Skip to content
#federated learning Open access

Privacy-Aware and Resource-Efficient Split Learning for IoT Botnet Detection: A Multi-Dataset Experimental and Systems Evaluation

Sep 2026 · IoT · 0 citations · 36 references
Network Security and Intrusion Detection

TL;DR

A traffic-constrained multi-client split-learning intrusion-detection system evaluated on BoT-IoT, N-BaIoT, and CIC-IDS2017, which identifies a practical accuracy–communication–energy–privacy operating point for constrained IoT clients.

Abstract

Internet of Things (IoT) botnet detection requires high predictive performance, low client-side resource demands, and limited exposure of raw traffic data. This paper presents a traffic-constrained multi-client split-learning (TC-SL) intrusion-detection system evaluated on BoT-IoT, N-BaIoT, and CIC-IDS2017 using eight clients and one edge server. TC-SL is positioned as a resource-constrained engineering adaptation of standard split learning: it profiles candidate cut layers, selects the highest-performing feasible cut under an explicit communication budget, and trains by exchanging cut-layer activations and gradients while raw records remain local. Centralized, federated, split-learning, and SplitFed-v1 models were compared with matched partitions and optimization budgets. Split learning achieved macro F1 scores of 98.88%, 98.42%, and 97.51% on the three datasets, respectively, with a mean macro F1 of 98.27%, compared with 98.52% for centralized learning, 97.84% for federated learning, and 98.39% for SplitFed. Its pooled ROC-AUC and average precision were 0.985 and 0.980. Within the fixed 10-epoch systems workload, the selected L4 cut logged 95 MB of bidirectional communication per epoch and 0.95 GB in total, versus 405 MB per epoch and 4.05 GB for the configured federated-learning baseline; these byte totals are fixed-workload measurements rather than communication-to-target-accuracy claims. The early split minimized cumulative client energy at 248 J, whereas the middle split minimized total-system energy at 780 J. Across L1–L6, reconstruction NRMSE increased from 0.18 to 0.71, membership-inference AUC decreased from 0.71 to 0.53, label- and attribute-inference success decreased from 0.84 and 0.76 to 0.55 and 0.54, inversion success decreased from 75% to 20%, and poisoning-induced macro-F1 degradation decreased from 6.8 to 3.9 percentage points. The results identify a practical accuracy–communication–energy–privacy operating point for constrained IoT clients.

Read PDF

Similar papers

Conference Sep 2026

Scenario-Based Federated Learning for Privacy-Aware IoT Botnet Intrusion Detection

Federated learning (FL) is a promising approach for IoT intrusion detection because it enables distributed clients to collaboratively train models without pooling raw network-flow records. However, IoT traffic is often heterogeneous across monitoring sites, devices, and attack scenarios, which can degrade federated mod...

Hassan A. Shafei · 0 citations
Open access Aug 2026

A Three-Stage Federated Distillation Framework for Robust Intrusion Detection in Heterogeneous IoT/Edge Networks

The framework is presented as a bounded, server-assisted robustness-oriented training strategy for heterogeneous IoT/edge intrusion detection, and shows competitive primary performance and stronger robustness in several severe label-skew settings.

Xu-Dong Yang, Zikui Lin, Qiu-Yan Li et al. · 0 citations
Conference Aug 2026

ResFed-IDS: Resource-Aware Federated Learning for Sustainable IoT Intrusion Detection

Federated learning (FL) reduces raw-data sharing in Internet of Things (IoT) intrusion detection systems (IDSs), but standard FL can still overuse battery-powered clients by assigning local training without considering device health. This paper presents ResFed-IDS, a resource-aware FL framework that combines server-sid...

Seidy Kante, K. Küçük, S. A. Khan · 0 citations
Conference Open access 2026

Enhanced Intrusion Detection in IoT Networks using Federated Learning

The results show a success in implementing a real time, scalable, privacy-preserving, and adaptive IDS in large-scale IoT deployments through intelligent workload distribution between edge and cloud layers.

Chidera Winifred John, Eduediuyai Ekerete Dan, P. Asuquo et al. · 0 citations
Open access 2026

A Family-Aware Hierarchical XGBoost Framework for Efficient IoT Intrusion Detection

A family-aware hierarchical intrusion detection framework for attack-family prediction that first separates normal and attack traffic, then routes attack samples into empirically defined majority and minority attack-family branches, and finally performs branch-specific family classification.

Motab F. Alenezi, F. Alotaibi, B. Alturki et al. · 0 citations
#edge computing Open access Aug 2026

Federated learning and edge computing-based collaborative detection system for IoT anomaly behavior

This study demonstrates the efficacy of the synergy between federated learning and edge computing in IoT security contexts, providing a scalable and privacy-centric solution for anomaly detection across large-scale distributed devices.

Quan Liu, Yuanyuan Feng · 0 citations

Related blog posts

Microsoft Research Blog Sep 30, 2026

Forecasting space weather risks on power grids

Extreme space-weather events can damage power systems on Earth and degrade GPS accuracy and satellite operations. A new machine learning system can predict where damage is likely to occur 30-60 minutes before a storm arrives. The post Forecasting space weather risks on power grids appeared first on Microsoft Research.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.