{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,7]],"date-time":"2026-08-07T00:22:23Z","timestamp":1786062143312,"version":"3.56.0"},"reference-count":36,"publisher":"MDPI AG","issue":"1","license":[{"start":{"date-parts":[[2022,12,28]],"date-time":"2022-12-28T00:00:00Z","timestamp":1672185600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Technological breakthroughs in the Internet of Things (IoT) easily promote smart lives for humans by connecting everything through the Internet. The de facto standardised IoT routing strategy is the routing protocol for low-power and lossy networks (RPL), which is applied in various heterogeneous IoT applications. Hence, the increase in reliance on the IoT requires focus on the security of the RPL protocol. The top defence layer is an intrusion detection system (IDS), and the heterogeneous characteristics of the IoT and variety of novel intrusions make the design of the RPL IDS significantly complex. Most existing IDS solutions are unified models and cannot detect novel RPL intrusions. Therefore, the RPL requires a customised global attack knowledge-based IDS model to identify both existing and novel intrusions in order to enhance its security. Federated transfer learning (FTL) is a trending topic that paves the way to designing a customised RPL-IoT IDS security model in a heterogeneous IoT environment. In this paper, we propose a federated-transfer-learning-assisted customised distributed IDS (FT-CID) model to detect RPL intrusion in a heterogeneous IoT. The design process of FT-CID includes three steps: dataset collection, FTL-assisted edge IDS learning, and intrusion detection. Initially, the central server initialises the FT-CID with a predefined learning model and observes the unique features of different RPL-IoTs to construct a local model. The experimental model generates an RPL-IIoT dataset with normal and abnormal traffic through simulation on the Contiki-NG OS. Secondly, the edge IDSs are trained using the local parameters and the globally shared parameters generated by the central server through federation and aggregation of different local parameters of various edges. Hence, transfer learning is exploited to update the server\u2019s and edges\u2019 local and global parameters based on relational knowledge. It also builds and customised IDS model with partial retraining through local learning based on globally shared server knowledge. Finally, the customised IDS in the FT-CID model enforces the detection of intrusions in heterogeneous IoT networks. Moreover, the FT-CID model accomplishes high RPL security by implicitly utilising the local and global parameters of different IoTs with the assistance of FTL. The FT-CID detects RPL intrusions with an accuracy of 85.52% in tests on a heterogeneous IoT network.<\/jats:p>","DOI":"10.3390\/s23010321","type":"journal-article","created":{"date-parts":[[2022,12,28]],"date-time":"2022-12-28T08:57:24Z","timestamp":1672217844000},"page":"321","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":37,"title":["Customised Intrusion Detection for an Industrial IoT Heterogeneous Network Based on Machine Learning Algorithms Called FTL-CID"],"prefix":"10.3390","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0257-2267","authenticated-orcid":false,"given":"Nasr","family":"Abosata","sequence":"first","affiliation":[{"name":"School of Aerospace, Transport and Manufacturing, Cranfield University, Cranfield MK43 0AL, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3293-904X","authenticated-orcid":false,"given":"Saba","family":"Al-Rubaye","sequence":"additional","affiliation":[{"name":"School of Aerospace, Transport and Manufacturing, Cranfield University, Cranfield MK43 0AL, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4490-8358","authenticated-orcid":false,"given":"Gokhan","family":"Inalhan","sequence":"additional","affiliation":[{"name":"School of Aerospace, Transport and Manufacturing, Cranfield University, Cranfield MK43 0AL, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,12,28]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"122877","DOI":"10.1016\/j.jclepro.2020.122877","article-title":"Internet of Things (IoT): Opportunities, issues and challenges towards a smart and sustainable future","volume":"274","author":"Patrono","year":"2020","journal-title":"J. Clean. Prod."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Varga, P., Peto, J., Franko, A., Balla, D., Haja, D., Janky, F., Soos, G., Ficzere, D., Maliosz, M., and Toka, L. (2020). 5G support for Industrial IoT Applications\u2014Challenges, Solutions, and Research gaps. Sensors, 20.","DOI":"10.3390\/s20030828"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"3211","DOI":"10.1007\/s11831-020-09496-0","article-title":"A Review on Machine Learning and Deep Learning Perspectives of IDS for IoT: Recent Updates, Security Issues, and Challenges","volume":"28","author":"Thakkar","year":"2020","journal-title":"Arch. Comput. Methods Eng."