Privacy-Enhanced Federated Learning Model for Secure Internet of Things Applications: A Systematic Review
DOI:
https://doi.org/10.26740/vubeta.v3i3.46474Keywords:
Edge Intelligence, Cybersecurity, Privacy Enhancing, Internet of Things, Federated LearningAbstract
The rapid expansion of Internet of Things (IoT) ecosystems has intensified security and privacy concerns due to massive volume of sensitive, distributed, and heterogeneous data generated by connected devices. Conventional machine learning approaches for IoT security are increasingly becoming unsuitable because they require raw data aggregation, leading to privacy risks, scalability issues, and regulatory challenges. This study adopts a systematic literature review to examine recent advancements in privacy-enhanced federated learning (PEFL) for secure IoT. Relevant peer-reviewed journal articles and conference papers were identified, screened, and analyzed to investigate FL architectures, optimization techniques, privacy-preserving mechanisms, and cybersecurity applications within heterogeneous IoT environments. A structured taxonomy is developed to classify existing approaches, identify prevailing research trends. It reveals that federated learning significantly reduces data exposure risks by keeping sensitive IoT data localized at edge devices. Privacy-enhancing techniques such as differential privacy, secure aggregation, and cryptographic methods improve confidentiality but often introduce trade-offs in model accuracy and communication efficiency. Hierarchical and adaptive FL architectures demonstrate improved scalability and robustness in large-scale IoT networks. FL-based intrusion detection systems show strong potential for distributed anomaly detection while preserving data privacy. However, performance degradation due to non-IID data and system heterogeneity remains a persistent challenge. Resource constraints on edge devices limit the adoption of complex privacy-preserving techniques. Experimental evaluations are predominantly simulation-based, with limited real-world deployments. The absenceof standardized benchmarks further complicates cross-study comparisons. PEFL represents a promising foundation for secure IoT systems, but further research is required toaddress practical deployment challenges and enhance real-world applicability.
References
[1] M. Abadi, A. Agarwal, P. Barham, E. Brevdo, Z. Chen, C. Citro, et al., “TensorFlow: Large-scale machine learning on heterogeneous systems,” in Proc. 12th USENIX Symp. Operating Systems Design and Implementation (OSDI), 2016.
[2] N. Abbas, Y. Zhang, A. Taherkordi, and T. Skeie, “Mobile edge computing: A survey,” IEEE Internet Things J., vol. 9, no. 1, pp. 1400–1421, 2022, doi: 10.1109/JIOT.2021.3097904.
[3] S. R. Abbas, Z. Abbas, A. Zahir, and S. W. Lee, “Federated learning in smart healthcare: A comprehensive review on privacy, security, and predictive analytics with IoT integration,” Healthcare, vol. 12, no. 24, p. 2587, 2025, doi: 10.3390/healthcare12242587.
[4] M. Ajuji, M. Dawaki, A. Mohammed, and A. Ahmad, “Estimating residential natural gas demand and consumption: A hybrid ensemble machine learning approach,” Vokasi Unesa Bulletin of Engineering, Technology and Applied Science, vol. 2, no. 3, pp. 549–557, 2025.
[5] M. N. Alatawi, “SAFEL-IoT: Secure adaptive federated learning with explainability for anomaly detection in 6G-enabled smart industry 5.0,” Electronics, vol. 14, no. 11, p. 2153, 2025, doi: 10.3390/electronics14112153.
[6] A. Alazab, A. Khraisat, S. Singh, and T. Jan, “Enhancing privacy-preserving intrusion detection through federated learning,” Electronics, vol. 12, no. 16, p. 3382, 2023, doi: 10.3390/electronics12163382.
[7] A. Al-Fuqaha, M. Guizani, M. Mohammadi, M. Aledhari, and M. Ayyash, “Internet of Things: A survey on enabling technologies, protocols, and applications,” IEEE Commun. Surv. Tutor., vol. 17, no. 4, pp. 2347–2376, 2015, doi: 10.1109/COMST.2015.2444095.
[8] E. Bagdasaryan, A. Veit, Y. Hua, D. Estrin, and V. Shmatikov, “How to backdoor federated learning,” in Proc. Int. Conf. Artif. Intell. Stat. (AISTATS), 2020.
[9] D. Bankov, E. Khorov, and A. Lyakhov, “On the limits of LoRaWAN channel access,” in Proc. Int. Conf. Eng. Telecommun. (EnT), pp. 10–14, 2018, doi: 10.1109/EnT.2016.011.
[10] E. M. Campos et al., “Evaluating federated learning for intrusion detection in Internet of Things: Review and challenges,” Comput. Netw., vol. 203, p. 108661, 2022.
