<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>cross-device cyberattack detection in IoT &#8211; Science</title>
	<atom:link href="https://scienmag.com/tag/cross-device-cyberattack-detection-in-iot/feed/" rel="self" type="application/rss+xml" />
	<link>https://scienmag.com</link>
	<description></description>
	<lastBuildDate>Sun, 04 Oct 2026 10:04:09 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.2</generator>

<image>
	<url>https://scienmag.com/wp-content/uploads/2024/07/cropped-scienmag_ico-32x32.jpg</url>
	<title>cross-device cyberattack detection in IoT &#8211; Science</title>
	<link>https://scienmag.com</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">73899611</site>	<item>
		<title>Federated AI Learns to Spot IoT Cyberattacks Without Sharing Private Data</title>
		<link>https://scienmag.com/federated-ai-learns-to-spot-iot-cyberattacks-without-sharing-private-data/</link>
		
		<dc:creator><![CDATA[Veronica Carney]]></dc:creator>
		<pubDate>Sun, 04 Oct 2026 10:04:09 +0000</pubDate>
				<category><![CDATA[Technology and Engineering]]></category>
		<category><![CDATA[collaborative AI models for IoT device protection]]></category>
		<category><![CDATA[contrastive learning]]></category>
		<category><![CDATA[cross-device cyberattack detection in IoT]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[decentralized intrusion detection systems]]></category>
		<category><![CDATA[distributed machine learning for healthcare and home IoT security]]></category>
		<category><![CDATA[extreme value theory]]></category>
		<category><![CDATA[Federated AI for IoT cybersecurity]]></category>
		<category><![CDATA[federated AI frameworks for industrial IoT security]]></category>
		<category><![CDATA[federated learning]]></category>
		<category><![CDATA[federated learning for heterogeneous Io]]></category>
		<category><![CDATA[federated learning in smart city security]]></category>
		<category><![CDATA[Few-shot learning]]></category>
		<category><![CDATA[intrusion detection]]></category>
		<category><![CDATA[IoT network traffic anomaly detection]]></category>
		<category><![CDATA[IoT security]]></category>
		<category><![CDATA[non-IID data]]></category>
		<category><![CDATA[non-IID data challenges in IoT cybersecurity]]></category>
		<category><![CDATA[open-set recognition]]></category>
		<category><![CDATA[privacy-aware intrusion detection in connected devices]]></category>
		<category><![CDATA[privacy-preserving machine learning for IoT]]></category>
		<category><![CDATA[prototypical networks]]></category>
		<category><![CDATA[smart cities]]></category>
		<category><![CDATA[zero-day attacks]]></category>
		<guid isPermaLink="false">https://scienmag.com/?p=234582</guid>

