{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,29]],"date-time":"2026-06-29T10:51:25Z","timestamp":1782730285651,"version":"3.54.5"},"reference-count":43,"publisher":"MDPI AG","issue":"9","license":[{"start":{"date-parts":[[2025,9,22]],"date-time":"2025-09-22T00:00:00Z","timestamp":1758499200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Symmetry"],"abstract":"<jats:p>Edge computing offers low-latency and distributed processing for IoT applications but poses new security challenges, due to limited resources and decentralized data. Intrusion detection systems (IDSs) are essential for real-time threat monitoring, yet traditional IDS frameworks often struggle in edge environments, failing to meet efficiency requirements. This paper presents an efficient intrusion detection framework that integrates spatiotemporal hashing, federated learning, and fast K-nearest neighbor (KNN) retrieval. A hashing neural network encodes network traffic into compact binary codes, enabling low-overhead similarity comparison via Hamming distance. To support scalable retrieval, multi-index hashing is applied for sublinear KNN searching. Additionally, we propose an attention-guided federated aggregation strategy that dynamically adjusts client contributions, reducing communication costs. Our experiments on benchmark datasets demonstrate that our method achieves competitive detection accuracy with significantly lower computational, memory, and communication overhead, making it well-suited for edge-based deployment.<\/jats:p>","DOI":"10.3390\/sym17091580","type":"journal-article","created":{"date-parts":[[2025,9,22]],"date-time":"2025-09-22T08:37:39Z","timestamp":1758530259000},"page":"1580","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["A Federated Intrusion Detection System for Edge Environments Using Multi-Index Hashing and Attention-Based KNN"],"prefix":"10.3390","volume":"17","author":[{"given":"Ying","family":"Liu","sequence":"first","affiliation":[{"name":"State Grid Corporation of China, Beijing 100124, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xing","family":"Liu","sequence":"additional","affiliation":[{"name":"Nari Information & Communication Technology Co., Ltd., Nanjing 210003, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hao","family":"Yu","sequence":"additional","affiliation":[{"name":"Nari Information & Communication Technology Co., Ltd., Nanjing 210003, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-6390-4398","authenticated-orcid":false,"given":"Bowen","family":"Guo","sequence":"additional","affiliation":[{"name":"The School of Intelligent Software and Engineering, Nanjing University, Suzhou 215163, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6943-9861","authenticated-orcid":false,"given":"Xiao","family":"Liu","sequence":"additional","affiliation":[{"name":"The School of Intelligent Software and Engineering, Nanjing University, Suzhou 215163, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,9,22]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Guo, B., Yang, Y., Li, Q., Hou, J., and Rao, Y. (2023). Boosting Adversarial Attacks with Improved Sign Method. Advanced Data Mining and Applications, Springer.","DOI":"10.1007\/978-3-031-46677-9_11"},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Guo, B., Li, Q., and Liu, X. (2023, January 24\u201326). Improving Adversarial Transferability with Heuristic Random Transformation. Proceedings of the 2023 26th International Conference on Computer Supported Cooperative Work in Design (CSCWD), Rio de Janeiro, Brazil.","DOI":"10.1109\/CSCWD57460.2023.10152656"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Liang, L., Guo, B., Lian, Z., Li, Q., and Jing, H. (2022). IMPGA: An Effective and Imperceptible Black-Box Attack Against Automatic Speech Recognition Systems. Asia-Pacific Web (APWeb) and Web-Age Information Management (WAIM) Joint International Conference on Web and Big Data, Springer.","DOI":"10.1007\/978-3-031-25201-3_27"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Agarwal, R., and Joshi, M.V. (2001, January 5\u20137). PNrule: A new framework for learning classifier models in data mining (a case-study in network intrusion detection). Proceedings of the 2001 SIAM International Conference on Data Mining, SIAM, Chicago, IL, USA.","DOI":"10.1137\/1.9781611972719.29"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"127","DOI":"10.1007\/s11235-010-9390-3","article-title":"Some similarity coefficients and application of data mining techniques to the anomaly-based IDS","volume":"50","author":"Nikolova","year":"2012","journal-title":"Telecommun. Syst."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"139","DOI":"10.1016\/j.matpr.2021.04.028","article-title":"High throughput token driven FSM based regex pattern matching for network intrusion detection system","volume":"47","author":"Nagaraju","year":"2021","journal-title":"Mater. Today Proc."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"57","DOI":"10.1016\/j.ins.2022.03.065","article-title":"PDAE: Efficient network intrusion detection in IoT using parallel deep auto-encoders","volume":"598","author":"Basati","year":"2022","journal-title":"Inf. Sci."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"246","DOI":"10.14429\/dsj.74.18953","article-title":"A Comprehensive Review of Dimensionality Reduction Techniques for Real-time Network Intrusion Detection with Applications in Cybersecurity","volume":"74","author":"Gondhalekar","year":"2024","journal-title":"Def. Sci. J."