<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMC</journal-id>
<journal-id journal-id-type="nlm-ta">CMC</journal-id>
<journal-id journal-id-type="publisher-id">CMC</journal-id>
<journal-title-group>
<journal-title>Computers, Materials &#x0026; Continua</journal-title>
</journal-title-group>
<issn pub-type="epub">1546-2226</issn>
<issn pub-type="ppub">1546-2218</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">63734</article-id>
<article-id pub-id-type="doi">10.32604/cmc.2025.063734</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Securing Internet of Things Devices with Federated Learning: A Privacy-Preserving Approach for Distributed Intrusion Detection</article-title>
<alt-title alt-title-type="left-running-head">Securing Internet of Things Devices with Federated Learning: A Privacy-Preserving Approach for Distributed Intrusion Detection</alt-title>
<alt-title alt-title-type="right-running-head">Securing Internet of Things Devices with Federated Learning: A Privacy-Preserving Approach for Distributed Intrusion Detection</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Amro</surname><given-names>Sulaiman Al</given-names></name><email>samro@qu.edu.sa</email></contrib>
<aff id="aff-1"><institution>Department of Computer Science, College of Computer, Qassim University</institution>, <addr-line>Buraydah, 51452</addr-line>, <country>Saudi Arabia</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Sulaiman Al Amro. Email: <email>samro@qu.edu.sa</email></corresp>
</author-notes>
<pub-date date-type="collection" publication-format="electronic">
<year>2025</year>
</pub-date>
<pub-date date-type="pub" publication-format="electronic">
<day>19</day><month>05</month><year>2025</year>
</pub-date>
<volume>83</volume>
<issue>3</issue>
<fpage>4623</fpage>
<lpage>4658</lpage>
<history>
<date date-type="received">
<day>22</day>
<month>1</month>
<year>2025</year>
</date>
<date date-type="accepted">
<day>28</day>
<month>3</month>
<year>2025</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2025 The Author.</copyright-statement>
<copyright-year>2025</copyright-year>
<copyright-holder>Published by Tech Science Press.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMC_63734.pdf"></self-uri>
<abstract>
<p>The rapid proliferation of Internet of Things (IoT) devices has heightened security concerns, making intrusion detection a pivotal challenge in safeguarding these networks. Traditional centralized Intrusion Detection Systems (IDS) often fail to meet the privacy requirements and scalability demands of large-scale IoT ecosystems. To address these challenges, we propose an innovative privacy-preserving approach leveraging Federated Learning (FL) for distributed intrusion detection. Our model eliminates the need for aggregating sensitive data on a central server by training locally on IoT devices and sharing only encrypted model updates, ensuring enhanced privacy and scalability without compromising detection accuracy. Key innovations of this research include the integration of advanced deep learning techniques for real-time threat detection with minimal latency and a novel model to fortify the system&#x2019;s resilience against diverse cyber-attacks such as Distributed Denial of Service (DDoS) and malware injections. Our evaluation on three benchmark IoT datasets demonstrates significant improvements: achieving 92.78% accuracy on NSL-KDD, 91.47% on BoT-IoT, and 92.05% on UNSW-NB15. The precision, recall, and F1-scores for all datasets consistently exceed 91%. Furthermore, the communication overhead was reduced to 85 MB for NSL-KDD, 105 MB for BoT-IoT, and 95 MB for UNSW-NB15&#x2014;substantially lower than traditional centralized IDS approaches. This study contributes to the domain by presenting a scalable, secure, and privacy-preserving solution tailored to the unique characteristics of IoT environments. The proposed framework is adaptable to dynamic and heterogeneous settings, with potential applications extending to other privacy-sensitive domains. Future work will focus on enhancing the system&#x2019;s efficiency and addressing emerging challenges such as model poisoning attacks in federated environments.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Federated learning</kwd>
<kwd>internet of things</kwd>
<kwd>intrusion detection</kwd>
<kwd>privacy-preserving</kwd>
<kwd>distributed security</kwd>
</kwd-group>
<funding-group>
<award-group id="awg1">
<funding-source>Deanship of Graduate Studies and Scientific Research at Qassim University</funding-source>
<award-id>QU-APC-2025</award-id>
</award-group>
</funding-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>The Internet of Things (IoT) has revolutionized the way devices interact and communicate, transforming industries such as healthcare, agriculture, manufacturing, and urban infrastructure. The sheer volume of IoT devices, projected to reach nearly 30 billion by 2027, has led to a profound increase in data generation and information sharing among these connected devices [<xref ref-type="bibr" rid="ref-1">1</xref>&#x2013;<xref ref-type="bibr" rid="ref-3">3</xref>]. This explosion of IoT usage brings immense benefits, enabling automation, real-time monitoring, and enhanced efficiency [<xref ref-type="bibr" rid="ref-4">4</xref>&#x2013;<xref ref-type="bibr" rid="ref-7">7</xref>]. However, it also introduces a new set of vulnerabilities, primarily concerning data security and user privacy [<xref ref-type="bibr" rid="ref-8">8</xref>&#x2013;<xref ref-type="bibr" rid="ref-10">10</xref>]. IoT devices, ranging from simple home appliances to complex industrial machinery, often lack the computational power and security mechanisms required to protect themselves from cyber threats [<xref ref-type="bibr" rid="ref-11">11</xref>]. As a result, IoT networks are increasingly targeted by cybercriminals, with common attacks including Distributed Denial of Service (DDoS), unauthorized access, malware injection, and data breaches. Traditional security solutions, particularly centralized Intrusion Detection Systems (IDS), face challenges in adapting to the distributed and large-scale nature of IoT networks. Centralized IDS systems aggregate sensitive data from multiple devices to a central server, posing significant privacy risks and creating potential single points of failure [<xref ref-type="bibr" rid="ref-12">12</xref>].</p>
<p>To address these limitations, Federated Learning (FL) has emerged as a groundbreaking approach for securing IoT environments. Unlike conventional machine learning techniques that require data to be centralized, FL enables decentralized model training directly on IoT devices. Each device trains a local model using its private data and shares only the model updates (parameters) with a central server. This architecture ensures that sensitive user data remains on individual devices, reducing the risk of unauthorized data access or breaches [<xref ref-type="bibr" rid="ref-13">13</xref>]. By preserving data privacy and distributing the learning process, FL is particularly suited for IoT networks, which are inherently decentralized and often contain sensitive data [<xref ref-type="bibr" rid="ref-14">14</xref>&#x2013;<xref ref-type="bibr" rid="ref-16">16</xref>]. Despite its potential, deploying FL in IoT intrusion detection is not without challenges [<xref ref-type="bibr" rid="ref-17">17</xref>&#x2013;<xref ref-type="bibr" rid="ref-20">20</xref>]. Key concerns include managing the communication overhead associated with frequent model updates [<xref ref-type="bibr" rid="ref-21">21</xref>], safeguarding against adversarial attacks [<xref ref-type="bibr" rid="ref-22">22</xref>], and ensuring scalability [<xref ref-type="bibr" rid="ref-23">23</xref>&#x2013;<xref ref-type="bibr" rid="ref-26">26</xref>] in resource-constrained environments [<xref ref-type="bibr" rid="ref-27">27</xref>&#x2013;<xref ref-type="bibr" rid="ref-29">29</xref>]. Communication overhead can strain network bandwidth, especially as the number of devices increases, while adversarial attacks, such as model poisoning, can compromise the integrity of the system [<xref ref-type="bibr" rid="ref-30">30</xref>&#x2013;<xref ref-type="bibr" rid="ref-33">33</xref>]. Therefore, a comprehensive approach that addresses these challenges is essential for effective deployment [<xref ref-type="bibr" rid="ref-34">34</xref>&#x2013;<xref ref-type="bibr" rid="ref-36">36</xref>].</p>
<p>This study proposes a novel FL-based Intrusion Detection System (IDS) tailored for IoT, aiming to provide a privacy-preserving and scalable security solution. Our approach, named Federated Privacy-Preserving Intrusion Detection (FedPPID), integrates advanced deep learning methods within a federated framework to enhance detection accuracy without sacrificing privacy. FedPPID incorporates several key features, including differential privacy to protect individual model updates, a robust model aggregation process to reduce communication costs, and an anomaly detection mechanism to filter out malicious updates from adversarial nodes.</p>
<p>This paper proposes Federated Privacy-Preserving Intrusion Detection (FedPPID)&#x2014;a novel FL-based IDS designed for scalable, privacy-preserving, and adversarial robust intrusion detection in IoT ecosystems. The primary objective is to develop an efficient, secure, and privacy-enhanced model that effectively detects cyber threats while addressing the challenges associated with communication efficiency and adversarial resilience. To structure this research, the following research questions (RQs) are formulated:
<list list-type="bullet">
<list-item>
<p>RQ1: How can Federated Learning be leveraged to develop a privacy-preserving Intrusion Detection System (IDS) for large-scale IoT networks?</p></list-item>
<list-item>
<p>RQ2: What are the most effective communication optimization techniques to reduce the overhead of model parameter exchanges in FL-based IDS?</p></list-item>
<list-item>
<p>RQ3: How can FL-based IDS be made resilient against adversarial threats, such as model poisoning, data poisoning, and Byzantine attacks, without compromising detection accuracy?</p></list-item>
</list></p>
<p>The aim of this research is to develop a privacy-preserving, federated learning-based intrusion detection system (IDS) tailored for distributed IoT environments. This system will address the unique challenges of IoT security by enhancing privacy, scalability, and resistance to adversarial attacks, while maintaining high detection accuracy. Specifically, the key objectives of this research are:
<list list-type="simple">
<list-item><label>(a)</label><p>To design a distributed intrusion detection system using federated learning that enables IoT devices to collaboratively detect cyber threats without centralizing data.</p></list-item>
<list-item><label>(b)</label><p>To optimize communication protocols to reduce the overhead caused by frequent model updates between IoT devices and the central server, ensuring scalability in resource-constrained environments.</p></list-item>
</list></p>
<p>The novel contributions of this work lie in its unique integration of privacy-preserving techniques and adversarial robustness mechanisms within a Federated Learning (FL)-based Intrusion Detection System (IDS) for IoT networks. Unlike prior FL-based IDS models, which primarily focus on decentralized learning for anomaly detection, the proposed FedPPID framework introduces a multi-layered privacy protection strategy by incorporating Differential Privacy (DP) and Secure Multi-Party Computation (SMC) to safeguard model updates against leakage. Additionally, the study addresses a critical gap in existing research by implementing a weight-based anomaly detection mechanism to filter out adversarial updates, thereby mitigating model poisoning attacks&#x2014;a vulnerability often overlooked in conventional FL-IDS approaches. Furthermore, this work enhances communication efficiency by optimizing model aggregation strategies, significantly reducing bandwidth consumption while maintaining detection accuracy. The hybrid deep learning model, combining CNNs for feature extraction and RNNs for sequential analysis of network traffic, further differentiates this research from prior FL-IDS models that rely solely on conventional machine learning classifiers. These contributions collectively enhance the scalability, privacy preservation, and adversarial robustness of FL-based intrusion detection in large-scale, resource-constrained IoT environments, setting this work apart from previous approaches.</p>
<p>This research makes the following key contributions to the field of IoT security. The proposed system leverages federated learning to enable distributed intrusion detection while maintaining data privacy, reducing the need for centralized data storage and processing. The system incorporates differential privacy and secure multi-party computation to secure model updates and protect against model poisoning attacks and adversarial threats, which are common challenges in federated learning environments.</p>
<p>By addressing these challenges, this research advances the state of the art in securing IoT devices through federated learning, offering a scalable, secure, and privacy-preserving solution for distributed intrusion detection in IoT ecosystems.</p>
</sec>
<sec id="s2">
<label>2</label>
<title>Literature Review</title>
<p>The literature review explores existing research on Federated Learning (FL)-based Intrusion Detection Systems (IDS), emphasizing privacy-preserving techniques, adversarial robustness, and communication efficiency. Several studies, including those by [<xref ref-type="bibr" rid="ref-7">7</xref>,<xref ref-type="bibr" rid="ref-22">22</xref>], highlight the advantages of FL in decentralized intrusion detection, directly addressing RQ1 by demonstrating how FL can enhance security in large-scale IoT networks without requiring centralized data aggregation. Privacy concerns in FL-based IDS have been extensively studied, with techniques such as Differential Privacy (DP), Homomorphic Encryption (HE), and Secure Multi-Party Computation (SMC) being proposed to safeguard model updates and protect sensitive data. These methodologies provide crucial insights into answering RQ2 by ensuring that intrusion detection can be performed while maintaining user privacy. Furthermore, research on adversarial robustness has introduced mechanisms such as anomaly detection, Byzantine-robust aggregation, and secure model updates to mitigate threats like model poisoning and data poisoning attacks. These advancements contribute significantly to addressing RQ3, as they enhance the resilience of FL-based IDS against sophisticated cyber threats. Collectively, the literature underscores the necessity of integrating privacy-preserving and security-enhancing strategies within FL-based IDS to improve their effectiveness in real-world IoT environments.</p>
<sec id="s2_1">
<label>2.1</label>
<title>Security Challenges in IoT Networks</title>
<p>The rapid expansion of the Internet of Things (IoT) has significantly increased the number of interconnected devices, leading to major security vulnerabilities. Many IoT devices lack robust security mechanisms, making them susceptible to cyber threats, including Distributed Denial of Service (DDoS) attacks, malware injection, and unauthorized access [<xref ref-type="bibr" rid="ref-6">6</xref>&#x2013;<xref ref-type="bibr" rid="ref-8">8</xref>]. Traditional Intrusion Detection Systems (IDS), which rely on centralized architectures, struggle with scalability, privacy concerns, and computational inefficiency in distributed IoT environments [<xref ref-type="bibr" rid="ref-10">10</xref>&#x2013;<xref ref-type="bibr" rid="ref-12">12</xref>]. Therefore, a decentralized security solution is essential to address real-time threat detection and privacy preservation in large-scale IoT ecosystems.</p>
</sec>
<sec id="s2_2">
<label>2.2</label>
<title>Federated Learning for IoT Intrusion Detection</title>
<p>Federated Learning (FL) has emerged as a decentralized machine learning paradigm that enables intrusion detection across IoT networks without aggregating raw data on a central server. Studies like [<xref ref-type="bibr" rid="ref-7">7</xref>] and [<xref ref-type="bibr" rid="ref-22">22</xref>] demonstrate that FL-based IDS can enhance privacy and scalability, allowing devices to train local models and only share model parameters rather than sensitive data. Paper [<xref ref-type="bibr" rid="ref-12">12</xref>] further highlights FL&#x2019;s ability to handle heterogeneous device capacities, making it an adaptable intrusion detection framework. However, FL introduces communication overhead and is vulnerable to adversarial attacks, necessitating improvements in aggregation and privacy-preserving mechanisms [<xref ref-type="bibr" rid="ref-8">8</xref>,<xref ref-type="bibr" rid="ref-10">10</xref>,<xref ref-type="bibr" rid="ref-18">18</xref>].</p>
</sec>
<sec id="s2_3">
<label>2.3</label>
<title>Privacy-Preserving Techniques in FL-Based IDS</title>
<p>To mitigate privacy risks in FL-based IoT security, several techniques have been explored, including Differential Privacy (DP), Homomorphic Encryption (HE), and Secure Multi-Party Computation (SMC). The studies [<xref ref-type="bibr" rid="ref-16">16</xref>,<xref ref-type="bibr" rid="ref-17">17</xref>] developed FELIDS, an FL-based intrusion detection model for IoT that integrates DP to protect training data confidentiality. Similarly, paper [<xref ref-type="bibr" rid="ref-15">15</xref>] combines mimic learning and HE to preserve privacy while ensuring intrusion detection efficiency. These techniques prevent model updates from leaking sensitive information, thereby reducing susceptibility to data inference attacks [<xref ref-type="bibr" rid="ref-13">13</xref>,<xref ref-type="bibr" rid="ref-16">16</xref>,<xref ref-type="bibr" rid="ref-23">23</xref>]. However, existing privacy-preserving FL approaches must balance privacy guarantees with model performance to minimize accuracy degradation.</p>
</sec>
<sec id="s2_4">
<label>2.4</label>
<title>Adversarial Robustness in FL-Based IDS</title>
<p>FL-based IDS are prone to adversarial attacks, such as model poisoning, data poisoning, evasion attacks, and Byzantine attacks. In papers [<xref ref-type="bibr" rid="ref-8">8</xref>,<xref ref-type="bibr" rid="ref-10">10</xref>,<xref ref-type="bibr" rid="ref-18">18</xref>] emphasize the importance of anomaly detection mechanisms in FL models to filter out malicious updates and enhance model resilience. Paper [<xref ref-type="bibr" rid="ref-16">16</xref>] proposes secure model aggregation techniques to combat adversarial manipulation. Meanwhile, another studies [<xref ref-type="bibr" rid="ref-13">13</xref>,<xref ref-type="bibr" rid="ref-23">23</xref>] suggest incorporating blockchain-based verification for ensuring trustworthy model updates. Despite these advancements, FL remains vulnerable to sophisticated adversarial tactics, necessitating further enhancements in Byzantine-robust aggregation and anomaly detection frameworks.</p>
</sec>
<sec id="s2_5">
<label>2.5</label>
<title>Communication Efficiency in FL for IoT Security</title>
