{"id":"https://openalex.org/W4415295195","doi":"https://doi.org/10.3390/fi17100475","title":"Decentralized Federated Learning for IoT Malware Detection at the Multi-Access Edge: A Two-Tier, Privacy-Preserving Design","display_name":"Decentralized Federated Learning for IoT Malware Detection at the Multi-Access Edge: A Two-Tier, Privacy-Preserving Design","publication_year":2025,"publication_date":"2025-10-17","ids":{"openalex":"https://openalex.org/W4415295195","doi":"https://doi.org/10.3390/fi17100475"},"language":"en","primary_location":{"id":"doi:10.3390/fi17100475","is_oa":true,"landing_page_url":"https://doi.org/10.3390/fi17100475","pdf_url":"https://www.mdpi.com/1999-5903/17/10/475/pdf?version=1760710475","source":{"id":"https://openalex.org/S34838331","display_name":"Future Internet","issn_l":"1999-5903","issn":["1999-5903"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310310987","host_organization_name":"Multidisciplinary Digital Publishing Institute","host_organization_lineage":["https://openalex.org/P4310310987"],"host_organization_lineage_names":["Multidisciplinary Digital Publishing Institute"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Future Internet","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://www.mdpi.com/1999-5903/17/10/475/pdf?version=1760710475","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5030403810","display_name":"Mohammed Yahya Asiri","orcid":"https://orcid.org/0000-0002-7639-7281"},"institutions":[{"id":"https://openalex.org/I185163786","display_name":"King Abdulaziz University","ror":"https://ror.org/02ma4wv74","country_code":"SA","type":"education","lineage":["https://openalex.org/I185163786"]}],"countries":["SA"],"is_corresponding":true,"raw_author_name":"Mohammed Asiri","raw_affiliation_strings":["Department of Computer Science, King Abdulaziz University, Jeddah 21589, Saudi Arabia"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, King Abdulaziz University, Jeddah 21589, Saudi Arabia","institution_ids":["https://openalex.org/I185163786"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5019492006","display_name":"Maher Khemakhem","orcid":"https://orcid.org/0000-0002-1287-1634"},"institutions":[{"id":"https://openalex.org/I185163786","display_name":"King Abdulaziz University","ror":"https://ror.org/02ma4wv74","country_code":"SA","type":"education","lineage":["https://openalex.org/I185163786"]}],"countries":["SA"],"is_corresponding":false,"raw_author_name":"Maher A. Khemakhem","raw_affiliation_strings":["Department of Computer Science, King Abdulaziz University, Jeddah 21589, Saudi Arabia"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, King Abdulaziz University, Jeddah 21589, Saudi Arabia","institution_ids":["https://openalex.org/I185163786"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5029498299","display_name":"Reemah Alhebshi","orcid":"https://orcid.org/0000-0001-7940-059X"},"institutions":[{"id":"https://openalex.org/I185163786","display_name":"King Abdulaziz University","ror":"https://ror.org/02ma4wv74","country_code":"SA","type":"education","lineage":["https://openalex.org/I185163786"]}],"countries":["SA"],"is_corresponding":true,"raw_author_name":"Reemah M. Alhebshi","raw_affiliation_strings":["Department of Computer Science, King Abdulaziz University, Jeddah 21589, Saudi Arabia"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, King Abdulaziz University, Jeddah 21589, Saudi Arabia","institution_ids":["https://openalex.org/I185163786"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5074637474","display_name":"Bassma Saleh Alsulami","orcid":null},"institutions":[{"id":"https://openalex.org/I185163786","display_name":"King Abdulaziz University","ror":"https://ror.org/02ma4wv74","country_code":"SA","type":"education","lineage":["https://openalex.org/I185163786"]}],"countries":["SA"],"is_corresponding":false,"raw_author_name":"Bassma S. Alsulami","raw_affiliation_strings":["Department of Computer Science, King Abdulaziz University, Jeddah 21589, Saudi Arabia"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, King Abdulaziz University, Jeddah 21589, Saudi Arabia","institution_ids":["https://openalex.org/I185163786"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5025984879","display_name":"Fathy Eassa","orcid":"https://orcid.org/0000-0003-3987-9051"},"institutions":[{"id":"https://openalex.org/I185163786","display_name":"King Abdulaziz University","ror":"https://ror.org/02ma4wv74","country_code":"SA","type":"education","lineage":["https://openalex.org/I185163786"]}],"countries":["SA"],"is_corresponding":false,"raw_author_name":"Fathy E. Eassa","raw_affiliation_strings":["Department of Computer Science, King Abdulaziz University, Jeddah 21589, Saudi