Related Experiment Videos
Federated ConvNeXt-swin temporal fusion network for malware and botnet detection in IoT systems
Faisal S Alsubaei1, Abdulwahab Ali Almazroi2, Nasir Ayub3
1Department of Cybersecurity, College of Computer Science and Engineering, University of Jeddah, Jeddah, 21959, Saudi Arabia. fsalsubaei@uj.edu.sa.
Scientific Reports
|June 8, 2026
Summary
This study introduces a Federated ConvNeXt-Swin Temporal Fusion Network (F-CSTFNet) for detecting Internet of Things (IoT) malware and botnets. The framework offers a scalable, privacy-preserving solution for enhanced IoT security.
Area of Science:
- Cybersecurity
- Machine Learning
- Network Security
Background:
- Internet of Things (IoT) devices face increasing malware and botnet threats.
- Centralized intrusion detection systems are inadequate for decentralized, privacy-sensitive IoT environments.
- Scalability and robustness challenges hinder current IoT security measures.
Purpose of the Study:
- To propose a novel federated deep learning framework for distributed IoT malware and botnet detection.
- To enhance the detection of both short-term anomalies and evolving attack dynamics in IoT network flows.
- To ensure privacy-preserving and robust intrusion detection in heterogeneous IoT ecosystems.
Main Methods:
- Developed the Federated ConvNeXt-Swin Temporal Fusion Network (F-CSTFNet) integrating ConvNeXt and Swin Transformer.
- Employed a hybrid convolution-attention design for capturing local and long-range network traffic patterns.
- Utilized a federated learning paradigm for collaborative model training without raw data sharing.
- Incorporated a channel-adaptive feature recalibration mechanism for improved robustness.
Main Results:
- F-CSTFNet demonstrated superior performance over state-of-the-art baselines on IoT-23 and N-BaIoT datasets.
- Achieved high detection accuracy, stable convergence, and excellent client-level fairness (high JFI).
- Exhibited low performance variance across clients, indicating resilience and fairness in distributed training.
Conclusions:
- The proposed F-CSTFNet is an effective, scalable, and privacy-preserving intrusion detection framework for IoT security.
- The hybrid architecture successfully addresses challenges in detecting diverse and evolving cyber threats in IoT.
- Federated learning enhances the robustness and fairness of distributed IoT malware and botnet detection systems.