Dynamic weighted federated learning with client level differential privacy for DDoS detection in IoT networks

Abstract The rapid expansion of Internet of Things (IoT) networks has introduced substantial security threats from distributed denial of service (DDoS) attacks to the availability of IoT systems. Existing intrusion detection systems (IDS) are often inefficient in IoT environments due to network heterogeneity, and privacy concerns associated with sharing sensitive data. To address the unresolved challenge of simultaneously handling non-IID data heterogeneity, dynamic client quality variation, and formally quantified privacy in distributed IoT DDoS detection, this paper proposes a client-level differential privacy (CLDP)-dynamic weighted federated learning (DWFL) framework that applies Gaussian-mechanism noise with Renyi differential privacy (DP) composition and privacy amplification by subsampling, combined with a quality-score-driven weighted aggregation mechanism, within a single unified architecture, where the weighting mechanism is deliberately lightweight to remain compatible with formal per-round privacy accounting rather than to outperform more elaborate trust or attention-based aggregation schemes. In the proposed framework, each IoT client trains on a local dataset. Later on, it applies update norm clipping and Gaussian noise injection on updates to enforce CLDP before transmitting model updates to a central aggregator. A dynamic weighted aggregation mechanism is added to combine client updates based on the data size, and quality of each client which ensures that contributions from more informative clients have a proportionally higher impact on the global model. The proposed framework is evaluated using two extensively recognized IoT datasets, CICIoT2023 and IoT23. Results demonstrate a maximum detection accuracy of 95.30% to 96.95%, and a formal privacy budget of ε (4.06 to 9.07) outperforming the standard FedAvg baseline by approximately 3.7% and FedProx by approximately 4.5%. An ablation study further validates the selection of key privacy hyperparameters, confirming that they represent an empirically optimal configuration. Overall, this research presents a practical, and formally privacy-preserving solution for DDoS detection.

Authors

Institutions

Publication Details

Journal
Discover Artificial Intelligence
Published
2026-10-07
DOI
https://doi.org/10.1007/s44163-026-02452-0
Primary Topic
Privacy-Preserving Technologies in Data
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

Dynamic weighted federated learning with client level differential privacy for DDoS detection in IoT networks

Muhammad Awais Sattar, Bilal Shabbir Qaisar, Mubashar Raza, Laiba Maryam
Discover Artificial Intelligence
Privacy-Preserving Technologies in Data
article

Dynamic weighted federated learning with client level differential privacy for DDoS detection in IoT networks

Muhammad Awais Sattar, Bilal Shabbir Qaisar, Mubashar Raza, Laiba Maryam
article en

Abstract

Abstract The rapid expansion of Internet of Things (IoT) networks has introduced substantial security threats from distributed denial of service (DDoS) attacks to the availability of IoT systems. Existing intrusion detection systems (IDS) are often inefficient in IoT environments due to network heterogeneity, and privacy concerns associated with sharing sensitive data. To address the unresolved challenge of simultaneously handling non-IID data heterogeneity, dynamic client quality variation, and formally quantified privacy in distributed IoT DDoS detection, this paper proposes a client-level differential privacy (CLDP)-dynamic weighted federated learning (DWFL) framework that applies Gaussian-mechanism noise with Renyi differential privacy (DP) composition and privacy amplification by subsampling, combined with a quality-score-driven weighted aggregation mechanism, within a single unified architecture, where the weighting mechanism is deliberately lightweight to remain compatible with formal per-round privacy accounting rather than to outperform more elaborate trust or attention-based aggregation schemes. In the proposed framework, each IoT client trains on a local dataset. Later on, it applies update norm clipping and Gaussian noise injection on updates to enforce CLDP before transmitting model updates to a central aggregator. A dynamic weighted aggregation mechanism is added to combine client updates based on the data size, and quality of each client which ensures that contributions from more informative clients have a proportionally higher impact on the global model. The proposed framework is evaluated using two extensively recognized IoT datasets, CICIoT2023 and IoT23. Results demonstrate a maximum detection accuracy of 95.30% to 96.95%, and a formal privacy budget of ε (4.06 to 9.07) outperforming the standard FedAvg baseline by approximately 3.7% and FedProx by approximately 4.5%. An ablation study further validates the selection of key privacy hyperparameters, confirming that they represent an empirically optimal configuration. Overall, this research presents a practical, and formally privacy-preserving solution for DDoS detection.

Discover Artificial IntelligenceVol. 6(1)
COMSATS University Islamabad (PK), Luleå University of Technology (SE)
Openalex Percentile: Top 12%
Privacy-Preserving Technologies in Data
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.