FBID: Adaptive Personalized Federated Learning for Robust Out-of-Distribution Attack Detection in IoT Networks

📅 2026-08-04
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the challenge of over-personalization in personalized federated learning within heterogeneous IoT environments, which can degrade out-of-distribution (OOD) attack detection performance. To mitigate this issue, the authors propose FBID, a novel framework that introduces, for the first time, a server-side personalization control mechanism. FBID dynamically adjusts the intensity of local client training via a contextual multi-armed bandit and integrates a trust-aware model interpolation strategy to balance global and local model updates. This approach effectively alleviates over-personalization while enhancing generalization to unseen threats. Experimental results on the CICIoT2023 dataset demonstrate that FBID improves OOD attack detection rates by up to 7.66% and F1 scores by 5.08% over the strongest baseline, exhibiting superior robustness against previously unseen attack categories.
📝 Abstract
Personalized Federated Learning (PFL) has emerged as a promising solution for intrusion detection in heterogeneous IoT environments, as it can improve local adaptation under highly Non-Independent and Identically Distributed (non-IID) data distributions. However, existing PFL methods often rely on client-side self-adjustment, which may lead to over-personalization and substantial degradation in out-of-distribution (OOD) attack detection. In this paper, we propose Federated Bandit Intrusion Detection (FBID), a novel adaptive PFL framework to address this limitation through server-side personalization control. In particular, FBID employs a contextual multi-armed bandit at the server to dynamically regulate each client's local training intensity according to its observed behavior and update quality. Moreover, FBID introduces a trust-based blending mechanism to derive client-specific interpolation coefficients between the global and local models, thereby preserving global attack-detection knowledge while still allowing beneficial local specialization. Through extensive experiments on the CICIoT2023 dataset under heterogeneous client distributions and OOD stress-test settings, we show that FBID improves individual client OOD Detection Rate (DR) by up to 7.66% and F1-Score (F1) by up to 5.08% (relative) over the strongest stable baseline, while also improving robustness to previously unseen attack classes.
Problem

Research questions and friction points this paper is trying to address.

Personalized Federated Learning
Out-of-Distribution Attack Detection
IoT Networks
non-IID Data
Intrusion Detection
Innovation

Methods, ideas, or system contributions that make the work stand out.

Personalized Federated Learning
Out-of-Distribution Detection
Contextual Multi-Armed Bandit
Trust-Based Blending
IoT Intrusion Detection
🔎 Similar Papers
No similar papers found.
A
An Khanh Bui
UTS-HCMUT JTIRC, Ho Chi Minh City University of Technology (HCMUT), Ho Chi Minh City 700000, Vietnam; Vietnam National University Ho Chi Minh City (VNU-HCM), Ho Chi Minh City 700000, Vietnam
C
Cong Thanh Nguyen
UTS-HCMUT JTIRC, Ho Chi Minh City University of Technology (HCMUT), Ho Chi Minh City 700000, Vietnam; Vietnam National University Ho Chi Minh City (VNU-HCM), Ho Chi Minh City 700000, Vietnam; School of Electrical and Data Engineering, University of Technology Sydney, Sydney, NSW 2007, Australia
Hoang-Anh Pham
Hoang-Anh Pham
HCMC University of Technology (HCMUT), Vietnam National University Ho Chi Minh City (VNU-HCM)
Cyber-Physical SystemsAIoTBlockchain
H
Hoang Thai Dinh
School of Electrical and Data Engineering, University of Technology Sydney, Sydney, NSW 2007, Australia
Diep N. Nguyen
Diep N. Nguyen
University of Technology Sydney
Mobile ComputingCommunications and NetworkingWireless and Cyber Security5G/6GApplied AI