An AI ‐Enabled Privacy‐Preserving Federated Learning Framework of Hybrid bi‐ LSTM ‐ RNN ‐ CNN for Deep Intelligent Intrusion Detection in Fog Computing in the IoT Domain
Vijay Prakash, Arun Kumar Shukla · Concurrency and Computation Practice and Experience · 2025
ABSTRACT The exploration of deep‐learning models for detecting intrusions on the Internet of Things (IoT) components within fog computing environments is an emerging field that addresses the significant security concerns of connected nodes. This vulnerability has driven the development of sophisticated intrusion detection systems (IDSs). These systems leverage advanced deep learning methodologies, emphasize deep learning algorithms, enhance the capacity of intrusion detection and mitigate the security threats associated with IoT devices. The integration of fog computing‐instead of depending entirely on centralized cloud servers, this paradigm analyzes data closer to the source—and has further intensified research efforts in this field. This architecture not only improves response times but also raises unique security considerations, requiring tailored the state‐of‐the‐art (SOTA) models deep learning models capable of adapting to dynamic attack patterns. Convolutional neural networks (CNNs), recurrent neural networks (RNNs) and long short‐term memory (LSTM) networks are prime examples of deep learning approaches that integrate various deep learning frameworks to develop hybrid methods. These methodologies to be highly effective in detecting intricate attack vectors across diverse datasets, consistently surpassing traditional models in terms of both accuracy and reliability. Notably, the development of several IoT attack detection datasets, such as the Fog‐IoT and IoT‐RPL 2021 datasets, has been essential for making it easier to train and assess these deep learning models. Researchers can model real‐world situations and create more reliable IDS solutions that are suited to the subtleties of IoT contexts that consider the availability of extensive datasets. However, challenges such as scalability, data privacy, and the models' capacity to generalize across diverse datasets continue to pose difficulties for both researchers and practitioners, underscoring the imperative for ongoing innovation in this domain. AI‐augmented novel privacy‐preserving federated learning, specifically through a hybrid BiLSTM‐RNN‐CNN framework, represents an innovative approach to enhancing intrusion detection systems (IDSs) within fog computing environments tailored for the Internet of Things (IoT). This technology aims to address critical challenges related to data privacy, security, and model accuracy in the rapidly evolving IoT landscape, where sensitive information is frequently processed and transferred across networks. By enabling decentralized model training that maintains local data on devices, this framework significantly mitigates the privacy risks associated with traditional centralized data processing methods. The hybrid framework integrates convolutional neural networks (CNNs), bidirectional long short‐term memory (BiLSTM) networks, and recurrent neural networks (RNNs) to effectively process critical patterns of data indicative of malicious activities. This integration allows for improved classification accuracy and real‐time response capabilities in intrusion detection, particularly for the limited resources in IoT systems. This method not only enhances detection performance but also preserves user privacy, fulfilling regulatory requirements such as the general data protection regulation (GDPR) while facilitating collaborative learning across devices. This innovative framework merges machine learning techniques with privacy‐preserving methodologies, to address the critical need for enhanced security measures. This paradigm is important because it can handle the special security issues that the fog layer—a decentralized architecture that occurs between cloud services and Internet of Things devices—presents. Traditional intrusion detection solutions, such signature‐based detection, often lag behind new threats such as zero‐day attacks. The hybrid Bi‐LSTM‐RNN‐CNN framework employs sophisticated techniques LIME (Local Interpretable Model‐agnostic Explanations), including optimized hyper‐parameters via adaptive gray wolf optimization (AGWO), which generate superior performance metrics, including accuracy rates over 99% on benchmark datasets such as NSL‐KDD and UNSW‐NB15. Furthermore, although the federated learning model significantly improves efficiency and reduces execution time, issues related to ensuring robust security and maintaining effective performance, significantly enhance interpretability, robustness, and trustworthiness across diverse IoT environments remain critical areas for ongoing research. This framework's commitment to safeguard sensitive user information while providing robust intrusion detection capabilities is implemented. Overall, the integration of AI‐augmented federated learning with a hybrid Bi‐LSTM‐RNN‐CNN framework improves the efficacy of anomaly identification systems in fog computing for secure, intelligent IoT applications. As research continues to evolve, this framework stands out for its potential to improve cybersecurity while addressing pressing privacy concerns, ultimately fostering trust in the deployment of IoT technology. Various deep learning models for IoT intrusion identification in the fog computing domain represent promising frontiers in cybersecurity research. The ability of the framework to inculcate evolving threats while maintaining high detection accuracy emphasizes its importance in safeguarding the integrity of increasingly complex IoT networks. In fog computing configurations, recurrent neural networks (RNNs) have become a key technique for identifying cyberattacks on Internet of Things (IoT) devices. RNNs are especially important as more IoT devices are used in different industries because they are very good at processing data in order, which helps them to find patterns over time, which might indicate security problems. The importance of RNNs in enhancing IoT security procedures is underscored by the correlation between the increasing number of connected components and increasing necessity for robust security measures to combat advanced cyber threats. Advanced RNN variants, including the Bi‐LSTM, RNN‐CNN and LSTM‐CNN networks, have proven to be highly effective in attack detection because they maintain contextual information across extended sequences. Research indicates that the LSTM, RNN and hybrid Bi‐LSTM models achieve detection accuracies as high as 98.8% in identifying specific attack types within complex IoT datasets, illustrating their potential to provide timely and accurate responses to security incidents. These models can also be used with other machine learning methods to increase their efficacy and create hybrid systems that improve the real‐time attack detection efficiency and accuracy. This innovative architecture is designed to facilitate a privacy‐preserving intrusion detection system (IDS), ensuring that user data remain secure while maintaining high detection performance and scalability. In summary, the hybrid Bi‐LSTM‐RNN model serves as an effective anomaly detection mechanism for IoT applications. It effectively addresses the issues of real‐time data processing in the fog computing domain while significantly improving the security posture of linked devices. In response to evolving cyber threats, advancements in this domain should enhance the efficacy and efficiency of the IoT security protocols. Overall, the integration of AI‐augmented federated learning with a hybrid BiLSTM‐RNN‐CNN framework not only enhances the effectiveness of intrusion detection systems in fog computing but also paves the way for future developments in secure, intelligent IoT applications. As research continues to evolve, this framework stands out for its potential to improve cybersecurity while addressing pressing privacy concerns, ultimately fostering trust in the deployment of IoT technology.