[11] T. Chen and C. Guestrin, “XGBoost: A scalable tree boosting system,” in Proc. ACM SIGKDD Int. Conf. Knowl. Discov. Data Min., pp. 785–794, 2016, doi: 10.1145/2939672.2939785.
[12] X. Chen et al., “Trustworthy federated learning: Privacy, security, and beyond,” Knowl. Inf. Syst., early access, 2024, doi: 10.1007/s10115-024-02285-2.
[13] Cisco, “Annual Internet Report,” 2023. [Online]. Available: Cisco. Accessed: May 12, 2025.
[14] J. W. Creswell and J. D. Creswell, Research Design: Qualitative, Quantitative, and Mixed Methods Approaches, 5th ed. Thousand Oaks, CA, USA: SAGE, 2018.
[15] J. W. Creswell and V. L. Plano Clark, Designing and Conducting Mixed Methods Research, 3rd ed. Thousand Oaks, CA, USA: SAGE, 2017.
[16] S. García, M. Grill, J. Stiborek, and A. Zunino, “An empirical comparison of botnet detection methods,” Comput. Secur., vol. 45, pp. 100–123, 2014, doi: 10.1016/j.cose.2014.05.011.
[17] R. C. Geyer, T. Klein, and M. Nabi, “Differentially private federated learning: A client-level perspective,” arXiv preprint arXiv:1712.07557, 2017.
[18] R. Gosselin et al., “Privacy and security in federated learning: A survey,” Appl. Sci., vol. 12, no. 19, p. 9901, 2022, doi: 10.3390/app12199901.
[19] C. He et al., “FedML: A research library and benchmark for federated machine learning,” arXiv preprint arXiv:2007.13518, 2020.
[20] S. Hochreiter and J. Schmidhuber, “Long short-term memory,” Neural Comput., vol. 9, no. 8, pp. 1735–1780, 1997, doi: 10.1162/neco.1997.9.8.1735.
[21] H. B. McMahan, E. Moore, D. Ramage, S. Hampson, and B. A. y Arcas, “Communication-efficient learning of deep networks from decentralized data,” in Proc. 20th Int. Conf. Artificial Intelligence and Statistics (AISTATS), 2017, pp. 1273–1282.
[22] P. Kairouz, H. B. McMahan, B. Avent, A. Bellet, M. Bennis, A. N. Bhagoji, et al., “Advances and open problems in federated learning,” Foundations and Trends® in Machine Learning, vol. 14, no. 1–2, pp. 1–210, 2021, doi: 10.1561/2200000083.
[23] N. Koroniotis et al., “Towards the development of realistic botnet dataset in the Internet of Things,” Future Gener. Comput. Syst., vol. 100, pp. 779–796, 2019, doi: 10.1016/j.future.2019.05.041.
[24] T. Li, A. K. Sahu, A. Talwalkar, and V. Smith, “Federated learning: Challenges, methods, and future directions,” IEEE Signal Process. Mag., vol. 37, no. 3, pp. 50–60, 2020, doi: 10.1109/MSP.2020.2975749.
[25] N. Moustafa and J. Slay, “UNSW-NB15: A comprehensive data set for network intrusion detection systems,” in Proc. Mil. Commun. Inf. Syst. Conf. (MilCIS), pp. 1–6, 2015, doi: 10.1109/MilCIS.2015.7348942.
[26] D. C. Nguyen et al., “Federated learning for Internet of Things: A comprehensive survey,” IEEE Commun. Surv. Tutor., vol. 23, no. 3, pp. 1622–1658, 2021, doi: 10.1109/COMST.2021.3075439.
[27] A. Paszke et al., “PyTorch: An imperative style, high-performance deep learning library,” in Adv. Neural Inf. Process. Syst., vol. 32, pp. 8026–8037, 2019.
[28] F. Pedregosa et al., “Scikit-learn: Machine learning in Python,” J. Mach. Learn. Res., vol. 12, pp. 2825–2830, 2011.
[29] I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, “Toward generating a new intrusion detection dataset,” in Proc. ICISSP, pp. 108–116, 2018, doi: 10.5220/0006639801080116.
[30] H. Zhu, J. Xu, S. Liu, and Y. Jin, “Federated learning on non-IID data: A survey,” Neurocomputing, vol. 465, pp. 371–390, 2021, doi: 10.1016/j.neucom.2021.01.119.