Arabia"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, King Abdulaziz University, Jeddah 21589, Saudi Arabia","institution_ids":["https://openalex.org/I185163786"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5029498299","https://openalex.org/A5030403810"],"corresponding_institution_ids":["https://openalex.org/I185163786"],"apc_list":{"value":1400,"currency":"CHF","value_usd":1515},"apc_paid":{"value":1400,"currency":"CHF","value_usd":1515},"fwci":2.4849,"has_fulltext":true,"cited_by_count":1,"citation_normalized_percentile":{"value":0.9185086,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":91,"max":95},"biblio":{"volume":"17","issue":"10","first_page":"475","last_page":"475"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9975000023841858,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9975000023841858,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9951000213623047,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.994700014591217,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/single-point-of-failure","display_name":"Single point of failure","score":0.6773999929428101},{"id":"https://openalex.org/keywords/homomorphic-encryption","display_name":"Homomorphic encryption","score":0.6018999814987183},{"id":"https://openalex.org/keywords/benchmark","display_name":"Benchmark (surveying)","score":0.5679000020027161},{"id":"https://openalex.org/keywords/overhead","display_name":"Overhead (engineering)","score":0.5648999810218811},{"id":"https://openalex.org/keywords/plaintext","display_name":"Plaintext","score":0.5573999881744385},{"id":"https://openalex.org/keywords/enhanced-data-rates-for-gsm-evolution","display_name":"Enhanced Data Rates for GSM Evolution","score":0.5030999779701233},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.4966000020503998},{"id":"https://openalex.org/keywords/encryption","display_name":"Encryption","score":0.47769999504089355},{"id":"https://openalex.org/keywords/semantic-security","display_name":"Semantic security","score":0.4528000056743622},{"id":"https://openalex.org/keywords/federated-learning","display_name":"Federated learning","score":0.4309999942779541}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.9014000296592712},{"id":"https://openalex.org/C165136773","wikidata":"https://www.wikidata.org/wiki/Q1363179","display_name":"Single point of failure","level":2,"score":0.6773999929428101},{"id":"https://openalex.org/C158338273","wikidata":"https://www.wikidata.org/wiki/Q2154943","display_name":"Homomorphic encryption","level":3,"score":0.6018999814987183},{"id":"https://openalex.org/C185798385","wikidata":"https://www.wikidata.org/wiki/Q1161707","display_name":"Benchmark (surveying)","level":2,"score":0.5679000020027161},{"id":"https://openalex.org/C2779960059","wikidata":"https://www.wikidata.org/wiki/Q7113681","display_name":"Overhead (engineering)","level":2,"score":0.5648999810218811},{"id":"https://openalex.org/C92717368","wikidata":"https://www.wikidata.org/wiki/Q1162538","display_name":"Plaintext","level":3,"score":0.5573999881744385},{"id":"https://openalex.org/C162307627","wikidata":"https://www.wikidata.org/wiki/Q204833","display_name":"Enhanced Data Rates for GSM Evolution","level":2,"score":0.5030999779701233},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.4966000020503998},{"id":"https://openalex.org/C148730421","wikidata":"https://www.wikidata.org/wiki/Q141090","display_name":"Encryption","level":2,"score":0.47769999504089355},{"id":"https://openalex.org/C204806902","wikidata":"https://www.wikidata.org/wiki/Q2333581","display_name":"Semantic security","level":5,"score":0.4528000056743622},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.44110000133514404},{"id":"https://openalex.org/C2992525071","wikidata":"https://www.wikidata.org/wiki/Q50818671","display_name":"Federated learning","level":2,"score":0.4309999942779541},{"id":"https://openalex.org/C4679612","wikidata":"https://www.wikidata.org/wiki/Q866298","display_name":"Aggregate (composite)","level":2,"score":0.4221999943256378},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.4009999930858612},{"id":"https://openalex.org/C120314980","wikidata":"https://www.wikidata.org/wiki/Q180634","display_name":"Distributed computing","level":1,"score":0.36649999022483826},{"id":"https://openalex.org/C28719098","wikidata":"https://www.wikidata.org/wiki/Q44946","display_name":"Point (geometry)","level":2,"score":0.36570000648498535},{"id":"https://openalex.org/C186967261","wikidata":"https://www.wikidata.org/wiki/Q5082128","display_name":"Mobile device","level":2,"score":0.3474000096321106},{"id":"https://openalex.org/C2778456923","wikidata":"https://www.wikidata.org/wiki/Q5337692","display_name":"Edge