A Robust and Scalable Federated Continual Learning Framework for Adaptive DDoS Detection in Heterogeneous IoT Environments
Rabaie Benameur, Amine Dahane, Sami Souihi, Abdelhamid Mellouk · 2025
The evolution of Distributed Denial-of-Service (DDoS) attack techniques on the Internet of Things (IoT) domain presents ongoing challenges as attackers increasingly emulate legitimate traffic patterns. This necessitates the continual adaptation of deep learning-based anomaly detection systems. Furthermore, the high cost of recurrently retraining deep learning models from scratch highlights the demand for adaptive detection approaches that can respond effectively to shifting threats in IoT environments. This paper investigates a range of Federated Continual Learning (FCL) techniques for identifying DDoS attacks within IoT systems, utilizing diverse federated learning approaches such as Prioritized Experience Replay (PER), Learning Without Forgetting (LWF), and Clustered Federated Learning (CFL). Continuous learning techniques, including Elastic Weight Consolidation (EWC), Agnostic Model Update (AMU), and Federated Proximal (FedProx), are also applied. The effectiveness of these methods is assessed across configurations with 16, 32, and 64 clients. Results indicate that LWF performed optimally in smaller client configurations, especially with FedAvg and FedProx, while EWC was more effective in larger setups. FedAvg and FedProx were consistently reliable strategies, whereas AMU and CFL demonstrated variable performance. This study highlights the critical role of advanced machine learning techniques in enabling real-time DDoS detection for IoT applications.