A Privacy-Preserving Intrusion Detection System for IoT Networks Using Federated Learning
DOI:
https://doi.org/10.31185/wjes.Vol14.Iss3.997Keywords:
Internet of Things (IoT), Intrusion Detection System (IDS), Federated Learning (FL)Abstract
With the increasing presence of IoT devices in the real world, this widespread presence leads to serious security challenges related to the privacy of these devices' data. Despite the important role of intrusion detection system (IDS) and its ability to identify malicious security activities in traditional centralized learning solutions that rely on collecting raw data from devices and sharing it directly to a central server, these solutions may raise concerns regarding data privacy and an increase in communication overhead. To address these challenges, this study proposes a privacy-preserving intrusion detection system using federated learning (FL) that enables distributed IoT devices to engage in collaborative learning, without share the raw data, only updates, with taking into account the preservation of data privacy, all existing IoT clients independently train the Multilayer Perceptron (MLP) models on their own data only, and then share only the models updates with the central server, the Federated Averaging (FedAvg) algorithm is used within the central server to aggregate the updates and create a global model. The proposed framework was evaluated using the NF-BoT-IoT dataset. The experimental results demonstrate that the proposed lightweight IDS achieves an accuracy of 83.21% and an F1-score of 81.78 %, with performance comparable to the centralized learning approach while preserving client data privacy. In addition, the proposed hybrid feature selection approach reduces the feature space from eight to five features, resulting in measurable computational benefits. In particular, leading to a 15.21% reduction in inference time, a 4.59% reduction in training time, and a 2.78% reduction in memory usage. These results demonstrate that the proposed framework not only maintains competitive detection performance and data privacy but also reduces computational and memory requirements, supporting its suitability as an effective and lightweight IDS for resource-constrained IoT environments.
References
[1] A. Heidari and M. A. Jabraeil Jamali, “Internet of Things intrusion detection systems: a comprehensive review and future directions,” Cluster Comput., vol. 26, no. 6, pp. 3753–3780, Dec. 2023, doi: 10.1007/s10586-022-03776-z. DOI: https://doi.org/10.1007/s10586-022-03776-z
[2] M. Aziz Al Kabir, W. Elmedany, and M. S. Sharif, “Securing IoT Devices Against Emerging Security Threats: Challenges and Mitigation Techniques,” 2023, Taylor and Francis Ltd. doi: 10.1080/23742917.2023.2228053. DOI: https://doi.org/10.1080/23742917.2023.2228053
[3] A. Zohourian, S. Dadkhah, H. Molyneaux, E. C. P. Neto, and A. A. Ghorbani, “IoT-PRIDS: Leveraging packet representations for intrusion detection in IoT networks,” Comput. Secur., vol. 146, Nov. 2024, doi: 10.1016/j.cose.2024.104034. DOI: https://doi.org/10.1016/j.cose.2024.104034
[4] M. M. Rahman, S. Al Shakil, and M. R. Mustakim, “A survey on intrusion detection system in IoT networks,” Dec. 01, 2025, KeAi Communications Co. doi: 10.1016/j.csa.2024.100082. DOI: https://doi.org/10.1016/j.csa.2024.100082
[5] M. Ali Khan, R. Naveed Bin Rais, O. Khalid, and F. Gul Khan, “A Comparative Analysis of Federated and Centralized Machine Learning for Intrusion Detection in IoT.”
