Secure and Explainable Federated Learning for IoT Intrusion Detection: A Comprehensive Survey
Muhammad Ahmad Bilal, Ihtesham Ul Islam, Muhammad Junaid Khan, Shibli Nisar, Maemoona Kayani, Hassan Khan · IEEE Open Journal of the Communications Society · 2026
Federated learning (FL) is increasingly used for internet of things (IoT) intrusion detection to avoid centralizing sensitive telemetry, but decentralization alone does not guarantee privacy: model updates can leak data, and FL introduces new integrity risks (poisoning, backdoors, sybils, partial participation). At the same time, explainable artificial intelligence (XAI) is being added to improve analyst trust, yet in FL settings, explanations can drift across non-independent and identically distributed (IID) clients even when accuracy appears stable, and privacy mechanisms such as secure aggregation and differential privacy (DP) can distort the signals that attribution methods rely on. This survey synthesizes secure and explainable FL-intrusion detection system (IDS) through an artifact-centric lens (data, updates, and explanations), unifying threat models, heterogeneity, explanation primitives, and evaluation practice. Unlike prior surveys that discuss FL-IDS, privacy, and explainability largely as separate themes, this article systematizes them within a single artifact-centric framework that jointly analyzes data artifacts, model-update artifacts, and explanation artifacts under explicit confidentiality and integrity threat models. We provide (i) a structured threat and risk view spanning confidentiality and integrity, (ii) an evaluation and reporting discipline that treats attack success, privacy leakage, calibration, and explanation faithfulness as first-class metrics, (iii) a synthesis mapping recurring gaps into concrete, testable contributions, and (iv) a minimal standardization checklist and reference architecture with deployable design patterns that enforce traceability, governance, and comparability across studies. The goal is to shift the literature from isolated demonstrations to defensible, reproducible evidence under explicit threat models and operational constraints.