fDoS: Explainable AI-Based Federated Learning for DDoS Detection in IoT Networks
Sai Sriram Gonthina, Karthikeya Prachodhan Mudumba, Mallikharjuna Rao Smieee · 2025
The growing number of Internet of Things (IoT) devices and embedded technology has created them popular targets for intrusions such as DDoS and malware, creating serious security problems. These attacks diminish network performance and pose privacy and data integrity issues in IoT environments. Existing centralized detection mechanisms struggle with scalability and data privacy concerns, highlighting the need for a distributed yet efficient solution. This study proposes a Federated Learning (FL)-based framework to detect DDoS attacks by incorporating a dual-stage feature mining approach using Recursive Feature Elimination (RFE) and correlation-based filtering to identify the most relevant and non-redundant features. Additionally, Explainable AI (XAI) techniques are integrated to enhance model transparency, allowing for better interpretability of feature contributions. Gradient boosting is the classification model used to achieve high accuracy while adapting to dynamic attack patterns. FL’s distributed design guarantees that the system is suitable for real-time deployment in IoT networks, since it processes data locally at edge devices without transferring critical information. The developed fDoS gives an accuracy of 99.73%, outperforming traditional centralized and distributed approaches in detection accuracy and computational efficiency. This solution enhances IoT network security by providing a scalable, privacy-preserving, and computationally efficient framework for detecting and mitigating DDoS attacks in real-time.