FedIn-NID: A Federated Learning Framework for Network Intrusion Detection in Large-Scale Heterogeneous Industrial IoT
Jingxin Mao, Zhiwei Wei, Bing Li, Rongqing Zhang, Lingyang Song · IEEE Transactions on Information Forensics and Security · 2025
The evolving Industrial Internet of Things (IIoT) is shifting towards decentralized collaborative manufacturing, posing heightened network security issues within interconnected value chains, thus requiring advanced Network Intrusion Detection (NID) systems to identify potential threats. In this context, traditional centralized NID systems are insufficient due to cross-industrial privacy concerns and interconnected secure threats. Federated Learning (FL) has emerged as a promising solution to enable the sharing of security insights without compromising privacy across participants. However, establishing an FL-based NID framework in realistic IIoT scenarios faces several hurdles, including the limited availability of large-scale devices and heterogeneous attack data distributions. The former leads to inconsistent client participation and degraded performance, while the latter hinders model convergence. To address these, we propose a novel Federated Learning-based Industrial Network Intrusion Detection (FedIn-NID) framework, incorporating a multidimensional client selection strategy and a dynamic global aggregation strategy. The selection strategy synergistically considers multidimensional factors including client availability, local dataset distribution, and dataset size. This approach accommodates clients with varying availability and avoids the selection of biased clients with data concentrated in a few categories. During model aggregation, the proposed strategy leverages the concept of exponential moving average to dynamically balance the holistic yet slightly older knowledge in the global model with the partial but relatively newer knowledge in local models, ensuring effective aggregation and convergence of the global NID model. Experiments demonstrate that FedIn-NID outperforms baselines by 10% to 30%, showcasing remarkable robustness with increasing data distribution heterogeneity and device count.