{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,10]],"date-time":"2026-08-10T19:26:06Z","timestamp":1786389966270,"version":"3.56.0"},"reference-count":70,"publisher":"Frontiers Media SA","license":[{"start":{"date-parts":[[2025,5,14]],"date-time":"2025-05-14T00:00:00Z","timestamp":1747180800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["frontiersin.org"],"crossmark-restriction":true},"short-container-title":["Front. Big Data"],"abstract":"<jats:p>Intrusion detection has been of prime concern in the Internet of Things (IoT) environment due to the rapid increase in cyber threats. Majority of traditional intrusion detection systems (IDSs) rely on centralized models, raising significant privacy concerns. Federated learning (FL) offers a decentralized alternative; however, many existing FL-based IDS frameworks suffer from poor performance due to suboptimal model architectures and ineffective hyperparameter selection. To address these challenges, this paper introduces a novel trust-centric FL framework based on the tab transformer (TTF) model for IDS. We enhance the Tab model through an optimization process, utilizing a hyperparameter tuning algorithm inspired by the nature-based electric eel foraging optimization (EEFO) algorithm. The goal of the developed framework is to improve the detection of IDS without using centralized data to preserve privacy. Whereas it enhances the processing and detection capability of huge amounts of data generated from IoT devices. Our framework is tested on three IoT datasets: N-BaIoT, UNSW-NB15, and CICIoT2023 to ensure the model's performance. Experimental results show that the proposed framework significantly exceeds traditional methods in terms of accuracy, precision, and recall. The results presented in this study confirm the effectiveness and superior performance of the proposed FL-based IDS framework.<\/jats:p>","DOI":"10.3389\/fdata.2025.1526480","type":"journal-article","created":{"date-parts":[[2025,5,14]],"date-time":"2025-05-14T05:41:01Z","timestamp":1747201261000},"update-policy":"https:\/\/doi.org\/10.3389\/crossmark-policy","source":"Crossref","is-referenced-by-count":26,"title":["Federated learning framework for IoT intrusion detection using tab transformer and nature-inspired hyperparameter optimization"],"prefix":"10.3389","volume":"8","author":[{"given":"Mohamed","family":"Abd Elaziz","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ibrahim A.","family":"Fares","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Abdelghani","family":"Dahou","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mansour","family":"Shrahili","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1965","published-online":{"date-parts":[[2025,5,14]]},"reference":[{"key":"B1","doi-asserted-by":"publisher","first-page":"346","DOI":"10.1016\/j.comcom.2022.09.012","article-title":"Federated Learning for intrusion detection system: concepts, challenges and future directions","volume":"195","author":"Agrawal","year":"2022","journal-title":"Comp. Commun"},{"key":"B2","doi-asserted-by":"publisher","first-page":"665","DOI":"10.11591\/eei.v13i1.5844","article-title":"Ensemble learning classifiers hybrid feature selection for enhancing performance of intrusion detection system","volume":"13","author":"Al Essa","year":"2024","journal-title":"Bullet. Elect. Eng. Inform"},{"key":"B3","doi-asserted-by":"publisher","first-page":"140699","DOI":"10.1109\/ACCESS.2020.3013541","article-title":"Federated learning: a survey on enabling technologies, protocols, and applications","volume":"8","author":"Aledhari","year":"2020","journal-title":"IEEE Access"},{"key":"B4","doi-asserted-by":"publisher","first-page":"0120574","DOI":"10.14569\/IJACSA.2021.0120574","article-title":"Evaluation of machine learning algorithms for intrusion detection system in WSN","volume":"12","author":"Alsahli","year":"2021","journal-title":"Int. J. Adv. Comp. Sci. Appl"},{"key":"B5","doi-asserted-by":"publisher","first-page":"101921","DOI":"10.1016\/j.cose.2020.101921","article-title":"A survey of machine learning-based solutions to protect privacy in the Internet of Things","volume":"96","author":"Amiri-Zarandi","year":"2020","journal-title":"Comp. Secur"},{"key":"B6","doi-asserted-by":"publisher","first-page":"110005","DOI":"10.1016\/j.comnet.2023.110005","article-title":"SIDS: A federated learning approach for intrusion detection in IoT using Social Internet of Things","volume":"236","author":"Amiri-Zarandi","year":"2023","journal-title":"Computer