Federated Intrusion Detection for IoT
Published research on detecting network intrusions without centralizing sensitive traffic — learning across IoT gateways while the raw packets stay where they belong.
Project Overview
Centralized intrusion detection means shipping raw traffic to one place — a privacy risk and a bandwidth problem at IoT scale. Our work trains detection models directly on gateway devices and shares only model updates, never packets.
I built the experiment pipeline and the evaluation harness, ran the non-IID data partitions that mirror real deployments, and wrote the sections on threat model and deployment constraints.
- •Privacy-preserving by design
- •Tested under skewed data splits
- •Gateway-class hardware profile
The Challenge
IoT gateways see wildly different traffic — a smart-building gateway and a factory-floor gateway barely overlap. Standard federated setups assume similar data everywhere, and naive aggregation collapses under that skew while missing slow, low-rate attacks.
- Highly non-identical traffic distributions across participating gateways break standard federated averaging.
- Constrained gateway hardware rules out heavyweight models and frequent communication rounds.
- Raw traffic can never leave the gateway, so every experiment must prove nothing sensitive leaks through updates.
Approach & Delivery
1 · Lightweight local models
Compact sequence models sized for gateway-class CPUs, with feature extraction tuned to flow metadata rather than payload bytes — nothing sensitive ever leaves the device.
2 · Skew-aware aggregation
Clustered aggregation groups gateways with similar traffic profiles before merging, keeping minority attack patterns from being averaged away.
3 · Realistic evaluation
Partitioned public IoT intrusion traces the way real deployments look — uneven, bursty, and imbalanced — and measured detection quality per attack family, not just top-line accuracy.
4 · Reproducible pipeline
Containerized the full experiment stack so reviewers could re-run every figure from a single command. Published code and preprocessing alongside the paper.


Outcomes & Deliverables
- Peer-reviewed publication with reproducible experiments, presented to an audience of networks and security researchers.
- Detection approach that holds up under realistic data skew, where baseline federated methods degrade sharply.
- Open experiment codebase adopted by the university networks lab for two follow-up student theses.
Related Work
Working on IoT security or applied ML?
I collaborate on research and proof-of-concept builds — from threat model to published result.
Discuss research