{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,3]],"date-time":"2026-08-03T05:59:45Z","timestamp":1785736785906,"version":"3.56.0"},"reference-count":46,"publisher":"MDPI AG","issue":"17","license":[{"start":{"date-parts":[[2024,8,24]],"date-time":"2024-08-24T00:00:00Z","timestamp":1724457600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Advanced metering infrastructures (AMIs) aim to enhance the efficiency, reliability, and stability of electrical systems while offering advanced functionality. However, an AMI collects copious volumes of data and information, making the entire system sensitive and vulnerable to malicious attacks that may cause substantial damage, such as a deficit in national security, a disturbance of public order, or significant economic harm. As a result, it is critical to guarantee a steady and dependable supply of information and electricity. Furthermore, storing massive quantities of data in one central entity leads to compromised data privacy. As such, it is imperative to engineer decentralized, federated learning (FL) solutions. In this context, the performance of participating clients has a significant impact on global performance. Moreover, FL models have the potential for a Single Point of Failure (SPoF). These limitations contribute to system failure and performance degradation. This work aims to develop a performance-based hierarchical federated learning (HFL) anomaly detection system for an AMI through (1) developing a deep learning model that detects attacks against this critical infrastructure; (2) developing a novel aggregation strategy, FedAvg-P, to enhance global performance; and (3) proposing a peer-to-peer architecture guarding against a SPoF. The proposed system was employed in experiments on the CIC-IDS2017 dataset. The experimental results demonstrate that the proposed system can be used to develop a reliable anomaly detection system for AMI networks.<\/jats:p>","DOI":"10.3390\/s24175492","type":"journal-article","created":{"date-parts":[[2024,8,26]],"date-time":"2024-08-26T03:32:01Z","timestamp":1724643121000},"page":"5492","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":15,"title":["FedAvg-P: Performance-Based Hierarchical Federated Learning-Based Anomaly Detection System Aggregation Strategy for Advanced Metering Infrastructure"],"prefix":"10.3390","volume":"24","author":[{"given":"Hend","family":"Alshede","sequence":"first","affiliation":[{"name":"Department of Computer Science, Faculty of Computing and Information Technology, King Abdulaziz University, Jeddah 21589, Saudi Arabia"},{"name":"Self-Development Skills Department, Common First Year Deanship, King Saud University, Riyadh 12211, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kamal","family":"Jambi","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Faculty of Computing and Information Technology, King Abdulaziz University, Jeddah 21589, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9707-1259","authenticated-orcid":false,"given":"Laila","family":"Nassef","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Faculty of Computing and Information Technology, King Abdulaziz University, Jeddah 21589, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4683-3716","authenticated-orcid":false,"given":"Nahed","family":"Alowidi","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Faculty of Computing and Information Technology, King Abdulaziz University, Jeddah 21589, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7204-9474","authenticated-orcid":false,"given":"Etimad","family":"Fadel","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Faculty of Computing and Information Technology, King Abdulaziz University, Jeddah 21589, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2024,8,24]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"43","DOI":"10.1007\/s10586-018-2820-9","article-title":"A survey of privacy-preserving schemes in IoE-enabled Smart Grid Advanced Metering Infrastructure","volume":"22","author":"Desai","year":"2019","journal-title":"Clust. Comput."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1016\/j.ijcip.2017.03.004","article-title":"Security analysis of an advanced metering infrastructure","volume":"18","author":"Hansen","year":"2017","journal-title":"Int. J. Crit. Infrastruct. Prot."