Skip to content

Lossless Privacy for Federated Security: Homomorphically-Encrypted Federated Learning Across IoT Intrusion Detection, Keystroke Dynamics, and Risk-Based Authentication

Aug 2026 · 2026 International Workshop on Intelligent Systems (IWIS) · pp. 1-6 · 0 citations · 23 references

Abstract

Federated Learning trains a shared model without centralizing raw data, yet the de-facto FedAvg protocol still reveals each client's plaintext model update to the aggregation server, opening the door to gradient-inversion and membership-inference attacks. We present HE-FedSec, a federated framework that performs secure aggregation directly on ciphertexts with the CKKS homomorphic-encryption scheme, so the server never observes any individual update. We evaluate HE-FedSec uniformly across three complementary, privacy-sensitive security domains under non-IID client partitions, which include 15-class network intrusion detection on Edge-IIoTset, 51-subject keystroke-dynamics identification on the CMU benchmark, and binary malicious-login detection on the large-scale RBA dataset. Relative to plaintext FedAvg, HE-FedSec is near-lossless on the two multiclass tasks, test accuracy changes by at most 0.26 percentage points, while on the imbalanced RBA task the ROC-AUC gap is only 0.11 points. This behavior is consistent with the small CKKS numerical error introduced into the weighted-mean aggregation. This privacy guarantee incurs a $21-27 \times$ communication expansion while introducing a minor cryptographic latency of only a few to tens of milliseconds per round. By contrast, an update-level differential-privacy baseline at a comparable privacy posture loses up to 5.9 accuracy points and converges more slowly. We release the complete, reproducible pipeline and benchmark.

View source

Similar papers

Preprint Aug 2026

SecureDrive-FL: Joint Differential Privacy and Gradient-Aware Selective Homomorphic Encryption for Federated Driver Monitoring

This work introduces GASHE (Gradient-Aware Selective Homomorphic Encryption), a novel selective encryption strategy that dynamically identifies and encrypts only the gradient components exceeding a DP-calibrated sensitivity threshold, rather than encrypting all parameters uniformly as in static layer-based or full-para...

Baran Can Gül, Hanuma Siddhartha Tunuguntla, Anjana Arvind Naik et al. · 0 citations
Open access 2026

FL-SQMPC: Secure Quantized Aggregation for Mitigating Gradient Inversion Attacks in Federated IoT Intrusion Detection

Federated Learning (FL) enables collaborative model training without centralizing raw data, but the exchange of model updates exposes clients to gradient inversion attacks (GIAs), which can reconstruct private training data from communicated gradients alone. To address this issue, we propose FL-SQMPC, a secure aggregat...

Imene Bessaa, Elmahdi Bentafat, Zakaria Abou El Houda et al. · 0 citations
Open access Aug 2026

FedMamba-IoMT: Federated state space models with differential privacy and byzantine resilience for privacy-preserving intrusion detection in Internet of Medical Things

FedMamba-IoMT is introduced, the first federated State Space Model framework for privacy-preserving intrusion detection in IoMT networks, incorporating differential privacy (DP-SGD), Byzantine-resilient aggregation, and multi-level explainability.

Y. Al-Sharo, Mohammed Tawfik, A. M. Al-madani et al. · 1 citation
Open access 2026

Privacy-Preserving and Byzantine-Robust Federated Learning With Mean-Constrained Secret Sharing

Federated learning faces three critical challenges in enabling cross-institutional collaboration: privacy leakage, poisoning by malicious clients, and unverifiable aggregation results. To address these issues in a unified manner, we propose PVeriFL—a federated learning framework that integrates privacy preservation, By...

Guang-Ye Zhu, Liqiang Wu, Ke-Qian Liu · 0 citations
Open access Aug 2026

An Explainable Federated Intrusion Detection Framework for SDN Using Distributed Key Generation and Threshold Homomorphic Encryption

The rapid advancement of software-defined networking (SDN) has enhanced network programmability, centralized control, and traffic management flexibility, while also increasing exposure to sophisticated attacks targeting the control plane. Although federated learning (FL) enables collaborative intrusion detection withou...

S. Shamim, Yuta Kodera, Md. Arshad Ali et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.