Arvind Prasad1,*, Ibrahim Aljubayri2, Mohammad Zubair Khan3,*, Abdulfattah Noorwali4
CMES-Computer Modeling in Engineering & Sciences, Vol.147, No.3, 2026, DOI:10.32604/cmes.2026.082021
- 30 June 2026
Abstract Intrusion detection in large-scale IoT deployments becomes particularly challenging during ongoing attack scenarios, where malicious traffic may temporarily dominate benign traffic. In such conditions, streaming network data exhibits severe class imbalance in favor of attack traffic, while device behavior remains heterogeneous, non-identically distributed (non-IID), and temporally evolving. Within federated learning environments, this imbalance can destabilize early aggregation rounds, dominant attack gradients bias the global model, distort decision boundaries, and degrade reliable discrimination of residual benign behavior. Since the server has no access to raw data, these effects can persist across communication rounds if not addressed… More >