The F-ELV-Based Privacy-Preserving Framework for Intrusion Detection in SDN-IoT Network

Citation

Kamaruddin, Abdullah and Tan, Saw Chin and Galan-Jimenez, Jaime and Awan, Irfan Ullah and Younas, Muhammad (2026) The F-ELV-Based Privacy-Preserving Framework for Intrusion Detection in SDN-IoT Network. IEEE Access, 14. pp. 92671-92696. ISSN 2169-3536

[img] Text
11563315.pdf - Published Version
Restricted to Repository staff only

Download (2MB)

Abstract

Network intrusion detection in Software-Defined Networking (SDN)-enabled Internet of Things (IoT) increasingly relies on machine learning techniques. However, existing federated learning solutions predominantly focus on deep learning. This approach is impractical for resource-constrained SDN-IoT networks. No prior Federated Learning (FL) frameworks systematically federate classical machine learning models with algorithm-specific aggregation. Classical algorithms are better suited to such networks because they are lightweight, computationally efficient, and easier to interpret. This paper presents a novel Federated Enhanced Learning Voting (F-ELV) framework that enablesresource-efficient and accurate intrusion detection by federating heterogeneous classical machine learning algorithms. The F-ELV framework introduces strategies tailored dynamically to each model type, including Decision Trees, Naive Bayes, K-Nearest Neighbors (KNN), Logistic Regression, and ensemble methods. We implement stratified federated data distribution to ensure balanced class representation across clients. This prevents model bias and maintains detection accuracy for minority attack classes. A comprehensive evaluation across three cybersecurity datasets demonstrates that F-ELV outperforms centralized and standard federated learning approaches. It preserves privacy and computational efficiency. Detection accuracies range from 79% to 100% across different algorithms and datasets, with minimal federated learning degradation (0.1–6.45%) for tree-based methods. F-ELV also provides an empirical framework for evaluating training and detection times in federated cybersecurity environments. Its design and evaluation highlight strong potential for real-time deployment within SDN-IoT intrusion detection systems.

Item Type: Article
Uncontrolled Keywords: Federated learning
Subjects: L Education > LB Theory and practice of education > LB1060 Learning
Divisions: Faculty of Computing and Informatics (FCI)
Depositing User: Ms Rosnani Abd Wahab
Date Deposited: 31 Jul 2026 05:52
Last Modified: 31 Jul 2026 05:52
URII: http://shdl.mmu.edu.my/id/eprint/16404

Downloads

Downloads per month over past year

View ItemEdit (login required)