Related Experiment Videos
Improving IoT security through an explainable hybrid CNN-transformer model and federated learning
Aymen M Al-Hejri1,2, Riyadh M Al-Tam3, Archana Harsing Sable4
1Faculty of Administrative and Computer Sciences, University of Albaydha, Albaydha, Yemen. aymen.muslih.alhejri@ar-rasheed.edu.ye.
Scientific Reports
|May 27, 2026
Summary
This study introduces a hybrid CNN-Transformer model with federated learning for privacy-preserving intrusion detection in Internet of Things (IoT) environments. It enhances cybersecurity by accurately identifying threats while maintaining data privacy.
Area of Science:
- Cybersecurity
- Artificial Intelligence
- Network Security
Background:
- Internet of Things (IoT) devices are rapidly increasing, leading to more sophisticated cybersecurity threats against critical infrastructure.
- Current intrusion detection systems (IDS) face challenges with data privacy in centralized models or limited pattern recognition in single-architecture systems.
- Existing methods struggle to simultaneously analyze local spatial patterns and long-range temporal dependencies in network traffic.
Purpose of the Study:
- To propose a novel, explainable, hybrid Convolutional Neural Network (CNN)-Transformer model integrated with federated learning (FL) for privacy-preserving intrusion detection in IoT.
- To address the limitations of existing IDS by enhancing both detection accuracy and data privacy.
- To improve the interpretability and trustworthiness of automated IoT intrusion detection systems.
Main Methods:
- Developed a dual-block CNN-Transformer architecture for comprehensive network traffic analysis.
- Integrated federated learning (FL) with FedAvg aggregation for privacy-preserving collaborative model training.
- Incorporated Local Interpretable Model-Agnostic Explanations (LIME) for transparent, feature-level insights into detection decisions.
- Evaluated the model on the IoT-23 dataset for both binary and multi-class attack classification.
Main Results:
- Achieved 94.89% accuracy in federated binary classification and 92.17% in federated multi-class classification on the IoT-23 dataset.
- Significantly outperformed standalone CNN and ensemble baseline models in intrusion detection tasks.
- Demonstrated model generalizability through an ablation study on the CIC IoT-DIAD 2024 dataset.
- LIME integration provided actionable explanations for real-time security analysis.
Conclusions:
- The proposed hybrid CNN-Transformer model with federated learning offers a robust and privacy-preserving solution for IoT intrusion detection.
- The integration of explainability features (LIME) enhances the trustworthiness and practical utility of the system for security analysts.
- This framework effectively addresses the limitations of traditional IDS, improving both detection performance and data privacy in complex IoT environments.