Research Article

Federated Intrusion Detection for Internet of Medical Things Networks: Differential Privacy, Non-IID Robustness, and Cross-Device Generalization

Authors

Abstract

Internet of Medical Things (IoMT) deployments combine clinically relevant sensing with heterogeneous wireless protocols and resource-constrained devices, creating a difficult setting for centralized intrusion detection. Federated learning can retain network-flow records at participating sites or gateways, but statistical heterogeneity and privacy protection can reduce utility. This study evaluates centralized and federated binary intrusion-detection models on a reproducible 71,326-row sample derived from the WiFi/MQTT portion of CICIoMT2024. After excluding 14,400 profiling-only benign flows, 28,740 training and 28,186 test flows covering 18 attack types and benign traffic were modeled with 44 predictors. Seven non-identically distributed client partitions were generated with a Dirichlet concentration of 0.30 over fine-grained labels; six participated in training and one was withheld from all model fitting. Centralized logistic regression and random forest were compared with FedAvg, FedProx, and record-level differentially private FedProx over five partition seeds. The private mechanism clipped per-record gradients, added Gaussian noise calibrated to replace-one-record sensitivity, and used zero-concentrated differential privacy composition, yielding (ε,δ)=(4.106,10^(-5) ) for 40 local mechanisms per client. Centralized random forest provided the empirical ceiling (mean F1 0.975; 95% CI 0.970–0.979). FedAvg and FedProx achieved mean F1 values of 0.855 and 0.855, respectively, showing no robustness gain from the selected proximal term. Differentially private FedProx achieved mean F1 0.822 (95% CI 0.818–0.826) and held-out-partition F1 0.844 (95% CI 0.797–0.891). In the primary partition, the private model’s F1 was 0.033 lower than FedProx (paired bootstrap 95% CI −0.035 to −0.031; exact McNemar p<10^(-200)); across only five seeds, the paired Wilcoxon test was not significant at 0.05 (p=0.0625). Critically, CICIoMT2024’s released processed table contains no verified physical-device identifier. Therefore, the withheld partition measures cross-partition generalization under synthetic label shift, not validated generalization to a new physical device. The study offers an auditable baseline and identifies device-aware metadata, stronger heterogeneity methods, and operational validation as necessary next steps.

Article information

Journal

Journal of Computer Science and Technology Studies

Volume (Issue)

8 (8)

Pages

303-315

Published

2026-08-10

How to Cite

Mahfuz Islam Khan Jabed, Md Parvez Ahmed, Fardous Mir Tofa, Md Faisal Islam, Clapher Ankur Gomes, & Riad Mahamud Sirazy. (2026). Federated Intrusion Detection for Internet of Medical Things Networks: Differential Privacy, Non-IID Robustness, and Cross-Device Generalization. Journal of Computer Science and Technology Studies, 8(8), 303-315. https://doi.org/10.32996/jcsts.2026.8.8.23

Publication History

  1. Submitted
  2. Published

Peer Review

This article has been peer reviewed.

Downloads

Views

44

Downloads

34

Keywords:

Internet of Medical Things (IoMT), Federated Learning, Intrusion Detection, Differential Privacy, Non-IID Data, Cybersecurity, Privacy-Preserving Machine Learning, Federated Optimization