Evaluating Privacy-Preserving Distributed AI for Resource-Constrained IoT Security : Federated Intrusion Detection with User-Level Differential Privacy on Edge IoT Devices

Joel Viggesjöö · KTH Publication Database DiVA (KTH Royal Institute of Technology) · 2025

Given the seemingly ever-growing amount of ubiquitous IoT devices in use today, ensuring their security and privacy has become a press ing matter. These IoT devices typically operate in sensitive areas such as healthcare, security, and industrial control systems, making them a prime target for cyberattacks. With this in mind, this thesis explored, implemented, and evaluated trustworthy DAI using decentralized methods on resource-constrained IoT hardware. Initially, a systematic literature review identified and compared potential DAI techniques, privacy preserving techniques, and datasets for intrusion detection. This led to three model implementations: a CL model, a FL model, and a FL model augmented with (ϵ = 10, δ = 1×10−7)-DP. All CL training and testing were performed on an aggregation server using the Edge IIoT cybersecurity dataset, while the FL and DP models were trained and evaluated across five Raspberry Pi 3 devices, demonstrating feasibility for intrusion detection on IoT edge devices. Standard ML metrics (accuracy, precision, recall, and F1-score) were gathered and visualized in confusion matrices and classification reports for a quantitative analysis. The results reveal that FL matches CL accuracy in binary- and multiclass tasks (100% and ∼94%, respectively). Adding DP to the FL model incurs a 5-12% accuracy loss in exchange for formal privacy guarantees for the 2-, 6-, and 15-class classifications, all while operating under the resource constraints of RaspberryPi-class devices. Based on existing literature found during the work of this thesis, this appears to be the first study to evaluate an implemented IDS using FL and DP for IIoT on actual IoT hardware. The result demonstrate that privacy preserving FL can be deployed on real IoT devices with only a minor loss in accuracy.

Read the paper · More papers on PaperTik