Skip to content
Open access

Mean/Std: Lightweight Distribution-Aware Aggregation for Federated IoT Botnet Detection

Jul 2026 · IoT · Vol 7, pp. 55 · 0 citations · 33 references

TL;DR

The results demonstrate that lightweight distribution-aware aggregation offers an effective, robust, and practically deployable solution for mitigating aggregation bias under simultaneous non-IID heterogeneity and severe multi-class imbalance in FL-based IoT botnet detection.

Abstract

Federated learning (FL) is a promising paradigm for privacy-preserving IoT intrusion detection, but its effectiveness can be substantially degraded by the combination of heterogeneous non-IID client distributions and severe multi-class imbalance. Under such conditions, conventional size-based aggregation may overemphasize large yet highly skewed clients, limiting the representation of minority attack classes in the global model. To address this issue, we propose Mean/Std, a lightweight distribution-aware aggregation strategy that combines a client-size proxy with two complementary statistics of local label distributions, namely the standard deviation and the dominance gap of class proportions, while preserving a communication footprint comparable to FedAvg. Experiments on the N-BaIoT benchmark, comprising seven heterogeneous IoT clients and eleven traffic classes, are conducted under a privacy-oriented update-perturbation setting inspired by secure aggregation workflows. The results show that Mean/Std consistently provides the strongest imbalance-aware performance among the evaluated FL baselines, achieving a Macro-F1 score of 0.8418 and a Balanced Accuracy of 0.8722 while improving the representation of minority attack classes. Additional experiments across five independent random seeds and a comprehensive hyperparameter sensitivity analysis further confirm the robustness and stability of the proposed aggregation mechanism. Overall, the results demonstrate that lightweight distribution-aware aggregation offers an effective, robust, and practically deployable solution for mitigating aggregation bias under simultaneous non-IID heterogeneity and severe multi-class imbalance in FL-based IoT botnet detection.

Read PDF

Similar papers

Aug 2026

Fed-blam: federated BERT and LLaMA for IoT malware detection

Experimental results demonstrate that the federated LLM-based models consistently outperform a multilayer perceptron baseline, with the LLaMA model achieving up to 99.9% accuracy and F1-score while generalising effectively to previously unseen device types.

Chloe Nazaruk, Rahim Taheri, Gelayol Golcarenarenji et al. · 0 citations
Preprint Aug 2026

FBID: Adaptive Personalized Federated Learning for Robust Out-of-Distribution Attack Detection in IoT Networks

Federated Bandit Intrusion Detection (FBID), a novel adaptive PFL framework to address this limitation through server-side personalization control, employs a contextual multi-armed bandit at the server to dynamically regulate each client's local training intensity according to its observed behavior and update quality.

A. Bui, C. T. Nguyen, Hoang-Anh Pham et al. · 0 citations
Open access Aug 2026

Adaptive Federated Baseline K-Means for Lightweight IoT Intrusion Detection: Auto-Thresholding and Robust Statistics Aggregation

AF-BKM is presented, an Adaptive Federated Baseline K-Means that repairs the federated mechanism with two label-free, statistics-only enhancements, and identifies merge-induced precision decay under non-IID workers as an open gap.

Mohammed Al Saleh, Joseph Azar · 0 citations
#federated learning Open access Sep 2026

Privacy-Aware and Resource-Efficient Split Learning for IoT Botnet Detection: A Multi-Dataset Experimental and Systems Evaluation

A traffic-constrained multi-client split-learning intrusion-detection system evaluated on BoT-IoT, N-BaIoT, and CIC-IDS2017, which identifies a practical accuracy–communication–energy–privacy operating point for constrained IoT clients.

M. Alja'afreh, Ali Karime, A. Oukaira · 0 citations
2026

MsaaDI: A Heterogeneity-Resilient Federated Learning Framework for IoT Device Identification With Multi-Scale Adaptive Aggregation

Accurate IoT device identification is critical to network forensics, access control, and anomaly detection in large-scale, security-sensitive environments. Federated learning (FL) provides a decentralized and privacy-enhancing approach well suited to IoT, but FL-based identification remains hampered by cross-client dat...

Tong Sun, Qian Lu, Hanlin Zhang et al. · 0 citations
Open access Aug 2026

Federated Learning for Privacy-Preserving Anomaly Detection in Heterogeneous IoT Networks

Simulation of a Federated Learning framework for privacy-preserving anomaly detection tailored to heterogeneous IoT networks characterised by non-independent and identically distributed data, variable computational capacities, and intermittent connectivity indicates that the proposed method offers a practical, scalable...

Raushan Raj, B. L. Pal, Saurab Singh · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.