{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T15:58:52Z","timestamp":1784390332555,"version":"3.55.0"},"reference-count":55,"publisher":"MDPI AG","issue":"16","license":[{"start":{"date-parts":[[2023,8,9]],"date-time":"2023-08-09T00:00:00Z","timestamp":1691539200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>With the proliferation of IoT devices, ensuring the security and privacy of these devices and their associated data has become a critical challenge. In this paper, we propose a federated sampling and lightweight intrusion-detection system for IoT networks that use K-meansfor sampling network traffic and identifying anomalies in a semi-supervised way. The system is designed to preserve data privacy by performing local clustering on each device and sharing only summary statistics with a central aggregator. The proposed system is particularly suitable for resource-constrained IoT devices such as sensors with limited computational and storage capabilities. We evaluate the system\u2019s performance using the publicly available NSL-KDD dataset. Our experiments and simulations demonstrate the effectiveness and efficiency of the proposed intrusion-detection system, highlighting the trade-offs between precision and recall when sharing statistics between workers and the coordinator. Notably, our experiments show that the proposed federated IDS can increase the true-positive rate up to 10% when the workers and the coordinator collaborate.<\/jats:p>","DOI":"10.3390\/s23167038","type":"journal-article","created":{"date-parts":[[2023,8,9]],"date-time":"2023-08-09T10:30:48Z","timestamp":1691577048000},"page":"7038","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":30,"title":["Cross-Layer Federated Learning for Lightweight IoT Intrusion Detection Systems"],"prefix":"10.3390","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5627-2625","authenticated-orcid":false,"given":"Suzan","family":"Hajj","sequence":"first","affiliation":[{"name":"Imagerie et Vision Artificielle (ImVIA) Laboratory, Universit\u00e9 de Bourgogne Franche-Comt\u00e9, 21078 Dijon, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4068-2996","authenticated-orcid":false,"given":"Joseph","family":"Azar","sequence":"additional","affiliation":[{"name":"Femto-St Institute, UMR 6174 CNRS, Universit\u00e9 de Franche-Comt\u00e9, 25030 Besan\u00e7on, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3482-9154","authenticated-orcid":false,"given":"Jacques","family":"Bou Abdo","sequence":"additional","affiliation":[{"name":"School of Information Technology, University of Cincinnati, Cincinnati, OH 45221, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9798-8390","authenticated-orcid":false,"given":"Jacques","family":"Demerjian","sequence":"additional","affiliation":[{"name":"LaRRIS, Faculty of Sciences, Lebanese University, Fanar P.O. Box 90656, Lebanon"},{"name":"Computer Science & IT Department, Faculty of Arts and Sciences, Holy Spirit University of Kaslik (USEK), Jounieh P.O. Box 446, Lebanon"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0195-4378","authenticated-orcid":false,"given":"Christophe","family":"Guyeux","sequence":"additional","affiliation":[{"name":"Femto-St Institute, UMR 6174 CNRS, Universit\u00e9 de Franche-Comt\u00e9, 25030 Besan\u00e7on, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Abdallah","family":"Makhoul","sequence":"additional","affiliation":[{"name":"Femto-St Institute, UMR 6174 CNRS, Universit\u00e9 de Franche-Comt\u00e9, 25030 Besan\u00e7on, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5911-2010","authenticated-orcid":false,"given":"Dominique","family":"Ginhac","sequence":"additional","affiliation":[{"name":"Imagerie et Vision Artificielle (ImVIA) Laboratory, Universit\u00e9 de Bourgogne Franche-Comt\u00e9, 21078 Dijon, France"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2023,8,9]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Hu\u010d, A., \u0160alej, J., and Trebar, M. (2021). Analysis of machine learning algorithms for anomaly detection on edge devices. Sensors, 