A resource-aware framework for energy and bandwidth efficient IoT intrusion detection using lightweight federated learning over SDN

The rapid growth of Internet of Things (IoT) deployments has widened the network attack surface while increasing the cost of centralised intrusion detection, particularly when raw traffic must be moved to remote servers. We propose HFL-SDN-IDS, a hierarchical, resource-aware framework that combines a lightweight federated intrusion-detection model, two-tier aggregation, and an SDN-assisted enforcement layer. The contribution is a system-level co-design rather than a new federated aggregation rule. Experiments use five benchmark datasets-CICIDS-2017, N-BaIoT, TON_IoT, Edge-IIoTset, and UNSW-NB15. Under the default CICIDS-2017 configuration ( \(N=100\) , \(K=10\) , \(\alpha =0.5\) ), the retained aggregate comparison reports 98.93% detection accuracy, 18.4 MB/round of model-based communication accounting, and 3.87 J/round of model-based energy consumption, compared with 38.6 MB/round and 9.82 J/round for FedAvg. In the fixed 10,000-sample six-family classification evaluation used for class-wise reporting, HFL-SDN-IDS achieves 98.6% accuracy, 98.6% weighted F1, and 96.9% Macro-F1. These values correspond to 52.3% lower reported bandwidth and 60.6% lower reported energy, while convergence is reached in 31.3% fewer communication rounds. In the scalability study, the reported HFL-SDN-IDS bandwidth increases from 18.4 MB/round at \(N=100\) to 41.6 MB/round at \(N=1{,}000\) ; the corresponding FedAvg reference at \(N=1{,}000\) is 389.7 MB/round. The SDN control channel has an analytical worst-case reporting overhead of approximately 1.28 KB/round under the default participation setting, and the Mininet enforcement measurements show a median latency of 4.3 ms and a 99th-percentile latency of 11.7 ms. Controlled ablation separates the contributions of the lightweight model, hierarchical topology, and SDN-assisted configuration. Overall, the results support a resource-aware, data-local approach to large-scale IoT intrusion detection while also highlighting the limitations of simulation-based resource accounting and the absence of formal privacy or Byzantine-robustness guarantees in the proposed method.

Authors

Institutions

Publication Details

Journal
Scientific Reports
Published
2026-10-06
DOI
https://doi.org/10.1038/s41598-026-74166-3
Primary Topic
Network Security and Intrusion Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

A resource-aware framework for energy and bandwidth efficient IoT intrusion detection using lightweight federated learning over SDN

Ali Ghaffari, Masoud Kargar, Nahideh Derakhshanfard, Hossein Baghalzadeh
Scientific Reports
Network Security and Intrusion Detection
article

A resource-aware framework for energy and bandwidth efficient IoT intrusion detection using lightweight federated learning over SDN

Ali Ghaffari, Masoud Kargar, Nahideh Derakhshanfard, Hossein Baghalzadeh
article en

Abstract

The rapid growth of Internet of Things (IoT) deployments has widened the network attack surface while increasing the cost of centralised intrusion detection, particularly when raw traffic must be moved to remote servers. We propose HFL-SDN-IDS, a hierarchical, resource-aware framework that combines a lightweight federated intrusion-detection model, two-tier aggregation, and an SDN-assisted enforcement layer. The contribution is a system-level co-design rather than a new federated aggregation rule. Experiments use five benchmark datasets-CICIDS-2017, N-BaIoT, TON_IoT, Edge-IIoTset, and UNSW-NB15. Under the default CICIDS-2017 configuration ( \(N=100\) , \(K=10\) , \(\alpha =0.5\) ), the retained aggregate comparison reports 98.93% detection accuracy, 18.4 MB/round of model-based communication accounting, and 3.87 J/round of model-based energy consumption, compared with 38.6 MB/round and 9.82 J/round for FedAvg. In the fixed 10,000-sample six-family classification evaluation used for class-wise reporting, HFL-SDN-IDS achieves 98.6% accuracy, 98.6% weighted F1, and 96.9% Macro-F1. These values correspond to 52.3% lower reported bandwidth and 60.6% lower reported energy, while convergence is reached in 31.3% fewer communication rounds. In the scalability study, the reported HFL-SDN-IDS bandwidth increases from 18.4 MB/round at \(N=100\) to 41.6 MB/round at \(N=1{,}000\) ; the corresponding FedAvg reference at \(N=1{,}000\) is 389.7 MB/round. The SDN control channel has an analytical worst-case reporting overhead of approximately 1.28 KB/round under the default participation setting, and the Mininet enforcement measurements show a median latency of 4.3 ms and a 99th-percentile latency of 11.7 ms. Controlled ablation separates the contributions of the lightweight model, hierarchical topology, and SDN-assisted configuration. Overall, the results support a resource-aware, data-local approach to large-scale IoT intrusion detection while also highlighting the limitations of simulation-based resource accounting and the absence of formal privacy or Byzantine-robustness guarantees in the proposed method.

Scientific Reports
Islamic Azad University of Tabriz (IR), Istinye University (TR)
Industry, innovation and infrastructure
Openalex Percentile: Top 11%
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.