PrivRobust-SL: a privacy- preserving and adversarially robust split learning framework for IoT intrusion detection
V Santhosh Kumar, Dhiraj Sunehra · Results in Engineering · 2026
The rapid expansion of Internet of Things (IoT) networks has intensified the demand for machine learning solutions that ensure both privacy and security. Traditional centralised learning models are highly vulnerable to privacy breaches and adversarial manipulations, pointing to the importance of distributed frameworks with integrated defence mechanisms. This work presents PrivRobust-SL, a novel split learning framework that jointly enforces differential privacy and adversarial robustness against privacy leakage and evasion attacks. In PrivRobust-SL, Gaussian differential privacy noise is applied to client-side activations, while the server employs FGSM and PGD-based adversarial perturbations within the joint Denoising Auto encoder (DAE) classifier to enhance feature stability. Experimental evaluations show that PrivRobust-SL maintains a high clean accuracy of 85.2% with only marginal utility loss of 1–2% while improving adversarial accuracy by over 15% at stronger perturbation levels. It achieves 74.22% (FGSM) and 73.10% (PGD) accuracies at ε = 0.05, offering robustness on par with AT-only and far exceeding DP-only performance. The higher reconstruction error shows enhanced privacy protection against feature inversion attacks. Overall, the proposed framework demonstrates balanced trade-off among privacy, utility, and robustness, maintaining stable detection accuracy under adversarial attacks, offering a reliable solution for secure IoT environments.