21.","DOI":"10.3390\/s21144946"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"100670","DOI":"10.1016\/j.iot.2022.100670","article-title":"Energy consumption of on-device machine learning models for IoT intrusion detection","volume":"21","author":"Tekin","year":"2023","journal-title":"Internet Things"},{"key":"ref_3","unstructured":"Hajj, S., El Sibai, R., Barada, A., Bou Abdo, J., Demerjian, J., Guyeux, C., Makhoul, A., and Ginhac, D. (2022, January 25\u201328). Cluster-based Sampling Algorithm for Lightweight IoT Intrusion Detection System. Proceedings of the 2022 20th International Conference on Security and Management, Las Vegas, VA, USA."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"138903","DOI":"10.1109\/ACCESS.2021.3118605","article-title":"A critical review on the implementation of static data sampling techniques to detect network attacks","volume":"9","author":"Hajj","year":"2021","journal-title":"IEEE Access"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"255","DOI":"10.1016\/j.cose.2017.09.009","article-title":"Slow rate denial of service attacks against HTTP\/2 and detection","volume":"72","author":"Tripathi","year":"2018","journal-title":"Comput. Secur."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"8469410","DOI":"10.1155\/2019\/8469410","article-title":"ForChaos: Real time application DDoS detection using forecasting and chaos theory in smart home IoT network","volume":"2019","author":"Procopiou","year":"2019","journal-title":"Wirel. Commun. Mob. Comput."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Reed, A., Dooley, L.S., and Mostefaoui, S.K. (2021, January 7\u201311). A Reliable Real-Time Slow DoS Detection Framework for Resource-Constrained IoT Networks. Proceedings of the 2021 IEEE Global Communications Conference (GLOBECOM), Madrid, Spain.","DOI":"10.1109\/GLOBECOM46510.2021.9685612"},{"key":"ref_8","unstructured":"(2023, March 21). Internet of Things Statistics for 2023\u2014Taking Things Apart. Available online: https:\/\/dataprot.net\/statistics\/iot-statistics\/."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"25","DOI":"10.1016\/j.jnca.2017.02.009","article-title":"A survey of intrusion detection in Internet of Things","volume":"84","author":"Miani","year":"2017","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"24188","DOI":"10.3390\/s141224188","article-title":"A malicious pattern detection engine for embedded security systems in the Internet of Things","volume":"14","author":"Oh","year":"2014","journal-title":"Sensors"},{"key":"ref_11","unstructured":"Lee, T.H., Wen, C.H., Chang, L.H., Chiang, H.S., and Hsieh, M.C. (2014). Advanced Technologies, Embedded and Multimedia for Human-Centric Computing, Springer."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Le, A., Loo, J., Chai, K.K., and Aiash, M. (2016). A specification-based IDS for detecting attacks on RPL-based network topology. Information, 7.","DOI":"10.3390\/info7020025"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"2661","DOI":"10.1016\/j.adhoc.2013.04.014","article-title":"SVELTE: Real-time intrusion detection in the Internet of Things","volume":"11","author":"Raza","year":"2013","journal-title":"Hoc Netw."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"42450","DOI":"10.1109\/ACCESS.2019.2907965","article-title":"Toward a lightweight intrusion detection system for the internet of things","volume":"7","author":"Jan","year":"2019","journal-title":"IEEE Access"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Soe, Y.N., Feng, Y., Santosa, P.I., Hartanto, R., and Sakurai, K. (2020). Towards a lightweight detection system for cyber attacks in the IoT environment using corresponding features. Electronics, 9.","DOI":"10.3390\/electronics9010144"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"5581","DOI":"10.1007\/s12652-020-01919-x","article-title":"Hybridizing genetic algorithm and grey wolf optimizer to advance an intelligent and lightweight intrusion detection system for IoT wireless networks","volume":"11","author":"Davahli","year":"2020","journal-title":"J. Ambient. Intell. Humaniz. Comput."