Open Access iconOpen Access

ARTICLE

Resilient Federated Ensemble Learning for IoT Intrusion Detection in Adversarial and Imbalanced Environments

Arvind Prasad1,*, Ibrahim Aljubayri2, Mohammad Zubair Khan3,*, Abdulfattah Noorwali4

1 Department of Computer Engineering & Applications, GLA University, Mathura, India
2 Department of Computer Science and Information, Imam Mohammad Ibn Saud Islamic University (IMSIU), Riyadh, Saudi Arabia
3 Faculty of Computer and Information Systems, Islamic University of Madinah, Medina, Saudi Arabia
4 Electrical Engineering Department, Umm Al-Qura University, Makkah, Saudi Arabia

* Corresponding Authors: Arvind Prasad. Email: email; Mohammad Zubair Khan. Email: email

(This article belongs to the Special Issue: Emerging Technologies in Information Security: Modeling, Algorithms, and Applications)

Computer Modeling in Engineering & Sciences 2026, 147(3), 48 https://doi.org/10.32604/cmes.2026.082021

Abstract

Intrusion detection in large-scale IoT deployments becomes particularly challenging during ongoing attack scenarios, where malicious traffic may temporarily dominate benign traffic. In such conditions, streaming network data exhibits severe class imbalance in favor of attack traffic, while device behavior remains heterogeneous, non-identically distributed (non-IID), and temporally evolving. Within federated learning environments, this imbalance can destabilize early aggregation rounds, dominant attack gradients bias the global model, distort decision boundaries, and degrade reliable discrimination of residual benign behavior. Since the server has no access to raw data, these effects can persist across communication rounds if not addressed at initialization. This article addresses the problem of distributed intrusion detection in streaming IoT networks under severe class imbalance and partial adversarial behavior. In ongoing attack scenarios, malicious traffic may dominate streaming observations, creating an inverted imbalance where benign behavior becomes underrepresented. To mitigate these issues, we propose a resilient federated ensemble framework with three key components: a similarity-guided balancing phase that selects a structurally diverse subset of majority-class samples to form a balanced initialization dataset, an incremental ensemble composed of Bernoulli Naïve Bayes, Passive–Aggressive, and SGD classifiers for pre-training over this data to produce a warm-start global model, and an accuracy-gating mechanism that accepts only performance-preserving local updates during online training. The proposed approach is evaluated on flow-level data from the CICIoT2023 benchmark that demonstrated stable client-wise convergence with high accuracy and consistent minority-class discrimination, even under skewed attack-dominant distributions. Under complete label-flipping poisoning, corrupted updates are systematically rejected, preventing global degradation. Ablation analysis confirms that removing structured initialization significantly increases early instability. The results indicate that balanced global conditioning and selective federation are critical for maintaining detection reliability in streaming IoT systems operating under sustained attack conditions.

Keywords

Federated learning; IoT intrusion detection; streaming analytics; class imbalance; adversarial robustness

Cite This Article

APA Style
Prasad, A., Aljubayri, I., Khan, M.Z., Noorwali, A. (2026). Resilient Federated Ensemble Learning for IoT Intrusion Detection in Adversarial and Imbalanced Environments. Computer Modeling in Engineering & Sciences, 147(3), 48. https://doi.org/10.32604/cmes.2026.082021
Vancouver Style
Prasad A, Aljubayri I, Khan MZ, Noorwali A. Resilient Federated Ensemble Learning for IoT Intrusion Detection in Adversarial and Imbalanced Environments. Comput Model Eng Sci. 2026;147(3):48. https://doi.org/10.32604/cmes.2026.082021
IEEE Style
A. Prasad, I. Aljubayri, M. Z. Khan, and A. Noorwali, “Resilient Federated Ensemble Learning for IoT Intrusion Detection in Adversarial and Imbalanced Environments,” Comput. Model. Eng. Sci., vol. 147, no. 3, pp. 48, 2026. https://doi.org/10.32604/cmes.2026.082021



cc Copyright © 2026 The Author(s). Published by Tech Science Press.
This work is licensed under a Creative Commons Attribution 4.0 International License , which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.
  • 283

    View

  • 67

    Download

  • 0

    Like

Share Link