A Federated Learning and LLM-Driven Threat Intelligence for Zero Trust IoT Architecture is presented, with FL for anomaly detection integrating privacy-preserving distributed learning, continuous identity verification, and LLM-driven autonomous threat response into a unified pipeline.
Abstract
While the Internet of Things (IoT) has become essential, they introduced serious security and privacy challenges, especially for mission-critical environments. Legacy devices are vulnerable to viruses, data breaches, and unauthorized access, and updating these devices would be infeasibly costly. As a solution, this paper presents a Federated Learning and LLM-Driven Threat Intelligence for Zero Trust IoT Architecture, with FL for anomaly detection integrating privacy-preserving distributed learning, continuous identity verification, and LLM-driven autonomous threat response into a unified pipeline. Unlike existing solutions, our framework enforces Zero Trust at every communication layer via mutual TLS (mTLS) over MQTT, ensuring no device or message is implicitly trusted. Our experiments with Raspberry Pis and various sensors achieve an F1 score of 0.9091 and an ROC-AUC of 1.0, highlighting the effectiveness of the proposed framework in enabling privacy-preserving anomaly detection for resource-constrained IoT devices.
A lightweight edge AI framework that employs federated learning, enabling model training across distributed Internet of People and Things (IoP) devices without transferring raw data to centralised servers is proposed, enabling responsive, privacy-preserving, and resilient edge AI operations in distributed environments.
F. Philip-Kpae, A. Imoize, Lloyd Endurance Ogbondamati et al.· E3S Web of Conferences· 0 citations
This work proposes an intelligent, lightweight Tiny LSTM–GRU hybrid IDS on the edge to monitor device-generated behavioral patterns in real time, with minimal computational and energy overhead, and proposes an adaptive FedProx-based weighted federated learning framework.
Emmanuel Udok, B. Stephen, U. Luke et al.· E3S Web of Conferences· 0 citations
AI security is a key design criterion for IoT and edge cloud architectures where learning models are embedded near physical processes, receive streaming data from sensors, and are subject to continuous updates. This survey research work proposes a lifecycle-based understanding of AI security threats and proposed a unified taxonomy for the four major categories of threats observed in real-world settings, namely, data poisoning and backdoor attacks on learning model updates, adversarial attacks on model outputs through input manipulation, privacy leakage of confidential information through model-based queries, and model extraction for intellectual property theft and creation of rogue replicas of learning models. The research in surveying these defenses takes account of the limitations posed by the use of edge computing platforms from a computational standpoint, latency tolerance, network connections, and variety of hardware. These defense mechanisms include model provenance and data screening, robust training and backdoor attacks, monitoring and calibration, privacy-preserving learning and access control, and model protection through throttling, fingerprinting, watermarking, and attestation. Unlike prior surveys that treat these threats separately, this survey unifies them under a lifecycle-based taxonomy tailored to IoT and edge cloud deployments and emphasizes deployable defenses under latency, compute, and hardware constraints.
Venkatesan Cherappa, Hsin-Hung Cho, Yasir Abdullah Rabi et al.· Journal of Internet Technolo...· 0 citations
—The proposed study suggests a to help cope with issues related to cybersecurity in Internet of Things and Industrial Internet of Things environments without compromising privacy. The proposed framework introduces several innovative features, such as federated learning with momentum-based optimization, adaptive differential privacy, trust verification via blockchain, and Byzantine-resilient aggregation, to enhance the security, scalability, and robustness of the system compared with traditional intrusion detection systems. It also integrates supervised classification with autoencoder-based anomaly detection to detect existing and emerging cyberattacks. The proposed system was assessed with respect to the extended Industrial Internet of Things Intrusion Dataset (X-IIoT) and Network-Based Botnet Attack detection for IoT (N-BaIoT) benchmark datasets, where the environments were simulated as federated ones. The accuracy of the Hybrid Robust Federated Intrusion Detection System increased to 97.15% on X-IIoT and 97.64% on N-BaIoT with only 41 communication rounds and was resilient against up to 20% of Byzantine clients. These results showcase its efficacy to secure, private and communication-efficient intrusion detection for next generation Internet of Things and Hybrid Robust Federated Intrusion Detection System networks.
The rapid expansion of Internet of Things (IoT) edge networks has introduced significant cybersecurity challenges due to the increasing number of resource-constrained devices operating outside traditional security perimeters. Conventional perimeter-based defenses are inadequate against Advanced Persistent Threats (APTs), which exploit compromised edge devices through stealthy, multi-stage attacks involving reconnaissance, lateral movement, command-and-control communication, and data exfiltration. This study presents Edge-ZTA, a lightweight Zero-Trust Architecture specifically designed for securing Industrial IoT edge environments. The proposed framework integrates three complementary components: dynamic device identity verification based on trusted attestation and behavioral fingerprinting, continuous behavioral monitoring using a Federated Deep Autoencoder for privacy-preserving anomaly detection, and Software-Defined Networking (SDN)-based dynamic micro-segmentation for real-time isolation of compromised devices. A comprehensive hybrid experimental testbed comprising physical edge devices, virtualized nodes, and 500,000 network flow records derived from benchmark cybersecurity datasets was developed to evaluate the proposed architecture under realistic APT scenarios. Experimental results demonstrated a weighted macro-average F1-score of 97.1%, with detection rates of 98.9%, 97.9%, 96.8%, and 95.9% for reconnaissance, lateral movement, command-and-control, and exfiltration attacks, respectively. Furthermore, the decentralized edge-based policy decision mechanism maintained end-to-end latency below 50 ms, while CPU utilization remained below 17%, confirming the framework's suitability for resource-constrained IoT deployments. Scalability experiments involving up to 500 edge nodes further verified stable detection accuracy and predictable latency under heterogeneous operating conditions. These findings demonstrate that Edge-ZTA provides an efficient, privacy-preserving, and scalable cybersecurity framework capable of mitigating sophisticated multi-stage cyberattacks while satisfying the stringent performance requirements of next-generation Industrial IoT infrastructures.
Ahmed Ramzi Rashid, Zaydon L. Ali, Al-Doori, Ahmed Sedeeq Baker· Al-Noor Journal of Engineeri...· 0 citations
Smart healthcare IoT systems are vulnerable to cyber threats as they deal with sensitive patient information. Problems such as privacy, scalability, and delayed response to threats in distributed healthcare environments challenge centralized security approaches. To mitigate the security challenges of cloud-edge healthcare IoT systems, this paper presents FL-EZTF, a privacy-preserving, Federated Deep Learning and Enhanced Zero Trust Framework. The framework combines federated learning, Enhanced Zero Trust Architecture (E-ZTA), and Secure Access Service Edge (SASE). In this framework, lightweight deep learning models are developed locally at hospitals and various edge nodes without the need to transfer sensitive medical data. In place of raw data, model updates are sent conveniently through a trustaware federated learning process. Simultaneously, E-ZTA performs continuous authentication, micro-segmentation, and access control to rapidly contain threats. The framework is assessed using CIC-IoT-2023, IoT-23, and WESAD datasets. The experimental results show improved accuracy in detection, lower rates of false positives, a significant reduction in the latency of decisions, and enhanced containment as compared to centralized and traditional federated learning.
Unknown authors· International Journal of Eng...· 0 citations