Dynamic weighted federated learning with client level differential privacy for DDoS detection in IoT networks
Abstract The rapid expansion of Internet of Things (IoT) networks has introduced substantial security threats from distributed denial of service (DDoS) attacks to the availability of IoT systems. Existing intrusion detection systems (IDS) are often inefficient in IoT environments due to network heterogeneity, and privacy concerns associated with sharing sensitive data. To address the unresolved challenge of simultaneously handling non-IID data heterogeneity, dynamic client quality variation, and formally quantified privacy in distributed IoT DDoS detection, this paper proposes a client-level differential privacy (CLDP)-dynamic weighted federated learning (DWFL) framework that applies Gaussian-mechanism noise with Renyi differential privacy (DP) composition and privacy amplification by subsampling, combined with a quality-score-driven weighted aggregation mechanism, within a single unified architecture, where the weighting mechanism is deliberately lightweight to remain compatible with formal per-round privacy accounting rather than to outperform more elaborate trust or attention-based aggregation schemes. In the proposed framework, each IoT client trains on a local dataset. Later on, it applies update norm clipping and Gaussian noise injection on updates to enforce CLDP before transmitting model updates to a central aggregator. A dynamic weighted aggregation mechanism is added to combine client updates based on the data size, and quality of each client which ensures that contributions from more informative clients have a proportionally higher impact on the global model. The proposed framework is evaluated using two extensively recognized IoT datasets, CICIoT2023 and IoT23. Results demonstrate a maximum detection accuracy of 95.30% to 96.95%, and a formal privacy budget of ε (4.06 to 9.07) outperforming the standard FedAvg baseline by approximately 3.7% and FedProx by approximately 4.5%. An ablation study further validates the selection of key privacy hyperparameters, confirming that they represent an empirically optimal configuration. Overall, this research presents a practical, and formally privacy-preserving solution for DDoS detection.
Authors
- Muhammad Awais Sattar (ORCID: https://orcid.org/0000-0002-2431-8182)
- Bilal Shabbir Qaisar
- Mubashar Raza
- Laiba Maryam
Institutions
- COMSATS University Islamabad (PK)
- Luleå University of Technology (SE)
Publication Details
- Journal
- Discover Artificial Intelligence
- Published
- 2026-10-07
- DOI
- https://doi.org/10.1007/s44163-026-02452-0
- Primary Topic
- Privacy-Preserving Technologies in Data
- Type
- article
- Field-Weighted Citation Impact
- 0.00