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Khater, B.S., Abdul Wahab, A.W., Idris, M.Y.I., Hussain, M.A., Ibrahim, A.A., Amin, M.A., and Shehadeh, H.A. (2021). Classifier performance evaluation for lightweight IDS using fog computing in IoT security. Electronics, 10.","DOI":"10.3390\/electronics10141633"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Sedjelmaci, H., Senouci, S.M., and Al-Bahri, M. (2016, January 22\u201327). A lightweight anomaly detection technique for low-resource IoT devices: A game-theoretic methodology. Proceedings of the 2016 IEEE International Conference on Communications (ICC), Kuala Lumpur, Malaysia.","DOI":"10.1109\/ICC.2016.7510811"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Nguyen, X.H., Nguyen, X.D., Huynh, H.H., and Le, K.H. (2022). Realguard: A lightweight network intrusion detection system for IoT gateways. Sensors, 22.","DOI":"10.3390\/s22020432"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Mai, J., Chuah, C.N., Sridharan, A., Ye, T., and Zang, H. (2006, January 25\u201327). Is sampled data sufficient for anomaly detection?. Proceedings of the 6th ACM SIGCOMM Conference on Internet Measurement, Rio de Janeriro, Brazil.","DOI":"10.1145\/1177080.1177102"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Roudi\u00e8re, G., and Owezarski, P. (2018, January 20). Evaluating the Impact of Traffic Sampling on AATAC\u2019s DDoS Detection. Proceedings of the 2018 Workshop on Traffic Measurements for Cybersecurity, Budapest, Hungary.","DOI":"10.1145\/3229598.3229605"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Pescap\u00e9, A., Rossi, D., Tammaro, D., and Valenti, S. (2010, January 7\u20139). On the impact of sampling on traffic monitoring and analysis. Proceedings of the 2010 22nd International Teletraffic Congress (lTC 22), Amsterdam, The Netherlands.","DOI":"10.1109\/ITC.2010.5608718"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Zhang, H., Liu, J., Zhou, W., and Zhang, S. (2016, January 27\u201328). Sampling method in traffic logs analyzing. Proceedings of the 2016 8th International Conference on Intelligent Human-Machine Systems and Cybernetics (IHMSC), Hangzhou, China.","DOI":"10.1109\/IHMSC.2016.62"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Silva, J.M.C., Carvalho, P., and Lima, S.R. (2015, January 16\u201318). A modular sampling framework for flexible traffic analysis. Proceedings of the 2015 23rd International Conference on Software, Telecommunications and Computer Networks (SoftCOM), Split, Croatia.","DOI":"10.1109\/SOFTCOM.2015.7314061"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Bartos, K., Rehak, M., and Krmicek, V. (2011, January 4\u20138). Optimizing flow sampling for network anomaly detection. Proceedings of the 2011 7th International Wireless Communications and Mobile Computing Conference, Istanbul, Turkey.","DOI":"10.1109\/IWCMC.2011.5982728"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Brauckhoff, D., Tellenbach, B., Wagner, A., May, M., and Lakhina, A. (2006, January 25\u201327). Impact of packet sampling on anomaly detection metrics. Proceedings of the 6th ACM SIGCOMM Conference on Internet Measurement, Rio de Janeriro, Brazil.","DOI":"10.1145\/1177080.1177101"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"7550","DOI":"10.1109\/ACCESS.2020.3048198","article-title":"Intrusion detection of imbalanced network traffic based on machine learning and deep learning","volume":"9","author":"Liu","year":"2020","journal-title":"IEEE Access"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"e4240","DOI":"10.1002\/ett.4240","article-title":"Anomaly-based intrusion detection systems: The requirements, methods, measurements, and datasets","volume":"32","author":"Hajj","year":"2021","journal-title":"Trans. Emerg. Telecommun. Technol."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"110087","DOI":"10.1016\/j.automatica.2021.110087","article-title":"Enhancement of opacity for distributed state estimation in cyber\u2013physical systems","volume":"136","author":"An","year":"2022","journal-title":"Automatica"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"108906","DOI":"10.1016\/j.comnet.2022.108906","article-title":"Personalized federated learning framework for network traffic anomaly detection","volume":"209","author":"Pei","year":"2022","journal-title":"Comput. Netw."