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"8414503","DOI":"10.1155\/2021\/8414503","article-title":"A Review of Intrusion Detection Systems in RPL Routing Protocol Based on Machine Learning for Internet of Things Applications","volume":"2021","author":"Seyfollahi","year":"2021","journal-title":"Wirel. Commun. Mob. Comput."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"102219","DOI":"10.1016\/j.cose.2021.102219","article-title":"Intrusion detection systems for RPL security: A comparative analysis","volume":"104","author":"Simoglou","year":"2021","journal-title":"Comput. Secur."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/JIOT.2021.3095077","article-title":"A Survey on Federated Learning for Resource-Constrained IoT Devices","volume":"9","author":"Imteaj","year":"2021","journal-title":"IEEE Internet Things J."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"1759","DOI":"10.1109\/COMST.2021.3090430","article-title":"Federated Learning for Internet of Things: Recent Advances, Taxonomy, and Open Challenges","volume":"23","author":"Khan","year":"2021","journal-title":"IEEE Commun. Surv. Tutorials"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"4088","DOI":"10.1109\/TII.2021.3088057","article-title":"Federated Transfer Learning Based Cross-Domain Prediction for Smart Manufacturing","volume":"18","author":"Wang","year":"2021","journal-title":"IEEE Trans. Ind. Informatics"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"2287","DOI":"10.1007\/s11277-019-06986-8","article-title":"Machine Learning Based Intrusion Detection Systems for IoT Applications","volume":"111","author":"Verma","year":"2020","journal-title":"Wirel. Pers. Commun."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3460822","article-title":"Machine Learning for Automated Industrial IoT Attack Detection: An Efficiency-Complexity Trade-off","volume":"12","author":"Chakraborty","year":"2021","journal-title":"ACM Trans. Manag. Inf. Syst."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"246","DOI":"10.1109\/ICJECE.2021.3053231","article-title":"A Novel Intrusion Detection System for RPL-Based Cyber\u2013Physical Systems","volume":"44","author":"Sharma","year":"2021","journal-title":"IEEE Can. J. Electr. Comput. Eng."},{"key":"ref_12","first-page":"2804291","article-title":"Employing a Machine Learning Approach to Detect Combined Internet of Things Attacks against Two Objective Functions Using a Novel Dataset","volume":"2020","author":"Foley","year":"2020","journal-title":"Secur. Commun. Networks"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"1178","DOI":"10.1109\/TNSM.2021.3075496","article-title":"DETONAR: Detection of Routing Attacks in RPL-Based IoT","volume":"18","author":"Agiollo","year":"2021","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"1622","DOI":"10.1109\/COMST.2021.3075439","article-title":"Federated learning for internet of things: A comprehensive survey","volume":"23","author":"Nguyen","year":"2021","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"e6812","DOI":"10.1002\/cpe.6812","article-title":"A federated learning method for network intrusion detection","volume":"34","author":"Tang","year":"2022","journal-title":"Concurr. Comput. Pract. Exp."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Maurya, S., Joseph, S., Asokan, A., Algethami, A.A., Hamdi, M., and Rauf, H.T. (2021). Federated Transfer Learning for Authentication and Privacy Preservation Using Novel Supportive Twin Delayed DDPG (S-TD3) Algorithm for IIoT. Sensors, 21.","DOI":"10.3390\/s21237793"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"3492","DOI":"10.1109\/TII.2021.3107783","article-title":"Security and Privacy-Enhanced Federated Learning for Anomaly Detection in IoT Infrastructures","volume":"18","author":"Cui","year":"2021","journal-title":"IEEE Trans. Ind. Informatics"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"108693","DOI":"10.1016\/j.comnet.2021.108693","article-title":"Federated learning for malware detection in IoT devices","volume":"204","author":"Rey","year":"2022","journal-title":"Comput. Networks"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Nguyen, T.D., Rieger, P., Miettinen, M., and Sadeghi, A.-R. (2020, January 23\u201326). Poisoning Attacks on Federated Learning-based IoT Intrusion Detection System. Proceedings of the 2020 Workshop on Decentralized IoT Systems and Security, San Diego, CA, USA.","DOI":"10.14722\/diss.2020.23003"},{"key":"ref_20","first-page":"9919030","article-title":"An Adaptive Communication-Efficient Federated Learning to Resist Gradient-Based Reconstruction Attacks","volume":"2021","author":"Li","year":"2021","journal-title":"Secur. Commun. Networks"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"35","DOI":"10.1109\/OJCS.2020.2993259","article-title":"Personalized Federated Learning for Intelligent IoT Applications: A Cloud-Edge Based Framework","volume":"1","author":"Wu","year":"2020","journal-title":"IEEE Open J. Comput. Soc."