Int J Performability Eng ›› 2026, Vol. 22 ›› Issue (8): 440-449.doi: 10.23940/ijpe.26.08.p2.440449

Previous Articles     Next Articles

Dependability-Aware Adaptive Federated Learning-Based Intrusion Detection for Evolving Cyberattacks in Heterogeneous IoT Networks

Harnit Saini* and Sanjeev Kumar Prasad   

  1. School of Computer Science & Engineering, Galgotias University, Greater Noida, India
  • Submitted on ; Revised on ; Accepted on
  • Contact: *E-mail address: harnit.22scse3010018_phd22@galgotiasuniversity.edu.in

Abstract: The rapid growth in the number of deployed Internet of Things (IoT) networks has made these devices more vulnerable to emerging cyberattacks, such as distributed denial-of-service, botnet, spoofing, reconnaissance, brute-force, malware, and data injection attacks. Centralized intrusion detection frameworks typically require the collection of traffic data in a central server to perform analysis and detection tasks. This process may involve potential privacy risks, large communication overheads, delayed detections, and scalability issues owing to the heterogeneous clients in IoT networks. To mitigate these problems, this study proposes a Dependability-Aware Adaptive Federated Learning-Based Intrusion Detection System (ADFed-IoTIDS) for detecting evolving cyberattacks in IoT networks. In this framework, several IoT clients or gateway nodes learn local intrusion detection models based on private traffic data, whereas only model updates are transmitted to the federated aggregation server. An adaptive aggregation method is introduced to enhance the performance of global learning models by considering aspects such as local learning performance, non-independent identically distributed (non-IID) data distribution, client reliability, local loss, validation scores, and attack diversity. The proposed framework was tested using benchmark IoT intrusion detection datasets, such as CICIoT2023 and Edge-IIoTset. The evaluation criteria included classification metrics such as accuracy, precision, recall, F1-score, and dependability metrics such as false alarm rate, detection delay, communication overhead, scalability, reliability and stability. The anticipated outcomes indicate that the ADFed-IoTIDS framework will be a better intrusion detection framework than centralized machine learning models, local learning models, FedAvg, and FedProx frameworks.

Key words: adaptive aggregation, cybersecurity, federated learning, internet of things, intrusion detection system, non IID data