Efficient and explainable intrusion detection for the internet of things using modified-LSTM and HTM-inspired sparse CNN with federated learning
According to the World Economic Forum, IoT devices have become a main target for Dark Web attacks. There is therefore a pressing need to develop intrusion detection systems suitable for deployment on IoT devices. To this end, we developed an IDS inspired from Hierarchical Temporal Memory (HTM) with Sparse CNN model that uses Federated Learning (FL) and provides explainable inferences. The use of FL enables collaborative model training between IoT devices without compromising data privacy. Moreover, explainable AI (XAI) provides confidence in the model's results and enhances their analysis. To evaluate our model's performance, we used a data set collected from nine IoT devices, where the model had three classification tasks: binary (benign vs. malicious), botnet-type, and attack-type. Moreover, we implemented an IDS based on a Long Short-Term Memory (LSTM) model from the literature, in order to compare both models. We show that our model achieves up to 500x faster inference time, making it highly suitable for resource-constrained IoT edge devices. On the other hand, the LSTM model excels in binary classification with 99.99% accuracy and faithfulness scores: 1.59–4.71. However, our HTM-Inspired Sparse CNN model, named FL-HTM, converges faster during FL rounds and offers superior efficiency for real-time deployment.
Authors
- Mohamed Abdelaziz (ORCID: https://orcid.org/0000-0002-1976-2182)
- Mohamed Saleh
- M. A. Abdou
Institutions
- Pharos University in Alexandria (EG)
- AlAlamein International University (EG)
Publication Details
- Journal
- International Journal of Computers and Applications
- Published
- 2026-09-18
- DOI
- https://doi.org/10.1080/1206212x.2026.2731403
- Primary Topic
- Network Security and Intrusion Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00