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"310","DOI":"10.1109\/MNET.011.2000286","article-title":"Internet of Things Intrusion Detection: Centralized, On-Device, or Federated Learning?","volume":"34","author":"Rahman","year":"2020","journal-title":"IEEE Netw."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"217463","DOI":"10.1109\/ACCESS.2020.3041793","article-title":"Intrusion Detection for Wireless Edge Networks Based on Federated Learning","volume":"8","author":"Chen","year":"2020","journal-title":"IEEE Access"},{"key":"ref_24","first-page":"9361348","article-title":"Intelligent Intrusion Detection Based on Federated Learning for Edge-Assisted Internet of Things","volume":"2021","author":"Man","year":"2021","journal-title":"Secur. Commun. Networks"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"117734","DOI":"10.1109\/ACCESS.2021.3107337","article-title":"An Ensemble Multi-View Federated Learning Intrusion Detection for IoT","volume":"9","author":"Attota","year":"2021","journal-title":"IEEE Access"},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"3688","DOI":"10.1109\/JSAC.2021.3118352","article-title":"Optimizing Federated Learning in Distributed Industrial IoT: A Multi-Agent Approach","volume":"39","author":"Zhang","year":"2021","journal-title":"IEEE J. Sel. Areas Commun."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"4405","DOI":"10.1109\/TIFS.2021.3096029","article-title":"A Transfer Learning Approach for Securing Resource-Constrained IoT Devices","volume":"16","author":"Yilmaz","year":"2021","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"98630","DOI":"10.1109\/ACCESS.2021.3095078","article-title":"Federated Transfer Learning for IIoT Devices With Low Computing Power Based on Blockchain and Edge Computing","volume":"9","author":"Zhang","year":"2021","journal-title":"IEEE Access"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"12163","DOI":"10.1109\/JIOT.2021.3062482","article-title":"Toward Deep Transfer Learning in Industrial Internet of Things","volume":"8","author":"Liu","year":"2021","journal-title":"IEEE Internet Things J."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"3351","DOI":"10.1007\/s13042-021-01415-4","article-title":"Deep transfer learning-based network traffic classification for scarce dataset in 5G IoT systems","volume":"12","author":"Guan","year":"2021","journal-title":"Int. J. Mach. Learn. Cybern."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"107763","DOI":"10.1016\/j.knosys.2021.107763","article-title":"Designing ECG monitoring healthcare system with federated transfer learning and explainable AI","volume":"236","author":"Raza","year":"2022","journal-title":"Knowledge-Based Syst."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Otoum, Y., Wan, Y., and Nayak, A. (2021, January 7\u201311). Federated Transfer Learning-Based IDS for the Internet of Medical Things (IoMT). Proceedings of the 2021 IEEE Globecom Workshops, Madrid, Spain.","DOI":"10.1109\/GCWkshps52748.2021.9682118"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"414","DOI":"10.1016\/j.future.2020.02.051","article-title":"Real time dataset generation framework for intrusion detection systems in IoT","volume":"108","author":"Hussain","year":"2020","journal-title":"Futur. Gener. Comput. Syst."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Ullah, I., and Mahmoud, Q.H. (2020, January 13\u201315). A Scheme for Generating a Dataset for Anomalous Activity Detection in IoT Networks. Proceedings of the Canadian Conference on Artificial Intelligence, Ottawa, ON, Canada.","DOI":"10.1007\/978-3-030-47358-7_52"},{"key":"ref_35","first-page":"113917","article-title":"An improved grey wolf optimizer for solving engineering problems","volume":"166","author":"Taghian","year":"2020","journal-title":"Expert Syst. Appl."},{"key":"ref_36","unstructured":"McMahan, B., Moore, E., Ramage, D., Hampson, S., and y Arcas, B.A. (2017, January 20\u201322). Communication-efficient learning of deep networks from decentralised data. In Artificial intelligence and statistics. Proceedings of the 20th International Conference on Artificial Intelligence and Statistics, Lauderdale, FL, USA."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/1\/321\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T01:53:57Z","timestamp":1760147637000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/1\/321"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,12,28]]},"references-count":36,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2023,1]]}},"alternative-id":["s23010321"],"URL":"https:\/\/doi.org\/10.3390\/s23010321","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,12,28]]}}}