[31] K. Peng, M. Li, H. Huang, C. Wang, S. Wan, and K. K. R. Choo, “Security challenges and opportunities for smart contracts in Internet of Things: A survey,” IEEE Internet Things J., vol. 8, no. 15, pp. 12004–12020, 2021.
[32] G. F. Riley and T. R. Henderson, “The ns-3 network simulator,” in Modeling and Tools for Network Simulation. Berlin, Germany: Springer, pp. 15–34, 2010, doi: 10.1007/978-3-642-12331-3_2.
[33] P. Ruzafa-Alcázar et al., “Intrusion detection based on privacy-preserving federated IDS using differential privacy,” IEEE Access, vol. 10, pp. 62098–62113, 2022, doi: 10.1109/ACCESS.2022.3178054.
[34] T. Ryffel et al., “A generic framework for privacy-preserving deep learning,” J. Mach. Learn. Res., vol. 21, no. 1, pp. 1–46, 2020.
[35] M. Sarhan, W. W. Lo, S. Layeghy, and M. Portmann, “HBFL: A hierarchical blockchain-based federated learning framework for collaborative IoT intrusion detection,” Comput. Electr. Eng., vol. 103, p. 108379, 2022.
[36] J. Shen et al., “Effective intrusion detection in heterogeneous Internet-of-Things networks via ensemble knowledge distillation-based federated learning,” arXiv preprint arXiv:2401.11968, 2024.
[37] A. Shostack, Threat Modeling: Designing for Security. Hoboken, NJ, USA: Wiley, 2014.
[38] B. Shubyn et al., “Resource consumption of federated learning approach applied on edge IoT devices in the AGV environment,” in Proc. Int. Conf. Comput. Sci. (ICCS), 2023, doi: 10.1007/978-3-031-36030-5_39.
[39] S. Sicari, A. Rizzardi, L. A. Grieco, and A. Coen-Porisini, “Security, privacy and trust in IoT: Challenges and solutions,” Comput. Netw., vol. 190, p. 107859, 2022, doi: 10.1016/j.comnet.2021.107859.
[40] H. Tabrizchi and M. Aghasi, “Cyber security intelligent systems based on federated learning,” in Adv. Multimedia and Ubiquitous Engineering: FutureTech 2024, C. Figueroa, T. H. Kim, and K. Choo, Eds. Singapore: Springer, pp. 33–43, 2024, doi: 10.1007/978-3-031-86592-3_4.
[41] M. Tavallaee, E. Bagheri, W. Lu, and A. A. Ghorbani, “A detailed analysis of the KDD CUP 99 data set,” in Proc. IEEE Symp. Comput. Intell. Secur. Def. Appl., pp. 1–6, 2009, doi: 10.1109/CISDA.2009.5356528.
[42] A. Vyas, P.-C. Lin, R.-H. Hwang, and M. Tripathi, “Privacy-preserving federated learning for intrusion detection in IoT environments: A survey,” IEEE Access, vol. 12, pp. 127018–127050, 2024, doi: 10.1109/ACCESS.2024.3454211.
[43] T. Xie, J. Liu, C. Zhang, and M. Chen, “Adaptive federated learning for heterogeneous IoT environments: A survey,” IEEE Internet Things J., vol. 10, no. 5, pp. 3212–3228, 2023, doi: 10.1109/JIOT.2022.3194719.
[44] Y. Zhang, R. Yu, and S. Xie, “Privacy-preserving machine learning for healthcare: A survey,” IEEE Trans. Ind. Informatics, vol. 17, no. 6, pp. 3772–3784, 2021.
[45] R. Zhao, H. Chen, Y. Li, Y. Yin, J. Xu, Z. Xu, and Q. Yang, “Federated learning with non-IID data in edge computing: A survey,” IEEE Internet of Things Journal, vol. 8, no. 6, pp. 4475–4497, Mar. 2021, doi: 10.1109/JIOT.2020.3033424.
[46] H. Zhu, J. Xu, S. Liu, and Y. Jin, “Federated learning on non-IID data: A survey,” Neurocomputing, vol. 465, pp. 371–390, 2021, doi: 10.1016/j.neucom.2021.01.119.
[47] A. G. Howard et al., “MobileNets: Efficient convolutional neural networks for mobile vision applications,” arXiv preprint arXiv:1704.04861, 2017.
[48] X. Huang, J. Liu, Y. Lai, B. Mao, and H. Lyu, “EEFED: Personalized federated learning of execution and evaluation dual network for CPS intrusion detection,” IEEE Trans. Inf. Forensics Secur., 2023, doi: 10.1109/TIFS.2023.3327481.
