Skip to content
Open access

HAF-BiTrans: A Heterogeneity-Aware Federated BiLSTM-Transformer Framework for Privacy-Preserving Detection of Multi-Stage APT Behaviors in IoT Networks

Sep 2026 · Sustainable Machine Intelligence Journal · 0 citations

TL;DR

HAF-BiTrans is presented as a compact, edge-oriented federated architecture whose robustness under difficult non-IID conditions still requires further optimization and its practical strength is efficiency.

Abstract

Advanced persistent threats (APTs) are difficult to detect in heterogeneous Internet of Things (IoT) environments because malicious behavior can unfold across reconnaissance, scanning, command-and-control, denial-of-service, and exfiltration stages. Centralized intrusion-detection pipelines also create privacy, communication, and latency concerns when traffic originates at distributed edge devices. This study presents HAF-BiTrans, a heterogeneity-aware federated BiLSTM-Transformer framework for privacy-preserving detection of multi-stage APT-like behavior. At each client, a bidirectional long short-term memory encoder captures temporal dependencies, a lightweight Transformer models broader contextual relationships, and a class-balanced focal objective addresses class imbalance. At the server, Heterogeneity-Aware Contribution-Trust Aggregation (HACTA) weights client updates using sample support, class-coverage entropy, validation macro-F1, update stability, and differential-privacy reliability. Experiments on CICIoT2023, TON_IoT, and BoT-IoT show marked variation across datasets. HAF-BiTrans + HACTA achieved 89.29% accuracy and 88.93% macro-F1 on TON_IoT and 84.91% accuracy and 84.77% macro-F1 on BoT-IoT. On the more imbalanced CICIoT2023 experiment, centralized HAF-BiTrans reached 25.42% accuracy and 16.88% macro-F1, whereas the federated HACTA configuration reached 20.34% accuracy and 9.59% macro-F1. Thus, the present CICIoT2023 implementation does not outperform a strong tabular baseline and should not be interpreted as a state-of-the-art result. Its practical strength is efficiency: the model occupies approximately 0.052 MB and performs inference in under 0.1 ms per window. These findings position HAF-BiTrans as a compact, edge-oriented federated architecture whose robustness under difficult non-IID conditions still requires further optimization.

Read PDF

Similar papers

Open access 2026

AP3-FedFleet: Asynchronous Federated Learning With Dynamic Layer-Wise Privacy Protection for Heterogeneous IoT Systems

Federated learning (FL) enables multiple devices to collaboratively train machine learning models without sharing raw data, making it well-suited for Internet of Things (IoT) applications. However, this approach is not fully secure, as the exchanged gradients can still leak sensitive information. Attacks such as Deep L...

Mounika Mellamarthi, Ammar Summaq, Mukkara Prasanna Kumar et al. · 0 citations
2026

MsaaDI: A Heterogeneity-Resilient Federated Learning Framework for IoT Device Identification With Multi-Scale Adaptive Aggregation

Accurate IoT device identification is critical to network forensics, access control, and anomaly detection in large-scale, security-sensitive environments. Federated learning (FL) provides a decentralized and privacy-enhancing approach well suited to IoT, but FL-based identification remains hampered by cross-client dat...

Tong Sun, Qian Lu, Hanlin Zhang et al. · 0 citations
Open access Aug 2026

FedMamba-IoMT: Federated state space models with differential privacy and byzantine resilience for privacy-preserving intrusion detection in Internet of Medical Things

FedMamba-IoMT is introduced, the first federated State Space Model framework for privacy-preserving intrusion detection in IoMT networks, incorporating differential privacy (DP-SGD), Byzantine-resilient aggregation, and multi-level explainability.

Y. Al-Sharo, Mohammed Tawfik, A. M. Al-madani et al. · 1 citation
#federated learning Open access Sep 2026

Privacy-Aware and Resource-Efficient Split Learning for IoT Botnet Detection: A Multi-Dataset Experimental and Systems Evaluation

A traffic-constrained multi-client split-learning intrusion-detection system evaluated on BoT-IoT, N-BaIoT, and CIC-IDS2017, which identifies a practical accuracy–communication–energy–privacy operating point for constrained IoT clients.

M. Alja'afreh, Ali Karime, A. Oukaira · 0 citations
Open access Aug 2026

A Privacy-Preserving Federated Learning Framework for Intrusion Detection in Healthcare IoT Environments

Healthcare Internet of Things (HIoT) deployments generate sensitive patient telemetry data on resource-constrained edge devices, which are prime targets for network intrusions. Centralizing raw telemetry for training intrusion detection system (IDS) models violates patient privacy and contravenes data-protection regula...

Nutan Gusain, J. Alzubi · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.