Related Experiment Videos
Structural impact of non-IID heterogeneity on federated behavioral anomaly detection in IoT and IoMT systems
Jorge Robalino-Díaz1, Alejandro Cabrera-Andrade2,3, Sergio Luján-Mora4
1Escuela de Ingeniería en Ciberseguridad, FICA, Universidad de Las Américas, Quito, Ecuador.
Abstract:
The expansion of Internet of Things (IoT) and Internet of Medical Things (IoMT) infrastructures has increased the generation of multivariate sensor streams that reflect complex operational behaviors in industrial and clinical environments. Centralized anomaly detection approaches face limitations in IoMT due to privacy constraints, latency, and device heterogeneity. Federated learning (FL) enables distributed model training without data centralization; however, its behavior under highly non-Independent and Identically Distributed (non-IID) conditions remains insufficiently understood. This study proposes a trace-level behavioral modeling approach combined with federated training via FedAvg to analyze the impact of non-IID heterogeneity on anomaly detection. An Integrated Hybrid Dataset (IHD) comprising 71,980 behavioral traces, with 22,698 used for evaluation, was constructed from Edge-IIoTset, TON_IoT, and IoMT data. The centralized model achieved F 1 = 0.981 and Recall = 0.993, while the federated model preserved discriminative capacity (AUC-ROC = 0.995) but reduced Recall to 0.530. Degradation is concentrated in IoMT (Recall = 0.290), with increased Brier Score and Expected Calibration Error, showing that preserved discrimination does not ensure operational effectiveness.
Related Concept Videos
Steps in Outbreak Investigation
Naturalistic Observations