[49] G. Ke et al., “LightGBM: A highly efficient gradient boosting decision tree,” in Adv. Neural Inf. Process. Syst. (NeurIPS), vol. 30, pp. 3146–3154, 2017.
[50] L. U. Khan, W. Saad, Z. Han, E. Hossain, and C. S. Hong, “Federated learning for Internet of Things: Recent advances, taxonomy, and open challenges,” arXiv preprint arXiv:2009.13012, 2020.
[51] L. Lyu, H. Yu, and Q. Yang, “Towards fair and privacy-preserving federated deep models,” IEEE Trans. Mobile Comput., vol. 21, no. 3, pp. 838–851, 2022, doi: 10.1109/TMC.2020.2981310.
[52] S. A. Mahmud, N. Islam, Z. Islam, Z. Rahman, and S. T. Mehedi, “Privacy-preserving federated learning-based intrusion detection technique for cyber-physical systems,” Mathematics, vol. 12, no. 20, p. 3194, 2024.
[53] H. U. Manzoor, A. Shabbir, A. Chen, D. Flynn, and A. Zoha, “A survey of security strategies in federated learning: Defending models, data, and privacy,” Future Internet, vol. 16, no. 10, p. 374, 2024, doi: 10.3390/fi16100374.
[54] T. M. Mengistu, T. Kim, and J.-W. Lin, “A survey on heterogeneity taxonomy, security, and privacy preservation in the integration of IoT, wireless sensor networks, and federated learning,” Sensors, vol. 24, no. 3, p. 968, 2024, doi: 10.3390/s24030968.
[55] MITRE, “MITRE ATT&CK: Adversarial tactics, techniques, and common knowledge,” 2023. [Online]. Available: https://attack.mitre.org/
[56] F. Mosaiyebzadeh et al., “Privacy-enhancing technologies in federated learning for the Internet of Healthcare Things: A survey,” Electronics, vol. 12, no. 12, p. 2703, 2023, doi: 10.3390/electronics12122703.
[57] N. Moustafa, “A new distributed architecture for evaluating AI-based security systems at the edge: Network TON_IoT datasets,” Sustain. Cities Soc., vol. 72, p. 102994, 2021, doi: 10.1016/j.scs.2021.102994.
[58] N. Naik, “Choice of effective messaging protocols for IoT systems: MQTT, CoAP, AMQP and HTTP,” in Proc. IEEE Int. Syst. Eng. Symp. (ISSE), pp. 1–7, 2017, doi: 10.1109/SysEng.2017.8088251.
[59] D. C. Nguyen, M. Ding, P. N. Pathirana, and A. Seneviratne, “Federated learning for smart cities: Recent advances and applications,” IEEE Commun. Surv. Tutor., vol. 25, no. 1, pp. 734–766, 2023.
[60] R. Ryffel et al., “A generic framework for privacy-preserving deep learning,” J. Mach. Learn. Res., vol. 21, no. 1, pp. 1–46, 2020.
[61] J. Zhang, R. Yu, and S. Xie, “Privacy-preserving machine learning for healthcare: A survey,” IEEE Trans. Ind. Informatics, vol. 17, no. 6, pp. 3772–3784, 2021.
[62] H. Zhu, J. Xu, S. Liu, and Y. Jin, “Federated learning on non-IID data: A survey,” Neurocomputing, vol. 465, pp. 371–390, 2021, doi: 10.1016/j.neucom.2021.01.119.
[63] D. Bestari and A. Wibowo, "IoT Based Real-Time Weather Monitoring System Using Telegram Bot and Thingsboard Platform", International Journal of Interactive Mobile Technologies (iJIM), vol. 17, no. 06, pp. 4-19, 2023. https://doi.org/10.3991/ijim.v17i06.34129
[64] R. D. Handayani, Z. Jamal, M. Alkahfiansyah, L. Rosmalia, N. H Sudibyo, and R. Herwanto, “Intelligent and Secure Package Receiver System Utilizing Internet of Things (IoT) Technology”, Vokasi Unesa Bull. Eng. Technol. Appl. Sci., vol. 2, no. 3, pp. 581–592, Sep. 2025.
[65] M. M. Mansour, A. M. lafta, A. M. Salman, and H. S. Salman, “Exploring the Impact of AI and IoT on Production Efficiency, Quality Precision, and Environmental Sustainability in Manufacturing”, Vokasi Unesa Bull. Eng. Technol. Appl. Sci., vol. 2, no. 2, pp. 342–355, Jun. 2025.
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Mohammed Ajuji, Yusuf Musa Malgwi, Asabe Sandra Ahmadu, Mustapha Ismail

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Abstract views: 0





