Federated transfer learning-based intrusion detection system in 5G networks
Andrea Bellmunt, Beatriz Otero, Eva Rodríguez, Xavi Masip‐Bruin · Expert Systems with Applications · 2025
• Proposing an FTL-based IDS framework for IoT networks using a pre-trained FL model on Bot-IoT and UNSW-NB15 datasets. • Comparing the FTL-based model with a standard FL model to assess detection performance, especially for unknown attacks. • Analyzing how varying local data distributions affect detection accuracy in federated environments. • Demonstrating improved attack detection in nodes with limited malicious data, enhancing realworld applicability. The development of Intrusion Detection Systems (IDS) for the Internet of Things (IoT) and 5G networks is rapidly advancing. This study investigates the application of federated architectures to train detection models while preserving data privacy by eliminating the need for data sharing among devices. We propose a Federated Transfer Learning (FTL) model tailored for scenarios with unbalanced nodes, enhancing the detection capabilities for unknown attacks compared to conventional Federated Learning (FL) approaches. Utilizing the Bot-IoT dataset as the source domain and the UNSW-NB15 dataset as the target domain, our experiments reveal significant improvements in detection performance. Specifically, nodes characterized by lower proportions of malicious traffic demonstrate up to a 62.614 % enhancement in detecting unknown attacks, increasing detection rates from 19.090 % to 81.704 %. Moreover, our findings indicate that FTL not only improves the identification of unknown threats but also maintains robust performance in detecting both attacks and benign traffic. Notably, the minimum accuracy achieved by the most imbalanced node reaches 0.912, in contrast to 0.741 with standard FL models. These results highlight the potential of FTL to train robust models across distributed nodes while ensuring privacy, thereby contributing to improved security measures in IoT and 5G networks.