{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,12]],"date-time":"2026-05-12T16:24:14Z","timestamp":1778603054156,"version":"3.51.4"},"reference-count":40,"publisher":"MDPI AG","issue":"2","license":[{"start":{"date-parts":[[2025,2,13]],"date-time":"2025-02-13T00:00:00Z","timestamp":1739404800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100015624","name":"University of Jeddah, Jeddah, Saudi Arabia","doi-asserted-by":"publisher","award":["UJ-23-SRP-13"],"award-info":[{"award-number":["UJ-23-SRP-13"]}],"id":[{"id":"10.13039\/501100015624","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>Industry-wide IoT networks have altered operations and increased vulnerabilities, notably DDoS attacks. IoT systems are decentralised. Therefore, these attacks flood networks with malicious traffic, creating interruptions, financial losses, and availability issues. We need scalable, privacy-preserving, and resource-efficient IoT intrusion detection algorithms to solve this essential problem. This paper presents a Federated-Learning (FL) framework using ResVGG-SwinNet, a hybrid deep-learning architecture, for multi-label DDoS attack detection. ResNet improves feature extraction, VGGNet optimises feature refining, and Swin-Transformer captures contextual dependencies, making the model sensitive to complicated attack patterns across varied network circumstances. Using the FL framework, decentralised training protects data privacy and scales and adapts across diverse IoT contexts. New preprocessing methods like Dynamic Proportional Class Adjustment (DPCA) and Dual Adaptive Selector (DAS) for feature optimisation improve system efficiency and accuracy. The model performed well on CIC-DDoS2019, UNSW-NB15, and IoT23 datasets, with 99.0% accuracy, 2.5% false alert rate, and 99.3% AUC. With a 93.0% optimisation efficiency score, the system balances computational needs with robust detection. With advanced deep-learning models, FL provides a scalable, safe, and effective DDoS detection solution that overcomes significant shortcomings in current systems. The framework protects IoT networks from growing cyber threats and provides a complete approach for current IoT-driven ecosystems.<\/jats:p>","DOI":"10.3390\/fi17020088","type":"journal-article","created":{"date-parts":[[2025,2,13]],"date-time":"2025-02-13T10:36:58Z","timestamp":1739443018000},"page":"88","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":18,"title":["Federated Deep Learning for Scalable and Privacy-Preserving Distributed Denial-of-Service Attack Detection in Internet of Things Networks"],"prefix":"10.3390","volume":"17","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9815-0319","authenticated-orcid":false,"given":"Abdulrahman A.","family":"Alshdadi","sequence":"first","affiliation":[{"name":"Department of Information Systems and Technology, College of Computer Science and Engineering, University of Jeddah, Jeddah 21959, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7181-2100","authenticated-orcid":false,"given":"Abdulwahab Ali","family":"Almazroi","sequence":"additional","affiliation":[{"name":"Department of Information Technology, College of Computing and Information Technology at Khulais, University of Jeddah, Jeddah 21959, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1153-5401","authenticated-orcid":false,"given":"Nasir","family":"Ayub","sequence":"additional","affiliation":[{"name":"Department of Creative Technologies, Air University Islamabad, Islamabad 44000, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7281-5458","authenticated-orcid":false,"given":"Miltiadis D.","family":"Lytras","sequence":"additional","affiliation":[{"name":"Management of Information Systems Department, School of Business and Economics, The American College of Greece, 15342 Athens, Greece"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Eesa","family":"Alsolami","sequence":"additional","affiliation":[{"name":"Department of Cybersecurity, College of Computer Science and Engineering, University of Jeddah, Jeddah 21959, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7332-3773","authenticated-orcid":false,"given":"Faisal S.","family":"Alsubaei","sequence":"additional","affiliation":[{"name":"Department of Cybersecurity, College of Computer Science and Engineering, University of Jeddah, Jeddah 21959, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Riad","family":"Alharbey","sequence":"additional","affiliation":[{"name":"Department of Information Systems and Technology, College of Computer Science and Engineering, University of Jeddah, Jeddah 21959, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2025,2,13]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"240","DOI":"10.1108\/DTS-08-2023-0061","article-title":"Organizational digital transformation: From evolution to future trends","volume":"3","author":"Omol","year":"2024","journal-title":"Digit. Transform. Soc."},{"key":"ref_2","first-page":"1","article-title":"Internet of Things (IoT) in Smart Cities: Enhancing Urban Living Through Technology","volume":"5","author":"Rehan","year":"2023","journal-title":"J. Eng. Technol."