Privacy-preserving intrusion detection in IoT smart homes using a federated hybrid 1D-CNN–LSTM model with explainable AI

dc.AffiliationOctober University for modern sciences and Arts MSA
dc.contributor.authorGhada Abdelhady
dc.contributor.authorKarim Wael Hussein
dc.contributor.authorIslam Anwar Ali Gad
dc.date.accessioned2026-09-04T07:03:44Z
dc.date.issued2026-09-02
dc.descriptionSJR 2025 0.893 Q1 H-Index 382 Subject Area and Category: Multidisciplinary Multidisciplinary
dc.description.abstractThe proliferation of Internet of Things (IoT) devices in smart home environments has dramatically expanded the attack surface for cyber threats, particularly botnet-driven Distributed Denial of Service (DDoS) attacks. Centralized Intrusion Detection Systems (IDS) are ill-suited to this domain because they violate user privacy, introduce single points of failure, and incur prohibitive communication overhead. Federated Learning (FL) offers a compelling privacy-preserving alternative, yet existing FL-based IDS solutions either deploy convolutional or recurrent models in isolation, lack human-interpretable outputs, or neglect real-world deployability constraints. This paper proposes FedShield-IDS, a novel federated intrusion detection framework that integrates a hybrid one-dimensional Convolutional Neural Network with Long Short-Term Memory units to simultaneously capture spatial traffic fingerprints and long-range temporal attack dynamics across IoT edge devices. Model interpretability is addressed through the integration of SHapley Additive exPlanations (SHAP), enabling administrators to receive human-readable justifications for every detected anomaly. The system is trained and evaluated on the large-scale CICIoT2023 dataset, comprising 712,311 flow records spanning eight attack families including DDoS, DoS, Mirai, Reconnaissance, Spoofing, Injection, and Malware. A multi-stage preprocessing pipeline combining infinite-value imputation, logarithmic feature scaling, Min-Max normalization, temporal windowing, and localized SMOTE oversampling is applied within each federated client to address non-IID data and extreme class imbalance. Federated Averaging aggregates encrypted model updates across seven virtual IoT client nodes over five communication rounds without exchanging raw traffic data, under a formal threat model characterizing the system’s adversarial assumptions and data-confidentiality guarantees. Experimental results demonstrate a Mirai F1-score of 0.99, a DDoS precision of 0.97, and a global weighted F1-score of 0.76 across all eight classes. Comprehensive kernel-size, architecture, and preprocessing ablations confirm the necessity of each design choice, and independent cross-dataset evaluation on the Edge-IIoTset benchmark achieves 98.58% accuracy, demonstrating strong generalization beyond CICIoT2023. The framework achieves sub-500 ms threat mitigation, empirically confirmed via a mitigation-gate threshold sensitivity analysis, and generates SHAP-gated explanations for every alert, bridging the gap between high-accuracy detection and the transparency required for trustworthy smart-home security.
dc.description.urihttps://www.scimagojr.com/journalsearch.php?q=21100200805&tip=sid&clean=0
dc.identifier.citationAbdelhady, G., Hussein, K. W., & Gad, I. A. A. (2026). Privacy-preserving intrusion detection in IoT smart homes using a federated hybrid 1D-CNN–LSTM model with explainable AI. Scientific Reports, 16(1). https://doi.org/10.1038/s41598-026-67450-9
dc.identifier.doihttps://doi.org/10.1038/s41598-026-67450-9
dc.identifier.otherhttps://doi.org/10.1038/s41598-026-67450-9
dc.identifier.urihttps://repository.msa.edu.eg/handle/123456789/6837
dc.language.isoen_US
dc.publisherNature Research
dc.relation.ispartofseriesScientific Reports ; volume 16 , Article number 27559 , (2026)
dc.subjectInternet of things security
dc.subjectFederated learning
dc.subjectIntrusion detection system
dc.subjectConvolutional neural network
dc.subjectLong short-term memory
dc.subjectExplainable AI
dc.subjectSHAP
dc.subjectCICIoT2023
dc.subjectEdge-IIoTset
dc.subjectBotnet detection
dc.subjectPrivacy-preserving machine learning
dc.titlePrivacy-preserving intrusion detection in IoT smart homes using a federated hybrid 1D-CNN–LSTM model with explainable AI
dc.typeArticle

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
s41598-026-67450-9.pdf
Size:
3.76 MB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
51 B
Format:
Item-specific license agreed upon to submission
Description: