FedP3E: Privacy-Preserving Prototype Exchange for Non-IID IoT Malware Detection in Cross-Silo Federated Learning
Darwish, Rami, Abdelsalam, Mahmoud, Khorsandroo, Sajad, Roy, Kaushik
–arXiv.org Artificial Intelligence
--As IoT ecosystems continue to expand across critical sectors, they have become prominent targets for increasingly sophisticated and large-scale malware attacks. The evolving threat landscape, combined with the sensitive nature of IoT - generated data, demands detection frameworks that are both privacy-preserving and resilient to data heterogeneity. Federated Learning (FL) offers a promising solution by enabling decentralized model training without exposing raw data. However, standard FL algorithms such as FedA vg and FedProx often fall short in real-world deployments characterized by class imbalance and non-IID data distributions--particularly in the presence of rare or disjoint malware classes. T o address these challenges, we propose FedP3E (Privacy-Preserving Prototype Exchange), a novel FL framework that supports indirect cross-client representation sharing while maintaining data privacy. The aggregated prototypes are then distributed back to clients and integrated into local training, supported by SMOTE-based augmentation to enhance representation of minority malware classes. Rather than relying solely on parameter averaging, our prototype-driven mechanism enables clients to enrich their local models with complementary structural patterns observed across the federation--without exchanging raw data or gradients. This targeted strategy reduces the adverse impact of statistical heterogeneity with minimal communication overhead. We evaluate FedP3E on the N-BaIoT dataset under realistic cross-silo scenarios with varying degrees of data imbalance. Results demonstrate that FedP3E consistently surpasses FedA vg and FedProx in malware detection performance, achieving accuracy ranging from 95.11% in severe non-IID conditions to 99.57% under light heterogeneity. HE rapid advancement of 5G and the anticipated deployment of Beyond 5G (B5G) technologies are driving the proliferation of IoT devices at an unprecedented scale [1]. This hyper-connectivity is enabling new capabilities across healthcare, transportation, industry, and military sectors--collectively referred to as the Extended IoT (XIoT) [2]. However, the expansion of these networks has also introduced a significantly larger attack surface, accelerating both the frequency and severity of cyber threats targeting IoT ecosystems.
arXiv.org Artificial Intelligence
Jul-11-2025
- Genre:
- Research Report > New Finding (0.88)
- Industry:
- Information Technology > Security & Privacy (1.00)
- Technology:
- Information Technology
- Security & Privacy (1.00)
- Communications > Networks (1.00)
- Data Science > Data Mining
- Big Data (0.91)
- Artificial Intelligence > Machine Learning
- Statistical Learning (1.00)
- Neural Networks (1.00)
- Information Technology