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Xu, S., Qian, Y., and Hu, R. (2017, January 6\u201311). A Study on Communication Network Reliability for Advanced Metering Infrastructure in Smart Grid. Proceedings of the 2017 IEEE 15th International Conference on Dependable, Autonomic and Secure Computing, 2017 IEEE 15th International Conference on Pervasive Intelligence and Computing, 2017 IEEE 3rd International Conference on Big Data Intelligence and Computer, Orlando, FL, USA.","DOI":"10.1109\/DASC-PICom-DataCom-CyberSciTec.2017.35"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"48992","DOI":"10.1109\/ACCESS.2021.3068752","article-title":"Clustering algorithm-based network planning for advanced metering infrastructure in smart grid","volume":"9","author":"Gallardo","year":"2012","journal-title":"IEEE Access"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"159291","DOI":"10.1109\/ACCESS.2021.3131220","article-title":"Energy Theft in Smart Grids: A Survey on Data-Driven Attack Strategies and Detection Methods","volume":"9","author":"Althobaiti","year":"2021","journal-title":"IEEE Access"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"13960","DOI":"10.1109\/ACCESS.2019.2894819","article-title":"Application of Big Data and Machine Learning in Smart Grid, and Associated Security Concerns: A Review","volume":"7","author":"Hossain","year":"2019","journal-title":"IEEE Access"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Zhang, Z., Hu, Z., Zhan, Y., Wang, X., and Guo, K. (2020). A smart grid AMI intrusion detection strategy based on extreme learning machine. Energies, 13.","DOI":"10.3390\/en13184907"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s11277-020-07808-y","article-title":"An Efficient Hybrid Evolutionary Approach for Identification of Zero-Day Attacks on Wired\/Wireless Network System","volume":"123","author":"Shukla","year":"2020","journal-title":"Wirel. Pers. Commun."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"192","DOI":"10.1016\/j.procs.2021.07.024","article-title":"On the analysis of open source datasets: Validating IDS implementation for well-known and zero-day attack detection","volume":"191","author":"Serinelli","year":"2021","journal-title":"Procedia Comput. Sci."},{"key":"ref_10","first-page":"5711","article-title":"Mitigating Zero-Day Attacks in IoT Using a Strategic Framework","volume":"4","author":"Lamba","year":"2019","journal-title":"SSRN Electron. J."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Tang, R., Yang, Z., Li, Z., Meng, W., Wang, H., Li, Q., Sun, Y., Pei, D., Wei, T., and Xu, Y. (2020, January 6\u20139). ZeroWall: Detecting Zero-Day Web Attacks through Encoder-Decoder Recurrent Neural Networks. Proceedings of the IEEE INFOCOM, Toronto, ON, Canada.","DOI":"10.1109\/INFOCOM41043.2020.9155278"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"108693","DOI":"10.1016\/j.comnet.2021.108693","article-title":"Federated learning for malware detection in IoT devices","volume":"204","author":"Rey","year":"2020","journal-title":"Comput. Netw."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"100008","DOI":"10.1016\/j.hcc.2021.100008","article-title":"A survey of federated learning for edge computing: Research problems and solutions","volume":"1","author":"Xia","year":"2021","journal-title":"High-Confid. Comput."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"941","DOI":"10.1016\/j.icte.2023.03.006","article-title":"Security of Internet of Things (IoT) using federated learning and deep learning\u2014Recent advancements, issues, and prospects","volume":"9","author":"Gugueoth","year":"2023","journal-title":"ICT Express"},{"key":"ref_15","first-page":"50","article-title":"Federated Learning: Challenges, Methods, and Future Directions","volume":"37","author":"Li","year":"2020","journal-title":"IEEE Signal Process. Mag."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Yan, G., Wang, H., Yuan, X., and Li, J. (2023, January 24). DeFL: Defending against Model Poisoning Attacks in Federated Learning via Critical Learning Periods Awareness. Proceedings of the 37th AAAI Conference on Artificial Intelligence, Washington, DC, USA.","DOI":"10.1609\/aaai.v37i9.26271"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"21811","DOI":"10.1109\/JIOT.2023.3299573","article-title":"Client Selection in Federated Learning: Principles, Challenges, and Opportunities","volume":"4","author":"Fu","year":"2023","journal-title":"IEEE Internet Things J."