PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
March 17, 2026Computer Networks2 citationsOpen Access

Hybrid Clustering-Guided Federated Learning for Robust Intrusion Detection in Highly Heterogeneous IoT Environments

View Full Paper
LGLuis Miguel García-SáezSRSergio Ruiz-VillafrancaJRJosé Roldán-Gómez

Key Points

  • The aim is to enhance intrusion detection robustness in IoT settings using a novel federated learning approach.
  • Introduced a double-clustering architecture for client-side and server-side coordination.
  • Utilized micro-clustering for local updates to minimize inconsistency.
  • Employed density-based clustering (HDBSCAN) for dynamic client organization.
  • Implemented stability-aware assignments across training rounds.
  • Achieved up to 19.9% increase in F1-score compared to standard federated learning methods.
  • Maintained over 90% peak performance even under severe non-IID conditions.
  • Kept runtime variations within ± 15% across experiments.

Abstract

The growing complexity and scale of Internet of Things (IoT) ecosystems have intensified the emergence of cyber threats and amplified the impact of data heterogeneity across devices. These environments are characterised by their inherent hostility, comprising resource-limited and intermittently connected devices. Consequently, this poses a considerable challenge to the stability and reliability of conventional Federated Learning (FL) approaches. Standard aggregation schemes such as FedAvg, FedProx, FedAdam, and SCAFFOLD often fail under such extreme non-Independent and Identically Distributed (non-IID) conditions, leading to unstable convergence and biased global models. This work introduces a double-clustering federated architecture for intrusion detection that coordinates training at two levels. Locally, lightweight micro-clustering organises client-side updates into consistent groups, reducing the influence of inconsistent local updates. At the server level, density-based (HDBSCAN) clustering discovers evolving families of distributionally compatible clients, allowing coordination to adapt as heterogeneity evolves over time. Clustering is stabilised across rounds through a stability-aware assignment rule. Training then proceeds via family-wise aggregation, producing one expert model per family and a global fallback model for outliers and unassigned participants. Extensive experiments on three public IoT cybersecurity datasets, X-IIoTID, RT-IoT22, and Edge-IIoTset, demonstrate the robustness of the proposed strategy across both lightweight and Deep Learning (DL) models. The architecture achieves up to 19.9% higher F1-score than standard FL methods and maintains over 90% of its peak performance even under severe non-IID conditions, while keeping runtime variations within ± 15%. These results establish clustering-guided coordination as a practical and resilient foundation for federated intrusion detection, capable of sustaining high accuracy and stability in the most adversarial IoT environments.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

García-Sáez et al. (2026) studied this question.

synapsesocial.com/papers/69b8ef52deb47d591b8c56a7https://doi.org/10.1016/j.comnet.2026.112205
Ask AI
Helpful
Bookmark
Share
View Full Paper