Networks"},{"key":"B7","first-page":"523","article-title":"\u201cFLUIDS: federated learning with semi-supervised approach for intrusion detection system,\u201d","volume-title":"2022 IEEE 19th Annual Consumer Communications and Networking Conference (CCNC)","author":"Aouedi","year":"2022"},{"key":"B8","article-title":"\u201cAlgorithms for hyper-parameter optimization,\u201d","author":"Bergstra","year":"2011","journal-title":"Advances in Neural Information Processing Systems"},{"key":"B9","doi-asserted-by":"publisher","first-page":"104337","DOI":"10.1016\/j.cose.2025.104337","article-title":"FedMSE: Semi-supervised federated learning approach for IoT network intrusion detection","volume":"2025","author":"Beuran","year":"2025","journal-title":"Comp. Secur"},{"key":"B10","article-title":"Poisoning attacks against support vector machines","author":"Biggio","year":"2012","journal-title":"arXiv"},{"key":"B11","article-title":"\u201cMachine learning with adversaries: Byzantine tolerant gradient descent,\u201d","author":"Blanchard","year":"2017","journal-title":"Advances In Neural Information Processing Systems"},{"key":"B12","first-page":"374","article-title":"Towards federated learning at scale: system design","volume":"1","author":"Bonawitz","year":"2019","journal-title":"Proc. Mach. Learn. Syst"},{"key":"B13","doi-asserted-by":"publisher","first-page":"103407","DOI":"10.1016\/j.adhoc.2024.103407","article-title":"Secure and privacy-preserving intrusion detection in wireless sensor networks: Federated learning with SCNN-Bi-LSTM for enhanced reliability","volume":"155","author":"Bukhari","year":"2024","journal-title":"Ad Hoc Networks"},{"key":"B14","doi-asserted-by":"publisher","first-page":"103106","DOI":"10.1016\/j.cose.2023.103106","article-title":"Generalizing intrusion detection for heterogeneous networks: a stacked-unsupervised federated learning approach","volume":"127","author":"Carvalho Bertoli","year":"2023","journal-title":"Comp. Security"},{"key":"B15","doi-asserted-by":"publisher","first-page":"341","DOI":"10.1109\/TMC.2022.3221212","article-title":"Decentralized federated learning with intermediate results in mobile edge computing","volume":"23","author":"Chen","year":"2024","journal-title":"IEEE Trans. Mobile Comp"},{"key":"B16","article-title":"\u201cFederated Bayesian optimization via Thompson sampling,\u201d","author":"Dai","year":"2020","journal-title":"Advances in Neural Information Processing Systems"},{"key":"B17","doi-asserted-by":"publisher","first-page":"200462","DOI":"10.1016\/j.iswa.2024.200462","article-title":"Computationally efficient deep federated learning with optimized feature selection for iot botnet attack detection","volume":"25","author":"Danquah","year":"2025","journal-title":"Intellig. Syst. Appl"},{"key":"B18","doi-asserted-by":"crossref","first-page":"581","DOI":"10.1109\/ICCSN.2016.7586590","article-title":"\u201cComparison deep learning method to traditional methods using for network intrusion detection,\u201d","volume-title":"2016 8th IEEE International Conference On Communication Software And Networks (ICCSN)","author":"Dong","year":"2016"},{"key":"B19","first-page":"1","article-title":"\u201cBalancing approaches towards ML for IDS: a survey for the CSE-CIC IDS dataset,\u201d","author":"Gopalan","year":"2021","journal-title":"2020 International Conference On Communications, Signal Processing, And Their Applications (ICCSPA)"},{"key":"B20","doi-asserted-by":"publisher","DOI":"10.1201\/9781003496724-41","article-title":"A comprehensive survey on client selections in federated learning","author":"Gouissem","year":"2023","journal-title":"arXiv"},{"key":"B21","doi-asserted-by":"publisher","first-page":"1576","DOI":"10.1109\/TIFS.2023.3336521","article-title":"Robust and secure federated learning against hybrid attacks: a generic architecture","volume":"19","author":"Hao","year":"2024","journal-title":"IEEE Trans. Inform. Forens. Secur"},{"key":"B22","article-title":"Tabtransformer: Tabular data modeling using contextual embeddings","author":"Huang","year":"2020","journal-title":"arXiv"},{"key":"B23","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1109\/TIFS.2022.3214723","article-title":"EEFED: personalized federated learning of executionandevaluation dual network for CPS intrusion detection","volume":"18","author":"Huang","year":"2023","journal-title":"IEEE Trans. Inform. Forens. Secur"},{"key":"B24","doi-asserted-by":"publisher","first-page":"103540","DOI":"10.1016\/j.adhoc.2024.103540","article-title":"A federated learning-based zero trust