Privacy-preserving intrusion detection in IoT smart homes using a federated hybrid 1D-CNN–LSTM model with explainable AI
| dc.Affiliation | October University for modern sciences and Arts MSA | |
| dc.contributor.author | Ghada Abdelhady | |
| dc.contributor.author | Karim Wael Hussein | |
| dc.contributor.author | Islam Anwar Ali Gad | |
| dc.date.accessioned | 2026-09-04T07:03:44Z | |
| dc.date.issued | 2026-09-02 | |
| dc.description | SJR 2025 0.893 Q1 H-Index 382 Subject Area and Category: Multidisciplinary Multidisciplinary | |
| dc.description.abstract | The proliferation of Internet of Things (IoT) devices in smart home environments has dramatically expanded the attack surface for cyber threats, particularly botnet-driven Distributed Denial of Service (DDoS) attacks. Centralized Intrusion Detection Systems (IDS) are ill-suited to this domain because they violate user privacy, introduce single points of failure, and incur prohibitive communication overhead. Federated Learning (FL) offers a compelling privacy-preserving alternative, yet existing FL-based IDS solutions either deploy convolutional or recurrent models in isolation, lack human-interpretable outputs, or neglect real-world deployability constraints. This paper proposes FedShield-IDS, a novel federated intrusion detection framework that integrates a hybrid one-dimensional Convolutional Neural Network with Long Short-Term Memory units to simultaneously capture spatial traffic fingerprints and long-range temporal attack dynamics across IoT edge devices. Model interpretability is addressed through the integration of SHapley Additive exPlanations (SHAP), enabling administrators to receive human-readable justifications for every detected anomaly. The system is trained and evaluated on the large-scale CICIoT2023 dataset, comprising 712,311 flow records spanning eight attack families including DDoS, DoS, Mirai, Reconnaissance, Spoofing, Injection, and Malware. A multi-stage preprocessing pipeline combining infinite-value imputation, logarithmic feature scaling, Min-Max normalization, temporal windowing, and localized SMOTE oversampling is applied within each federated client to address non-IID data and extreme class imbalance. Federated Averaging aggregates encrypted model updates across seven virtual IoT client nodes over five communication rounds without exchanging raw traffic data, under a formal threat model characterizing the system’s adversarial assumptions and data-confidentiality guarantees. Experimental results demonstrate a Mirai F1-score of 0.99, a DDoS precision of 0.97, and a global weighted F1-score of 0.76 across all eight classes. Comprehensive kernel-size, architecture, and preprocessing ablations confirm the necessity of each design choice, and independent cross-dataset evaluation on the Edge-IIoTset benchmark achieves 98.58% accuracy, demonstrating strong generalization beyond CICIoT2023. The framework achieves sub-500 ms threat mitigation, empirically confirmed via a mitigation-gate threshold sensitivity analysis, and generates SHAP-gated explanations for every alert, bridging the gap between high-accuracy detection and the transparency required for trustworthy smart-home security. | |
| dc.description.uri | https://www.scimagojr.com/journalsearch.php?q=21100200805&tip=sid&clean=0 | |
| dc.identifier.citation | Abdelhady, G., Hussein, K. W., & Gad, I. A. A. (2026). Privacy-preserving intrusion detection in IoT smart homes using a federated hybrid 1D-CNN–LSTM model with explainable AI. Scientific Reports, 16(1). https://doi.org/10.1038/s41598-026-67450-9 | |
| dc.identifier.doi | https://doi.org/10.1038/s41598-026-67450-9 | |
| dc.identifier.other | https://doi.org/10.1038/s41598-026-67450-9 | |
| dc.identifier.uri | https://repository.msa.edu.eg/handle/123456789/6837 | |
| dc.language.iso | en_US | |
| dc.publisher | Nature Research | |
| dc.relation.ispartofseries | Scientific Reports ; volume 16 , Article number 27559 , (2026) | |
| dc.subject | Internet of things security | |
| dc.subject | Federated learning | |
| dc.subject | Intrusion detection system | |
| dc.subject | Convolutional neural network | |
| dc.subject | Long short-term memory | |
| dc.subject | Explainable AI | |
| dc.subject | SHAP | |
| dc.subject | CICIoT2023 | |
| dc.subject | Edge-IIoTset | |
| dc.subject | Botnet detection | |
| dc.subject | Privacy-preserving machine learning | |
| dc.title | Privacy-preserving intrusion detection in IoT smart homes using a federated hybrid 1D-CNN–LSTM model with explainable AI | |
| dc.type | Article |