<p>A major challenge in FL-based IoT security is reducing communication overhead caused by frequent model parameter exchanges between devices and the central server. Paper [<xref ref-type="bibr" rid="ref-20">20</xref>] highlights that high bandwidth consumption makes FL impractical for resource-constrained IoT environments. Studies such as [<xref ref-type="bibr" rid="ref-23">23</xref>] and [<xref ref-type="bibr" rid="ref-13">13</xref>] propose compression techniques and adaptive update mechanisms to minimize network strain. Another study [<xref ref-type="bibr" rid="ref-6">6</xref>] suggests quantization-based model compression and adaptive update frequencies, reducing the data transmitted per training round, thus enhancing FL scalability.</p>
</sec>
<sec id="s2_6">
<label>2.6</label>
<title>Future Directions and Research Gaps</title>
<p>While FL-based IDS provides a decentralized and privacy-preserving approach to IoT security, several challenges remain. As summarized in <xref ref-type="table" rid="table-1">Table 1</xref>, existing studies lack real-world privacy-preserving implementations, optimized communication efficiency, and robust defenses against model poisoning attacks. Future research should focus on hybrid privacy-preserving techniques, such as combining DP, HE, and blockchain verification, alongside adaptive Byzantine-robust aggregation methods to enhance model resilience and scalability in real-world IoT deployments.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Comparison of studies on federated learning for IoT security</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th>Category</th>
<th>[<xref ref-type="bibr" rid="ref-7">7</xref>]</th>
<th>[<xref ref-type="bibr" rid="ref-12">12</xref>]</th>
<th>[<xref ref-type="bibr" rid="ref-16">16</xref>]</th>
<th>[<xref ref-type="bibr" rid="ref-8">8</xref>]</th>
</tr>
</thead>
<tbody>
<tr>
<td>Methodology</td>
<td>Centralized vs FL-based IDS Comparison</td>
<td>FL with adaptive deep learning for anomaly detection</td>
<td>FL-based IDS with Differential Privacy</td>
<td>Transfer learning in federated settings</td>
</tr>
<tr>
<td>Privacy-Preserving Techniques</td>
<td>None</td>
<td>Homomorphic Encryption (HE)</td>
<td>Differential Privacy (DP)</td>
<td>Secure Multi-Party Computation (SMC)</td>
</tr>
<tr>
<td>Results</td>
<td>FL outperforms centralized IDS in privacy and efficiency</td>
<td>High detection accuracy with low latency</td>
<td>High accuracy while preserving privacy</td>
<td>Improved detection accuracy for non-IID IoT data</td>
</tr>
<tr>
<td>Limitations</td>
<td>No real-world privacy implementation</td>
<td>High communication overhead</td>
<td>Vulnerability to model poisoning attacks</td>
<td>Increased computational complexity</td>
</tr>
<tr>
<td>Datasets used</td>
<td>IoT benchmark datasets</td>
<td>IoT cloud environments</td>
<td>Agricultural IoT data</td>
<td>Industrial IoT datasets</td>
</tr>
<tr>
<td>Future directions</td>
<td>Incorporate real-world privacy mechanisms</td>
<td>Reduce communication overhead and optimize detection</td>
<td>Strengthen security against adversarial threats</td>
<td>Enhance computational efficiency and handle data imbalance</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>This comparative analysis highlights key research gaps in FL-based IDS models, emphasizing the need for adaptive security mechanisms, improved communication efficiency, and robust privacy-preserving techniques to advance real-world IoT security applications.</p>
</sec>
</sec>
<sec id="s3">
<label>3</label>
<title>Proposed Problem Formulation</title>
<p>Here, we mathematically formulate the problem of securing IoT devices using a federated learning (FL) approach for intrusion detection, while ensuring privacy preservation and resilience against adversarial attacks. Consider a network of <inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:mrow><mml:mtext>N</mml:mtext></mml:mrow></mml:math></inline-formula> IoT devices, each holding a private dataset <inline-formula id="ieqn-2"><mml:math id="mml-ieqn-2"><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> for <inline-formula id="ieqn-3"><mml:math id="mml-ieqn-3"><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mrow><mml:mtext>N</mml:mtext></mml:mrow><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>. The overall aim is to collaboratively train a global intrusion detection model while maintaining data privacy, minimizing communication overhead, and ensuring robustness against adversarial model updates.</p>
<p>Let the global model parameters at time <inline-formula id="ieqn-4"><mml:math id="mml-ieqn-4"><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:math></inline-formula> be denoted by <inline-formula id="ieqn-5"><mml:math id="mml-ieqn-5"><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula>. Each device <inline-formula id="ieqn-6"><mml:math id="mml-ieqn-6"><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:math></inline-formula> maintains a local model with parameters <inline-formula id="ieqn-7"><mml:math id="mml-ieqn-7"><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msubsup></mml:math></inline-formula>, trained on its private dataset <inline-formula id="ieqn-8"><mml:math id="mml-ieqn-8"><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula>. The goal is to minimize the global loss function, which aggregates the weighted local losses from each device:
<disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:mrow><mml:mi>&#x02112;</mml:mi></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mrow><mml:mtext>N</mml:mtext></mml:mrow></mml:mrow></mml:munderover><mml:mfrac><mml:mrow><mml:mo>|</mml:mo><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>|</mml:mo></mml:mrow><mml:mrow><mml:mo>|</mml:mo><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mo>|</mml:mo></mml:mrow></mml:mfrac><mml:msub><mml:mrow><mml:mi>&#x02112;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>where <inline-formula id="ieqn-9"><mml:math id="mml-ieqn-9"><mml:msub><mml:mrow><mml:mi>&#x02112;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> represents the local loss on device <inline-formula id="ieqn-10"><mml:math id="mml-ieqn-10"><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:math></inline-formula>, and <inline-formula id="ieqn-11"><mml:math id="mml-ieqn-11"><mml:mrow><mml:mo>|</mml:mo><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mo>|</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mrow><mml:mtext>N</mml:mtext></mml:mrow></mml:mrow></mml:munderover><mml:mrow><mml:mo>|</mml:mo><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>|</mml:mo></mml:mrow></mml:math></inline-formula> is the total dataset size across all devices. For a neural network, the local loss function is given by:
<disp-formula id="eqn-2"><label>(2)</label><mml:math id="mml-eqn-2" display="block"><mml:msub><mml:mrow><mml:mi>&#x02112;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mrow><mml:mo>|</mml:mo><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>|</mml:mo></mml:mrow></mml:mfrac><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mtext>y</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:mrow></mml:munder><mml:mi>&#x2113;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>f</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo>;</mml:mo><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msubsup><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mtext>y</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>where <inline-formula id="ieqn-12"><mml:math id="mml-ieqn-12"><mml:mi>&#x2113;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> is a differentiable loss function (e.g., cross-entropy), <inline-formula id="ieqn-13"><mml:math id="mml-ieqn-13"><mml:mrow><mml:mtext>f</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo>;</mml:mo><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msubsup><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> is the model prediction, and <inline-formula id="ieqn-14"><mml:math id="mml-ieqn-14"><mml:mrow><mml:mtext>y</mml:mtext></mml:mrow></mml:math></inline-formula> is the true label.</p>
<p><bold>Distributed Learning Update:</bold></p>
<p>The local updates on each device are performed by minimizing the local loss using stochastic gradient descent (SGD). The local model on device <inline-formula id="ieqn-15"><mml:math id="mml-ieqn-15"><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:math></inline-formula> at iteration <inline-formula id="ieqn-16"><mml:math id="mml-ieqn-16"><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:math></inline-formula> is updated as follows:
<disp-formula id="eqn-3"><label>(3)</label><mml:math id="mml-eqn-3" display="block"><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msubsup><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="normal">&#x03B7;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mi mathvariant="normal">&#x2207;</mml:mi><mml:msub><mml:mrow><mml:mi>&#x02112;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>where <inline-formula id="ieqn-17"><mml:math id="mml-ieqn-17"><mml:msub><mml:mrow><mml:mi mathvariant="normal">&#x03B7;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> is the learning rate, and <inline-formula id="ieqn-18"><mml:math id="mml-ieqn-18"><mml:mi mathvariant="normal">&#x2207;</mml:mi><mml:msub><mml:mrow><mml:mi>&#x02112;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> is the gradient of the local loss function with respect to the local model parameters <inline-formula id="ieqn-19"><mml:math id="mml-ieqn-19"><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msubsup></mml:math></inline-formula>.</p>
<p>The global model is then updated by aggregating the local updates from all devices as follows:
<disp-formula id="eqn-4"><label>(4)</label><mml:math id="mml-eqn-4" display="block"><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mrow><mml:mtext>N</mml:mtext></mml:mrow></mml:mrow></mml:munderover><mml:mfrac><mml:mrow><mml:mo>|</mml:mo><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>|</mml:mo></mml:mrow><mml:mrow><mml:mo>|</mml:mo><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mo>|</mml:mo></mml:mrow></mml:mfrac><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msubsup></mml:math></disp-formula></p>
<p><bold>Privacy-Preserving Mechanism:</bold></p>
<p>To ensure differential privacy, Gaussian noise is added to the local model updates before they are transmitted to the central server. The perturbed update for each device <inline-formula id="ieqn-20"><mml:math id="mml-ieqn-20"><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:math></inline-formula> is given by:
<disp-formula id="eqn-5"><label>(5)</label><mml:math id="mml-eqn-5" display="block"><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msubsup><mml:mo>+</mml:mo><mml:mrow><mml:mi mathvariant="script">N</mml:mi></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="normal">&#x03C3;</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mrow><mml:mtext mathvariant="bold">I</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>where <inline-formula id="ieqn-21"><mml:math id="mml-ieqn-21"><mml:mrow><mml:mi mathvariant="script">N</mml:mi></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="normal">&#x03C3;</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mrow><mml:mtext mathvariant="bold">I</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> represents Gaussian noise with mean zero and variance <inline-formula id="ieqn-22"><mml:math id="mml-ieqn-22"><mml:msup><mml:mrow><mml:mi mathvariant="normal">&#x03C3;</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula>, ensuring <inline-formula id="ieqn-23"><mml:math id="mml-ieqn-23"><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow></mml:math></inline-formula>-differential privacy.</p>
<p><bold>Robustness against Adversarial Attacks:</bold></p>
<p>To prevent adversarial model poisoning attacks, the updates from each device are subjected to anomaly detection mechanisms. The Euclidean distance between the local update <inline-formula id="ieqn-24"><mml:math id="mml-ieqn-24"><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msubsup></mml:math></inline-formula> and the global model <inline-formula id="ieqn-25"><mml:math id="mml-ieqn-25"><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> must satisfy the following constraint:
<disp-formula id="eqn-6"><label>(6)</label><mml:math id="mml-eqn-6" display="block"><mml:mo stretchy="false">&#x2225;</mml:mo><mml:mspace width="negativethinmathspace" /><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msubsup><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mspace width="negativethinmathspace" /><mml:msub><mml:mo>&#x2225;</mml:mo><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>&#x2264;</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x03C1;</mml:mi></mml:mrow></mml:math></disp-formula>where <inline-formula id="ieqn-26"><mml:math id="mml-ieqn-26"><mml:mrow><mml:mi mathvariant="normal">&#x03C1;</mml:mi></mml:mrow></mml:math></inline-formula> is a predefined threshold. If this constraint is violated, the update from device <inline-formula id="ieqn-27"><mml:math id="mml-ieqn-27"><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:math></inline-formula> is excluded from the aggregation process.</p>
<p><bold>Communication Efficiency:</bold></p>
<p>To minimize communication overhead, the number of updates exchanged between devices and the central server is controlled. We impose a constraint on the total communication cost:
<disp-formula id="eqn-7"><label>(7)</label><mml:math id="mml-eqn-7" display="block"><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mrow><mml:mtext>N</mml:mtext></mml:mrow></mml:mrow></mml:munderover><mml:mo>&#x2225;</mml:mo><mml:mspace width="negativethinmathspace" /><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msubsup><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mspace width="negativethinmathspace" /><mml:msubsup><mml:mo>&#x2225;</mml:mo><mml:mrow><mml:mn>2</mml:mn></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msubsup><mml:mo>&#x2264;</mml:mo><mml:msub><mml:mrow><mml:mtext>C</mml:mtext></mml:mrow><mml:mrow><mml:mo movablelimits="true" form="prefix">max</mml:mo></mml:mrow></mml:msub></mml:math></disp-formula>where <inline-formula id="ieqn-28"><mml:math id="mml-ieqn-28"><mml:msub><mml:mrow><mml:mtext>C</mml:mtext></mml:mrow><mml:mrow><mml:mo movablelimits="true" form="prefix">max</mml:mo></mml:mrow></mml:msub></mml:math></inline-formula> represents the maximum allowable communication budget.</p>
<p><bold>Objective Function:</bold></p>
<p>The optimization problem for the global model can be formulated as follows:
<disp-formula id="eqn-8"><label>(8)</label><mml:math id="mml-eqn-8" display="block"><mml:munder><mml:mo movablelimits="true" form="prefix">min</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:mrow></mml:munder><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mrow><mml:mtext>N</mml:mtext></mml:mrow></mml:mrow></mml:munderover><mml:mfrac><mml:mrow><mml:mo>|</mml:mo><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>|</mml:mo></mml:mrow><mml:mrow><mml:mo>|</mml:mo><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mo>|</mml:mo></mml:mrow></mml:mfrac><mml:msub><mml:mrow><mml:mi>&#x02112;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p><bold>Subject to:</bold></p>
<p>1. Privacy Constraint: Ensuring <inline-formula id="ieqn-29"><mml:math id="mml-ieqn-29"><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow></mml:math></inline-formula>-differential privacy through Gaussian noise addition:
<disp-formula id="eqn-9"><label>(9)</label><mml:math id="mml-eqn-9" display="block"><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msubsup><mml:mo>+</mml:mo><mml:mrow><mml:mi mathvariant="script">N</mml:mi></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="normal">&#x03C3;</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mrow><mml:mtext mathvariant="bold">I</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p>2. Robustness Constraint: Limiting the deviation of local updates from the global model:
<disp-formula id="eqn-10"><label>(10)</label><mml:math id="mml-eqn-10" display="block"><mml:mo stretchy="false">&#x2225;</mml:mo><mml:mspace width="negativethinmathspace" /><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msubsup><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mspace width="negativethinmathspace" /><mml:msub><mml:mo>&#x2225;</mml:mo><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>&#x2264;</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x03C1;</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mspace width="1em" /><mml:mi mathvariant="normal">&#x2200;</mml:mi><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mrow><mml:mtext>N</mml:mtext></mml:mrow><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></disp-formula></p>
<p>3. Communication Constraint: Controlling the communication cost between devices and the server:
<disp-formula id="eqn-11"><label>(11)</label><mml:math id="mml-eqn-11" display="block"><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mrow><mml:mtext>N</mml:mtext></mml:mrow></mml:mrow></mml:munderover><mml:mo>&#x2225;</mml:mo><mml:mspace width="negativethinmathspace" /><mml:msubsup><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msubsup><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mspace width="negativethinmathspace" /><mml:msubsup><mml:mo>&#x2225;</mml:mo><mml:mrow><mml:mn>2</mml:mn></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msubsup><mml:mo>&#x2264;</mml:mo><mml:msub><mml:mrow><mml:mtext>C</mml:mtext></mml:mrow><mml:mrow><mml:mo movablelimits="true" form="prefix">max</mml:mo></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p>The formulated problem aims to minimize the global loss across all IoT devices by leveraging federated learning, while maintaining strict privacy guarantees and ensuring robustness against adversarial attacks. Differential privacy ensures that individual device updates are protected, while robustness constraints prevent adversarial devices from negatively influencing the global model. Additionally, communication constraints ensure that the system remains scalable and efficient in large IoT networks.</p>
</sec>
<sec id="s4">
<label>4</label>
<title>Methodology</title>
<p>To address RQ1 (How can Federated Learning be leveraged to develop a privacy-preserving Intrusion Detection System (IDS) for large-scale IoT networks?), this study proposes the Federated Privacy-Preserving Intrusion Detection (FedPPID) framework, which enables IoT devices to collaboratively train intrusion detection models without sharing raw data. The methodology incorporates Differential Privacy (DP) and Secure Multi-Party Computation (SMC) to protect model updates while employing Byzantine-robust aggregation to mitigate adversarial attacks. The framework&#x2019;s ability to preserve privacy while maintaining detection accuracy is further supported by the hybrid deep learning model (CNN-RNN), which efficiently processes IoT network traffic.</p>
<p>For RQ2 (What are the most effective communication optimization techniques to reduce the overhead of model parameter exchanges in FL-based IDS?), this study optimizes communication efficiency by implementing quantization-based compression and adaptive update strategies. Instead of transmitting updates at fixed intervals, FedPPID selectively transmits model updates only when significant learning improvements are detected. This approach reduces bandwidth consumption while maintaining model accuracy, making it feasible for resource-constrained IoT environments.</p>
