Activation-Level Privacy and Certified Robustness in Federated Split Learning for IoT Intrusion Detection
Federated learning for IoT intrusion detection must protect each client's training records, yet the standard remedy (DP-SGD on full-encoder gradients) collapses utility under non-IID, label-scarce traffic because the Gaussian noise is injected into a parameter space of 10 5 dimensions. We propose SplitFed-DP, a federated split-learning pipeline with a dual guarantee. First, it relocates the Gaussian DP mechanism from the high-dimensional gradient to the low-dimensional activation space at the cut layer, audited under Rényi differential privacy; this recovers tens of points of accuracy and macro-F1 over gradient-level DP-SGD and, at a fixed privacy budget, statistically ties non-private federated baselines that pay no privacy cost. Second, we prove that this same Gaussian release coincides with the randomised-smoothing operator of Cohen et al. at the cut layer, so a single training run yields both (ɛ,δ)-DP and a certified l 2 -robustness guarantee in input space at no additional training cost. On TON-IoT and Bot-IoT, S plit F ed -DP closes about two-thirds of the DP-SGD-to-oracle utility gap and certifies a large majority of inputs at non-trivial radii. All reported numbers come from executed runs; no values are interpolated.