Joshi, Vaibhav and Chowdhury, Abishi and Pal, Amrit and Singh, Vishal Krishna and Rathore, Rajkumar Singh (2026) Real‐Time Anomaly Detection Using Federated Learning in Edge Devices. Software - Practice and Experience. DOI https://doi.org/10.1002/spe.70101
Joshi, Vaibhav and Chowdhury, Abishi and Pal, Amrit and Singh, Vishal Krishna and Rathore, Rajkumar Singh (2026) Real‐Time Anomaly Detection Using Federated Learning in Edge Devices. Software - Practice and Experience. DOI https://doi.org/10.1002/spe.70101
Joshi, Vaibhav and Chowdhury, Abishi and Pal, Amrit and Singh, Vishal Krishna and Rathore, Rajkumar Singh (2026) Real‐Time Anomaly Detection Using Federated Learning in Edge Devices. Software - Practice and Experience. DOI https://doi.org/10.1002/spe.70101
Abstract
Background The widespread expansion of IoT devices has significantly increased the scope for malicious activities on the part of cybercriminals. This has made edge computing highly vulnerable to various types of network intrusions, including DDoS floods and brute‐force attacks. However, traditional centralized Intrusion Detection Systems (IDS) do not address these concerns due to their inherent latency and lack of consideration of data privacy. To overcome these drawbacks of traditional IDS, we have developed a distributed real‐time anomaly detection system architecturally designed for deployment on edge computing hardware Method A monitoring agent collects system and network telemetry and real‐time network flow data on a Raspberry Pi∼3 and sends it to a centralized server via a TCP socket. The server uses a dual‐engine detection system consisting of rule‐based heuristics and a DNN model. To address the concerns of data privacy and non‐IID data distribution inherent to distributed IoT networks, our system uses a collaboratively trained DNN model using three different Federated Learning (FL) techniques: Clustered Federated Learning (CFL), FedDyn, and FedNova. Results These techniques were evaluated on the CIC‐IoT‐DIAD∼2024 dataset with severe non‐IID data distribution. The results show that CFL outperforms others with an F1‐score of 0.89 and an AUC of 0.95. This work shows that production‐grade, privacy‐preserving intrusion detection is feasible in IoT networks at the edge.
| Item Type: | Article |
|---|---|
| Uncontrolled Keywords: | anomaly detection; clustered federated learning (CFL); edge computing; federated learning; intrusion detection system |
| Subjects: | Z Bibliography. Library Science. Information Resources > ZR Rights Retention |
| Divisions: | Faculty of Science and Health Faculty of Science and Health > Computer Science and Electronic Engineering, School of |
| SWORD Depositor: | Unnamed user with email elements@essex.ac.uk |
| Depositing User: | Unnamed user with email elements@essex.ac.uk |
| Date Deposited: | 14 Sep 2026 09:41 |
| Last Modified: | 14 Sep 2026 09:44 |
| URI: | http://repository.essex.ac.uk/id/eprint/43827 |
Available files
Filename: 2nd Revision - Final Copy - WIley.pdf
Licence: Creative Commons: Attribution 4.0