<p>To address RQ3 (How can FL-based IDS be made resilient against adversarial threats, such as model poisoning, data poisoning, and Byzantine attacks, without compromising detection accuracy?), the FedPPID model incorporates an anomaly-based gradient filtering mechanism to identify and exclude adversarial updates. Additionally, the system enforces a distance-based thresholding technique, ensuring that malicious updates with extreme deviations from the global model are discarded. This robust privacy-aware aggregation strategy strengthens FedPPID&#x2019;s resilience against model poisoning, Byzantine failures, and backdoor attacks, thereby securing IoT networks from sophisticated threats.</p>
<p>The paper&#x2019;s proposed weight-distance mechanism for defending against adversarial attacks, which evaluates the goodness of individual participants&#x2019; updates by imposing a fixed upper bound on the <inline-formula id="ieqn-30"><mml:math id="mml-ieqn-30"><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> distance between the global model&#x2019;s weights and the updated weights sent by participants, has several critical limitations. The underlying assumption is that adversarial attacks will result in significantly divergent weight distributions in the updated local model. However, for well-designed poisoning or backdoor attacks, this divergence may be minimal, as adversaries can craft updates that remain within the expected distribution while embedding malicious influence [<xref ref-type="bibr" rid="ref-1">1</xref>,<xref ref-type="bibr" rid="ref-2">2</xref>]. Additionally, this approach does not account for the inherent differences in data distributions among participants, which is a fundamental aspect of federated learning. These distributional differences naturally result in diverse weight updates, even among benign participants. Consequently, maintaining a low threshold to detect attacks could lead to a high number of false positives, while increasing the threshold to avoid false positives may allow even basic poisoning attacks to go undetected.</p>
<p>The datasets used in this research, including NSL-KDD, BoT-IoT, and UNSW-NB15, were chosen for their wide representation of network activities in IoT environments, covering both benign and malicious traffic. Preprocessing was applied to ensure uniformity in features, and irrelevant attributes were removed. The datasets were divided into training and testing sets, maintaining a balance between attack and non-attack samples. The FedPPID model integrates a hybrid neural network, combining Convolutional Neural Networks (CNNs) for feature extraction and Recurrent Neural Networks (RNNs) for sequence modeling. This architecture was chosen to capture both spatial and temporal characteristics in IoT traffic data. Each device trains its model locally using Stochastic Gradient Descent (SGD), optimizing on a local dataset to minimize the local loss function. The updated parameters are then shared with the central server, where they are aggregated to create the global model. Differential privacy is applied to the model updates shared by each device. Gaussian noise is added to the gradients before transmission to the central server, ensuring that individual device contributions cannot be reverse-engineered. This method balances privacy with accuracy, maintaining strong privacy protection without severely impacting the model&#x2019;s predictive performance. The central server performs secure aggregation on the model updates received from devices. Secure multi-party computation (SMC) is employed to prevent the central server from learning any individual update&#x2019;s specifics, further enhancing data privacy. This step is critical for protecting against model poisoning attacks, as it ensures that no individual update disproportionately influences the global model. To reduce the communication burden, adaptive communication protocols were employed, where model updates are transmitted based on local model improvements rather than in fixed intervals. Additionally, model compression techniques such as quantization were applied to minimize the size of transmitted updates, further reducing bandwidth usage and making the model suitable for large IoT deployments. The FedPPID model&#x2019;s effectiveness was evaluated using key metrics such as accuracy, precision, recall, F1-score, and communication overhead. The model&#x2019;s robustness was assessed by simulating adversarial attacks, such as model poisoning, and monitoring performance degradation. Privacy loss was measured using the differential privacy budget, and convergence time was monitored to evaluate real-time suitability. The Federated Learning approach in FedPPID is justified by its ability to address the unique privacy, scalability, and adaptability requirements of IoT networks. The proposed methodology aims to create a robust and scalable IDS, designed specifically for resource-constrained and privacy-sensitive IoT environments. By combining FL with advanced privacy-preserving and communication-efficient techniques, the FedPPID model addresses the core challenges in IoT security, offering a practical solution for real-world applications.</p>
<sec id="s4_1">
<label>4.1</label>
<title>Justification for Using Federated Learning (FL)</title>
<p>Federated Learning was selected for this research due to its suitability for privacy-preserving and decentralized data processing within large-scale IoT environments. Traditional Intrusion Detection Systems (IDS), which typically rely on centralized machine learning models, require IoT devices to send raw data to a central server. However, IoT devices often collect sensitive information, raising significant privacy concerns. Additionally, the large-scale and heterogeneous nature of IoT networks imposes a high communication cost, making centralized solutions inefficient. Federated Learning addresses these challenges by allowing IoT devices to train local models on their data, while only sharing model parameters (gradients) with a central server for aggregation, thus keeping sensitive data localized. This approach ensures:</p>
<p>Privacy Preservation: Since FL retains data on local devices, user privacy is significantly enhanced. This is particularly important for IoT applications, where data can include personal or location-based information, such as those found in healthcare, home automation, and industrial settings.</p>
<p>Scalability and Efficiency: FL enables scalability by reducing the need for raw data transmission across devices. In large IoT networks with thousands of devices, this reduces bandwidth usage and computational load on central servers, making the IDS more efficient.</p>
<p>Adaptability to Device Heterogeneity: IoT networks consist of devices with varying computational capacities and data distributions (non-IID data). FL accommodates this heterogeneity by allowing each device to independently train a local model, which the central server aggregates to create a global model that is both comprehensive and adaptive to diverse data distributions.</p>
</sec>
<sec id="s4_2">
<label>4.2</label>
<title>Key Assumptions in the FL Model</title>
<p>Several assumptions were made in employing FL for IoT intrusion detection:</p>
<p>Device Participation and Network Stability: The model assumes that participating devices have stable network connectivity and can periodically transmit model updates to the central server. In real-world IoT environments, intermittent connectivity could hinder timely updates, so stable network conditions are essential for effective model aggregation.</p>
<p>Data Locality and Privacy Needs: It is assumed that the privacy of data collected by IoT devices is a primary concern. For this reason, FL is employed to avoid direct data transmission to the server, with the assumption that privacy-preserving mechanisms such as differential privacy can further protect shared model parameters.</p>
<p>Computational Capacity: Although IoT devices are often resource-constrained, the methodology assumes that each device can perform basic model training operations without overwhelming its computational resources. To accommodate devices with limited resources, lightweight neural networks and optimized training algorithms were utilized.</p>
<p>Uniform Contribution to the Global Model: Each IoT device is assumed to contribute useful patterns for intrusion detection. The model&#x2019;s performance relies on the premise that data from various devices reflect potential security threats, providing a comprehensive dataset for building an effective global model.</p>
</sec>
<sec id="s4_3">
<label>4.3</label>
<title>Dataset Collection</title>
<p>The dataset used in this study was collected from publicly available sources specifically designed for evaluating intrusion detection systems in Internet of Things (IoT) environments. For this research, we utilized datasets such as NSL-KDD, BoT-IoT, and UNSW-NB15 (all taken from <ext-link ext-link-type="uri" xlink:href="https://www.kaggle.com">www.kaggle.com</ext-link>), which contain a wide variety of network traffic data, including both benign and malicious activity. These datasets offer labeled examples of various types of attacks, including Denial of Service (DoS), Distributed Denial of Service (DDoS), and probing attacks. Each dataset was preprocessed to ensure that only relevant features were included, and redundant or irrelevant attributes were removed. The collected data was split into training and testing sets, ensuring an appropriate balance between attack and non-attack samples to avoid any biases during the model evaluation phase. Furthermore, the privacy of the datasets was maintained by applying differential privacy techniques where necessary, ensuring compliance with data protection regulations.</p>
<p>In an IoT-enabled environment, sensitive data can encompass a wide range of information that is tied to both devices and users. This includes Personal Identifiable Information (PII) such as user names, addresses, and health-related data from medical devices. Location data, including GPS coordinates and movement patterns, is another type of sensitive information often collected by IoT devices. Device-specific data, such as device identifiers (e.g., MAC addresses or IMEI numbers), settings, and usage statistics, can also be sensitive, as they might be traced back to specific individuals. Additionally, behavioral data, including usage patterns and interactions with IoT devices, as well as sensor data such as environmental measurements (e.g., temperature or humidity), can provide insights into personal habits and routines. Communication data, such as network traffic and logs from IoT communication channels, are sensitive because they can reveal private activities and network behaviors. Security data, including login credentials, encryption keys, and access logs, is critical as it relates to the protection of IoT devices and user privacy. Finally, financial data, such as payment details from IoT-enabled transactions, can also be part of the sensitive information collected. In terms of the dataset used for this study, the proportion of sensitive data largely depends on the types of IoT devices and the application of the intrusion detection system. For example, network traffic data, device activity logs, and sensor readings involved in intrusion detection often contain sensitive information. This can include communication patterns, device configurations, and even user-specific data, which makes up a substantial portion of the dataset, depending on the context and the devices being monitored.</p>
</sec>
<sec id="s4_4">
<label>4.4</label>
<title>Dataset Description</title>
<p>The dataset used for this study comprises real-time network traffic data captured from IoT environments, focusing on various types of network activities, including normal and malicious behavior. The dataset includes a total of 500,000 records, distributed across multiple classes, such as Denial of Service (DoS), Distributed Denial of Service (DDoS), probing, and remote-to-local (R2L) attacks. Each record consists of 41 features, including network-related attributes like protocol type, service, duration, and various statistical measurements. The dataset was derived from widely used IoT-specific datasets such as NSL-KDD [<xref ref-type="bibr" rid="ref-24">24</xref>], BoT-IoT [<xref ref-type="bibr" rid="ref-25">25</xref>] and UNSWNB15 [<xref ref-type="bibr" rid="ref-26">26</xref>], ensuring that it represents contemporary attack vectors observed in modern IoT networks. Additionally, the dataset was cleaned and preprocessed to remove redundant and irrelevant features, and was normalized to ensure consistency. The distribution of the dataset is balanced, with approximately 50% of the records representing attack traffic and the remaining 50% comprising benign activity, making it suitable for training machine learning-based intrusion detection models.</p>
<p><xref ref-type="table" rid="table-2">Table 2</xref> shows the dataset used in this study contains 500,000 network traffic records from IoT environments, divided evenly between attack and benign classes. It includes five classes (Normal, DoS, DDoS, Probing, R2L) and 41 features, such as protocol type and duration. Sourced from NSL-KDD and BoT-IoT datasets, it underwent preprocessing steps like feature selection and normalization to support machine learning intrusion detection.</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Dataset description</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Attribute</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td>Total records</td>
<td>500,000</td>
</tr>
<tr>
<td>Number of classes</td>
<td>5 (Normal, DoS, DDoS, Probing, R2L)</td>
</tr>
<tr>
<td>Number of features</td>
<td>41 (including protocol type, service, duration, and statistical measurements)</td>
</tr>
<tr>
<td>Source</td>
<td>NSL-KDD, BoT-IoT</td>
</tr>
<tr>
<td>Data type</td>
<td>Network traffic data from IoT environments</td>
</tr>
<tr>
<td>Attack distribution</td>
<td>50% Attack, 50% Benign</td>
</tr>
<tr>
<td>Preprocessing steps</td>
<td>Feature selection, normalization, and data cleaning</td>
</tr>
<tr>
<td>Purpose</td>
<td>Evaluating machine learning-based intrusion detection models</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s4_5">
<label>4.5</label>
<title>Federated Learning Model for Privacy-Preserving Intrusion Detection (FedPPID)</title>
<p>In this paper, we propose a novel Federated Learning (FL) model designed to enhance privacy preservation in IoT-based Intrusion Detection Systems (IDS). The proposed model, named Federated Privacy-Preserving Intrusion Detection (FedPPID), leverages decentralized data processing to ensure that sensitive information remains local to IoT devices while enabling collaborative model training across distributed devices. The proposed FedPPID model consists of the following steps as shown in <xref ref-type="fig" rid="fig-1">Fig. 1</xref>.</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>Model architecture</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_63734-fig-1.tif"/>
</fig>
<p><xref ref-type="fig" rid="fig-1">Fig. 1</xref> illustrated the architecture of the Federated Privacy-Preserving Intrusion Detection (FedPPID) model. It highlighted the decentralized approach where IoT devices locally processed and retained sensitive data while collaboratively training the IDS model across distributed devices, ensuring privacy throughout the process.</p>

<sec id="s4_5_1">
<label>4.5.1</label>
<title>Local Model Training</title>
<p>Each IoT device <inline-formula id="ieqn-31"><mml:math id="mml-ieqn-31"><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mrow><mml:mtext>N</mml:mtext></mml:mrow><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula> has its own private dataset <inline-formula id="ieqn-32"><mml:math id="mml-ieqn-32"><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> containing both benign and malicious network traffic data. The local training phase uses a hybrid deep learning model composed of Convolutional Neural Networks (CNNs) for feature extraction and Recurrent Neural Networks (RNNs) for sequence modeling of network traffic behavior. The goal of each IoT device is to minimize the local loss function <inline-formula id="ieqn-33"><mml:math id="mml-ieqn-33"><mml:msub><mml:mrow><mml:mi>&#x02112;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> on its own dataset, which can be written as:
<disp-formula id="eqn-12"><label>(12)</label><mml:math id="mml-eqn-12" display="block"><mml:msub><mml:mrow><mml:mi>&#x02112;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mrow><mml:mo>|</mml:mo><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>|</mml:mo></mml:mrow></mml:mfrac><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mtext>y</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:mrow></mml:munder><mml:mi>&#x2113;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>f</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo>;</mml:mo><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mtext>y</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>where <inline-formula id="ieqn-34"><mml:math id="mml-ieqn-34"><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> represents the model parameters for device <inline-formula id="ieqn-35"><mml:math id="mml-ieqn-35"><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:math></inline-formula>, <inline-formula id="ieqn-36"><mml:math id="mml-ieqn-36"><mml:mrow><mml:mtext>f</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo>;</mml:mo><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> is the model prediction, and <inline-formula id="ieqn-37"><mml:math id="mml-ieqn-37"><mml:mi>&#x2113;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> is a differentiable loss function (e.g., cross-entropy).</p>
<p>Each device trains the model locally using Stochastic Gradient Descent (SGD) or any optimization algorithm, and computes the gradient of the loss function:
<disp-formula id="eqn-13"><label>(13)</label><mml:math id="mml-eqn-13" display="block"><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi mathvariant="normal">&#x2207;</mml:mi><mml:msub><mml:mrow><mml:mi>&#x02112;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula></p>
</sec>
<sec id="s4_5_2">
<label>4.5.2</label>
<title>Model Aggregation with Differential Privacy</title>
<p>After local training, instead of sending raw data to the server, each device transmits only its model updates (gradients). To preserve the privacy of individual data points, we apply a Differential Privacy (DP) mechanism by adding Gaussian noise to the gradient updates. The noisy update sent by device <inline-formula id="ieqn-38"><mml:math id="mml-ieqn-38"><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:math></inline-formula> to the central server is:
<disp-formula id="eqn-14"><label>(14)</label><mml:math id="mml-eqn-14" display="block"><mml:msub><mml:mrow><mml:mover><mml:mrow><mml:mi>&#x03B4;</mml:mi><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow></mml:mrow><mml:mo>&#x007E;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>&#x03B4;</mml:mi><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mrow><mml:mi mathvariant="script">N</mml:mi></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mrow><mml:mtext mathvariant="bold">I</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>where <inline-formula id="ieqn-39"><mml:math id="mml-ieqn-39"><mml:mrow><mml:mi mathvariant="script">N</mml:mi></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="normal">&#x03C3;</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mrow><mml:mtext mathvariant="bold">I</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> is Gaussian noise with mean 0 and variance <inline-formula id="ieqn-40"><mml:math id="mml-ieqn-40"><mml:msup><mml:mrow><mml:mi mathvariant="normal">&#x03C3;</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula>, ensuring &#x03B5;-differential privacy. The amount of noise <inline-formula id="ieqn-41"><mml:math id="mml-ieqn-41"><mml:mrow><mml:mi mathvariant="normal">&#x03C3;</mml:mi></mml:mrow></mml:math></inline-formula> is chosen to balance the trade-off between privacy and model accuracy.</p>
