Scenario-Based Federated Learning for Privacy-Aware IoT Botnet Intrusion Detection
Abstract
Federated learning (FL) is a promising approach for IoT intrusion detection because it enables distributed clients to collaboratively train models without pooling raw network-flow records. However, IoT traffic is often heterogeneous across monitoring sites, devices, and attack scenarios, which can degrade federated model performance. This paper evaluates scenariobased FL for privacy-aware IoT botnet intrusion detection using IoT-23. Instead of randomly partitioning data into artificial clients, real IoT-23 capture scenarios are treated as federated clients to simulate non-IID IoT gateways. A compact multilayer perceptron, SmallMLP, is evaluated on binary benign/malicious detection and seven-class attack-family classification under centralized learning, local-only training, FedAvg, and personalized FedAvg. The final experiment uses a balanced 35,000-record IoT-23 flow-level subset with five scenario-based clients. Results show that FedAvg performs strongly for binary intrusion detection, achieving 0.9721 accuracy and 0.9382 macro-F1, improving over local-only training by 0.4307 macro-F1. In contrast, multiclass FedAvg reaches 0.6901 accuracy and 0.5979 macro-F1, improving over local-only training by 0.4870 but remaining sensitive to scenario-level non-IID partitions. The findings suggest that FedAvg can support raw-data-minimizing IoT IDS training for binary detection, but more advanced federated and personalization methods are needed for robust multiclass botnet classification.