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"117734","DOI":"10.1109\/ACCESS.2021.3107337","article-title":"An ensemble multi-view federated learning intrusion detection for IoT","volume":"9","author":"Attota","year":"2021","journal-title":"IEEE Access"},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"2545","DOI":"10.1109\/JIOT.2021.3077803","article-title":"Federated-learning-based anomaly detection for iot security attacks","volume":"9","author":"Mothukuri","year":"2021","journal-title":"IEEE Internet Things J."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Nguyen, T.D., Rieger, P., Miettinen, M., and Sadeghi, A.R. (2020, January 23\u201326). Poisoning attacks on federated learning-based IoT intrusion detection system. Proceedings of the Workshop on Decentralized IoT Systems and Security (DISS) 2020, San Diego, CA, USA.","DOI":"10.14722\/diss.2020.23003"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"299","DOI":"10.1016\/j.comcom.2022.06.015","article-title":"Fedgan-ids: Privacy-preserving ids using gan and federated learning","volume":"192","author":"Tabassum","year":"2022","journal-title":"Comput. Commun."},{"key":"ref_35","unstructured":"Zhao, Y., Chen, J., Zhang, J., Wu, D., Teng, J., and Yu, S. (2019, January 9\u201311). PDGAN: A novel poisoning defense method in federated learning using generative adversarial network. Proceedings of the Algorithms and Architectures for Parallel Processing: 19th International Conference, ICA3PP 2019, Melbourne, VIC, Australia."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Saadat, H., Aboumadi, A., Mohamed, A., Erbad, A., and Guizani, M. (2021, January 7\u201310). Hierarchical federated learning for collaborative IDS in IoT applications. Proceedings of the 2021 10th Mediterranean Conference on Embedded Computing (MECO), Budva, Montenegro.","DOI":"10.1109\/MECO52532.2021.9460304"},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"108379","DOI":"10.1016\/j.compeleceng.2022.108379","article-title":"HBFL: A hierarchical blockchain-based federated learning framework for collaborative IoT intrusion detection","volume":"103","author":"Sarhan","year":"2022","journal-title":"Comput. Electr. Eng."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"108661","DOI":"10.1016\/j.comnet.2021.108661","article-title":"Evaluating Federated Learning for intrusion detection in Internet of Things: Review and challenges","volume":"203","author":"Campos","year":"2022","journal-title":"Comput. Netw."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"310","DOI":"10.1109\/MNET.011.2000286","article-title":"Internet of things intrusion detection: Centralized, on-device, or federated learning?","volume":"34","author":"Rahman","year":"2020","journal-title":"IEEE Netw."},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Belenguer, A., Navaridas, J., and Pascual, J.A. (2022). A review of federated learning in intrusion detection systems for IoT. arXiv.","DOI":"10.2139\/ssrn.4261807"},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"346","DOI":"10.1016\/j.comcom.2022.09.012","article-title":"Federated learning for intrusion detection system: Concepts, challenges and future directions","volume":"195","author":"Agrawal","year":"2022","journal-title":"Comput. Commun."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"8229","DOI":"10.1109\/JIOT.2022.3150363","article-title":"Recent advances on federated learning for cybersecurity and cybersecurity for federated learning for internet of things","volume":"9","author":"Ghimire","year":"2022","journal-title":"IEEE Internet Things J."},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"4059","DOI":"10.1109\/JIOT.2022.3203249","article-title":"A survey on iot intrusion detection: Federated learning, game theory, social psychology and explainable ai as future directions","volume":"10","author":"Arisdakessian","year":"2022","journal-title":"IEEE Internet Things J."