</sec>
<sec id="s4_5_3">
<label>4.5.3</label>
<title>Secure Model Aggregation</title>
<p>Once the noisy updates <inline-formula id="ieqn-42"><mml:math id="mml-ieqn-42"><mml:msub><mml:mrow><mml:mover><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow></mml:mrow><mml:mo>&#x007E;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> are received by the central server, the server aggregates the updates to compute a new global model. The aggregation is done using secure multi-party computation (SMC) to ensure that the server cannot infer sensitive information from individual model updates. The global model update is computed as:
<disp-formula id="eqn-15"><label>(15)</label><mml:math id="mml-eqn-15" display="block"><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x03B7;</mml:mi></mml:mrow><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mrow><mml:mtext>N</mml:mtext></mml:mrow></mml:mrow></mml:munderover><mml:mfrac><mml:mrow><mml:mo>|</mml:mo><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>|</mml:mo></mml:mrow><mml:mrow><mml:mo>|</mml:mo><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mo>|</mml:mo></mml:mrow></mml:mfrac><mml:msub><mml:mrow><mml:mover><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow></mml:mrow><mml:mo>&#x007E;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:math></disp-formula>where <inline-formula id="ieqn-43"><mml:math id="mml-ieqn-43"><mml:mrow><mml:mi mathvariant="normal">&#x03B7;</mml:mi></mml:mrow></mml:math></inline-formula> is the learning rate, <inline-formula id="ieqn-44"><mml:math id="mml-ieqn-44"><mml:mrow><mml:mo>|</mml:mo><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>|</mml:mo></mml:mrow></mml:math></inline-formula> is the size of the local dataset, and <inline-formula id="ieqn-45"><mml:math id="mml-ieqn-45"><mml:mrow><mml:mo>|</mml:mo><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mo>|</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mrow><mml:mtext>N</mml:mtext></mml:mrow></mml:mrow></mml:munderover><mml:mrow><mml:mo>|</mml:mo><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>|</mml:mo></mml:mrow></mml:math></inline-formula> is the total dataset size across all devices. The global model is updated without accessing raw data from individual devices, ensuring privacy preservation.</p>
</sec>
<sec id="s4_5_4">
<label>4.5.4</label>
<title>Global Model Distribution</title>
<p>After the central server updates the global model <inline-formula id="ieqn-46"><mml:math id="mml-ieqn-46"><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>, it is distributed back to the IoT devices. Each device then updates its local model with the new global parameters and retrains it on its private data. This process is iterative and continues until convergence. The iterative nature of this learning process allows the system to adapt to new threats dynamically.</p>
</sec>
<sec id="s4_5_5">
<label>4.5.5</label>
<title>Adversarial Robustness</title>
<p>In addition to ensuring privacy, the FedPPID model incorporates mechanisms to defend against adversarial attacks, such as model poisoning. During the model aggregation phase, the central server performs anomaly detection on the received gradients to filter out abnormal updates that may have been manipulated by adversaries. The distance between the local gradient <inline-formula id="ieqn-47"><mml:math id="mml-ieqn-47"><mml:msub><mml:mrow><mml:mover><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow></mml:mrow><mml:mo>&#x007E;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> and the average global gradient is computed using the Euclidean norm:
<disp-formula id="eqn-16"><label>(16)</label><mml:math id="mml-eqn-16" display="block"><mml:mrow><mml:mtext>d</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mover><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow></mml:mrow><mml:mo>&#x007E;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>=&#x2225;</mml:mo><mml:mspace width="negativethinmathspace" /><mml:msub><mml:mrow><mml:mover><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow></mml:mrow><mml:mo>&#x007E;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mspace width="negativethinmathspace" /><mml:msub><mml:mo stretchy="false">&#x2225;</mml:mo><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p>If the distance exceeds a predefined threshold <inline-formula id="ieqn-48"><mml:math id="mml-ieqn-48"><mml:mrow><mml:mi mathvariant="normal">&#x03C1;</mml:mi></mml:mrow></mml:math></inline-formula>, the local update is excluded from the aggregation process. This ensures that malicious updates do not degrade the global model performance.</p>
</sec>
<sec id="s4_5_6">
<label>4.5.6</label>
<title>Mathematical Model of the Proposed FedPPID Framework</title>
<p>The overall objective of the FedPPID model is to minimize the global loss function, while preserving privacy and ensuring robustness against adversarial attacks. The global loss function <inline-formula id="ieqn-49"><mml:math id="mml-ieqn-49"><mml:msub><mml:mrow><mml:mi>&#x02112;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>global</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> can be written as:
<disp-formula id="eqn-17"><label>(17)</label><mml:math id="mml-eqn-17" display="block"><mml:msub><mml:mrow><mml:mi>&#x02112;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>global</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mrow><mml:mtext>N</mml:mtext></mml:mrow></mml:mrow></mml:munderover><mml:mfrac><mml:mrow><mml:mo>|</mml:mo><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>|</mml:mo></mml:mrow><mml:mrow><mml:mo>|</mml:mo><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mo>|</mml:mo></mml:mrow></mml:mfrac><mml:msub><mml:mrow><mml:mi>&#x02112;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p>Subject to the following constraints:
<list list-type="bullet">
<list-item>
<p><bold>Privacy Constraint:</bold> The model updates must satisfy <inline-formula id="ieqn-50"><mml:math id="mml-ieqn-50"><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow></mml:math></inline-formula>-differential privacy through noise addition:</p></list-item>
</list>
<disp-formula id="eqn-18"><label>(18)</label><mml:math id="mml-eqn-18" display="block"><mml:msub><mml:mrow><mml:mover><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow></mml:mrow><mml:mo>&#x007E;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mrow><mml:mi mathvariant="script">N</mml:mi></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="normal">&#x03C3;</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mrow><mml:mtext mathvariant="bold">I</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>
<list list-type="bullet">
<list-item>
<p><bold>Adversarial Robustness Constraint:</bold> The Euclidean distance between the local update and the global model must not exceed a predefined threshold <inline-formula id="ieqn-51"><mml:math id="mml-ieqn-51"><mml:mrow><mml:mi mathvariant="normal">&#x03C1;</mml:mi></mml:mrow></mml:math></inline-formula>:</p></list-item>
</list>
<disp-formula id="eqn-19"><label>(19)</label><mml:math id="mml-eqn-19" display="block"><mml:mrow><mml:mtext>d</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mover><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow></mml:mrow><mml:mo>&#x007E;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mrow><mml:mtext>i</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mtext mathvariant="bold">w</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2264;</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x03C1;</mml:mi></mml:mrow></mml:math></disp-formula>
<list list-type="bullet">
<list-item>
<p><bold>Communication Efficiency Constraint:</bold> The communication cost between devices and the central server must be minimized to ensure scalability in IoT environments.</p></list-item>
</list></p>
<p>By minimizing the global loss function while satisfying the above constraints, the FedPPID model ensures high intrusion detection accuracy, privacy preservation, and robustness in highly dynamic IoT networks.</p>
</sec>
<sec id="s4_5_7">
<label>4.5.7</label>
<title>Experimental Validation</title>
<p>To validate the proposed model, we conducted experiments on several benchmark IoT datasets, including NSL-KDD and BoT-IoT, using simulated adversarial attacks. The results demonstrate that the FedPPID model achieves comparable detection accuracy to traditional centralized models, with significantly reduced privacy risks and improved robustness against adversarial attacks. Algorithm 1 shows the presents a novel privacy-preserving federated learning model for intrusion detection in IoT environments, named FedPPID. The model ensures that sensitive data remains local to IoT devices while enabling collaborative model training through secure aggregation and differential privacy mechanisms.</p>
<fig id="fig-17">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_63734-fig-17.tif"/>
</fig>
<p>This algorithm ensures privacy preservation through differential privacy, robustness against adversarial attacks via anomaly detection, and scalability for large-scale IoT environments. The FedPPID (Federated Privacy-Preserving Intrusion Detection) is designed to enhance privacy in intrusion detection by leveraging federated learning across distributed IoT devices. The algorithm begins with a central server initializing a global model <inline-formula id="ieqn-70"><mml:math id="mml-ieqn-70"><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>, which will be updated iteratively over <inline-formula id="ieqn-71"><mml:math id="mml-ieqn-71"><mml:mi>T</mml:mi></mml:math></inline-formula> communication rounds. For each round <inline-formula id="ieqn-72"><mml:math id="mml-ieqn-72"><mml:mi>t</mml:mi></mml:math></inline-formula>, every IoT device <inline-formula id="ieqn-73"><mml:math id="mml-ieqn-73"><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mi>N</mml:mi><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula> locally trains its model <inline-formula id="ieqn-74"><mml:math id="mml-ieqn-74"><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> using its private dataset <inline-formula id="ieqn-75"><mml:math id="mml-ieqn-75"><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>.</p>
<p>The device minimizes a local loss function:
<disp-formula id="eqn-20"><label>(20)</label><mml:math id="mml-eqn-20" display="block"><mml:mrow><mml:mi>&#x02112;</mml:mi></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mrow><mml:mo>|</mml:mo><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>|</mml:mo></mml:mrow></mml:mfrac><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mi>y</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:munder><mml:mi>&#x2113;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mi>y</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>where <inline-formula id="ieqn-76"><mml:math id="mml-ieqn-76"><mml:mi>&#x2113;</mml:mi></mml:math></inline-formula> is the loss function, and <inline-formula id="ieqn-77"><mml:math id="mml-ieqn-77"><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> represents the model&#x2019;s prediction on input <inline-formula id="ieqn-78"><mml:math id="mml-ieqn-78"><mml:mi>x</mml:mi></mml:math></inline-formula> with parameters <inline-formula id="ieqn-79"><mml:math id="mml-ieqn-79"><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>.</p>
<p>After computing the local gradient <inline-formula id="ieqn-80"><mml:math id="mml-ieqn-80"><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi mathvariant="normal">&#x2207;</mml:mi><mml:mrow><mml:mi>&#x02112;</mml:mi></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula>, each device applies differential privacy by adding Gaussian noise <inline-formula id="ieqn-81"><mml:math id="mml-ieqn-81"><mml:mrow><mml:mi mathvariant="script">N</mml:mi></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mi>I</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> to the gradient, resulting in a noisy update:
<disp-formula id="eqn-21"><label>(21)</label><mml:math id="mml-eqn-21" display="block"><mml:msub><mml:mrow><mml:mover><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>w</mml:mi></mml:mrow><mml:mo>&#x007E;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mrow><mml:mi mathvariant="script">N</mml:mi></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mi>I</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p>This noisy update <inline-formula id="ieqn-82"><mml:math id="mml-ieqn-82"><mml:msub><mml:mrow><mml:mover><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>w</mml:mi></mml:mrow><mml:mo>&#x007E;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> is then sent to the central server to prevent leakage of sensitive information from individual devices.</p>
<p>At the central server, anomaly detection is performed by calculating the Euclidean distance <inline-formula id="ieqn-83"><mml:math id="mml-ieqn-83"><mml:mi>d</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mover><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>w</mml:mi></mml:mrow><mml:mo>&#x007E;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> between each received update <inline-formula id="ieqn-84"><mml:math id="mml-ieqn-84"><mml:msub><mml:mrow><mml:mover><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>w</mml:mi></mml:mrow><mml:mo>&#x007E;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> and the current global model <inline-formula id="ieqn-85"><mml:math id="mml-ieqn-85"><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>:
<disp-formula id="eqn-22"><label>(22)</label><mml:math id="mml-eqn-22" display="block"><mml:mi>d</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mover><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>w</mml:mi></mml:mrow><mml:mo>&#x007E;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>=&#x2225;</mml:mo><mml:mspace width="negativethinmathspace" /><mml:msub><mml:mrow><mml:mover><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>w</mml:mi></mml:mrow><mml:mo>&#x007E;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mspace width="negativethinmathspace" /><mml:msub><mml:mo stretchy="false">&#x2225;</mml:mo><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p>If the distance exceeds a pre-defined threshold <inline-formula id="ieqn-86"><mml:math id="mml-ieqn-86"><mml:mi>&#x03C1;</mml:mi></mml:math></inline-formula>, the update from device <inline-formula id="ieqn-87"><mml:math id="mml-ieqn-87"><mml:mi>i</mml:mi></mml:math></inline-formula> is excluded, as it might indicate an adversarial or noisy influence.</p>
<p>Once valid updates are filtered, the central server aggregates them to update the global model using the formula:</p>
<p><disp-formula id="eqn-23"><label>(23)</label><mml:math id="mml-eqn-23" display="block"><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mi>&#x03B7;</mml:mi><mml:mfrac><mml:mn>1</mml:mn><mml:mi>N</mml:mi></mml:mfrac><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>N</mml:mi></mml:mrow></mml:munderover><mml:mfrac><mml:mrow><mml:mo>|</mml:mo><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>|</mml:mo></mml:mrow><mml:mrow><mml:mo>|</mml:mo><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mo>|</mml:mo></mml:mrow></mml:mfrac><mml:msub><mml:mrow><mml:mover><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mi>w</mml:mi></mml:mrow><mml:mo>&#x007E;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula>where <inline-formula id="ieqn-88"><mml:math id="mml-ieqn-88"><mml:mi>&#x03B7;</mml:mi></mml:math></inline-formula> is the learning rate, and <inline-formula id="ieqn-89"><mml:math id="mml-ieqn-89"><mml:mrow><mml:mo>|</mml:mo><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>|</mml:mo></mml:mrow></mml:math></inline-formula> is the size of each device&#x2019;s dataset relative to the global dataset size <inline-formula id="ieqn-90"><mml:math id="mml-ieqn-90"><mml:mrow><mml:mo>|</mml:mo><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mo>|</mml:mo></mml:mrow></mml:math></inline-formula>. The updated model <inline-formula id="ieqn-91"><mml:math id="mml-ieqn-91"><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> is then distributed back to all IoT devices, allowing them to synchronize with the refined global model for the next communication round. This process continues until the model reaches the desired accuracy or completes the specified number of rounds.</p>
<p>This paper presents a novel privacy-preserving federated learning model for intrusion detection in IoT environments, named FedPPID. The model ensures that sensitive data remains local to IoT devices while enabling collaborative model training through secure aggregation and differential privacy mechanisms. The proposed model demonstrates high accuracy, scalability, and robustness against adversarial attacks, making it suitable for real-time applications in large-scale IoT networks. Future work may focus on further optimizing the model&#x2019;s communication efficiency and exploring its applicability in other privacy-sensitive domains.</p>
</sec>
</sec>
<sec id="s4_6">
<label>4.6</label>
<title>Evaluation Metrics</title>
<p>The proposed FedPPID model is evaluated using the following key metrics. <xref ref-type="table" rid="table-3">Table 3</xref> shows the Evaluation Metrics for the FedPPID Model.</p>
<table-wrap id="table-3">
<label>Table 3</label>
<caption>
<title>Evaluation metrics for the FedPPID model</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th>Metric</th>
<th>Description</th>
<th>Formula</th>
</tr>
</thead>
<tbody>
<tr>
<td>Accuracy</td>
<td>Proportion of correctly classified samples.</td>
<td><inline-formula id="ieqn-92"><mml:math id="mml-ieqn-92"><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mrow><mml:mtext>TP</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mtext>TN</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mtext>Total</mml:mtext></mml:mrow></mml:mfrac></mml:mstyle></mml:math></inline-formula></td>
</tr>
<tr>
<td>Precision</td>
<td>Proportion of correctly identified attacks out of all predicted attacks.</td>
<td><inline-formula id="ieqn-93"><mml:math id="mml-ieqn-93"><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mtext>TP</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>TP</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mtext>FP</mml:mtext></mml:mrow></mml:mrow></mml:mfrac></mml:mstyle></mml:math></inline-formula></td>
</tr>
<tr>
<td>Recall (Sensitivity)</td>
<td>Proportion of actual attacks that are correctly identified.</td>
<td><inline-formula id="ieqn-94"><mml:math id="mml-ieqn-94"><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mtext>TP</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>TP</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mtext>FN</mml:mtext></mml:mrow></mml:mrow></mml:mfrac></mml:mstyle></mml:math></inline-formula></td>
</tr>
<tr>
<td>F1-Score</td>
<td>Harmonic mean of precision and recall.</td>
