A secure authentication protocol for detecting intrusions in IoT traffic data streams using federated learning
摘要
The large-scale deployment of the Internet of Things (IoT) is expected to increase the diversity and frequency of security attacks. The rapid growth of heterogeneous, resource-constrained IoT devices creates new opportunities for attackers to compromise network security. Although many studies address specific aspects of IoT security, a comprehensive and integrated solution remains lacking. The paper presents a secure and scalable Federated Learning (FL)–based architecture with a lightweight authentication protocol to enable collaborative learning from distributed IoT data streams. Device and data security are ensured using an authentication mechanism based on the Edwards-Curve Digital Signature Algorithm (EdDSA) and the Secure Hash Algorithm (SHA-256). A thorough security analysis of the proposed method is conducted. To support real-time learning, a federated version of the Hoeffding tree algorithm is developed for secure IoT data streams. The proposed framework is evaluated using diverse IoT intrusion detection datasets and compared with FedAvg, Fed+, and FedStream algorithms. Experimental results demonstrate that the proposed approach achieves higher accuracy and stability than Fed+ and FedStream in large-scale IoT environments, while maintaining performance comparable to FedAvg. These findings highlight the potential of the proposed framework for developing robust and scalable IoT intrusion detection solutions.