EdgeSecure: A Heterogeneous Federated Learning Framework for Lightweight Malware Detection in Resource-Constrained IoT Networks
Abstract
The rapid expansion of Internet of Things (IoT) devices has intensified security challenges, particularly malware attacks that continue to grow in sophistication while operating under strict resource constraints. Conventional centralized machine learning–based malware detection approaches face significant limitations in IoT environments due to privacy risks, high communication overhead, and computational inefficiency. To overcome these challenges, this paper presents a lightweight federated learning framework tailored for real-time malware detection in resource-constrained IoT systems. The proposed approach employs the Federated Proximal (FedProx) algorithm to effectively address the non-IID data distribution inherent in heterogeneous IoT networks. In parallel, a compact multilayer perceptron (MLP) architecture is designed with fewer than 10,000 parameters, ensuring low computational complexity and energy efficiency suitable for edge devices. The framework also integrates intelligent data preprocessing strategies to mitigate class imbalance and supports automatic binary transformation of multi-class malware detection tasks. Comprehensive experimental evaluations are conducted on two representative IoT security datasets, IoT23 and DNN-EdgeIIoT. Using five federated clients across 50 communication rounds, the proposed framework demonstrates robust and consistent performance. On the IoT23 dataset, it achieves an accuracy of 93.90%, an F1-score of 96.44%, and an AUC of 99.01%. Similarly, on the DNN-EdgeIIoT dataset, the framework attains 99.32% accuracy, a 98.73% F1- score, and a 99.80% AUC. Notably, the model maintains exceptionally high precision, reaching 99.74% on IoT23 and 99.85% on DNN-EdgeIIoT.Overall, the proposed framework addresses three critical research gaps: preserving data privacy without centralized data aggregation, handling non-IID data distributions in IoT networks, and enabling efficient computation for resource-limited devices. The results demonstrate that the federated model achieves performance comparable to or exceeding centralized approaches, while significantly reducing communication overhead, making it a practical and scalable solution for IoT malware detection.