intrusion detection system for Internet of Things","volume":"162","author":"Javeed","year":"2024","journal-title":"Ad Hoc Netw"},{"key":"B25","doi-asserted-by":"publisher","first-page":"57","DOI":"10.1016\/j.future.2023.09.019","article-title":"FL-IIDS: A novel federated learning-based incremental intrusion detection system","volume":"151","author":"Jin","year":"2024","journal-title":"Future Generat. Comp. Syst"},{"key":"B26","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1561\/9781680837896","article-title":"Advances and open problems in federated learning","volume":"14","author":"Kairouz","year":"2021","journal-title":"Found. Trends"},{"key":"B27","unstructured":"\u201cFederated hyperparameter tuning: Challenges, baselines, and connections to weight-sharing,\u201d\n          \n          \n            \n              Khodak\n              M.\n            \n            \n              Tu\n              R.\n            \n            \n              Li\n              T.\n            \n            \n              Li\n              L.\n            \n            \n              Balcan\n              M.\n            \n            \n              Smith\n              V.\n            \n          \n          Advances In Neural Information Processing Systems\n          \n          2021"},{"key":"B28","article-title":"Federated learning: Strategies for improving communication efficiency","author":"Kon\u011bcn\u0177","year":"2016","journal-title":"arXiv"},{"key":"B29","doi-asserted-by":"publisher","first-page":"101740","DOI":"10.1016\/j.jksuci.2023.101740","article-title":"Federated learning with hyper-parameter optimization","volume":"35","author":"Kundroo","year":"2023","journal-title":"J. King Saud Univer.-Comp. Inform. Sci"},{"key":"B30","doi-asserted-by":"publisher","first-page":"96","DOI":"10.1109\/MNET.2018.1700202","article-title":"Learning IoT in edge: deep learning for the Internet of Things with edge computing","volume":"32","author":"Li","year":"2018","journal-title":"IEEE Netw"},{"key":"B31","doi-asserted-by":"publisher","DOI":"10.1109\/JSYST.2023.3236995","article-title":"An efficient federated learning system for network intrusion detection","author":"Li","year":"2023","journal-title":"IEEE Syst. J"},{"key":"B32","doi-asserted-by":"publisher","first-page":"106854","DOI":"10.1016\/j.cie.2020.106854","article-title":"A review of applications in federated learning","volume":"149","author":"Li","year":"2020","journal-title":"Comp. Indust. Eng"},{"key":"B33","first-page":"429","article-title":"Federated optimization in heterogeneous networks","volume":"2","author":"Li","year":"2020","journal-title":"Proc. Mach. Learn. Syst"},{"key":"B34","first-page":"153","article-title":"\u201cRealization for implementing federated learning based intrusion detection with non-IID IoT datasets,\u201d","author":"Lin","year":"2023","journal-title":"Proceedings Of The 2023 8th International Conference On Cloud Computing And Internet Of Things"},{"key":"B35","doi-asserted-by":"publisher","first-page":"8726","DOI":"10.1109\/TNNLS.2022.3216981","article-title":"Privacy and robustness in federated learning: attacks and defenses","volume":"35","author":"Lyu","year":"2022","journal-title":"IEEE Trans. Neural Netw. Learn. Syst"},{"key":"B36","doi-asserted-by":"publisher","first-page":"110500","DOI":"10.1016\/j.asoc.2023.110500","article-title":"Ensemble federated learning: an approach for collaborative pneumonia diagnosis","volume":"2023","author":"Mabrouk","year":"2023","journal-title":"Appl. Soft Comp"},{"key":"B37","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-08333-4_11","article-title":"\u201cRandom forest based on federated learning for intrusion detection,\u201d","author":"Markovic","year":"2022","journal-title":"IFIP International Conference On Artificial Intelligence Applications and Innovations"},{"key":"B38","first-page":"1273","article-title":"\u201cCommunication-efficient learning of deep networks from decentralized data,\u201d","author":"McMahan","year":"2017","journal-title":"Artificial Intelligence And Statistics"},{"key":"B39","doi-asserted-by":"publisher","first-page":"12","DOI":"10.1109\/MPRV.2018.03367731","article-title":"Network-based detection of IoT botnet attacks using deep autoencoders","volume":"17","author":"Meidan","year":"2018","journal-title":"IEEE Pervasive Comp"},{"key":"B40","first-page":"1","article-title":"\u201cParameterizing poisoning attacks in federated learning-based intrusion detection,\u201d","author":"Merzouk","year":"2023","journal-title":"Proceedings Of The 18th International Conference On Availability, Reliability And Security"},{"key":"B41","doi-asserted-by":"publisher","first-page":"102994","DOI":"10.1016\/j.scs.2021.102994","article-title":"A new distributed architecture for evaluating AIbased security systems at the edge: network TON_IoT datasets","volume":"72","author":"Moustafa","year":"2021","journal-title":"Sustain. Cities Soc"},{"key":"B42","unstructured":"\u201cUNSW-NB15: a comprehensive dataset for network intrusion detection systems (UNSW-NB15 network data set),\u201d\n          \n          \n            \n              Moustafa\n              N.