<td><inline-formula id="ieqn-95"><mml:math id="mml-ieqn-95"><mml:mn>2</mml:mn><mml:mo>&#x22C5;</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mrow><mml:mtext>Precision</mml:mtext></mml:mrow><mml:mo>&#x22C5;</mml:mo><mml:mrow><mml:mtext>Recall</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mtext>Precision</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mtext>Recall</mml:mtext></mml:mrow></mml:mrow></mml:mfrac></mml:mstyle></mml:math></inline-formula></td>
</tr>
<tr>
<td>Communication overhead</td>
<td>Total data transmitted between IoT devices and server during training.</td>
<td>&#x2013;</td>
</tr>
<tr>
<td>Privacy loss</td>
<td>Degree of privacy preservation, quantified using differential privacy budget <inline-formula id="ieqn-96"><mml:math id="mml-ieqn-96"><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow></mml:math></inline-formula>.</td>
<td>&#x2013;</td>
</tr>
<tr>
<td>Convergence time</td>
<td>Time required for the global model to converge to an optimal solution.</td>
<td>&#x2013;</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="table" rid="table-3">Table 3</xref> outlines key metrics for evaluating the FedPPID model, focusing on effectiveness, privacy, and efficiency. Accuracy reflects overall classification success, while Precision and Recall assess the model&#x2019;s ability to identify attacks accurately and detect actual threats, respectively. F1-Score balances precision and recall. Communication Overhead measures data transfer during training, and Privacy Loss uses the differential privacy budget &#x03B5; to indicate privacy strength. Convergence Time represents the speed at which the model reaches an optimal solution, supporting real-time threat adaptability.</p>

</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Results and Discussion</title>
<p>This section presents the results obtained from evaluating the proposed FedPPID model on benchmark IoT datasets, including NSL-KDD, BoT-IoT, and UNSW-NB15. The performance of the model was assessed using the evaluation metrics described earlier: accuracy, precision, recall, F1-score, communication overhead, privacy loss, and convergence time. We also conducted a comparative analysis between the FedPPID model, traditional centralized IDS, and non-privacy-preserving federated learning models.</p>
<p>The proposed framework, which discards model updates that significantly deviate from others, could inadvertently lead to the undetection of new types of attacks, particularly those exhibiting behaviors that differ substantially from known attack patterns. This mechanism, designed to filter out outliers and ensure model stability, may exclude legitimate updates that reflect novel attack strategies. As cyber threats in IoT environments continue to evolve, some attacks may present entirely new characteristics that do not align with previously observed behaviors. If such updates are discarded due to their deviation from the norm, the model might fail to recognize and adapt to these emerging threats. Consequently, this rigid approach to outlier rejection may hinder the model&#x2019;s adaptability, reducing its capacity to learn from and detect unfamiliar attacks. The loss of potentially valuable updates could impair the system&#x2019;s ability to maintain high detection accuracy, especially in dynamic environments where attackers frequently modify their tactics. Therefore, while the filtering mechanism improves model generalization and reduces noise, it also introduces a risk of missing critical insights, which may affect the overall effectiveness of the intrusion detection system. To mitigate this limitation, a more flexible and adaptive integration of updates is necessary, allowing the model to evolve in response to new, potentially unseen attack behaviors.</p>
<sec id="s5_1">
<label>5.1</label>
<title>Model Accuracy and Detection Performance</title>
<p>The accuracy of the proposed model was evaluated across the different datasets. The results show that the FedPPID model consistently achieved high accuracy, demonstrating its ability to effectively identify various attack types, including Denial of Service (DoS), Distributed Denial of Service (DDoS), and probing attacks.</p>
<p><xref ref-type="table" rid="table-4">Table 4</xref> compared the accuracy of the proposed FedPPID model with centralized and non-privacy-preserving federated IDS models across three datasets (NSL-KDD, BoT-IoT, and UNSW-NB15). The FedPPID model achieved the highest accuracy in all cases, demonstrating its effectiveness over baseline models.</p>
<table-wrap id="table-4">
<label>Table 4</label>
<caption>
<title>Accuracy comparison of FedPPID and baseline models</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Model</th>
<th align="center">NSL-KDD accuracy (%)</th>
<th align="center">BoT-IoT accuracy (%)</th>
<th align="center">UNSW-NB15 accuracy (%)</th>
</tr>
</thead>
<tbody>
<tr>
<td>Centralized IDS</td>
<td>88.45</td>
<td>85.12</td>
<td>86.73</td>
</tr>
<tr>
<td>Non-Privacy-Preserving Federated IDS</td>
<td>91.23</td>
<td>89.34</td>
<td>90.78</td>
</tr>
<tr>
<td><bold>Proposed FedPPID Model</bold></td>
<td><bold>92.78</bold></td>
<td><bold>91.47</bold></td>
<td><bold>92.05</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="fig" rid="fig-2">Fig. 2</xref> illustrated the accuracy comparison of the proposed FedPPID model with centralized and non-privacy-preserving federated IDS models across three datasets: NSL-KDD, BoT-IoT, and UNSW-NB15. The proposed FedPPID model consistently showed higher accuracy across all datasets, outperforming both the centralized IDS and non-privacy-preserving federated IDS, indicating its superior effectiveness in intrusion detection while maintaining privacy.</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>Accuracy comparison of FedPPID and baseline models across datasets</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_63734-fig-2.tif"/>
</fig>
</sec>
<sec id="s5_2">
<label>5.2</label>
<title>Precision, Recall, and F1-Score</title>
<p>To further evaluate the performance of the FedPPID model, we calculated the precision, recall, and F1-score across all datasets. These metrics provide deeper insights into the model&#x2019;s ability to avoid false positives (precision) and detect actual attacks (recall).</p>
<p><xref ref-type="table" rid="table-5">Table 5</xref> showed the precision, recall, and F1-score of the FedPPID model across the NSL-KDD, BoT-IoT, and UNSW-NB15 datasets. The model achieved high scores on all metrics, with precision reflecting its effectiveness in minimizing false positives and recall indicating its ability to detect actual attacks, resulting in balanced F1-scores across datasets.</p>
<table-wrap id="table-5">
<label>Table 5</label>
<caption>
<title>Precision, recall, and F1-Score of FedPPID model</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Dataset</th>
<th>Precision (%)</th>
<th>Recall (%)</th>
<th>F1-Score (%)</th>
</tr>
</thead>
<tbody>
<tr>
<td>NSL-KDD</td>
<td>93.10</td>
<td>92.45</td>
<td>92.77</td>
</tr>
<tr>
<td>BoT-IoT</td>
<td>91.87</td>
<td>90.93</td>
<td>91.40</td>
</tr>
<tr>
<td>UNSW-NB15</td>
<td>92.54</td>
<td>91.78</td>
<td>92.16</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="fig" rid="fig-3">Fig. 3</xref> displayed the precision, recall, and F1-score of the FedPPID model across the NSL-KDD, BoT-IoT, and UNSW-NB15 datasets. For NSL-KDD, the model achieved a precision of 93.10%, recall of 92.45%, and F1-score of 92.77%. In the BoT-IoT dataset, it reached a precision of 91.87%, recall of 90.93%, and F1-score of 91.40%. For UNSW-NB15, the model recorded a precision of 92.54%, recall of 91.78%, and F1-score of 92.16%. These high scores across all datasets demonstrated the model&#x2019;s robustness in accurately detecting attacks while minimizing false positives.</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>Precision, recall, and F1-Score of FedPPID model across datasets</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_63734-fig-3.tif"/>
</fig>
</sec>
<sec id="s5_3">
<label>5.3</label>
<title>Communication Overhead</title>
<p>One of the key benefits of federated learning is the reduction in communication overhead, as only model updates are shared between devices and the central server rather than raw data.</p>
<p><xref ref-type="table" rid="table-6">Table 6</xref> showed the communication overhead in megabytes (MB) during training for different models across the NSL-KDD, BoT-IoT, and UNSW-NB15 datasets. The centralized IDS model had the highest overhead, with 150 MB for NSL-KDD, 210 MB for BoT-IoT, and 180 MB for UNSW-NB15. The non-privacy-preserving federated IDS model reduced the overhead to 95, 120, and 110 MB, respectively. The proposed FedPPID model further minimized communication overhead, achieving 85 MB for NSL-KDD, 105 MB for BoT-IoT, and 95 MB for UNSW-NB15, demonstrating its efficiency in reducing data transfer during training.</p>
<table-wrap id="table-6">
<label>Table 6</label>
<caption>
<title>Communication overhead (MB) during training</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Model</th>
<th>NSL-KDD (MB)</th>
<th>BoT-IoT (MB)</th>
<th>UNSW-NB15 (MB)</th>
</tr>
</thead>
<tbody>
<tr>
<td>Centralized IDS</td>
<td>150</td>
<td>210</td>
<td>180</td>
</tr>
<tr>
<td>Non-Privacy-Preserving Federated IDS</td>
<td>95</td>
<td>120</td>
<td>110</td>
</tr>
<tr>
<td><bold>Proposed FedPPID Model</bold></td>
<td><bold>85</bold></td>
<td><bold>105</bold></td>
<td><bold>95</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="fig" rid="fig-4">Fig. 4</xref> illustrated the communication overhead in megabytes (MB) for different models across the NSL-KDD, BoT-IoT, and UNSW-NB15 datasets. The centralized IDS model incurred the highest overhead, with 150 MB for NSL-KDD, 210 MB for BoT-IoT, and 180 MB for UNSW-NB15. The non-privacy-preserving federated IDS model showed reduced overhead at 95, 120, and 110 MB for NSL-KDD, BoT-IoT, and UNSW-NB15, respectively. The proposed FedPPID model achieved the lowest overhead across all datasets, recording 85 MB for NSL-KDD, 105 MB for BoT-IoT, and 95 MB for UNSW-NB15, highlighting its efficiency in minimizing data transmission during training.</p>
<fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>Communication overhead (MB) comparison across models and datasets</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_63734-fig-4.tif"/>
</fig>
</sec>
<sec id="s5_4">
<label>5.4</label>
<title>Privacy Loss</title>
<p>The privacy of the model was evaluated using differential privacy parameters, specifically the privacy budget <inline-formula id="ieqn-97"><mml:math id="mml-ieqn-97"><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow></mml:math></inline-formula>. The results show that the model maintains a strong level of privacy protection, with varying levels of noise addition to balance accuracy and privacy.</p>
<p><xref ref-type="table" rid="table-7">Table 7</xref> displayed the accuracy of the FedPPID model under different privacy budgets &#x03B5;, which controlled the balance between privacy and model accuracy. For a stricter privacy budget of &#x03B5; &#x003D; 0.5, the model achieved 90.43% accuracy on NSL-KDD, 89.12% on BoT-IoT, and 90.01% on UNSW-NB15. As the privacy budget increased to &#x03B5; &#x003D; 1.0, accuracy improved to 92.78% on NSL-KDD, 91.47% on BoT-IoT, and 92.05% on UNSW-NB15. With &#x03B5; &#x003D; 1.5, accuracy slightly increased further to 92.90% on NSL-KDD, 91.54% on BoT-IoT, and 92.13% on UNSW-NB15, indicating that higher privacy budgets allowed the model to achieve better accuracy while slightly relaxing privacy constraints.</p>
<table-wrap id="table-7">
<label>Table 7</label>
<caption>
<title>Privacy loss for different privacy budgets <inline-formula id="ieqn-98"><mml:math id="mml-ieqn-98"><mml:mi mathvariant="bold-italic">&#x03F5;</mml:mi></mml:math></inline-formula></title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Privacy budget <inline-formula id="ieqn-99"><mml:math id="mml-ieqn-99"><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow></mml:math></inline-formula></th>
<th>NSL-KDD accuracy (%)</th>
<th>BoT-IoT accuracy (%)</th>
<th>UNSW-NB15 accuracy (%)</th>
</tr>
</thead>
<tbody>
<tr>
<td><inline-formula id="ieqn-100"><mml:math id="mml-ieqn-100"><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mn>0.5</mml:mn></mml:math></inline-formula></td>
<td>90.43</td>
<td>89.12</td>
<td>90.01</td>
</tr>
<tr>
<td><inline-formula id="ieqn-101"><mml:math id="mml-ieqn-101"><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mn>1.0</mml:mn></mml:math></inline-formula></td>
<td>92.78</td>
<td>91.47</td>
<td>92.05</td>
</tr>
<tr>
<td><inline-formula id="ieqn-102"><mml:math id="mml-ieqn-102"><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mn>1.5</mml:mn></mml:math></inline-formula></td>
<td>92.90</td>
<td>91.54</td>
<td>92.13</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="fig" rid="fig-5">Fig. 5</xref> illustrated the accuracy of the FedPPID model across different privacy budgets (&#x03B5;) for the NSL-KDD, BoT-IoT, and UNSW-NB15 datasets. With a strict privacy budget of &#x03B5; &#x003D; 0.5, the model achieved accuracies of 90.43% for NSL-KDD, 89.12% for BoT-IoT, and 90.01% for UNSW-NB15. As the privacy budget increased to &#x03B5; &#x003D; 1.0, accuracy improved to 92.78%, 91.47%, and 92.05% for NSL-KDD, BoT-IoT, and UNSW-NB15, respectively. At &#x03B5; &#x003D; 1.5, accuracies reached 92.90% for NSL-KDD, 91.54% for BoT-IoT, and 92.13% for UNSW-NB15, indicating that relaxing privacy constraints slightly enhanced accuracy across all datasets.</p>
<fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>Privacy loss for different privacy budgets &#x03B5;</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_63734-fig-5.tif"/>
</fig>
</sec>
<sec id="s5_5">
<label>5.5</label>
<title>Convergence Time</title>
<p>The time taken for the FedPPID model to converge was measured and compared with the centralized IDS and non-privacy-preserving federated models.</p>
<p><xref ref-type="table" rid="table-8">Table 8</xref> presented the convergence time (in seconds) for the FedPPID model compared with centralized IDS and non-privacy-preserving federated IDS models across the NSL-KDD, BoT-IoT, and UNSW-NB15 datasets. The centralized IDS model took the longest time, with 120 s for NSL-KDD, 150 s for BoT-IoT, and 130 s for UNSW-NB15. The non-privacy-preserving federated IDS reduced the convergence time to 85, 100, and 95 s, respectively. The proposed FedPPID model achieved the fastest convergence, taking 78 s for NSL-KDD, 90 s for BoT-IoT, and 85 s for UNSW-NB15, demonstrating its efficiency in achieving quicker model training.</p>
<table-wrap id="table-8">
<label>Table 8</label>
<caption>
<title>Convergence time (seconds) comparison</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Model</th>
<th>NSL-KDD (s)</th>
<th>BoT-IoT (s)</th>
<th>UNSW-NB15 (s)</th>
</tr>
</thead>
<tbody>
<tr>
<td>Centralized IDS</td>
<td>120</td>
<td>150</td>
<td>130</td>
</tr>
<tr>
<td>Non-Privacy-Preserving Federated IDS</td>
<td>85</td>
<td>100</td>
<td>95</td>
</tr>
<tr>
<td><bold>Proposed FedPPID Model</bold></td>
<td><bold>78</bold></td>
<td><bold>90</bold></td>
<td><bold>85</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="fig" rid="fig-6">Fig. 6</xref> displayed the convergence time (in seconds) comparison across different models and datasets. The centralized IDS model showed the longest convergence times, taking 120 s for NSL-KDD, 150 s for BoT-IoT, and 130 s for UNSW-NB15. The non-privacy-preserving federated IDS reduced the time to 85 s for NSL-KDD, 100 s for BoT-IoT, and 95 s for UNSW-NB15. The proposed FedPPID model achieved the fastest convergence, requiring only 78 s for NSL-KDD, 90 s for BoT-IoT, and 85 s for UNSW-NB15, highlighting its efficiency in training across all datasets.</p>
<fig id="fig-6">
<label>Figure 6</label>
<caption>
<title>Convergence time comparison across different models and datasets</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_63734-fig-6.tif"/>
</fig>
</sec>
<sec id="s5_6">
<label>5.6</label>
<title>Securing IoT Devices with FL: A Privacy-Preserving Approach for Intrusion Detection</title>
<p>The proposed federated learning model for securing IoT devices through privacy-preserving intrusion detection (FedPPID) demonstrates significant improvements in terms of performance, privacy preservation, and communication efficiency. This subsection presents the results of the FedPPID model, including its detection accuracy, privacy loss, communication overhead, and system scalability.</p>
<sec id="s5_6_1">
<label>5.6.1</label>
<title>Scalability Analysis</title>
<p>The scalability of the FedPPID model was evaluated by increasing the number of IoT devices. As seen in <xref ref-type="fig" rid="fig-7">Fig. 7</xref>, the model maintained high detection accuracy while minimizing latency and communication overhead, demonstrating its suitability for large-scale IoT deployments.</p>
<fig id="fig-7">
<label>Figure 7</label>
<caption>
<title>Scalability analysis: system performance with increasing IoT devices</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_63734-fig-7.tif"/>
</fig>
<p><xref ref-type="fig" rid="fig-7">Fig. 7</xref> illustrated the scalability analysis of the system&#x2019;s performance as the number of IoT devices increased. Detection accuracy (shown in cyan) gradually declined with more devices, reflecting the challenge of maintaining high accuracy in larger networks. Latency (in magenta) showed a steady increase, indicating longer processing times as devices scaled up. Communication overhead (in yellow) remained relatively stable, with only minor increases as the number of IoT devices grew.</p>
<p><xref ref-type="fig" rid="fig-8">Fig. 8</xref> compared the convergence time of the model with and without privacy techniques. The top plot showed the model without privacy techniques, where convergence followed a smooth exponential decay, reaching stability quickly. The bottom plot depicted the model with privacy techniques, displaying an oscillatory pattern that slowed convergence. This indicated that privacy mechanisms introduced a slight delay in convergence, affecting the speed but ensuring data privacy.</p>
<fig id="fig-8">
<label>Figure 8</label>
<caption>
<title>Convergence time comparison</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_63734-fig-8.tif"/>
</fig>
</sec>
<sec id="s5_6_2">
<label>5.6.2</label>
<title>Robustness against Adversarial Attacks</title>
<p>The robustness of the FedPPID model was tested against adversarial attacks, such as model poisoning, to assess its ability to maintain performance under malicious conditions. The model demonstrated resilience, successfully detecting malicious activity and preventing significant degradation in performance.</p>
<p>These results in <xref ref-type="table" rid="table-9">Table 9</xref> confirm that the FedPPID model outperforms centralized IDS and traditional federated learning approaches, demonstrating strong resilience against adversarial manipulations. Despite a slight accuracy degradation under sophisticated attacks, the proposed framework successfully limits the impact through anomaly filtering, model aggregation security, and robust privacy mechanisms. Future research will focus on further hardening defenses against Byzantine and evasion attacks by integrating blockchain-based verification for model updates and real-time adversarial detection techniques.</p>
<table-wrap id="table-9">
<label>Table 9</label>
<caption>
<title>Robustness against adversarial attacks</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Attack type</th>
<th align="center">Centralized IDS accuracy (%)</th>
<th align="center">FedAvg accuracy (%)</th>
<th align="center">FedProx accuracy (%)</th>
<th align="center">FedPPID accuracy (%)</th>
<th align="center">Accuracy drop in FedPPID (%)</th>
</tr>
</thead>
<tbody>
<tr>
<td>No attack (Baseline)</td>
<td>88.45</td>
<td>90.12</td>
<td>91.67</td>
<td>92.78</td>
<td>&#x2013;</td>
</tr>
<tr>
<td>Model poisoning</td>
<td>75.23</td>
<td>79.65</td>
<td>83.42</td>
<td>88.32</td>
<td>4.46%</td>
</tr>
<tr>
<td>Data poisoning</td>
<td>73.67</td>
<td>78.12</td>
<td>81.90</td>
<td>87.56</td>
<td>5.22%</td>
</tr>
<tr>
<td>Backdoor attack</td>
<td>70.45</td>
<td>76.32</td>
<td>80.51</td>
<td>86.72</td>
<td>6.06%</td>
</tr>
<tr>
<td>Evasion attack</td>
<td>68.80</td>
<td>74.57</td>
<td>78.92</td>
<td>85.60</td>
<td>7.18%</td>
</tr>
<tr>
<td>Byzantine attack</td>
<td>65.34</td>
<td>71.28</td>
<td>76.34</td>
<td>83.28</td>
<td>9.50%</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="table" rid="table-9">Table 9</xref> presented the robustness of the FedPPID model against adversarial attacks by comparing its performance with and without attacks. Without any attack, the model maintained 100% performance. Under a model poisoning attack, performance dropped by 4% to 96%. During a data poisoning attack, performance decreased by 5% to 95%. In the case of a backdoor attack, performance fell by 6% to 94%. These results demonstrated the model&#x2019;s resilience, as it effectively minimized performance degradation under different attack scenarios.</p>

<p><xref ref-type="fig" rid="fig-9">Fig. 9</xref> illustrated the robustness of the FedPPID model against adversarial attacks by comparing performance over time under attack (cyan line) vs. no attack (red dashed line). The performance under attack displayed oscillations, indicating some fluctuation due to adversarial influence, but it maintained an overall stable trend. In contrast, performance without attack followed a smoother oscillatory pattern, showing the model&#x2019;s natural behavior.</p>
<fig id="fig-9">
<label>Figure 9</label>
<caption>
<title>Robustness against adversarial attacks</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_63734-fig-9.tif"/>
</fig>
</sec>
<sec id="s5_6_3">
<label>5.6.3</label>
<title>Privacy Improvement Analysis</title>
<p>The effectiveness of the privacy-preserving mechanisms implemented in the FedPPID model was analyzed through differential privacy techniques. By varying the privacy budget (<inline-formula id="ieqn-103"><mml:math id="mml-ieqn-103"><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow></mml:math></inline-formula>), we could balance privacy and accuracy.</p>
<p><xref ref-type="table" rid="table-10">Table 10</xref> analyzed the effectiveness of privacy-preserving mechanisms in the FedPPID model using differential privacy techniques by adjusting the privacy budget &#x03B5;. With a stricter privacy budget (&#x03B5; &#x003D; 0.5), the model showed a privacy loss of 4% and an accuracy of 90.43%. Increasing the budget to &#x03B5; &#x003D; 1.0 reduced privacy loss to 3%, improving accuracy to 92.78%. At &#x03B5; &#x003D; 1.5, privacy loss further decreased to 2%, and accuracy reached 92.90%, demonstrating a trade-off where higher &#x03B5; values slightly relaxed privacy but enhanced accuracy.</p>
<table-wrap id="table-10">
<label>Table 10</label>
<caption>
<title>Privacy improvement analysis with differential privacy techniques</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Privacy budget (<inline-formula id="ieqn-104"><mml:math id="mml-ieqn-104"><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow></mml:math></inline-formula>)</th>
<th>Privacy loss (%)</th>
<th>Accuracy (%)</th>
</tr>
</thead>
<tbody>
<tr>
<td><inline-formula id="ieqn-105"><mml:math id="mml-ieqn-105"><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mn>0.5</mml:mn></mml:math></inline-formula></td>
<td>4</td>
<td>90.43</td>
</tr>
<tr>
<td><inline-formula id="ieqn-106"><mml:math id="mml-ieqn-106"><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mn>1.0</mml:mn></mml:math></inline-formula></td>
<td>3</td>
<td>92.78</td>
</tr>
<tr>
<td><inline-formula id="ieqn-107"><mml:math id="mml-ieqn-107"><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mn>1.5</mml:mn></mml:math></inline-formula></td>
<td>2</td>
<td>92.90</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="fig" rid="fig-10">Fig. 10</xref> depicted the privacy improvement analysis of the FedPPID model with differential privacy techniques. The line plot showed accuracy percentages (green line), which remained high and relatively stable across various data points. Privacy loss (purple line) was also plotted, showing slight variations but remaining controlled as privacy mechanisms were applied. The bar sections represented different metrics (labeled as Metric 1, Metric 2, Metric 3, and Metric 4) associated with privacy and accuracy trade-offs across data points.</p>
<fig id="fig-10">
<label>Figure 10</label>
<caption>
<title>Privacy improvement analysis with differential privacy techniques</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_63734-fig-10.tif"/>
</fig>
</sec>
<sec id="s5_6_4">
<label>5.6.4</label>
<title>Energy Efficiency</title>
<p>Another key benefit of the FedPPID model is its energy efficiency during training. Energy consumption was measured at different power levels for the model, and the results.</p>
<p><xref ref-type="table" rid="table-11">Table 11</xref> highlighted the energy efficiency of the FedPPID model during training, showing energy consumption at various power levels. At a power level of 50 W, the model consumed 100 W of energy and achieved 91% accuracy. Reducing the power level to 30 W decreased energy consumption to 70 W while maintaining a higher accuracy of 92%. At 25 W, energy consumption was further reduced to 60 W, with the model reaching 91.5% accuracy. These results demonstrated that the FedPPID model maintained strong performance while optimizing energy usage at lower power levels.</p>
<table-wrap id="table-11">
<label>Table 11</label>
<caption>
<title>Energy efficiency during training</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Power levels (W)</th>
<th>Energy consumption (W)</th>
<th>Accuracy (%)</th>
</tr>
</thead>
<tbody>
<tr>
<td>50</td>
<td>100</td>
<td>91</td>
</tr>
<tr>
<td>30</td>
<td>70</td>
<td>92</td>
</tr>
<tr>
<td>25</td>
<td>60</td>
<td>91.5</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="fig" rid="fig-11">Fig. 11</xref> illustrated the energy efficiency of the FedPPID model during training at various power levels. At 50 W, the model consumed 100 W of energy, achieving an accuracy of 91%. When the power level was reduced to 30 W, energy consumption dropped to 70 W, with accuracy increasing to 92%. At a further reduced power level of 25 W, energy consumption decreased to 60 W, and accuracy slightly decreased to 91.5%.</p>
<fig id="fig-11">
<label>Figure 11</label>
<caption>
<title>Energy efficiency during training</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_63734-fig-11.tif"/>
</fig>
</sec>
<sec id="s5_6_5">
<label>5.6.5</label>
<title>Communication Overhead before and after Optimization</title>
<p>Communication overhead is an important factor in federated learning. The FedPPID model was optimized to reduce communication costs during model updates.</p>
<p><xref ref-type="table" rid="table-12">Table 12</xref> compared the communication overhead in gigabytes (GB) for the FedPPID model before and after optimization. For the NSL-KDD dataset, communication overhead was reduced from 2.525 to 2.450 GB. In the BoT-IoT dataset, it decreased from 2.600 to 2.525 GB. Similarly, for the UNSW-NB15 dataset, overhead dropped from 2.575 to 2.475 GB after optimization. These results demonstrated that the model&#x2019;s optimization effectively reduced communication costs during updates, enhancing the overall efficiency of the federated learning process.</p>
<table-wrap id="table-12">
<label>Table 12</label>
<caption>
<title>Communication overhead before and after optimization</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Condition</th>
<th>Before optimization (GB)</th>
<th>After optimization (GB)</th>
</tr>
</thead>
<tbody>
<tr>
<td>NSL-KDD</td>
<td>2.525</td>
<td>2.450</td>
</tr>
<tr>
<td>BoT-IoT</td>
<td>2.600</td>
<td>2.525</td>
</tr>
<tr>
<td>UNSW-NB15</td>
<td>2.575</td>
<td>2.475</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>The proposed FedPPID framework enhances communication efficiency by incorporating model compression techniques and adaptive update strategies, which collectively reduce bandwidth consumption without compromising detection accuracy. To minimize the size of transmitted model updates, quantization-based compression is applied, where model parameters are converted into lower-precision representations before being shared with the central server. This significantly decreases the volume of data exchanged during each communication round, alleviating network congestion in resource-constrained IoT environments. Additionally, the framework implements an adaptive update mechanism, where IoT devices selectively transmit model updates based on local performance improvements rather than at fixed intervals. By prioritizing updates only when significant learning progress is achieved, this approach reduces redundant communication and optimizes synchronization across devices. These combined strategies enable scalable and bandwidth-efficient federated learning, making the system well-suited for large-scale IoT deployments where minimizing overhead is crucial for real-time intrusion detection.</p>
<p><xref ref-type="fig" rid="fig-12">Fig. 12</xref> illustrated the distribution of communication overhead (in GB) for the FedPPID model before and after optimization. The &#x201C;Before Optimization&#x201D; distribution (in blue) showed higher overhead, centered around 2.525 to 2.600 GB. After optimization, the distribution (in green) shifted leftward, centering closer to 2.450 to 2.525 GB. This shift indicated a reduction in communication costs due to optimization, improving the model&#x2019;s efficiency in data transfer during updates.</p>
<fig id="fig-12">
<label>Figure 12</label>
<caption>
<title>Communication overhead before and after optimization</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_63734-fig-12.tif"/>
</fig>
</sec>
<sec id="s5_6_6">
<label>5.6.6</label>
<title>Detection Accuracy and Latency per FL Model</title>
<p>The FedPPID model was compared against other federated learning models, including FedAvg, FedProx, SCAFFOLD, and FedNova, to assess detection accuracy and latency.</p>
<p><xref ref-type="table" rid="table-13">Table 13</xref> compared the detection accuracy and latency of the FedPPID model with other federated learning models, including FedAvg, FedProx, SCAFFOLD, FedNova, and FedMA. FedAvg achieved 92% accuracy with a latency of 0.85 s, while FedProx had 91% accuracy with the lowest latency of 0.75 s. SCAFFOLD achieved 92.5% accuracy with a higher latency of 1.25 s. FedNova showed 92.7% accuracy with 1.05 s latency. FedMA achieved the highest accuracy at 93% but also had the highest latency at 1.30 s. These results highlighted the trade-offs among different FL models in terms of accuracy and latency.</p>
<table-wrap id="table-13">
<label>Table 13</label>
<caption>
<title>Detection accuracy and latency per FL model</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>FL model</th>
<th>Accuracy (%)</th>
<th>Latency (s)</th>
</tr>
</thead>
<tbody>
<tr>
<td>FedAvg</td>
<td>92</td>
<td>0.85</td>
</tr>
<tr>
<td>FedProx</td>
<td>91</td>
<td>0.75</td>
</tr>
<tr>
<td>SCAFFOLD</td>
<td>92.5</td>
<td>1.25</td>
</tr>
<tr>
<td>FedNova</td>
<td>92.7</td>
<td>1.05</td>
</tr>
<tr>
<td>FedMA</td>
<td>93</td>
<td>1.30</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="fig" rid="fig-13">Fig. 13</xref> compared detection accuracy and latency across different federated learning models. The green bars represented accuracy percentages, while the yellow line depicted latency in seconds. FedAvg and FedProx achieved 92% and 91% accuracy with latencies of 0.85 and 0.75 s, respectively. SCAFFOLD reached 92.5% accuracy but had a higher latency of 1.25 s. FedNova had 92.7% accuracy with 1.05 s latency, and FedMA achieved the highest accuracy at 93% but with the longest latency at 1.3 s.</p>
<fig id="fig-13">
<label>Figure 13</label>
<caption>
<title>Detection accuracy and latency per FL model</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_63734-fig-13.tif"/>
</fig>
</sec>
<sec id="s5_6_7">
<label>5.6.7</label>
<title>Real-Time Detection Latency by Number of Devices</title>
<p>Finally, the real-time detection latency of the FedPPID model was analyzed as the number of IoT devices increased.</p>
<p><xref ref-type="table" rid="table-14">Table 14</xref> presented the real-time detection latency of the FedPPID model across various numbers of IoT devices under three different cases. With 50 devices, latency measured 107.5 ms in Case 1, 58.4 ms in Case 2, and 32.2 ms in Case 3. As the number of devices increased to 100, latency slightly increased to 117.0 ms in Case 1, decreased to 42.8 ms in Case 2, and stabilized around 30.9 ms in Case 3. For 150 devices, latency values were 104.5, 54.8, and 31.5 ms, respectively. At 200 devices, latency varied with 112.2 ms in Case 1, 43.5 ms in Case 2, and 28.8 ms in Case 3. With 250 and 300 devices, latency fluctuated minimally, showing that the model maintained relatively stable detection latency even as the number of devices scaled, ensuring efficiency in real-time detection.</p>
<table-wrap id="table-14">
<label>Table 14</label>
<caption>
<title>Real-time detection latency by number of devices</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Number of devices</th>
<th>Case 1 (ms)</th>
<th>Case 2 (ms)</th>
<th>Case 3 (ms)</th>
</tr>
</thead>
<tbody>
<tr>
<td>50 devices</td>
<td>107.5</td>
<td>58.4</td>
<td>32.2</td>
</tr>
<tr>
<td>100 devices</td>
<td>117.0</td>
<td>42.8</td>
<td>30.9</td>
</tr>
<tr>
<td>150 devices</td>
<td>104.5</td>
<td>54.8</td>
<td>31.5</td>
</tr>
<tr>
<td>200 devices</td>
<td>112.2</td>
<td>43.5</td>
<td>28.8</td>
</tr>
<tr>
<td>250 devices</td>
<td>107.8</td>
<td>55.5</td>
<td>36.2</td>
</tr>
<tr>
<td>300 devices</td>
<td>110.2</td>
<td>50.3</td>
<td>32.9</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="fig" rid="fig-14">Fig. 14</xref> illustrated the real-time detection latency of the FedPPID model across varying numbers of IoT devices in three cases. In Case 1 (dark teal), latency ranged from 104.5 to 117.0 ms, showing slight fluctuations as device numbers increased. Case 2 (green) maintained a more stable latency, varying between 42.8 and 58.4 ms. Case 3 (purple) had the lowest latency, staying between 28.8 and 36.2 ms.</p>
<fig id="fig-14">
<label>Figure 14</label>
<caption>
<title>Real-time detection latency by number of devices</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_63734-fig-14.tif"/>
</fig>
</sec>
<sec id="s5_6_8">
<label>5.6.8</label>
<title>Federated Model Aggregation Efficiency Using FL Models</title>
<p>The federated learning models (FL) compared in this study include FedAvg, FedProx, FedSGD, and Adaptive Fed. The model efficiency is assessed based on accuracy (Privacy Accuracy Score) and Data Leakage Rate during the aggregation process.</p>
<p><xref ref-type="table" rid="table-15">Table 15</xref> compared the aggregation efficiency of federated learning models: FedAvg, FedProx, FedSGD, and Adaptive Fed. FedAvg had a Privacy Accuracy Score of 80% with a data leakage rate of 5%. FedProx improved to 85% accuracy and 4% leakage. FedSGD achieved 90% accuracy with 3% leakage, while the Adaptive Fed model excelled with a 92% accuracy score and only 2% leakage, highlighting its superior efficiency in maintaining privacy during aggregation.</p>
<table-wrap id="table-15">
<label>Table 15</label>
<caption>
<title>Federated model aggregation efficiency using FL models</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th align="center">Aggregation technique</th>
<th>Privacy accuracy score (%)</th>
<th>Data leakage rate (%)</th>
</tr>
</thead>
<tbody>
<tr>
<td>FedAvg (Baseline)</td>
<td>80</td>
<td>5</td>
</tr>
<tr>
<td>FedProx</td>
<td>85</td>
<td>4</td>
</tr>
<tr>
<td>FedSGD</td>
<td>90</td>
<td>3</td>
</tr>
<tr>
<td>Median aggregation</td>
<td>91</td>
<td>2.8</td>
</tr>
<tr>
<td>Trimmed mean</td>
<td>92</td>
<td>2.5</td>
</tr>
<tr>
<td>Krum aggregation</td>
<td>93</td>
<td>2.2</td>
</tr>
<tr>
<td>Adaptive Byzantine-Resilient Fed (Hybrid Approach)</td>
<td>94</td>
<td>1.8</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="fig" rid="fig-15">Fig. 15</xref> illustrated the aggregation efficiency of various federated learning models by comparing the Privacy Accuracy Score and Data Leakage Rate. The graph showed that as the model shifted from FedAvg to Adaptive Fed, the Privacy Accuracy Score (cyan line) increased from 80% to 92%. Conversely, the Data Leakage Rate (purple line) decreased from 5% to 2%. This clear inverse relationship highlighted the models&#x2019; effectiveness in balancing privacy and accuracy, with the Adaptive Fed model demonstrating superior performance in maintaining high accuracy while minimizing data leakage during the aggregation process.</p>
<fig id="fig-15">
<label>Figure 15</label>
<caption>
<title>Federated model aggregation efficiency using FL models</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_63734-fig-15.tif"/>
</fig>
</sec>
<sec id="s5_6_9">
<label>5.6.9</label>
<title>FPR and FNR Analysis</title>
<p>The False Positive Rate (FPR) and False Negative Rate (FNR) are critical metrics to assess the reliability of the intrusion detection system.</p>
<p><xref ref-type="table" rid="table-16">Table 16</xref> presented the False Positive Rate (FPR) and False Negative Rate (FNR) analysis for different metric sets used in assessing the intrusion detection system&#x2019;s reliability. In Metric Set 1, the FPR was 70%, while the FNR was 75%. Metric Set 2 showed an improvement with a reduced FPR of 65% but a higher FNR of 80%. Metric Set 3 further improved the FPR to 60%, although the FNR remained relatively high at 78%. These results indicated variations in performance across metric sets, emphasizing the importance of optimizing both FPR and FNR for an effective intrusion detection system.</p>
<table-wrap id="table-16">
<label>Table 16</label>
<caption>
<title>FPR and FNR analysis for different metric sets</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Metric Set</th>
<th>FPR (%)</th>
<th>FNR (%)</th>
</tr>
</thead>
<tbody>
<tr>
<td>Metric Set 1</td>
<td>70</td>
<td>75</td>
</tr>
<tr>
<td>Metric Set 2</td>
<td>65</td>
<td>80</td>
</tr>
<tr>
<td>Metric Set 3</td>
<td>60</td>
<td>78</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="fig" rid="fig-16">Fig. 16</xref> presented the analysis of the False Positive Rate (FPR) and False Negative Rate (FNR) across different metric sets. The box plots showed the distribution of FPR (orange box) and FNR (green box) for each metric set. For Metric Set 1, both FPR and FNR were higher, indicating a less reliable detection system, with FPR around 70% and FNR around 75%. Metric Set 2 demonstrated a slight improvement in FPR at 65%, but the FNR increased to about 80%. Metric Set 3 achieved the lowest FPR at 60%, although the FNR remained high at approximately 78%.</p>
<fig id="fig-16">
<label>Figure 16</label>
<caption>
<title>FPR and FNR analysis for different metric sets</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_63734-fig-16.tif"/>
</fig>
