research has therefore shifted toward lightweight, intelligent and distributed cybersecurity frameworks capable of providing robust protection under severe resource limitations. This survey comprehensively reviews recent advances in AI-based intrusion detection and malware analysis for IoT ecosystems, covering lightweight machine learning models (ML), deep learning (DL) architectures for edge deployment, federated learning (FL) based privacy-preserving detection, TinyML on-device intelligence, blockchain-based trust management, Explainable AI (XAI) driven transparent monitoring and adaptive cyber defense. A unified conceptual framework is proposed integrating lightweight detection, distributed collaborative learning, trust-based orchestration and adaptive defense.