\n            \n            \n              Slay\n              J.\n            \n          \n          2015 Military Communications And Information Systems Conference (MilCIS)\n          \n          2015"},{"key":"B43","doi-asserted-by":"publisher","DOI":"10.3390\/s23135941","article-title":"CICIoT2023: A real-time dataset and benchmark for large-scale attacks in IoT environment","author":"Neto","year":"2023","journal-title":"Sensors"},{"key":"B44","doi-asserted-by":"publisher","first-page":"1622","DOI":"10.1109\/COMST.2021.3075439","article-title":"Federated learning for internet of things: a comprehensive survey","volume":"23","author":"Nguyen","year":"2021","journal-title":"IEEE Commun. Surv. Tutor"},{"key":"B45","first-page":"160","article-title":"\u201cFederated learning based approach to intrusion detection,\u201d","author":"Novikova","year":"2023","journal-title":"2023 V International Conference On Control In Technical Systems (CTS)"},{"key":"B46","doi-asserted-by":"publisher","first-page":"100068","DOI":"10.1016\/j.csa.2024.100068","article-title":"Federated learning-based intrusion detection system for the internet of things using unsupervised and supervised deep learning models","volume":"3","author":"Olanrewaju-George","year":"2025","journal-title":"Cyber Secur. Appl"},{"key":"B47","doi-asserted-by":"publisher","first-page":"310","DOI":"10.1109\/MNET.011.2000286","article-title":"Internet of things intrusion detection: Centralized, on-device, or federated learning?","volume":"34","author":"Rahman","year":"2020","journal-title":"IEEE Netw"},{"key":"B48","doi-asserted-by":"publisher","first-page":"106051","DOI":"10.1016\/j.engappai.2023.106051","article-title":"AnoFed: Adaptive anomaly detection for digital health using transformer-based federated learning and support vector data description","volume":"121","author":"Raza","year":"2023","journal-title":"Eng. Appl. Artif. Intellig"},{"key":"B49","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2003.00295","article-title":"Adaptive federated optimization","author":"Reddi","year":"2020","journal-title":"arXiv"},{"key":"B50","doi-asserted-by":"publisher","first-page":"108693","DOI":"10.1016\/j.comnet.2021.108693","article-title":"Federated learning for malware detection in IoT devices","volume":"204","author":"Rey","year":"2022","journal-title":"Comp. Netw"},{"key":"B51","doi-asserted-by":"publisher","first-page":"1145","DOI":"10.1109\/TII.2021.3126728","article-title":"Intrusion Detection Based on Privacy-Preserving Federated Learning for the Industrial IoT","volume":"19","author":"Ruzafa-Alc\u00e1zar","year":"2023","journal-title":"IEEE Trans. Indust. Inform"},{"key":"B52","doi-asserted-by":"publisher","first-page":"107810","DOI":"10.1016\/j.compeleceng.2022.107810","article-title":"Anomaly-based intrusion detection system for IoT networks through deep learning model","volume":"99","author":"Saba","year":"2022","journal-title":"Comp. Elect. Eng"},{"key":"B53","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/s10922-022-09691-3","article-title":"Cyber threat intelligence sharing scheme based on federated learning for network intrusion detection","volume":"31","author":"Sarhan","year":"2023","journal-title":"J. Netw. Systems Managem"},{"key":"B54","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s11036-021-01843-0","article-title":"Towards a standard feature set for network intrusion detection system datasets","volume":"2022","author":"Sarhan","year":"2022","journal-title":"Mobile Netw. Appl"},{"key":"B55","doi-asserted-by":"publisher","first-page":"296","DOI":"10.1007\/s11036-022-01937-3","article-title":"Internet of things (IoT) security intelligence: a comprehensive overview, machine learning solutions and research directions","volume":"28","author":"Sarker","year":"2023","journal-title":"Mobile Netw. Appl"},{"key":"B56","doi-asserted-by":"publisher","DOI":"10.13052\/rp-9788770040723.047","article-title":"Enhancing Intrusion Detection In Internet Of Vehicles Through Federated Learning","author":"Sebastian","year":"2023","journal-title":"arXiv"},{"key":"B57","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2206.12342","article-title":"Feathers: Federated architecture and hyperparameter search","author":"Seng","year":"2022","journal-title":"arXiv [preprint]"},{"key":"B58","unstructured":"\u201cDetailed specifications of the terrestrial radio interfaces of international mobile telecommunications-2020 (IMT-2020),\u201d\n          \n          \n            \n              Series\n              M.