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"100527","DOI":"10.1016\/j.measen.2022.100527","article-title":"Recurrent nonsymmetric deep auto encoder approach for network intrusion detection system","volume":"24","author":"Kalpana","year":"2022","journal-title":"Meas. Sens."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"1153","DOI":"10.1109\/COMST.2015.2494502","article-title":"A survey of data mining and machine learning methods for cyber security intrusion detection","volume":"18","author":"Buczak","year":"2015","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"637","DOI":"10.1109\/JIOT.2016.2579198","article-title":"Edge computing: Vision and challenges","volume":"3","author":"Shi","year":"2016","journal-title":"IEEE Internet Things J."},{"key":"ref_12","first-page":"446","article-title":"A study on NSL-KDD dataset for intrusion detection system based on classification algorithms","volume":"4","author":"Dhanabal","year":"2015","journal-title":"Int. J. Adv. Res. Comput. Commun. Eng."},{"key":"ref_13","unstructured":"McMahan, B., Moore, E., Ramage, D., Hampson, S., and y Arcas, B.A. (2017, January 20\u201322). Communication-efficient learning of deep networks from decentralized data. Proceedings of the 20th International Conference on Artificial Intelligence and Statistics (AISTATS) 2017, Fort Lauderdale, FL, USA."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"127018","DOI":"10.1109\/ACCESS.2024.3454211","article-title":"Privacy-Preserving Federated Learning for Intrusion Detection in IoT Environments: A Survey","volume":"12","author":"Vyas","year":"2024","journal-title":"IEEE Access"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Norouzi, M., Punjani, A., and Fleet, D.J. (2012, January 16\u201321). Fast search in hamming space with multi-index hashing. Proceedings of the 2012 IEEE Conference on Computer Vision and Pattern Recognition, Providence, RI, USA.","DOI":"10.1109\/CVPR.2012.6248043"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Kolosnjaji, B., Zarras, A., Webster, G., and Eckert, C. (2016, January 5\u20138). Deep learning for classification of malware system call sequences. Proceedings of the AI 2016: Advances in Artificial Intelligence: 29th Australasian Joint Conference, Hobart, TAS, Australia. Proceedings 29.","DOI":"10.1007\/978-3-319-50127-7_11"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"8048","DOI":"10.1109\/ACCESS.2018.2888816","article-title":"GAN-based semi-supervised learning approach for clinical decision support in health-IoT platform","volume":"7","author":"Yang","year":"2019","journal-title":"IEEE Access"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Gyamfi, E., and Jurcut, A. (2022). Intrusion detection in internet of things systems: A review on design approaches leveraging multi-access edge computing, machine learning and datasets. Sensors, 22.","DOI":"10.3390\/s22103744"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"76","DOI":"10.1016\/j.jnca.2019.02.026","article-title":"Intrusion detection in smart cities using Restricted Boltzmann Machines","volume":"135","author":"Elsaeidy","year":"2019","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Ashraf, E., Areed, N.F., Salem, H., Abdelhay, E.H., and Farouk, A. (2022). FIDChain: Federated intrusion detection system for blockchain-enabled IoT healthcare applications. Healthcare, 10.","DOI":"10.3390\/healthcare10061110"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Solanki, T., Patel, K., Pande, S., and Nimkar, A.V. (2023, January 18\u201320). BlockID: Blockchain based Digital ID and Authentication System for Privacy Improvement. Proceedings of the 2023 3rd International Conference on Advances in Computing, Communication, Embedded and Secure Systems (ACCESS), Ernakulam, India.","DOI":"10.1109\/ACCESS57397.2023.10199733"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"346","DOI":"10.1016\/j.comcom.2022.09.012","article-title":"Federated learning for intrusion detection system: Concepts, challenges and future directions","volume":"195","author":"Agrawal","year":"2022","journal-title":"Comput. Commun."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Friji, H., Olivereau, A., and Sarkiss, M. (2023). Efficient network representation for GNN-based intrusion detection. Applied Cryptography and Network Security, Springer.","DOI":"10.1007\/978-3-031-33488-7_20"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"52215","DOI":"10.1109\/ACCESS.2024.3386631","article-title":"Fl-ids: Federated learning-based intrusion detection system using edge devices for transportation iot","volume":"12","author":"Bhavsar","year":"2024","journal-title":"IEEE Access"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"57","DOI":"10.1016\/j.future.2023.09.019","article-title":"FL-IIDS: A novel federated learning-based incremental intrusion detection system","volume":"151","author":"Jin","year":"2024","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"101592","DOI":"10.1016\/j.iot.2025.101592","article-title":"A novel federated learning-based IDS for enhancing UAVs privacy and security","volume":"31","author":"Ceviz","year":"2025","journal-title":"Internet Things"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"100068","DOI":"10.1016\/j.csa.2024.100068","article-title":"Federated learning-based intrusion detection system for the internet of things using unsupervised and supervised deep learning models","volume":"3","author":"Pranggono","year":"2025","journal-title":"Cyber Secur. Appl."