Skip to content
Open access

SEAF-FL-MLP: Audited Federated Edge-AI Anomaly Detection with Client Heterogeneity and Shortcut-Sensitivity Analysis

Jul 2026 · مجلة جامعة صنعاء للعلوم التطبيقية والتكنولوجيا · Vol 4, pp. 2292-2305 · 0 citations · 19 references

TL;DR

The results position SEAF-FL-MLP as a compact, communication-efficient, and reproducible federated edge-AI baseline while emphasizing the necessity of transparent client-level, fairness, and shortcut-robustness analysis.

Abstract

Smart agriculture and industrial Internet-of-Things(IoT) systems increasingly rely on distributed sensors, edge gate-ways, and networked control services, making privacy-preserving and communication-efficient anomaly detection essential. Centralized learning can expose operational telemetry, increase communication overhead, and degrade under heterogeneous non-independent and identically distributed (non-IID) client conditions. This paper presents SEAF-FL-MLP, a leakage safe federated edge-AI framework for binary anomaly detection across five heterogeneous IoT clients: AGRI, SWAT, WADI, WUSTL-IIoT, and TON-IoT. The framework integrates split-first preprocessing, train-only imputation/encoding/scaling/feature selection, client- specific processing, a compact multilayer perceptron (MLP), FedAvg aggregation, validation-only threshold selection, and test-only final evaluation. In the audited V9 output, the balanced validation-selected threshold achieved Accuracy=96.32%, Precision=96.67%, Recall = 93.74%, F1-score = 95.18%, ROC-AUC = 98.86%, and PR-AUC = 98.03% on the global held-out test set, with a model size of 0.0372 MB and an estimated total communication cost of 4.4682 MB across 12 federated rounds and five clients. Client-wise analysis revealed substantial heterogeneity: WUSTL-IIoT, TON-IoT, and SWAT achieved strong F1-scores, whereas AGRI and WADI remained challenging stress cases. WUSTL shortcut-reduced sensitivity showed that the WUSTL client remained strong after removing high-risk shortcut-sensitive features, although the global pipeline was partially sensitive to replacing WUSTL with the shortcut-reduced version. FedProx did not materially improve performance under the tested configuration, and the ablation results did not support claiming mutual-information feature selection as a performance-improving component in this run. The results position SEAF-FL-MLP as a compact, communication-efficient, and reproducible federated edge-AI baseline while emphasizing the necessity of transparent client-level, fairness, and shortcut-robustness analysis.

Read PDF

Similar papers

Open access Aug 2026

A Three-Stage Federated Distillation Framework for Robust Intrusion Detection in Heterogeneous IoT/Edge Networks

The framework is presented as a bounded, server-assisted robustness-oriented training strategy for heterogeneous IoT/edge intrusion detection, and shows competitive primary performance and stronger robustness in several severe label-skew settings.

Xu-Dong Yang, Zikui Lin, Qiu-Yan Li et al. · 0 citations
Open access Aug 2026

Adaptive Federated Baseline K-Means for Lightweight IoT Intrusion Detection: Auto-Thresholding and Robust Statistics Aggregation

AF-BKM is presented, an Adaptive Federated Baseline K-Means that repairs the federated mechanism with two label-free, statistics-only enhancements, and identifies merge-induced precision decay under non-IID workers as an open gap.

Mohammed Al Saleh, Joseph Azar · 0 citations
Open access 2026

XEAD-AgriSec: An Explainable Edge Anomaly Detection Framework for Cybersecurity in AI-Powered Agricultural IoT Systems

The convergence of generative artificial intelligence (GAI), large language models, and automated vulnerability discovery tools has fundamentally altered the cyber-threat landscape for Internet of Things (IoT) infrastructures in precision agriculture. Adversaries now leverage AI-powered attack generators to craft sophi...

Yassine Boukhali, S. Drǎguşin, N. Bizon et al. · 0 citations
Open access Oct 2026

Protocol-Conditioned Feature Analysis, Multi-Dataset Intrusion Detection, and Context-Aware Alert Prioritization for IoT Network Security

Internet of Things (IoT) malware and intrusions generate network-observable flow patterns, but high benchmark accuracy does not by itself establish transfer to new environments. This study presents Protocol-conditioned Analysis with Behavioral Threat Identification (PA-BTI) as an evidence-bounded framework combining da...

Abdullah Abbasi, D. Hakro, Akhtar Hussain et al. · 0 citations
Conference Open access 2026

Enhanced Intrusion Detection in IoT Networks using Federated Learning

The results show a success in implementing a real time, scalable, privacy-preserving, and adaptive IDS in large-scale IoT deployments through intelligent workload distribution between edge and cloud layers.

Chidera Winifred John, Eduediuyai Ekerete Dan, P. Asuquo et al. · 0 citations
Review 2026

A Comprehensive Review of Multi-Resource Anomaly Detection Using Federated AI and IoT

The integration of Artificial Intelligence (AI), Internet of Things (IoT), and Federated Learning (FL) has enabled advanced and privacy-preserving anomaly detection for smart resource management. Modern infrastructures generate large volumes of sensor data related to energy consumption, water usage, and electrical devi...

B. R. Vinay Kumar, M. D, Nizamuddin et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.