\n            \n          \n          Recommendation ITU 2150\n          \n          2021"},{"key":"B59","doi-asserted-by":"publisher","first-page":"44","DOI":"10.3844\/jcssp.2024.44.51","article-title":"Cybersecurity mechanism for automatic detection of IoT intrusions using machine learning","volume":"20","author":"Seyed","year":"2024","journal-title":"J. Comp. Sci"},{"key":"B60","article-title":"\u201cIntrusion detection evaluation dataset (CIC-IDS2017),\u201d","author":"Sharafaldin","year":"2018","journal-title":"Proceedings of the Canadian Institute For Cybersecurity"},{"key":"B61","article-title":"\u201cAttention is all you need,\u201d","author":"Vaswani","year":"2017","journal-title":"Advances In Neural Information Processing Systems"},{"key":"B62","doi-asserted-by":"publisher","first-page":"1015","DOI":"10.1109\/TIFS.2023.3322328","article-title":"LDS-FL: loss differential strategy based federated learning for privacy preserving","volume":"19","author":"Wang","year":"2024","journal-title":"IEEE Trans. Inform. Forens. Secur"},{"key":"B63","doi-asserted-by":"publisher","first-page":"103993","DOI":"10.1016\/j.jisa.2025.103993","article-title":"IDS-DWKAFL: An intrusion detection scheme based on Dynamic Weighted K-asynchronous Federated Learning for smart grid","volume":"89","author":"Wen","year":"2025","journal-title":"J. Inform. Secu. Appl"},{"key":"B64","doi-asserted-by":"publisher","first-page":"421","DOI":"10.1177\/03611981231159118","article-title":"Secure intrusion detection by differentially private federated learning for inter-vehicle networks","volume":"2677","author":"Xu","year":"2023","journal-title":"Transp. Res. Record"},{"key":"B65","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3298981","article-title":"Federated machine learning: Concept and applications","volume":"10","author":"Yang","year":"2019","journal-title":"ACM Trans. Intellig. Syst. Technol"},{"key":"B66","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2023.3253813","article-title":"Federated learning hyper-parameter tuning from a system perspective","author":"Zhang","year":"2023","journal-title":"IEEE Intern. Things J"},{"key":"B67","article-title":"\u201cIoT intrusion detection based on personalized federated learning,\u201d","author":"Zhang","year":"2023","journal-title":"2023 24st Asia-Pacific Network Operations And Management Symposium (APNOMS)"},{"key":"B68","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2022.3175918","article-title":"Semi-supervised federated learning based intrusion detection method for internet of things","author":"Zhao","year":"2023","journal-title":"IEEE Intern. Things J"},{"key":"B69","doi-asserted-by":"publisher","first-page":"122200","DOI":"10.1016\/j.eswa.2023.122200","article-title":"Electric Eel Foraging Optimization: A new bio-inspired optimizer for engineering applications","volume":"2023","author":"Zhao","year":"2023","journal-title":"Expert Syst. Appl"},{"key":"B70","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2112.08524","article-title":"Flora: Single-shot hyper-parameter optimization for federated learning","author":"Zhou","year":"2021","journal-title":"arXiv"}],"container-title":["Frontiers in Big Data"],"original-title":[],"link":[{"URL":"https:\/\/www.frontiersin.org\/articles\/10.3389\/fdata.2025.1526480\/full","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,14]],"date-time":"2025-05-14T05:41:10Z","timestamp":1747201270000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.frontiersin.org\/articles\/10.3389\/fdata.2025.1526480\/full"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,5,14]]},"references-count":70,"alternative-id":["10.3389\/fdata.2025.1526480"],"URL":"https:\/\/doi.org\/10.3389\/fdata.2025.1526480","relation":{},"ISSN":["2624-909X"],"issn-type":[{"value":"2624-909X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,5,14]]},"article-number":"1526480"}}