Federated Adversarial Learning for Scalable and Robust Zero-Day Cyber Threat Detection in IoT Networks

S N Prajwalasimha, Amit Purushottam Pimpalkar, Nilesh M Shelke, Dilip Kumar Jang Bahadur Saini, G Hemanth Kumar, A Sindhu · 2025

The swift growth of Internet of Things (IoT) devices has brought about a record surge in cyber-attacks, such as zero-day attacks that bypass conventional detection techniques. Federated Learning (FL) has proven to be a promising privacy-enhancing method for collaborative intrusion detection, allowing distributed clients to train models without exchanging raw data. Yet, FL is susceptible to adversarial attacks, such as model poisoning, backdoor attacks, and Byzantine failures, that can severely compromise detection performance. In this work, we introduce FedDefender, a new Federated Adversarial Learning (FAL) framework that improves the robustness of FL-based intrusion detection systems (IDS) against adversarial attacks in IoT networks. Our solution combines adversarial training, anomaly-aware aggregation, and blockchain-based client reputation scoring to identify and counter malicious model updates. We propose a hybrid Transformer + Graph Neural Network (GNN)-based IDS that utilizes sequential attack behavior modeling and graph-based traffic pattern learning. Comprehensive experiments on benchmark cybersecurity datasets (CICIDS2017, BoT-IoT, and TON_IoT) show that FedDefender is up to 30% more adversarially robust and 20% more effective in detecting zero-day attacks than state-of-the-art FL-based IDS. Our work provides a scalable and adversary-resistant federated intrusion detection framework, opening the door to secure and smart cyber threat protection in decentralized IoT systems.

Read the paper · More papers on PaperTik