Adaptive Federated Learning-Based Architecture for Intrusion Detection in IoT/IIoT Environments
Luis Miguel García-Sáez, Sergio Ruiz-Villafranca, José Roldán-Gómez, Javier Carrillo-Mondéjar, José Luis Martínez · 2025
The rapid expansion and growth of Internet of Things (IoT) and Industrial Internet of Things (IIoT) environments has led to an increase in the number of attacks and risks in these environments. This presents new cybersecurity challenges that require more advanced intrusion detection systems (IDS). However, IDS based on centralised Machine Learning (ML) face problems of scalability, latency, and privacy. In this context, Federated Learning (FL) offers a decentralised approach that allows multiple nodes to train models collaboratively without exposing sensitive data. This work presents a federated IDS tailored for IoT/IIoT environments and introduces FedWLA, an aggregation strategy that dynamically weights updates according to the quality and uncertainty of local data. The proposed architecture is evaluated through different IoT/IIoT traffic datasets orientated to cybersecurity and widely used in these environments. It shows comparable and even superior performance to centralised methods, with an average F1-Score ranging between 0.98 - 0.99 for the tests performed. Moreover, the proposed FedWLA strategy consistently outperforms other federated aggregation approaches, such as FedAvg and FedProx, particularly in heterogeneous scenarios. These results demonstrate the capability and potential of FL in intrusion detection, effectively leveraging the scalability and privacy advantages it offers.