Federated learning approaches for DDoS detection in IoMT: Challenges, models, and performance evaluation

Tejinder Sharma, Bharti Sharma · 2025

To improve DDoS attack detection in IoMT, federated learning (FL) has provided an effective decentralized model that enables training machine learning models on different devices with the data kept private. In this study, we evaluate the FL-based Intrusion Detection Systems (IDS) and compare them with other previous studies using traditional ML and DL. Different models were experimented with over benchmark datasets such as CICIDS2017, BoT-IoT, and CICDDoS2019, and the performance metrics such as accuracy, precision, recall, and F1-score were analyzed. It is demonstrated through results that federated learning–based models (such as FedMSE, FedDB, and FedMADE) can achieve high detection accuracy and preserve data privacy. FedMSE achieved an accuracy of 97.3%, while Fed MADE increased the minority attack classification by 71.07% compared to FedAvg. The results achieved by machine learning models like XGBoost and Random Forests are 99.99% and 99.25%, respectively, and by deep learning models like CNN-GRU. However, FL suffers from several issues, such as non-IID data distribution, resource constraints on IoMT devices, and communication overhead. Adversarial attacks and data poisoning introduce additional security vulnerabilities to the deployment problem. Yet, dynamic aggregation (FedMADE) and encryption techniques (FL INTRODUCTION—scalable, homomorphic encryption, and differential privacy) seem to counter these hurdles. This study finally proves that FL-based IDS can provide a scalable, privacy-preserving, and adaptive DDoS attack detection in IoMT ecosystems. Future work in FL for IoMT cybersecurity should focus on improving aspects such as real-time detection, decreasing communication latency, and improving model security to make the FL method more applicable for our scenario.

Read the paper · More papers on PaperTik