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"57","DOI":"10.9734\/ajrcos\/2024\/v17i3424","article-title":"AI-driven cloud security: Examining the impact of user behavior analysis on threat detection","volume":"17","author":"Olabanji","year":"2024","journal-title":"Asian J. Res. Comput. Sci."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Almazroi, A.A., and Ayub, N. (2023). Enhancing smart IoT malware detection: A GhostNet-based hybrid approach. Systems, 11.","DOI":"10.3390\/systems11110547"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"103096","DOI":"10.1016\/j.cose.2023.103096","article-title":"A comprehensive study of DDoS attacks over IoT network and their countermeasures","volume":"127","author":"Kumari","year":"2023","journal-title":"Comput. Secur."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"163","DOI":"10.12700\/APH.21.3.2024.3.11","article-title":"Security Implications of Computer Botnets","volume":"21","year":"2024","journal-title":"Acta Polytech. Hung."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"18951","DOI":"10.1109\/JIOT.2024.3349381","article-title":"Vulnerability of Machine Learning Approaches Applied in IoT-Based Smart Grid: A Review","volume":"11","author":"Zhang","year":"2024","journal-title":"IEEE Internet Things J."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"155","DOI":"10.1016\/j.iotcps.2023.04.001","article-title":"Security of federated learning with IoT systems: Issues, limitations, challenges, and solutions","volume":"3","author":"Yaacoub","year":"2023","journal-title":"Internet Things-Cyber-Phys. Syst."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"3753","DOI":"10.1007\/s10586-022-03776-z","article-title":"Internet of Things intrusion detection systems: A comprehensive review and future directions","volume":"26","author":"Heidari","year":"2023","journal-title":"Clust. Comput."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"42357","DOI":"10.1109\/ACCESS.2024.3378727","article-title":"Federated Learning for Decentralized DDoS Attack Detection in IoT Networks","volume":"12","author":"Alhasawi","year":"2024","journal-title":"IEEE Access"},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"8367","DOI":"10.1007\/s10586-024-04436-0","article-title":"Enhancing IoT security: A collaborative framework integrating federated learning, dense neural networks, and blockchain","volume":"27","author":"Nazir","year":"2024","journal-title":"Clust. Comput."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Kumar, M., and Kim, S. (2024). Securing the Internet of Health Things: Embedded Federated Learning-Driven Long Short-Term Memory for Cyberattack Detection. Electronics, 13.","DOI":"10.3390\/electronics13173461"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Sah, A., Bhushan, B., and Shetty, C. (2023, January 8\u20139). A Comprehensive Study on Artificial Intelligence (AI) Driven Internet of Healthcare Things (IOHT). Proceedings of the International Conference on Intelligent Systems in Computing and Communication, Moodabidri, India.","DOI":"10.1007\/978-3-031-75605-4_17"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"127018","DOI":"10.1109\/ACCESS.2024.3454211","article-title":"Privacy-Preserving Federated Learning for Intrusion Detection in IoT Environments: A Survey","volume":"12","author":"Vyas","year":"2024","journal-title":"IEEE Access"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"109139","DOI":"10.1016\/j.compeleceng.2024.109139","article-title":"SIM-FED: Secure IoT malware detection model with federated learning","volume":"116","author":"Nobakht","year":"2024","journal-title":"Comput. Electr. Eng."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"18009","DOI":"10.1007\/s00521-024-10306-y","article-title":"Machine learning approaches to intrusion detection in unmanned aerial vehicles (UAVs)","volume":"36","year":"2024","journal-title":"Neural Comput. Appl."},{"key":"ref_17","first-page":"1","article-title":"Leveraging LSTM and GRU-based deep neural coordination in intelligent transportation to strengthen security in the Internet of Vehicles","volume":"1","author":"Chen","year":"2024","journal-title":"Int. J. Mach. Learn. Cybern."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"50","DOI":"10.1007\/s10586-024-04711-0","article-title":"Securing fog-assisted IoT smart homes: A federated learning-based intrusion detection approach","volume":"28","author":"Bensaid","year":"2025","journal-title":"Clust. Comput."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"103597","DOI":"10.1016\/j.cose.2023.103597","article-title":"FLAD: Adaptive federated learning for DDoS attack detection","volume":"137","author":"Siracusa","year":"2024","journal-title":"Comput. Secur."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"1389","DOI":"10.2298\/CSIS240401041S","article-title":"BLSAE-SNIDS: A Bi-LSTM sparse autoencoder framework for satellite network intrusion detection","volume":"21","author":"Shi","year":"2024","journal-title":"Comput. Sci. Inf. Syst."