Related Experiment Videos
Fed-DTCN: A Federated Disentangled Learning Framework for Unsupervised Zero-Day Anomaly Detection in IoT with
Muhammad Ali Khan1, Osman Khalid1, Rao Naveed Bin Rais2
1Department of Computer Science, COMSATS University Islamabad, Abbottabad Campus, Abbottabad 22060, Pakistan.
Sensors (Basel, Switzerland)
|March 28, 2026
Summary
This study introduces Fed-DTCN, an unsupervised federated learning framework for detecting zero-day cyber threats in Internet of Things (IoT) networks. It effectively identifies novel attacks without prior labels, enhancing IoT security.
Area of Science:
- Cybersecurity
- Machine Learning
- Internet of Things (IoT)
Background:
- The expansion of IoT devices increases network vulnerabilities and privacy concerns, complicating intrusion detection.
- Existing federated intrusion detection methods struggle with data heterogeneity and zero-day attacks due to reliance on labeled data or reconstruction.
Purpose of the Study:
- To propose Fed-DTCN, an unsupervised federated framework for robust zero-day anomaly detection in IoT environments.
- To enhance intrusion detection capabilities by learning representations of benign IoT traffic resistant to statistical heterogeneity.
Main Methods:
- Employs federated learning for collaborative training without raw data centralization.
- Utilizes contrastive learning with semantic-preserving augmentations and a dual-encoder architecture to disentangle shared and specific features.
- Incorporates a temporal convolutional backbone and a soft-weighted contrastive objective for anomaly detection.
Main Results:
- Fed-DTCN achieves high performance on standard attacks, matching a supervised baseline with a 99.99% F1-score on TON_IoT.
- Demonstrates significant effectiveness against zero-day attacks (96% F1-score) when specific attack classes are withheld during training.
- Evaluations show reduced inter-client variance and consistent improvements under heterogeneous conditions.
Conclusions:
- Fed-DTCN offers a privacy-preserving, unsupervised solution for zero-day anomaly detection in heterogeneous IoT environments.
- The framework's ability to generalize and adapt to varying network conditions makes it suitable for real-world IoT deployments.
- Fed-DTCN significantly advances intrusion detection for IoT by addressing limitations of existing federated approaches.