[6] T. Bunko, M. N. Johnstone, W. Yang, and B. A. Scott, “A survey of privacy-preserving federated learning for intrusion detection systems,” Artif. Intell. Rev., vol. 59, no. 5, May 2026, doi: 10.1007/s10462-026-11519-4. DOI: https://doi.org/10.1007/s10462-026-11519-4
[7] T. D. Nguyen, S. Marchal, M. Miettinen, H. Fereidooni, N. Asokan, and A.-R. Sadeghi, “DÏoT: A Federated Self-learning Anomaly Detection System for IoT,” May 2019, [Online]. Available: http://arxiv.org/abs/1804.07474 DOI: https://doi.org/10.1109/ICDCS.2019.00080
[8] R. Zhao, Y. Yin, Y. Shi, and Z. Xue, “Intelligent intrusion detection based on federated learning aided long short-term memory,” Physical Communication, vol. 42, Oct. 2020, doi: 10.1016/j.phycom.2020.101157. DOI: https://doi.org/10.1016/j.phycom.2020.101157
[9] S. A. Rahman, H. Tout, C. Talhi, and A. Mourad, “Internet of Things intrusion Detection: Centralized, On-Device, or Federated Learning?,” IEEE Netw., vol. 34, no. 6, pp. 310–317, Nov. 2020, doi: 10.1109/MNET.011.2000286. DOI: https://doi.org/10.1109/MNET.011.2000286
[10] E. Novikova, E. Doynikova, and S. Golubev, “Federated Learning for Intrusion Detection in the Critical Infrastructures: Vertically Partitioned Data Use Case,” Algorithms, vol. 15, no. 4, Apr. 2022, doi: 10.3390/a15040104. DOI: https://doi.org/10.3390/a15040104
[11] E. M. Campos et al., “Evaluating Federated Learning for intrusion detection in Internet of Things: Review and challenges,” Computer Networks, vol. 203, Feb. 2022, doi: 10.1016/j.comnet.2021.108661. DOI: https://doi.org/10.1016/j.comnet.2021.108661
[12] A. Khraisat, A. Alazab, M. Alazab, A. Obeidat, S. Singh, and T. Jan, “Federated learning for intrusion detection in IoT environments: a privacy-preserving strategy,” Discover Internet of Things, vol. 5, no. 1, p. 72, Jun. 2025, doi: 10.1007/s43926-025-00169-7. DOI: https://doi.org/10.1007/s43926-025-00169-7
[13] J. Arshad, M. A. Azad, M. M. Abdeltaif, and K. Salah, “An intrusion detection framework for energy constrained IoT devices,” Mech. Syst. Signal Process., vol. 136, Feb. 2020, doi: 10.1016/j.ymssp.2019.106436. DOI: https://doi.org/10.1016/j.ymssp.2019.106436
[14] Z. ElSayed, A. Abdelgawad, and N. Elsayed, “Cybersecurity and Frequent Cyber Attacks on IoT Devices in Healthcare: Issues and Solutions,” Jan. 2025, [Online]. Available: http://arxiv.org/abs/2501.11250 DOI: https://doi.org/10.1109/ICMI65310.2025.11141075
[15] M. Bhavsar, K. Roy, J. Kelly, and O. Olusola, “Anomaly-based intrusion detection system for IoT application,” Discover Internet of Things, vol. 3, no. 1, Dec. 2023, doi: 10.1007/s43926-023-00034-5. DOI: https://doi.org/10.1007/s43926-023-00034-5
[16] E. Altulaihan, M. A. Almaiah, and A. Aljughaiman, “Anomaly Detection IDS for Detecting DoS Attacks in IoT Networks Based on Machine Learning Algorithms,” Sensors, vol. 24, no. 2, Jan. 2024, doi: 10.3390/s24020713. DOI: https://doi.org/10.3390/s24020713
[17] N. Islam et al., “Towards Machine Learning Based Intrusion Detection in IoT Networks,” Computers, Materials and Continua, vol. 69, no. 2, pp. 1801–1821, 2021, doi: 10.32604/cmc.2021.018466. DOI: https://doi.org/10.32604/cmc.2021.018466
[18] Safana Hyder Abbas, Wedad Abdul Khuder Naser, and Amal Abbas Kadhim, “Subject review: Intrusion Detection System (IDS) and Intrusion Prevention System (IPS),” Global Journal of Engineering and Technology Advances, vol. 14, no. 2, pp. 155–158, Feb. 2023, doi: 10.30574/gjeta.2023.14.2.0031. DOI: https://doi.org/10.30574/gjeta.2023.14.2.0031
