Federated Intrusion Detection for IoT

Published research on detecting network intrusions without centralizing sensitive traffic — learning across IoT gateways while the raw packets stay where they belong.

Role:Co-author & Prototype Lead Venue:Peer-reviewed publication Domain:Security · Federated Learning · IoT
Close-up of a monitor showing cybersecurity and data protection interfaces

Project Overview


Centralized intrusion detection means shipping raw traffic to one place — a privacy risk and a bandwidth problem at IoT scale. Our work trains detection models directly on gateway devices and shares only model updates, never packets.

I built the experiment pipeline and the evaluation harness, ran the non-IID data partitions that mirror real deployments, and wrote the sections on threat model and deployment constraints.

Output:Published paper + code
Data:IoT intrusion traces
  • •Privacy-preserving by design
  • •Tested under skewed data splits
  • •Gateway-class hardware profile

The Challenge


IoT gateways see wildly different traffic — a smart-building gateway and a factory-floor gateway barely overlap. Standard federated setups assume similar data everywhere, and naive aggregation collapses under that skew while missing slow, low-rate attacks.

  • Highly non-identical traffic distributions across participating gateways break standard federated averaging.
  • Constrained gateway hardware rules out heavyweight models and frequent communication rounds.
  • Raw traffic can never leave the gateway, so every experiment must prove nothing sensitive leaks through updates.

Approach & Delivery


1 · Lightweight local models

Compact sequence models sized for gateway-class CPUs, with feature extraction tuned to flow metadata rather than payload bytes — nothing sensitive ever leaves the device.

2 · Skew-aware aggregation

Clustered aggregation groups gateways with similar traffic profiles before merging, keeping minority attack patterns from being averaged away.

3 · Realistic evaluation

Partitioned public IoT intrusion traces the way real deployments look — uneven, bursty, and imbalanced — and measured detection quality per attack family, not just top-line accuracy.

4 · Reproducible pipeline

Containerized the full experiment stack so reviewers could re-run every figure from a single command. Published code and preprocessing alongside the paper.

Outcomes & Deliverables


  • Peer-reviewed publication with reproducible experiments, presented to an audience of networks and security researchers.
  • Detection approach that holds up under realistic data skew, where baseline federated methods degrade sharply.
  • Open experiment codebase adopted by the university networks lab for two follow-up student theses.
PythonPyTorchFlowerZeekDocker

Related Work


Working on IoT security or applied ML?

I collaborate on research and proof-of-concept builds — from threat model to published result.

Discuss research