Related Experiment Videos
A crowdsensing intrusion detection dataset for decentralized federated learning models.
Chao Feng1, Alberto Huertas Celdrán2,3, Jing Han2
1Communication Systems Group, Department of Informatics, University of Zurich, 8050, Zürich, Switzerland. cfeng@ifi.uzh.ch.
Scientific Data
|April 3, 2026
Summary
Decentralized Federated Learning (DFL) enhances Internet of Things (IoT) crowdsensing malware detection by preserving data locality. DFL outperforms Centralized Federated Learning (CFL) in most scenarios, offering competitive performance.
Area of Science:
- Cybersecurity
- Machine Learning
- Internet of Things (IoT)
Background:
- IoT crowdsensing environments generate vast amounts of behavioral data.
- Malware detection in IoT is crucial due to increasing cyber threats.
- Existing methods may compromise data privacy or incur high communication costs.
Purpose of the Study:
- Introduce a novel dataset for IoT crowdsensing malware detection.
- Evaluate Decentralized Federated Learning (DFL) performance against traditional ML and CFL.
- Assess DFL's effectiveness in preserving data locality and security.
Main Methods:
- Collected 21,582,484 records from diverse IoT sources (system calls, network, etc.).
- Aggregated data into 30-second windows, creating 342,106 training/evaluation records.
- Conducted experiments comparing ML, CFL, and DFL under various conditions.
Main Results:
- DFL demonstrated competitive performance in malware detection.
- DFL outperformed CFL in most experimental settings.
- DFL effectively preserved data locality, a key advantage for privacy.
Conclusions:
- The developed dataset is valuable for IoT security research.
- DFL presents a promising approach for secure and efficient IoT malware detection.
- DFL offers a viable alternative to CFL, especially when data locality is paramount.