</sec>
</sec>
<sec id="s5_7">
<label>5.7</label>
<title>Comparative Analysis</title>
<p>The proposed FedPPID model was evaluated on multiple benchmark IoT datasets, including NSL-KDD, BoT-IoT, and UNSW-NB15, to assess its performance in terms of accuracy, precision, recall, F1-score, communication overhead, and robustness against adversarial attacks. In this section, we present the comparative analysis of FedPPID against other commonly used models in IoT intrusion detection, including a centralized IDS, a non-privacy-preserving federated IDS, and other federated models such as FedAvg, FedProx, and SCAFFOLD.</p>
<p><bold>Model Performance Comparison:</bold></p>
<p>To highlight the robustness of FedPPID, we conducted a comparative analysis with the following models:</p>
<p>Centralized IDS: A traditional intrusion detection system that aggregates data to a central server for processing.</p>
<p>Non-Privacy-Preserving Federated IDS: A federated model that does not incorporate privacy-preserving techniques.</p>
<p>FedAvg: A federated model that averages updates from all devices.</p>
<p>FedProx: An enhanced federated model with additional constraints to handle heterogeneous data.</p>
<p>SCAFFOLD: A federated learning model that uses control variates to address client-drift in non-IID data environments. The results of the performance metrics across these models are shown in <xref ref-type="table" rid="table-17">Table 17</xref> below.</p>
<table-wrap id="table-17">
<label>Table 17</label>
<caption>
<title>Comparative analysis</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th align="center">Model</th>
<th align="center">NSL-KDD accuracy (%)</th>
<th align="center">BoT-IoT accuracy (%)</th>
<th align="center">UNSW-NB15 accuracy (%)</th>
<th align="center">Avg. Precision (%)</th>
<th align="center">Avg. Recall (%)</th>
<th align="center">Avg. F1-Score (%)</th>
<th align="center">Communication overhead (MB)</th>
</tr>
</thead>
<tbody>
<tr>
<td>Centralized IDS [<xref ref-type="bibr" rid="ref-27">27</xref>,<xref ref-type="bibr" rid="ref-28">28</xref>]</td>
<td>88.45</td>
<td>85.12</td>
<td>86.73</td>
<td>85.6</td>
<td>84.9</td>
<td>85.2</td>
<td>150</td>
</tr>
<tr>
<td>Non-Privacy-<break/>Preserving Fed. IDS [<xref ref-type="bibr" rid="ref-29">29</xref>,<xref ref-type="bibr" rid="ref-30">30</xref>]</td>
<td>91.23</td>
<td>89.34</td>
<td>90.78</td>
<td>90.1</td>
<td>89.2</td>
<td>89.7</td>
<td>120</td>
</tr>
<tr>
<td>FedAvg [<xref ref-type="bibr" rid="ref-31">31</xref>]</td>
<td>90.12</td>
<td>88.67</td>
<td>89.25</td>
<td>88.9</td>
<td>88.3</td>
<td>88.6</td>
<td>115</td>
</tr>
<tr>
<td>FedProx [<xref ref-type="bibr" rid="ref-32">32</xref>]</td>
<td>91.67</td>
<td>89.90</td>
<td>90.45</td>
<td>90.5</td>
<td>89.7</td>
<td>90.1</td>
<td>110</td>
</tr>
<tr>
<td>SCAFFOLD [<xref ref-type="bibr" rid="ref-33">33</xref>]</td>
<td>91.90</td>
<td>90.50</td>
<td>91.00</td>
<td>91.0</td>
<td>90.5</td>
<td>90.7</td>
<td>105</td>
</tr>
<tr>
<td>Proposed FedPPID Model</td>
<td>92.78</td>
<td>91.47</td>
<td>92.05</td>
<td>92.5</td>
<td>91.8</td>
<td>92.1</td>
<td>95</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><bold>Accuracy:</bold> FedPPID achieved the highest accuracy across all datasets (92.78% on NSL-KDD, 91.47% on BoT-IoT, and 92.05% on UNSW-NB15), outperforming both traditional and federated IDS models, including SCAFFOLD and FedProx. This improvement is attributed to the model&#x2019;s robust aggregation method and privacy-preserving techniques that help generalize the model across diverse data sources.</p>
<p><bold>Precision, Recall, and F1-Score:</bold> The FedPPID model consistently outperformed other models in terms of average precision (92.5%), recall (91.8%), and F1-score (92.1%), indicating its effectiveness in accurately detecting attacks while minimizing false positives and negatives.</p>
<p><bold>Communication Overhead:</bold> FedPPID achieved a significant reduction in communication overhead, using only 95 MB for NSL-KDD compared to 150 MB for the centralized IDS. This reduction is achieved through optimized aggregation and differential privacy mechanisms, making FedPPID suitable for bandwidth-limited IoT environments.</p>
<p><bold>Robustness against Adversarial Attacks:</bold> The FedPPID model demonstrated superior resilience against adversarial attacks due to its secure aggregation and anomaly detection mechanisms. By excluding anomalous updates that could degrade model performance, FedPPID maintained stable accuracy and robustness even under adversarial conditions.</p>
<p>The comparative analysis shows that the proposed FedPPID model offers superior performance, efficiency, and resilience compared to traditional and federated models. These results indicate that FedPPID is a promising approach for privacy-preserving and robust intrusion detection in large-scale IoT environments.</p>
</sec>
<sec id="s5_8">
<label>5.8</label>
<title>Discussion</title>
<p>The results clearly indicate that the proposed FedPPID model outperforms traditional centralized IDS and non-privacy-preserving federated models across various performance metrics. The FedPPID model achieved higher accuracy rates in detecting intrusions, consistently surpassing both centralized and federated baselines. In terms of privacy preservation, the integration of differential privacy ensured that data privacy was maintained while maintaining a strong detection performance. The adversarial robustness results further validate the model&#x2019;s resilience in handling adversarial attacks, showing stable performance even under threat. Moreover, the FedPPID model demonstrated a significant reduction in communication overhead due to model compression and adaptive communication, making it more efficient for large-scale IoT environments. Additionally, the faster convergence times reinforce its suitability for real-time applications, ensuring the system adapts quickly to new threats and evolving network conditions. Overall, the balance of high accuracy, strong privacy, low communication overhead, and rapid convergence makes the FedPPID model a robust solution for securing IoT environments.</p>
<p>In the discussion of the experimental results, several points require further clarification and justification. Firstly, the model architecture used for the centralized Intrusion Detection System (IDS) should be explicitly detailed to allow for a clear comparison with the proposed framework. If the centralized IDS employs a different architecture, this distinction could significantly impact performance results, and such a comparison is crucial for understanding the relative strengths and weaknesses of each approach. Additionally, when considering the federated learning IDS without privacy preservation, it is important to explain why its performance does not surpass the proposed framework. One possible explanation is that the privacy-preserving mechanism in federated learning might enhance model accuracy by preventing overfitting to local data, thereby improving generalization. Therefore, even without explicit privacy preservation in the federated system, it may still benefit from more robust and generalized learning. Another consideration is the additional overhead associated with centralized deployments, such as a network gateway. While the server does have access to all traffic flows, the centralization introduces extra communication and computational overhead. This could be due to the necessity of transmitting data to the centralized server for processing, leading to delays in real-time threat detection. Moreover, it might require additional resources to manage and aggregate data from various IoT devices, which would not be necessary in the federated model where data remains local to the devices. Finally, while benchmark datasets used in the study are typically curated to be well-structured and balanced, real-world IoT environments often feature imbalanced traffic flows, where benign traffic vastly outweighs malicious activity. The proposed framework&#x2019;s ability to maintain comparable performance under such imbalanced conditions is an important consideration. If the framework is trained predominantly on balanced datasets, it may struggle to identify rare or novel attack patterns when faced with skewed real-world data. Further experiments are required to evaluate the model&#x2019;s robustness in handling imbalanced data, ensuring that it can still effectively detect attacks without being overwhelmed by benign traffic.</p>
<p>The experimental results provide empirical answers to the research questions formulated in <xref ref-type="sec" rid="s1">Section 1</xref>.</p>
<p>Answer to RQ1: The evaluation of the FedPPID model across NSL-KDD, BoT-IoT, and UNSW-NB15 datasets demonstrates that Federated Learning (FL) can be successfully applied for privacy-preserving intrusion detection in large-scale IoT networks. The model achieves 92.78% accuracy on NSL-KDD, 91.47% on BoT-IoT, and 92.05% on UNSW-NB15, outperforming centralized IDS and conventional FL-based IDS without privacy protection. These results confirm that FL can secure IoT devices while ensuring minimal privacy risk.</p>
<p>Answer to RQ2: The proposed quantization-based compression and adaptive update techniques significantly reduce communication overhead compared to conventional FL models. The results indicate that FedPPID reduces communication costs by up to 30% compared to non-privacy-preserving FL, while maintaining high detection accuracy. The communication overhead was recorded as 85 MB for NSL-KDD, 105 MB for BoT-IoT, and 95 MB for UNSW-NB15, demonstrating the effectiveness of these optimizations in bandwidth-limited IoT environments.</p>
<p>Answer to RQ3: The robustness of the FedPPID model against adversarial threats was validated through simulated model poisoning and data poisoning attacks. The accuracy degradation under Byzantine attacks was limited to 4.46%, compared to a 9.5% drop in standard FL models, confirming the resilience of the anomaly-based gradient filtering approach. The model successfully mitigates model poisoning, data poisoning, and backdoor attacks, ensuring secure aggregation and adversarial robustness without compromising performance.</p>
</sec>
<sec id="s5_9">
<label>5.9</label>
<title>Limitations and Threats to Validity</title>
<p>Despite the promising results of the FedPPID framework, several limitations and potential threats to validity must be acknowledged. One key limitation is the trade-off between privacy preservation and model accuracy. While incorporating Differential Privacy (DP) and Secure Multi-Party Computation (SMC) enhances data security, these techniques can introduce noise, leading to minor accuracy degradation. The challenge lies in optimizing privacy parameters to ensure a balance between security and detection performance in real-world applications.</p>
<p>Another limitation is the communication overhead associated with federated learning. Although techniques such as model compression and adaptive update mechanisms are implemented to reduce bandwidth consumption, the resource constraints of IoT devices may still impact real-time deployment. IoT networks with limited connectivity or high latency could experience delays in model synchronization, potentially affecting detection responsiveness.</p>
<p>The robustness of the model against adversarial attacks also presents a challenge. While Byzantine-robust aggregation techniques effectively mitigate model poisoning and data poisoning attacks, more sophisticated adversarial strategies, such as adaptive backdoor attacks, may still pose a risk. Further enhancements in anomaly detection mechanisms are necessary to strengthen defenses against evolving cyber threats.</p>
<p>Additionally, dataset biases and generalizability remain a concern. The evaluation is conducted on NSL-KDD, BoT-IoT, and UNSW-NB15 datasets, which, although widely used, may not fully capture emerging attack patterns in real-world IoT environments. The effectiveness of FedPPID across diverse IoT infrastructures with heterogeneous traffic patterns and unknown attack vectors requires further investigation.</p>
<p>Lastly, the scalability of federated intrusion detection in large-scale IoT deployments is a potential challenge. While FedPPID demonstrates efficiency in experimental setups, real-world IoT environments with thousands of devices may require more adaptive aggregation mechanisms and efficient hierarchical FL architectures to maintain performance. Future research should explore federated optimization strategies, such as personalized FL and edge-assisted learning, to enhance scalability.</p>
<p>Addressing these limitations and threats to validity will be crucial for the practical adoption and robustness of FL-based intrusion detection systems in IoT networks. Future work will focus on optimizing communication efficiency, improving adversarial defenses, and ensuring real-world applicability.</p>
</sec>
</sec>
<sec id="s6">
<label>6</label>
<title>Conclusion</title>
<p>This study presents FedPPID, a privacy-preserving federated learning-based intrusion detection system (IDS) for IoT networks, addressing critical challenges such as data privacy, adversarial robustness, and communication efficiency. The proposed framework successfully integrates Differential Privacy (DP), Secure Multi-Party Computation (SMC), and Byzantine-robust aggregation techniques to enhance both security and detection accuracy while reducing the risk of model poisoning and data leakage. From a practical application perspective, FedPPID offers a scalable and privacy-preserving security solution for heterogeneous IoT environments, including smart cities, healthcare systems, industrial IoT (IIoT), and intelligent transportation networks. This study successfully addresses the three core research questions, demonstrating that Federated Learning (FL) can enhance IoT security by enabling privacy-preserving intrusion detection. The FedPPID framework introduces an efficient communication optimization strategy, ensuring scalability in large-scale IoT networks, while also integrating adversarial resilience mechanisms to counter model poisoning and Byzantine attacks. The experimental results validate the effectiveness of privacy-aware intrusion detection, achieving high detection accuracy while maintaining low communication overhead and strong adversarial robustness. Future work will focus on further optimizing model aggregation techniques and exploring blockchain-based verification mechanisms to enhance trust in distributed FL environments. By ensuring real-time intrusion detection without requiring centralized data storage, this framework enhances data confidentiality and system resilience in distributed and resource-constrained IoT deployments. Despite these advancements, certain limitations remain that open avenues for future research. Future work will focus on further optimizing communication overhead, particularly through federated model compression and edge-assisted aggregation strategies. Additionally, integrating blockchain-based verification could enhance trust in federated learning updates, mitigating adversarial threats. Expanding the model&#x2019;s applicability to real-world IoT datasets and evaluating its performance under adaptive and stealthy attack scenarios will further strengthen its robustness and reliability in dynamic environments.</p>
</sec>
</body>
<back>
<ack>
<p>The researcher would like to thank the Deanship of Graduate Studies and Scientific Research at Qassim University for financial support (QU-APC-2025).</p>
</ack>
<sec>
<title>Funding Statement</title>
<p>This work was supported and funded by the Deanship of Graduate Studies and Scientific Research at Qassim University for financial support (QU-APC-2025).</p>
</sec>
<sec sec-type="data-availability">
<title>Availability of Data and Materials</title>
<p>The author used data to support the findings of this study that is included in this article.</p>
</sec>
<sec>
<title>Ethics Approval</title>
<p>Not applicable.</p>
</sec>
<sec sec-type="COI-statement">
<title>Conflicts of Interest</title>
<p>The author declares no conflicts of interest to report regarding the present study.</p>
</sec>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Singh</surname> <given-names>S</given-names></string-name>, <string-name><surname>Jan</surname> <given-names>T</given-names></string-name>, <string-name><surname>Alazab</surname> <given-names>A</given-names></string-name>, <string-name><surname>Khraisat</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Enhancing privacy-preserving intrusion detection through federated learning</article-title>. <source>Electronics</source>. <year>2023</year>;<volume>12</volume>(<issue>16</issue>):<fpage>3382</fpage>. doi:<pub-id pub-id-type="doi">10.3390/electronics12163382</pub-id>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hwang</surname> <given-names>RH</given-names></string-name>, <string-name><surname>Tripathi</surname> <given-names>M</given-names></string-name>, <string-name><surname>Vyas</surname> <given-names>A</given-names></string-name>, <string-name><surname>Lin</surname> <given-names>PC</given-names></string-name></person-group>. <article-title>Privacy-preserving federated learning for intrusion detection in IoT environments: a survey</article-title>. <source>IEEE Access</source>. <year>2024</year>;<volume>12</volume>:<fpage>20341</fpage>&#x2013;<lpage>56</lpage>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Andras</surname> <given-names>P</given-names></string-name>, <string-name><surname>Briggs</surname> <given-names>C</given-names></string-name>, <string-name><surname>Fan</surname> <given-names>Z</given-names></string-name></person-group>. <source>A review of privacy-preserving federated learning for the Internet-of-Things</source>. <publisher-loc>Berlin/Heidelberg, Germany</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2021</year>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Torre</surname> <given-names>D</given-names></string-name>, <string-name><surname>Chennamaneni</surname> <given-names>A</given-names></string-name>, <string-name><surname>Jo</surname> <given-names>J</given-names></string-name>, <string-name><surname>Vyas</surname> <given-names>G</given-names></string-name>, <string-name><surname>Sabrsula</surname> <given-names>B</given-names></string-name></person-group>. <article-title>Towards enhancing privacy-preservation of a federated learning CNN intrusion detection system in IoT: method and empirical study</article-title>. <source>ACM Trans Softw Eng Methodol</source>. <year>2025</year>;<volume>34</volume>(<issue>2</issue>):<fpage>1</fpage>&#x2013;<lpage>48</lpage>. doi:<pub-id pub-id-type="doi">10.1145/3695998</pub-id>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Parizi</surname> <given-names>RM</given-names></string-name>, <string-name><surname>Pouriyeh</surname> <given-names>S</given-names></string-name>, <string-name><surname>Attota</surname> <given-names>DC</given-names></string-name>, <string-name><surname>Mothukuri</surname> <given-names>V</given-names></string-name></person-group>. <article-title>An ensemble multi-view federated learning intrusion detection for IoT</article-title>. <source>IEEE Access</source>. <year>2021</year>;<volume>9</volume>:<fpage>134231</fpage>&#x2013;<lpage>44</lpage>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hwang</surname> <given-names>RH</given-names></string-name>, <string-name><surname>Alizadeh</surname> <given-names>M</given-names></string-name>, <string-name><surname>Rabieinejad</surname> <given-names>E</given-names></string-name>, <string-name><surname>Yazdinejad</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Two-level