FedP3E: Privacy-Preserving Prototype Exchange for Non-IID IoT Malware Detection in Cross-Silo Federated Learning

Darwish, Rami, Abdelsalam, Mahmoud, Khorsandroo, Sajad, Roy, Kaushik

arXiv.org Artificial Intelligence 

--As IoT ecosystems continue to expand across critical sectors, they have become prominent targets for increasingly sophisticated and large-scale malware attacks. The evolving threat landscape, combined with the sensitive nature of IoT - generated data, demands detection frameworks that are both privacy-preserving and resilient to data heterogeneity. Federated Learning (FL) offers a promising solution by enabling decentralized model training without exposing raw data. However, standard FL algorithms such as FedA vg and FedProx often fall short in real-world deployments characterized by class imbalance and non-IID data distributions--particularly in the presence of rare or disjoint malware classes. T o address these challenges, we propose FedP3E (Privacy-Preserving Prototype Exchange), a novel FL framework that supports indirect cross-client representation sharing while maintaining data privacy. The aggregated prototypes are then distributed back to clients and integrated into local training, supported by SMOTE-based augmentation to enhance representation of minority malware classes. Rather than relying solely on parameter averaging, our prototype-driven mechanism enables clients to enrich their local models with complementary structural patterns observed across the federation--without exchanging raw data or gradients. This targeted strategy reduces the adverse impact of statistical heterogeneity with minimal communication overhead. We evaluate FedP3E on the N-BaIoT dataset under realistic cross-silo scenarios with varying degrees of data imbalance. Results demonstrate that FedP3E consistently surpasses FedA vg and FedProx in malware detection performance, achieving accuracy ranging from 95.11% in severe non-IID conditions to 99.57% under light heterogeneity. HE rapid advancement of 5G and the anticipated deployment of Beyond 5G (B5G) technologies are driving the proliferation of IoT devices at an unprecedented scale [1]. This hyper-connectivity is enabling new capabilities across healthcare, transportation, industry, and military sectors--collectively referred to as the Extended IoT (XIoT) [2]. However, the expansion of these networks has also introduced a significantly larger attack surface, accelerating both the frequency and severity of cyber threats targeting IoT ecosystems.

Duplicate Docs Excel Report

Title
None found

Similar Docs  Excel Report  more

TitleSimilaritySource
None found