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"5226","DOI":"10.3934\/era.2023266","article-title":"FedSC: A federated learning algorithm based on client-side clustering","volume":"31","author":"Wang","year":"2023","journal-title":"Electron. Res. Arch."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Yang, C., and Zhao, X. (2023). Study on the Selection Method of Federated Learning Clients for Smart Manufacturing. Electronics, 12.","DOI":"10.3390\/electronics12112532"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Khajehali, N., Yan, J., Chow, Y., and Fahmideh, M. (2023). A Comprehensive Overview of IoT-Based Federated Learning: Focusing on Client Selection Methods. Sensors, 23.","DOI":"10.3390\/s23167235"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"4","DOI":"10.1186\/s42400-021-00105-6","article-title":"Threats, attacks and defenses to federated learning: Issues, taxonomy, and perspectives","volume":"5","author":"Liu","year":"2022","journal-title":"Cybersecurity"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Wang, Z., Kang, Q., Zhang, X., and Hu, Q. (2022, January 10\u201313). Defense Strategies toward Model Poisoning Attacks in Federated Learning: A Survey. Proceedings of the IEEE Wireless Communications and Networking Conference, WCNC, Austin, TX, USA.","DOI":"10.1109\/WCNC51071.2022.9771619"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"10708","DOI":"10.1109\/ACCESS.2023.3238823","article-title":"Poisoning Attacks in Federated Learning: A Survey","volume":"11","author":"Xia","year":"2023","journal-title":"IEEE Access"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"22359","DOI":"10.1109\/ACCESS.2022.3151670","article-title":"Differential Privacy for Deep and Federated Learning: A Survey","volume":"10","author":"Abdelhadi","year":"2022","journal-title":"IEEE Access"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"108379","DOI":"10.1016\/j.compeleceng.2022.108379","article-title":"HBFL: A hierarchical blockchain-based federated learning framework for collaborative IoT intrusion detection","volume":"103","author":"Sarhan","year":"2022","journal-title":"Comput. Electr. Eng."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Sun, X., Tang, Z., Du, M., Deng, C., Lin, W., Chen, J., Qi, Q., and Zheng, H. (2022). A Hierarchical Federated Learning-Based Intrusion Detection System for 5G Smart Grids. Electronics, 11.","DOI":"10.3390\/electronics11162627"},{"key":"ref_27","unstructured":"Schueller, Q., Basu, K., Younas, M., Patel, M., and Ball, F. (2018, January 21\u201323). A Hierarchical Intrusion Detection System using Data Center. Proceedings of the 2018 28th International Telecommunication Networks and Applications Conference (ITNAC), Sydney, NSW, Australia."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"158","DOI":"10.3390\/network3010008","article-title":"A Federated Learning-Based Approach for Improving Intrusion Detection in Industrial Internet of Things Networks","volume":"3","author":"Rashid","year":"2023","journal-title":"Network"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"2913293","DOI":"10.1155\/2022\/2913293","article-title":"An Efficient Intrusion Detection Method Based on Federated Transfer Learning and an Extreme Learning Machine with Privacy Preservation","volume":"2022","author":"Wang","year":"2022","journal-title":"Secur. Commun. Netw."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"703","DOI":"10.1007\/s12243-023-00965-8","article-title":"Enhanced DASS-CARE 2.0: A blockchain-based and decentralized FL framework","volume":"78","author":"Ayache","year":"2023","journal-title":"Ann. Des. Telecommun. Ann. Telecommun."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"100657","DOI":"10.1016\/j.iot.2022.100657","article-title":"ACS: Accuracy-based client selection mechanism for federated industrial IoT","volume":"21","author":"Putra","year":"2023","journal-title":"Internet Things"},{"key":"ref_32","first-page":"1047","article-title":"A Client Selection Method Based on Loss Function Optimization for Federated Learning","volume":"137","author":"Zeng","year":"2023","journal-title":"Comput. Model. Eng. Sci."