					<description><![CDATA[A new federated learning framework called FedCAMP-IDS detects known and zero-day cyberattacks across heterogeneous IoT networks with up to 99.16 percent accuracy while keeping all training data on local devices.]]></description>
										<content:encoded><![CDATA[<p>Researchers in India and Taiwan have unveiled a new artificial intelligence framework that can detect cyberattacks across sprawling networks of Internet of Things devices while keeping the underlying data locked away on each device. The system, called FedCAMP-IDS, was described in a study published in the journal Cluster Computing by Amrendra Singh Yadav of ABV-Indian Institute of Information Technology and Management Gwalior, Vijayant Pawar of Bennett University, and Roshni Yadav of National Chung Hsing University. Their work tackles one of the most stubborn problems in modern cybersecurity: how to train a single, powerful intrusion detection model when the devices that need protection are wildly different from one another, generate non-uniform traffic, and cannot legally or practically pool their data in one place.</p>
<p>The challenge the team set out to solve is rooted in the architecture of the Internet of Things itself. Smart cities, factories, hospitals, and homes now host billions of connected sensors, cameras, controllers, and industrial instruments, each producing its own distinctive stream of network traffic. A security model trained on data from one site often fails dismally when deployed at another, because the statistical distribution of traffic differs from client to client. Machine learning researchers call this non-independent and non-identically distributed data, or non-IID data for short, and it is the bane of federated learning, the technique in which many devices collaboratively train a shared model by exchanging only model updates rather than raw records. Centralized intrusion detection systems, meanwhile, raise privacy concerns because they require collecting sensitive network logs in one location, and they generalize poorly across domains.</p>
<p>FedCAMP-IDS answers these problems with a layered design that combines several ideas from the frontiers of machine learning into one federated pipeline. The first stage is what the authors call Cluster-Aware Contrastive Pretraining, or CACP. Before the network ever learns to classify traffic as benign or malicious, it groups similar traffic patterns using K-means clustering and then applies a contrastive optimization objective guided by cosine similarity. In plain terms, the model is rewarded for pulling representations of similar network behavior closer together in its internal embedding space while pushing dissimilar behavior apart. This produces compact, consistent embeddings that remain comparable across clients even when each client sees a very different slice of the network world, which is precisely the condition that breaks most federated systems.</p>
<p>The second pillar of the framework is a memory-augmented prototypical network, a class of model built for few-shot learning, meaning it can learn to recognize attack categories from only a handful of examples. Prototypical networks work by computing a representative vector, or prototype, for each class of traffic and then classifying new samples by measuring their distance to those prototypes. FedCAMP-IDS enhances this mechanism with an external memory module and an adaptive prototype mixing and refinement procedure, allowing each participating device to personalize its prototypes to local conditions while still benefiting from the collective knowledge of the federation. Because the prototypes, rather than entire datasets or full models, are what get shared, the communication burden stays light and the memory footprint remains bounded, two properties the authors highlight as essential for deployment on resource-constrained IoT infrastructure.</p>
<p>Perhaps the most consequential feature for real-world defenders is the framework&#8217;s approach to the unknown. Most intrusion detectors are closed-set classifiers: they can only assign traffic to the attack categories they were trained on. A genuinely novel exploit, a zero-day attack, or an out-of-distribution anomaly simply gets forced into the nearest familiar bucket, often labeled as benign. FedCAMP-IDS incorporates open-set recognition based on Extreme Value Theory, a statistical framework for modeling the tails of probability distributions. By calibrating how extreme a sample&#8217;s distance from known prototypes is, the system can flag traffic that does not belong to any known class as suspicious without retraining the model. The authors report that this EVT-based calibration enabled robust detection of zero-day and anomalous attacks across their experiments, a capability that could buy network operators precious time when facing adversaries wielding techniques no dataset has ever recorded.</p>
<p>To test the framework, the team ran comprehensive experiments in a distributed federated setting using five widely used benchmark datasets: UNSW-NB15, Bot-IoT, ToN-IoT, CICIDS2018, and NF-UQ-NIDS-v2. These datasets collectively span consumer IoT botnets, industrial telemetry, enterprise network attacks, and modern flow-based traffic captures, giving the evaluation a breadth that mirrors the heterogeneity of real deployments. The results were striking. FedCAMP-IDS achieved up to 99.16 percent accuracy, a 98.53 percent F1-score, and 98.57 percent AUROC, a measure of the model&#8217;s ability to separate malicious from benign traffic across all decision thresholds. Against existing federated intrusion detection baselines, the system outperformed by up to 5.7 percentage points in heterogeneous environments, the very settings where competing approaches tend to falter.</p>
<p>Even more telling was the framework&#8217;s performance under blind cross-dataset evaluation, a brutal test in which a model trained on one dataset is unleashed on an entirely different one it has never seen. Without any additional retraining, FedCAMP-IDS maintained an average accuracy of 82.5 percent across these cross-domain trials. That figure signals strong generalization and open-set robustness, suggesting the learned representations capture fundamental structure in network behavior rather than overfitting to the quirks of a particular capture environment. For security teams, this kind of transferability matters enormously, because attackers do not respect the boundaries between datasets, vendors, or network segments, and retraining models from scratch for every new deployment is rarely feasible at scale.</p>
<p>The design choices also carry practical weight for the economics of deployment. Federated learning systems can choke on communication costs when they require frequent exchange of large model updates among thousands of devices. FedCAMP-IDS sidesteps this with a lightweight prototype-sharing strategy and a bounded-memory design, which the authors say reduces both communication and storage overhead enough to make the framework suitable for scalable rollout in smart-city, enterprise, and industrial IoT infrastructures. The work forms part of the Blockchain Technology Research Group, known as BTrust Lab, at ABV-IIITM Gwalior, and the authors note that the study received no external funding and that they declare no competing interests.</p>
<p>The study arrives amid a wave of research into federated and privacy-preserving intrusion detection, with recent efforts exploring graph-based clustering for aggregation, personalized federated learning, knowledge distillation, contrastive federated approaches, and few-shot self-supervised frameworks for IoT defense. Against that backdrop, FedCAMP-IDS distinguishes itself by unifying pretraining, few-shot prototypical learning, personalization, and open-set recognition in a single architecture rather than treating them as separate problems. If its reported numbers hold up in field deployments, the framework could offer a template for securing the next generation of connected infrastructure, one in which devices learn collectively to defend themselves without ever surrendering the sensitive traffic data that makes them vulnerable in the first place.</p>
<p><strong>Subject of Research:</strong> Privacy-preserving federated learning for intrusion detection in heterogeneous IoT environments</p>
<p><strong>Article Title:</strong> FedCAMP-IDS: a federated cluster-aware memory-augmented prototypical network for intrusion detection in heterogeneous IoT environments</p>
<p><strong>Article References:</strong> Yadav, A. S., Pawar, V., &amp; Yadav, R. (2026). FedCAMP-IDS: a federated cluster-aware memory-augmented prototypical network for intrusion detection in heterogeneous IoT environments. <em>Cluster Computing, 29</em>(14), Article 794. <a href="https://doi.org/10.1007/s10586-026-06538-3" rel="noopener noreferrer">https://doi.org/10.1007/s10586-026-06538-3</a></p>
<p><strong>Image Credits:</strong> AI Generated</p>
<p><strong>DOI:</strong> <a href="https://doi.org/10.1007/s10586-026-06538-3" rel="noopener noreferrer">10.1007/s10586-026-06538-3</a></p>
<p><strong>Keywords:</strong> intrusion detection, federated learning, IoT security, prototypical networks, contrastive learning, zero-day attacks, open-set recognition, extreme value theory, few-shot learning, cybersecurity, non-IID data, smart cities</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">234582</post-id>	</item>
	</channel>
</rss>