},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Amouri, A., Alaparthy, V.T., and Morgera, S.D. (2018, January 9\u201310). Cross layer-based intrusion detection based on network behavior for IoT. Proceedings of the 2018 IEEE 19th Wireless and Microwave Technology Conference (WAMICON), Sand Key, FL, USA.","DOI":"10.1109\/WAMICON.2018.8363921"},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Canbalaban, E., and Sen, S. (2020, January 19\u201321). A cross-layer intrusion detection system for RPL-based Internet of Things. Proceedings of the Ad-Hoc, Mobile, and Wireless Networks: 19th International Conference on Ad-Hoc Networks and Wireless, ADHOC-NOW 2020, Bari, Italy.","DOI":"10.1007\/978-3-030-61746-2_16"},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"1747","DOI":"10.1109\/TII.2022.3204034","article-title":"A Regularized Cross-Layer Ladder Network for Intrusion Detection in Industrial Internet of Things","volume":"19","author":"Long","year":"2022","journal-title":"IEEE Trans. Ind. Inform."},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"28066","DOI":"10.1109\/JSEN.2021.3124886","article-title":"IoT-Sentry: A cross-layer-based intrusion detection system in standardized Internet of Things","volume":"21","author":"Malik","year":"2021","journal-title":"IEEE Sens. J."},{"key":"ref_48","doi-asserted-by":"crossref","first-page":"727","DOI":"10.1007\/s11277-020-07250-0","article-title":"IC-MADS: IoT enabled cross layer man-in-middle attack detection system for smart healthcare application","volume":"113","author":"Kore","year":"2020","journal-title":"Wirel. Pers. Commun."},{"key":"ref_49","first-page":"311","article-title":"A survey on issues and possible solutions of cross-layer design in Internet of Things","volume":"8","author":"Parween","year":"2021","journal-title":"Int. J. Comput. Netw. Appl."},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Boudargham, N., Abdo, J.B., Demerjian, J., Guyeux, C., and Atechian, T. (2018, January 18\u201320). Efficient cluster-based routing algorithm for body sensor networks. Proceedings of the 2018 IEEE Middle East and North Africa Communications Conference (MENACOMM), Jounieh, Lebanon.","DOI":"10.1109\/MENACOMM.2018.8371004"},{"key":"ref_51","unstructured":"(2023, March 21). Baseline K-Means Open-Source Code. Available online: https:\/\/github.com\/josephazar\/baselineKmeans."},{"key":"ref_52","first-page":"1848","article-title":"A detailed analysis on NSL-KDD dataset using various machine learning techniques for intrusion detection","volume":"2","author":"Revathi","year":"2013","journal-title":"Int. J. Eng. Res. Technol."},{"key":"ref_53","doi-asserted-by":"crossref","unstructured":"Tavallaee, M., Bagheri, E., Lu, W., and Ghorbani, A.A. (2009, January 8\u201310). A detailed analysis of the KDD CUP 99 data set. Proceedings of the 2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications, Ottawa, ON, Canada.","DOI":"10.1109\/CISDA.2009.5356528"},{"key":"ref_54","doi-asserted-by":"crossref","unstructured":"Belarbi, O., Spyridopoulos, T., Anthi, E., Mavromatis, I., Carnelli, P., and Khan, A. (2023). Federated Intrusion Detection System based on Deep Belief Networks. arXiv.","DOI":"10.1007\/978-3-031-17551-0_25"},{"key":"ref_55","doi-asserted-by":"crossref","unstructured":"Nak\u0131p, M., G\u00fcl, B.C., and Gelenbe, E. (2023). Decentralized Online Federated G-Network Learning for Lightweight Intrusion Detection. arXiv.","DOI":"10.1109\/MASCOTS59514.2023.10387644"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/16\/7038\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T20:28:39Z","timestamp":1760128119000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/16\/7038"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,8,9]]},"references-count":55,"journal-issue":{"issue":"16","published-online":{"date-parts":[[2023,8]]}},"alternative-id":["s23167038"],"URL":"https:\/\/doi.org\/10.3390\/s23167038","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,8,9]]}}}