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"509","DOI":"10.3390\/ai4030028","article-title":"Federated learning for IoT intrusion detection","volume":"4","author":"Lazzarini","year":"2023","journal-title":"AI"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"103407","DOI":"10.1016\/j.adhoc.2024.103407","article-title":"Secure and privacy-preserving intrusion detection in wireless sensor networks: Federated learning with SCNN-Bi-LSTM for enhanced reliability","volume":"155","author":"Bukhari","year":"2024","journal-title":"Ad Hoc Netw."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"358","DOI":"10.55730\/1300-0632.4075","article-title":"Unveiling anomalies: A survey on XAI-based anomaly detection for IoT","volume":"32","author":"Eren","year":"2024","journal-title":"Turk. J. Electr. Eng. Comput. Sci."},{"key":"ref_24","first-page":"4","article-title":"FSL: Federated sequential learning-based cyberattack detection for Industrial Internet of Things","volume":"1","author":"Li","year":"2023","journal-title":"Ind. Artif. Intell."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"15","DOI":"10.1007\/s10723-023-09725-3","article-title":"Intrusion detection using federated attention neural network for edge-enabled internet of things","volume":"22","author":"Song","year":"2024","journal-title":"J. Grid Comput."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Ta\u015fc\u0131, B. (2024). Deep-Learning-Based Approach for IoT Attack and Malware Detection. Appl. Sci., 14.","DOI":"10.3390\/app14188505"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"103097","DOI":"10.1016\/j.cose.2023.103097","article-title":"2DF-IDS: Decentralized and differentially private federated learning-based intrusion detection system for industrial IoT","volume":"127","author":"Friha","year":"2023","journal-title":"Comput. Secur."},{"key":"ref_28","unstructured":"Garcia, S., Parmisano, A., and Erquiaga, M.J. (2020). IoT-23: A Labeled Dataset with Malicious and Benign IoT Network Traffic, Zenodo."},{"key":"ref_29","unstructured":"Moustafa, N., and Slay, J. (2024). UNSW-NB15, Kaggle."},{"key":"ref_30","unstructured":"Sharafaldin, I., Lashkari, A.H., Hakak, S., and Ghorbani, A.A. (2022). CIC-DDoS2019, Kaggle."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Luengo, J., Garc\u00eda-Gil, D., Ram\u00edrez-Gallego, S., Garc\u00eda, S., and Herrera, F. (2020). Big Data Preprocessing, Springer.","DOI":"10.1007\/978-3-030-39105-8"},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"4845","DOI":"10.1007\/s10994-022-06268-8","article-title":"The class imbalance problem in deep learning","volume":"113","author":"Ghosh","year":"2024","journal-title":"Mach. Learn."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"56","DOI":"10.38094\/jastt1224","article-title":"A comprehensive review of dimensionality reduction techniques for feature selection and feature extraction","volume":"1","author":"Zebari","year":"2020","journal-title":"J. Appl. Sci. Technol. Trends"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"47","DOI":"10.1016\/j.future.2020.11.022","article-title":"An ensemble machine learning approach through effective feature extraction to classify fake news","volume":"117","author":"Hakak","year":"2021","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"6733","DOI":"10.1109\/TIP.2022.3215905","article-title":"Drnet: Double recalibration network for few-shot semantic segmentation","volume":"31","author":"Gao","year":"2022","journal-title":"IEEE Trans. Image Process."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Koonce, B., and Koonce, B. (2021). ResNet 50. Convolutional Neural Networks with Swift for Tensorflow: Image Recognition and Dataset Categorization, Apress.","DOI":"10.1007\/978-1-4842-6168-2"},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Zhang, X. (2021, January 24\u201326). The AlexNet, LeNet-5 and VGG NET applied to CIFAR-10. Proceedings of the 2021 2nd International Conference on Big Data & Artificial Intelligence & Software Engineering (ICBASE), Zhuhai, China.","DOI":"10.1109\/ICBASE53849.2021.00083"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Liu, Z., Lin, Y., Cao, Y., Hu, H., Wei, Y., Zhang, Z., and Guo, B. (2021, January 10\u201317). Swin transformer: Hierarchical vision transformer using shifted windows. Proceedings of the IEEE\/CVF International Conference on Computer Vision, Montreal, QC, Canada.","DOI":"10.1109\/ICCV48922.2021.00986"},{"key":"ref_39","first-page":"599","article-title":"Classification model evaluation metrics","volume":"12","year":"2021","journal-title":"Int. J. Adv. Comput. Sci. Appl."},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Nikolaidis, F., Symeonides, M., and Trihinas, D. (2023). Towards Efficient Resource Allocation for Federated Learning in Virtualized Managed Environments. Future Internet, 15.","DOI":"10.3390\/fi15080261"}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/17\/2\/88\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T16:33:09Z","timestamp":1760027589000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/17\/2\/88"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,2,13]]},"references-count":40,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2025,2]]}},"alternative-id":["fi17020088"],"URL":"https:\/\/doi.org\/10.3390\/fi17020088","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,2,13]]}}}