FL-MU: A Benchmark Dataset for Federated Intrusion Detection in IoT Networks

Linthoingambi Takhellambam, Urikhimbam Boby Clinton, Nazrul Hoque, Khumukcham Robindro Singh, Monowar H. Bhuyan · IEEE Access · 2025

Due to the tremendous deployment of sensors, actuators, and remote devices, Internet of Things (IoT) networks have gained popularity across a wide range of application domains. As a result, the number of attackers and the dynamics of IoT network attacks are also increasing proportionately. Moreover, IoT networks generate a huge amount of sensitive data that must be carefully protected to prevent potential exploitation and exploration by adversaries. The advent of Federated Learning (FL) paved the way for enhancing data privacy and security of IoT data. Although several FL-based security systems have been developed for IoT networks, many lack effectiveness and efficiency. This limitation is due to the unavailability of up-to-date benchmark IoT network intrusion datasets that accurately reflect real-world IoT network traffic, encompassing a wide range of IoT protocols and recent, diverse attack types. This discrepancy significantly hinders the development, validation, and comparative evaluation of existing security solutions. To meet this critical need, we develop a practical IoT network intrusion dataset called FL-MU using client-specific IoT network testbeds. Each client testbed comprises more than 30 devices communicating over seven different IoT communication protocols. The FL-MU dataset includes eleven types of attacks, comprising over 19 million instances with 121 features. The effectiveness of the dataset is established on multiple state-of-the-art FL-based Intrusion Detection Systems (IDSs). The FL-based IDS models exhibit superior performance when trained on our FL-MU dataset as compared to other existing datasets. This highlights the quality and suitability of the developed FL-MU dataset for training robust and accurate FL-based security systems. The FL-MU dataset and the related implementation codes are made available at the Kaggle repository: https://doi.org/10.34740/kaggle/dsv/13106381, contributing to the research community for the advancement of IoT security.

Read the paper · More papers on PaperTik