[19] H. Liu et al., “Blockchain and Federated Learning for Collaborative Intrusion Detection in Vehicular Edge Computing,” IEEE Trans. Veh. Technol., vol. 70, pp. 6073–6084, Apr. 2021, doi: 10.1109/TVT.2021.3076780. DOI: https://doi.org/10.1109/TVT.2021.3076780
[20] I. H. Sarker, “Deep Learning: A Comprehensive Overview on Techniques, Taxonomy, Applications and Research Directions,” Nov. 01, 2021, Springer. doi: 10.1007/s42979-021-00815-1. DOI: https://doi.org/10.20944/preprints202108.0060.v1
[21] Bassam et al., “A Comparative Study of IDS-Based Deep Learning Models for IoT Network,” 2023 International Conference on Advances in Artificial Intelligence and Applications (AAIA 2023), November 18â•fi20, 2023, Wuhan, China, vol. 1, 2023, doi: 10.1145/3603273. DOI: https://doi.org/10.1145/3603273
[22] S. Maza and M. Touahria, “Feature selection algorithms in intrusion detection system: A survey,” KSII Transactions on Internet and Information Systems, vol. 12, no. 10, pp. 5079–5099, 2018, doi: 10.3837/tiis.2018.10.024. DOI: https://doi.org/10.3837/tiis.2018.10.024
[23] N. Pudjihartono, T. Fadason, A. W. Kempa-Liehr, and J. M. O’Sullivan, “A Review of Feature Selection Methods for Machine Learning-Based Disease Risk Prediction,” 2022, Frontiers Media SA. doi: 10.3389/fbinf.2022.927312. DOI: https://doi.org/10.3389/fbinf.2022.927312
[24] A. Omotosho, Y. Qendah, and C. Hammer, “IDS-MA: Intrusion Detection System for IoT MQTT Attacks Using Centralized and Federated Learning.” [Online]. Available: https://www.kaggle.com/datasets/edotfs/dht11-temperature-and-humidity-
[25] M. Ali Khan, R. N. Bin Rais, O. Khalid, and M. Deriche, “Comparative Analysis of Centralized and Federated Intrusion Detection in IoT-Enabled Cyber-Physical Systems Under Data and Label-Skew,” IEEE Access, vol. 13, pp. 160767–160785, 2025, doi: 10.1109/ACCESS.2025.3608856. DOI: https://doi.org/10.1109/ACCESS.2025.3608856
[26] G. Drainakis, K. V. Katsaros, P. Pantazopoulos, V. Sourlas, and A. Amditis, “Federated vs. Centralized Machine Learning under Privacy-elastic Users: A Comparative Analysis,” in 2020 IEEE 19th International Symposium on Network Computing and Applications, NCA 2020, Institute of Electrical and Electronics Engineers Inc., Nov. 2020. doi: 10.1109/NCA51143.2020.9306745. DOI: https://doi.org/10.1109/NCA51143.2020.9306745
[27] D. C. Nguyen, M. Ding, P. N. Pathirana, A. Seneviratne, J. Li, and H. V. Poor, “Federated Learning for Internet of Things: A Comprehensive Survey,” Apr. 2021, doi: 10.1109/COMST.2021.3075439. DOI: https://doi.org/10.1109/COMST.2021.3075439
[28] M. Venkatasubramanian, A. H. Lashkari, and S. Hakak, “IoT Malware Analysis Using Federated Learning: A Comprehensive Survey,” IEEE Access, vol. 11, pp. 5004–5018, 2023, doi: 10.1109/ACCESS.2023.3235389. DOI: https://doi.org/10.1109/ACCESS.2023.3235389
[29] J. Wen, Z. Zhang, Y. Lan, Z. Cui, J. Cai, and W. Zhang, “A survey on federated learning: challenges and applications,” International Journal of Machine Learning and Cybernetics, vol. 14, no. 2, pp. 513–535, Feb. 2023, doi: 10.1007/s13042-022-01647-y. DOI: https://doi.org/10.1007/s13042-022-01647-y
[30] S. Agrawal et al., “Federated Learning for Intrusion Detection System: Concepts, Challenges and Future Directions,” Jun. 2021, [Online]. Available: http://arxiv.org/abs/2106.09527
[31] M. Sarhan, S. Layeghy, N. Moustafa, and M. Portmann, “NetFlow Datasets for Machine Learning-based Network Intrusion Detection Systems,” Nov. 2020, doi: 10.1007/978-3-030-72802-1_9. DOI: https://doi.org/10.1007/978-3-030-72802-1_9
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Ali Abd alraheem, Ali Obeid, Bassam Noori Shaker

This work is licensed under a Creative Commons Attribution 4.0 International License.