},{"key":"ref_28","unstructured":"Jafari, O., Maurya, P., Nagarkar, P., Islam, K.M., and Crushev, C. (2021). A survey on locality sensitive hashing algorithms and their applications. arXiv."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"2916","DOI":"10.1109\/TPAMI.2012.193","article-title":"Iterative quantization: A procrustean approach to learning binary codes for large-scale image retrieval","volume":"35","author":"Gong","year":"2012","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Zhou, J., Ding, G., Guo, Y., Liu, Q., and Dong, X. (2014, January 14\u201318). Kernel-based supervised hashing for cross-view similarity search. Proceedings of the 2014 IEEE International Conference on Multimedia and Expo (ICME), Chengdu, China.","DOI":"10.1109\/ICME.2014.6890242"},{"key":"ref_31","unstructured":"Norouzi, M., and Fleet, D.J. (July, January 28). Minimal loss hashing for compact binary codes. Proceedings of the ICML\u201911: Proceedings of the 28th International Conference on International Conference on Machine Learning, Bellevue, DC, USA."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"2403","DOI":"10.1109\/TVCG.2018.2887262","article-title":"H-CNN: Spatial hashing based CNN for 3D shape analysis","volume":"26","author":"Shao","year":"2018","journal-title":"IEEE Trans. Vis. Comput. Graph."},{"key":"ref_33","unstructured":"Zhao, F., Huang, Y., Wang, L., and Tan, T. (2015, January 7\u201312). Deep semantic ranking based hashing for multi-label image retrieval. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Boston, MA, USA."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Wan, J., Tang, S., Zhang, Y., Huang, L., and Li, J. (2013, January 15\u201318). Data driven multi-index hashing. Proceedings of the 2013 IEEE International Conference on Image Processing, Melbourne, Australia.","DOI":"10.1109\/ICIP.2013.6738550"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Kapoor, A., and Kumar, D. (2025, January 6\u201311). K-HashFed: Communication Efficient Federated Learning through Gradient Clustering and Hashing. Proceedings of the ICASSP 2025-2025 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), Hyderabad, India.","DOI":"10.1109\/ICASSP49660.2025.10888623"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"1107","DOI":"10.1109\/TPAMI.2013.231","article-title":"Fast exact search in hamming space with multi-index hashing","volume":"36","author":"Norouzi","year":"2013","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Meena, G., and Choudhary, R.R. (2017, January 1\u20132). A review paper on IDS classification using KDD 99 and NSL KDD dataset in WEKA. Proceedings of the 2017 International Conference on Computer, Communications and Electronics (Comptelix), Jaipur, India.","DOI":"10.1109\/COMPTELIX.2017.8004032"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Moustafa, N., and Slay, J. (2015, January 10\u201312). UNSW-NB15: A comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). Proceedings of the 2015 Military Communications and Information Systems Conference (MilCIS), Canberra, Australia.","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Rosay, A., Cheval, E., Carlier, F., and Leroux, P. (2022). Network intrusion detection: A comprehensive analysis of CIC-IDS2017. 8th International Conference on Information Systems Security and Privacy, SCITEPRESS-Science and Technology Publications.","DOI":"10.5220\/0010774000003120"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Zhou, H., Jia, X., Shu, J., and Zhou, L. (2021, January 7\u201311). Cowatch: Collaborative prediction of ddos attacks in edge computing with distributed sdn. Proceedings of the 2021 IEEE Global Communications Conference (GLOBECOM), Madrid, Spain.","DOI":"10.1109\/GLOBECOM46510.2021.9685281"},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"122564","DOI":"10.1016\/j.eswa.2023.122564","article-title":"Flowtransformer: A transformer framework for flow-based network intrusion detection systems","volume":"241","author":"Manocchio","year":"2024","journal-title":"Expert Syst. Appl."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"103285","DOI":"10.1016\/j.cose.2023.103285","article-title":"NE-GConv: A lightweight node edge graph convolutional network for intrusion detection","volume":"130","author":"Altaf","year":"2023","journal-title":"Comput. Secur."},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Ren, K., Zeng, Y., Cao, Z., and Zhang, Y. (2022). ID-RDRL: A deep reinforcement learning-based feature selection intrusion detection model. Sci. Rep., 12.","DOI":"10.1038\/s41598-022-19366-3"}],"container-title":["Symmetry"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-8994\/17\/9\/1580\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T18:46:49Z","timestamp":1760035609000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-8994\/17\/9\/1580"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,22]]},"references-count":43,"journal-issue":{"issue":"9","published-online":{"date-parts":[[2025,9]]}},"alternative-id":["sym17091580"],"URL":"https:\/\/doi.org\/10.3390\/sym17091580","relation":{},"ISSN":["2073-8994"],"issn-type":[{"value":"2073-8994","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9,22]]}}}