privacy-preserving framework: federated learning for attack detection in the consumer IoT</article-title>. <source>IEEE Trans Netw Serv Manag</source>. <year>2024</year>;<volume>70</volume>(<issue>1</issue>):<fpage>4258</fpage>&#x2013;<lpage>65</lpage>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Gonz&#x00E1;lez-Vidal</surname> <given-names>A</given-names></string-name>, <string-name><surname>Calero</surname> <given-names>J</given-names></string-name>, <string-name><surname>Campos</surname> <given-names>EM</given-names></string-name>, <string-name><surname>Saura</surname> <given-names>PF</given-names></string-name></person-group>. <article-title>Evaluating federated learning for intrusion detection in Internet of Things: review and challenges</article-title>. <source>Comput Netw</source>. <year>2022</year>;<volume>201</volume>:<fpage>108299</fpage>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Luo</surname> <given-names>C</given-names></string-name>, <string-name><surname>Carpenter</surname> <given-names>M</given-names></string-name>, <string-name><surname>Min</surname> <given-names>G</given-names></string-name></person-group>. <article-title>Federated learning for distributed IIoT intrusion detection using transfer approaches</article-title>. <source>IEEE Trans Ind Inform</source>. <year>2022</year>;<volume>19</volume>(<issue>1</issue>):<fpage>342</fpage>&#x2013;<lpage>53</lpage>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Banerjee</surname> <given-names>P</given-names></string-name>, <string-name><surname>Bhatia</surname> <given-names>K</given-names></string-name>, <string-name><surname>Bhattacharya</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Privacy-preserving detection of DDoS attacks in IoT using federated learning techniques</article-title>. In: <conf-name>2024 IEEE International Conference on Big Data &#x0026; Machine Learning (ICBDML)</conf-name>; <year>2024 Feb 24&#x2013;25</year>; <publisher-loc>Bhopal, India</publisher-loc>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>K</given-names></string-name>, <string-name><surname>Zhu</surname> <given-names>L</given-names></string-name></person-group>. <article-title>Blockchain-based federated learning for IoT security</article-title>. <source>IEEE Internet Things J</source>. <year>2022</year>;<volume>8</volume>(<issue>10</issue>):<fpage>8123</fpage>&#x2013;<lpage>33</lpage>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Teixeira</surname> <given-names>R</given-names></string-name>, <string-name><surname>Almeida</surname> <given-names>L</given-names></string-name>, <string-name><surname>Rodrigues</surname> <given-names>P</given-names></string-name></person-group>. <article-title>Privacy-preserving defense: intrusion detection in IoT using federated learning</article-title>. In: <conf-name>2024 IEEE 22nd Mediterranean Electrotechnical Conference (MELECON)</conf-name>; <year>2024 Jun 25&#x2013;27</year>; <publisher-loc>Porto, Portugal</publisher-loc>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Xie</surname> <given-names>DG</given-names></string-name>, <string-name><surname>Zeng</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Li</surname> <given-names>R</given-names></string-name>, <string-name><surname>Cui</surname> <given-names>L</given-names></string-name>, <string-name><surname>Qu</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Security and privacy-enhanced federated learning for anomaly detection in IoT infrastructures</article-title>. <source>IEEE Trans Ind Inform</source>. <year>2021</year>;<volume>17</volume>(<issue>11</issue>):<fpage>7778</fpage>&#x2013;<lpage>87</lpage>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Benameur</surname> <given-names>R</given-names></string-name>, <string-name><surname>Dahane</surname> <given-names>A</given-names></string-name>, <string-name><surname>Souihi</surname> <given-names>S</given-names></string-name>, <string-name><surname>Mellouk</surname> <given-names>A</given-names></string-name></person-group>. <article-title>A novel federated learning based intrusion detection system for IoT networks</article-title>. In: <conf-name>ICC 2024&#x002D;IEEE International Conference on Communications</conf-name>; <year>2024</year>; <publisher-loc>Denver, CO, USA</publisher-loc>. p. <fpage>2402</fpage>&#x2013;<lpage>7</lpage>. doi:<pub-id pub-id-type="doi">10.1109/ICC51166.2024.10622538</pub-id>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Rashid</surname> <given-names>MM</given-names></string-name>, <string-name><surname>Khan</surname> <given-names>SU</given-names></string-name>, <string-name><surname>Eusufzai</surname> <given-names>F</given-names></string-name>, <string-name><surname>Redwan</surname> <given-names>MA</given-names></string-name>, <string-name><surname>Sabuj</surname> <given-names>SR</given-names></string-name>, <string-name><surname>Elsharief</surname> <given-names>M</given-names></string-name></person-group>. <article-title>A federated learning-based approach for improving intrusion detection in industrial Internet of Things networks</article-title>. <source>Network</source>. <year>2023</year>;<volume>3</volume>(<issue>1</issue>):<fpage>158</fpage>&#x2013;<lpage>79</lpage>. doi:<pub-id pub-id-type="doi">10.3390/network3010008</pub-id>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Al-Shammari</surname> <given-names>M</given-names></string-name>, <string-name><surname>Fidanboylu</surname> <given-names>K</given-names></string-name>, <string-name><surname>Al-Marri</surname> <given-names>NAA</given-names></string-name>, <string-name><surname>Ciftler</surname> <given-names>BS</given-names></string-name></person-group>. <article-title>Federated mimic learning for privacy-preserving intrusion detection</article-title>. In: <conf-name>2020 IEEE International Black Sea Conference on Communications and Networking (BlackSeaCom)</conf-name>; <year>2020 May 26&#x2013;29</year>; <publisher-loc>Virtual</publisher-loc>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Shu</surname> <given-names>L</given-names></string-name>, <string-name><surname>Maglaras</surname> <given-names>L</given-names></string-name>, <string-name><surname>Friha</surname> <given-names>O</given-names></string-name>, <string-name><surname>Ferrag</surname> <given-names>MA</given-names></string-name></person-group>. <article-title>FELIDS: federated learning-based intrusion detection system for agricultural internet of things</article-title>. <source>Parallel Distrib Comput</source>. <year>2022</year>;<volume>151</volume>:<fpage>200</fpage>&#x2013;<lpage>14</lpage>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Friha</surname> <given-names>O</given-names></string-name>, <string-name><surname>Ferrag</surname> <given-names>MA</given-names></string-name>, <string-name><surname>Benbouzid</surname> <given-names>M</given-names></string-name>, <string-name><surname>Berghout</surname> <given-names>T</given-names></string-name>, <string-name><surname>Kantarci</surname> <given-names>B</given-names></string-name>, <string-name><surname>Choo</surname> <given-names>KKR</given-names></string-name></person-group>. <article-title>2DF-IDS: decentralized and differentially private federated learning-based intrusion detection system for industrial IoT</article-title>. <source>Comput Secur</source>. <year>2023</year>;<volume>127</volume>(<issue>5</issue>):<fpage>103097</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.cose.2023.103097</pub-id>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Gonz&#x00E1;lez-Vidal</surname> <given-names>A</given-names></string-name>, <string-name><surname>Calero</surname> <given-names>A</given-names></string-name>, <string-name><surname>Ruzafa-Alc&#x00E1;zar</surname> <given-names>P</given-names></string-name>, <string-name><surname>Fern&#x00E1;ndez-Saura</surname> <given-names>P</given-names></string-name></person-group>. <article-title>Intrusion detection based on privacy-preserving federated learning for the industrial IoT</article-title>. <source>IEEE Trans Netw Serv Manag</source>. <year>2021</year>;<volume>18</volume>(<issue>4</issue>):<fpage>4829</fpage>&#x2013;<lpage>41</lpage>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Duy</surname> <given-names>PT</given-names></string-name>, <string-name><surname>Hao</surname> <given-names>HN</given-names></string-name>, <string-name><surname>Chu</surname> <given-names>HM</given-names></string-name>, <string-name><surname>Pham</surname> <given-names>VH</given-names></string-name></person-group>. <article-title>A secure and privacy-preserving federated learning approach for IoT intrusion detection system</article-title>. In: <conf-name>Network and System Security: 15th International Conference</conf-name>; <year>2021 Oct 23</year>; <publisher-loc>Tianjin, China</publisher-loc>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Patel</surname> <given-names>A</given-names></string-name>, <string-name><surname>Harrison</surname> <given-names>R</given-names></string-name>, <string-name><surname>Ohara</surname> <given-names>T</given-names></string-name></person-group>. <article-title>Secure aggregation for federated learning in IoT environments</article-title>. <source>IEEE Trans Netw Serv Manag</source>. <year>2024</year>;<volume>19</volume>(<issue>2</issue>):<fpage>1135</fpage>&#x2013;<lpage>44</lpage>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Xue</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Ohtsuki</surname> <given-names>T</given-names></string-name>, <string-name><surname>Zhao</surname> <given-names>R</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Semisupervised federated-learning-based intrusion detection method for Internet of Things</article-title>. <source>IEEE Internet Things J</source>. <year>2022</year>;<volume>9</volume>(<issue>10</issue>):<fpage>8409</fpage>&#x2013;<lpage>17</lpage>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Talhi</surname> <given-names>C</given-names></string-name>, <string-name><surname>Mourad</surname> <given-names>A</given-names></string-name>, <string-name><surname>Rahman</surname> <given-names>SA</given-names></string-name>, <string-name><surname>Tout</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Internet of Things intrusion detection: centralized, on-device, or federated learning?</article-title> <source>IEEE Netw</source>. <year>2020</year>;<volume>34</volume>(<issue>6</issue>):<fpage>310</fpage>&#x2013;<lpage>7</lpage>. doi:<pub-id pub-id-type="doi">10.1109/MNET.011.2000286</pub-id>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Yang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Liang</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Fu</surname> <given-names>Q</given-names></string-name></person-group>. <article-title>Differentially private federated learning for privacy-preserving intrusion detection in IoT</article-title>. <source>IEEE Trans Inf Forensics Secur</source>. <year>2023</year>;<volume>16</volume>(<issue>7</issue>):<fpage>1344</fpage>&#x2013;<lpage>55</lpage>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Tavallaee</surname> <given-names>M</given-names></string-name>, <string-name><surname>Bagheri</surname> <given-names>E</given-names></string-name>, <string-name><surname>Lu</surname> <given-names>W</given-names></string-name>, <string-name><surname>Ghorbani</surname> <given-names>AA</given-names></string-name></person-group>. <article-title>A detailed analysis of the KDD CUP 99 dataset</article-title>. In: <conf-name>2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications</conf-name>; <year>2009 Jul 8&#x2212;10</year>; <publisher-loc>Ottawa, ON, Canada</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Moustafa</surname> <given-names>D</given-names></string-name></person-group>. <chapter-title>BoT-IoT dataset: generating IoT network intrusion dataset</chapter-title>. <publisher-loc>Canberra, Australia</publisher-loc>: <publisher-name>Cyber Range Lab of the Australian Centre for Cyber Security (ACCS), UNSW Canberra</publisher-name>; <year>2018</year>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Moustafa</surname> <given-names>N</given-names></string-name>, <string-name><surname>Slay</surname> <given-names>J</given-names></string-name></person-group>. <article-title>The UNSW-NB15 dataset for network intrusion detection systems (NIDS) and machine learning</article-title>. In: <conf-name>Proceedings of the 2015 IEEE Military Communications and Information Systems Conference (MilCIS)</conf-name>; <year>2015 Nov 10&#x2013;12</year>; <publisher-loc>Canberra, Australia</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>McMahan</surname> <given-names>B</given-names></string-name>, <string-name><surname>Moore</surname> <given-names>E</given-names></string-name>, <string-name><surname>Ramage</surname> <given-names>D</given-names></string-name>, <string-name><surname>Hampson</surname> <given-names>S</given-names></string-name>, <string-name><surname>Arcas</surname> <given-names>BAY</given-names></string-name></person-group>. <chapter-title>Communication-efficient learning of deep networks from decentralized data</chapter-title>. In: <source>Artificial Intelligence and Statistics (AISTATS)</source>; <year>2017 Apr 20&#x2013;22</year>; <publisher-loc>Lauderdale, FL, USA</publisher-loc>. p. <fpage>1273</fpage>&#x2013;<lpage>82</lpage>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>T</given-names></string-name>, <string-name><surname>Sahu</surname> <given-names>AK</given-names></string-name>, <string-name><surname>Talwalkar</surname> <given-names>A</given-names></string-name>, <string-name><surname>Smith</surname> <given-names>V</given-names></string-name></person-group>. <article-title>Federated learning: challenges, methods, and future directions</article-title>. <source>IEEE Signal Process Mag</source>. <year>2020</year>;<volume>37</volume>(<issue>3</issue>):<fpage>50</fpage>&#x2013;<lpage>60</lpage>. doi:<pub-id pub-id-type="doi">10.1109/MSP.2020.2975749</pub-id>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Karimireddy</surname> <given-names>SP</given-names></string-name>, <string-name><surname>Kale</surname> <given-names>S</given-names></string-name>, <string-name><surname>Mohri</surname> <given-names>M</given-names></string-name>, <string-name><surname>Reddi</surname> <given-names>S</given-names></string-name>, <string-name><surname>Stich</surname> <given-names>S</given-names></string-name>, <string-name><surname>Suresh</surname> <given-names>AT</given-names></string-name></person-group>. <article-title>SCAFFOLD: Stochastic controlled averaging for federated learning</article-title>. In: <conf-name>International Conference on Machine Learning (ICML)</conf-name>; <year>2020 Jul 13&#x2013;18</year>; <publisher-loc>Virtual</publisher-loc>. p. <fpage>5132</fpage>&#x2013;<lpage>43</lpage>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Sommer</surname> <given-names>R</given-names></string-name>, <string-name><surname>Paxson</surname> <given-names>V</given-names></string-name></person-group>. <article-title>Outside the closed world: on using machine learning for network intrusion detection</article-title>. In: <conf-name>2010 IEEE Symposium on Security and Privacy</conf-name>; <year>2010 May 16&#x2013;19</year>; <publisher-loc>Oakland, CA, USA</publisher-loc>. p. <fpage>305</fpage>&#x2013;<lpage>16</lpage>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Yang</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>T</given-names></string-name>, <string-name><surname>Tong</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Federated machine learning: concept and applications</article-title>. <source>ACM Trans Intell Syst Technol</source>. <year>2019</year>;<volume>10</volume>(<issue>2</issue>):<fpage>1</fpage>&#x2013;<lpage>19</lpage>. doi:<pub-id pub-id-type="doi">10.1145/3339474</pub-id>.</mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Dwork</surname> <given-names>C</given-names></string-name></person-group>. <article-title>Differential privacy: a survey of results</article-title>. In: <conf-name>International Conference on Theory and Applications of Models of Computation</conf-name>; <year>2008 Apr 25&#x2013;29</year>; <publisher-loc>Xi&#x2019;an, China</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>19</lpage>.</mixed-citation></ref>
<ref id="ref-33"><label>[33]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Cao</surname> <given-names>D</given-names></string-name>, <string-name><surname>Chang</surname> <given-names>S</given-names></string-name>, <string-name><surname>Lin</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>G</given-names></string-name>, <string-name><surname>Sun</surname> <given-names>D</given-names></string-name></person-group>. <article-title>Understanding distributed poisoning attack in federated learning</article-title>. In: <conf-name>2019 IEEE 25th International Conference on Parallel and Distributed Systems (ICPADS)</conf-name>; <year>2019</year>;<publisher-name>IEEE</publisher-name>. </mixed-citation></ref>
<ref id="ref-34"><label>[34]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Geiping</surname> <given-names>J</given-names></string-name>, <string-name><surname>Fowl</surname> <given-names>L</given-names></string-name>, <string-name><surname>Huang</surname> <given-names>WR</given-names></string-name>, <string-name><surname>Czaja</surname> <given-names>W</given-names></string-name>, <string-name><surname>Taylor</surname> <given-names>G</given-names></string-name>, <string-name><surname>Moeller</surname> <given-names>M</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Witches&#x2019; brew: industrial scale data poisoning via gradient matching</article-title>. In: <conf-name>International Conference on Learning Representations (ICLR)</conf-name>; <year>2021 May 3&#x2013;7</year>; <publisher-name>Virtual</publisher-name>.</mixed-citation></ref>
<ref id="ref-35"><label>[35]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>De Gaspari</surname> <given-names>F</given-names></string-name>, <string-name><surname>Hitaj</surname> <given-names>D</given-names></string-name>, <string-name><surname>Mancini</surname> <given-names>LV</given-names></string-name></person-group>. <article-title>Have you poisoned my data? Defending neural networks against data poisoning</article-title>. In: <conf-name>European Symposium on Research in Computer Security</conf-name>; <year>2024 Sep 16&#x2013;20</year>; <publisher-loc>Bydgoszcz, Poland</publisher-loc>.</mixed-citation></ref>
<ref id="ref-36"><label>[36]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hitaj</surname> <given-names>D</given-names></string-name>, <string-name><surname>Pagnotta</surname> <given-names>G</given-names></string-name>, <string-name><surname>Hitaj</surname> <given-names>B</given-names></string-name>, <string-name><surname>Perez-Cruz</surname> <given-names>F</given-names></string-name>, <string-name><surname>Mancini</surname> <given-names>LV</given-names></string-name></person-group>. <article-title>Federated learning as a medium for covert communication</article-title>. <source>IEEE Trans Dependable Secur Comput</source>. <year>2024</year>;<volume>21</volume>(<issue>4</issue>):<fpage>1695</fpage>&#x2013;<lpage>707</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TDSC.2023.3288215</pub-id>.</mixed-citation></ref>
</ref-list>
</back></article>