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Zhang, W., Zhao, Y., Li, F., and Zhu, H. (2023). A Hierarchical Federated Learning Algorithm Based on Time Aggregation in Edge Computing Environment. Appl. Sci., 13.","DOI":"10.3390\/app13095821"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Tong, W., Lu, L., Li, Z., Lin, J., and Jin, X. (2016, January 21\u201323). A survey on intrusion detection system for advanced metering infrastructure. Proceedings of the 2016 6th International Conference on Instrumentation and Measurement, Computer, Communication and Control, IMCCC, Harbin, China.","DOI":"10.1109\/IMCCC.2016.193"},{"key":"ref_35","unstructured":"(2022, April 09). IDS 2017|Datasets|Research|Canadian Institute for Cybersecurity|UNB. Available online: https:\/\/www.unb.ca\/cic\/datasets\/ids-2017.html."},{"key":"ref_36","first-page":"479","article-title":"A detailed analysis of CICIDS2017 dataset for designing Intrusion Detection Systems","volume":"7","author":"Panigrahi","year":"2018","journal-title":"Int. J. Eng. Technol."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Pratama, I., Permanasari, A., Ardiyanto, I., and Indrayani, R. (2016, January 24\u201327). A review of missing values handling methods on time-series data. Proceedings of the 2016 International Conference on Information Technology Systems and Innovation, Bandung, Indonesia.","DOI":"10.1109\/ICITSI.2016.7858189"},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"25036","DOI":"10.1109\/ACCESS.2021.3056566","article-title":"Towards Sustainable Energy Efficiency with Intelligent Electricity Theft Detection in Smart Grids Emphasising Enhanced Neural Networks","volume":"9","author":"Aldegheishem","year":"2021","journal-title":"IEEE Access"},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"32150","DOI":"10.1109\/ACCESS.2020.2973219","article-title":"Increasing the Performance of Machine Learning-Based IDSs on an Imbalanced and Up-to-Date Dataset","volume":"8","author":"Karatas","year":"2020","journal-title":"IEEE Access"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Galv\u00e1n-Tejada, C., Zanella-Calzada, L., Garc\u00eda-Dom\u00ednguez, A., Magallanes-Quintanar, R., Luna-Garc\u00eda, H., Celaya-Padilla, J.M., Galv\u00e1n-Tejada, J.I., V\u00e9lez-Rodr\u00edguez, A., and Gamboa-Rosales, H. (2020). Estimation of indoor location through magnetic field data: An approach based on convolutional neural networks. ISPRS Int. J. Geoinf., 9.","DOI":"10.3390\/ijgi9040226"},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Imrana, Y., Xiang, Y., Ali, L., Abdul-Rauf, Z., Hu, Y., Kadry, S., and Lim, S. (2022). \u03c72-BidLSTM: A Feature Driven Intrusion Detection System Based on \u03c72 Statistical Model and Bidirectional LSTM. Sensors, 22.","DOI":"10.3390\/s22052018"},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Rahman, M., Watanobe, Y., and Nakamura, K. (2021). A bidirectional LSTM language model for code evaluation and repair. Symmetry, 13.","DOI":"10.3390\/sym13020247"},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"353","DOI":"10.1016\/j.egyr.2021.10.024","article-title":"Intrusion detection system in the Smart Distribution Network: A feature engineering based AE-LightGBM approach","volume":"7","author":"Yao","year":"2021","journal-title":"Energy Rep."},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"297","DOI":"10.32604\/iasc.2023.026799","article-title":"Hybrid Deep Learning Based Attack Detection for Imbalanced Data Classification","volume":"35","author":"Almarshdi","year":"2023","journal-title":"Intell. Autom. Soft Comput."},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"3257","DOI":"10.32604\/iasc.2023.035874","article-title":"Ensemble Voting-Based Anomaly Detection for a Smart Grid Communication Infrastructure","volume":"36","author":"Alshede","year":"2023","journal-title":"Intell. Autom. Soft Comput."},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"65092","DOI":"10.1109\/ACCESS.2022.3184309","article-title":"FLY-SMOTE: Re-Balancing the Non-IID IoT Edge Devices Data in Federated Learning System","volume":"10","author":"Younis","year":"2022","journal-title":"IEEE Access"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/24\/17\/5492\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T15:42:50Z","timestamp":1760110970000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/24\/17\/5492"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,8,24]]},"references-count":46,"journal-issue":{"issue":"17","published-online":{"date-parts":[[2024,9]]}},"alternative-id":["s24175492"],"URL":"https:\/\/doi.org\/10.3390\/s24175492","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,8,24]]}}}