computing","level":3,"score":0.33970001339912415},{"id":"https://openalex.org/C40305131","wikidata":"https://www.wikidata.org/wiki/Q2616305","display_name":"Obfuscation","level":2,"score":0.31630000472068787},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.3138999938964844},{"id":"https://openalex.org/C81860439","wikidata":"https://www.wikidata.org/wiki/Q251212","display_name":"Internet of Things","level":2,"score":0.31380000710487366},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.313400000333786},{"id":"https://openalex.org/C62611344","wikidata":"https://www.wikidata.org/wiki/Q1062658","display_name":"Node (physics)","level":2,"score":0.3091999888420105},{"id":"https://openalex.org/C93974786","wikidata":"https://www.wikidata.org/wiki/Q1589480","display_name":"Ciphertext","level":3,"score":0.30559998750686646},{"id":"https://openalex.org/C82578977","wikidata":"https://www.wikidata.org/wiki/Q16773055","display_name":"Data aggregator","level":3,"score":0.30489999055862427},{"id":"https://openalex.org/C2777210771","wikidata":"https://www.wikidata.org/wiki/Q4927124","display_name":"Block (permutation group theory)","level":2,"score":0.30140000581741333},{"id":"https://openalex.org/C136810230","wikidata":"https://www.wikidata.org/wiki/Q188961","display_name":"Decentralization","level":2,"score":0.29910001158714294},{"id":"https://openalex.org/C123657996","wikidata":"https://www.wikidata.org/wiki/Q12271","display_name":"Architecture","level":2,"score":0.2741999924182892},{"id":"https://openalex.org/C93996380","wikidata":"https://www.wikidata.org/wiki/Q44127","display_name":"Server","level":2,"score":0.2689000070095062},{"id":"https://openalex.org/C180505990","wikidata":"https://www.wikidata.org/wiki/Q498267","display_name":"News aggregator","level":2,"score":0.2687999904155731},{"id":"https://openalex.org/C21308566","wikidata":"https://www.wikidata.org/wiki/Q7169365","display_name":"Permutation (music)","level":2,"score":0.266400009393692},{"id":"https://openalex.org/C114725131","wikidata":"https://www.wikidata.org/wiki/Q190837","display_name":"Tipping point (physics)","level":2,"score":0.265500009059906},{"id":"https://openalex.org/C164226766","wikidata":"https://www.wikidata.org/wiki/Q7293202","display_name":"Rank (graph theory)","level":2,"score":0.2630999982357025},{"id":"https://openalex.org/C2780821482","wikidata":"https://www.wikidata.org/wiki/Q25381721","display_name":"Crowdsensing","level":2,"score":0.26109999418258667},{"id":"https://openalex.org/C21200559","wikidata":"https://www.wikidata.org/wiki/Q7451068","display_name":"Sensitivity (control systems)","level":2,"score":0.259799987077713}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.3390/fi17100475","is_oa":true,"landing_page_url":"https://doi.org/10.3390/fi17100475","pdf_url":"https://www.mdpi.com/1999-5903/17/10/475/pdf?version=1760710475","source":{"id":"https://openalex.org/S34838331","display_name":"Future Internet","issn_l":"1999-5903","issn":["1999-5903"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310310987","host_organization_name":"Multidisciplinary Digital Publishing Institute","host_organization_lineage":["https://openalex.org/P4310310987"],"host_organization_lineage_names":["Multidisciplinary Digital Publishing Institute"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Future Internet","raw_type":"journal-article"},{"id":"pmh:oai:doaj.org/article:6d8321cc3fc44b36822f4a6ad2d7cc2f","is_oa":true,"landing_page_url":"https://doaj.org/article/6d8321cc3fc44b36822f4a6ad2d7cc2f","pdf_url":null,"source":{"id":"https://openalex.org/S112646816","display_name":"SHILAP Revista de lepidopterolog\u00eda","issn_l":"0300-5267","issn":["0300-5267","2340-4078"],"is_oa":true,"is_in_doaj":true,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Future Internet, Vol 17, Iss 10, p 475 (2025)","raw_type":"article"}],"best_oa_location":{"id":"doi:10.3390/fi17100475","is_oa":true,"landing_page_url":"https://doi.org/10.3390/fi17100475","pdf_url":"https://www.mdpi.com/1999-5903/17/10/475/pdf?version=1760710475","source":{"id":"https://openalex.org/S34838331","display_name":"Future Internet","issn_l":"1999-5903","issn":["1999-5903"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310310987","host_organization_name":"Multidisciplinary Digital Publishing Institute","host_organization_lineage":["https://openalex.org/P4310310987"],"host_organization_lineage_names":["Multidisciplinary Digital Publishing Institute"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Future Internet","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4415295195.pdf","grobid_xml":"https://content.openalex.org/works/W4415295195.grobid-xml"},"referenced_works_count":28,"referenced_works":["https://openalex.org/W2615459164","https://openalex.org/W2763398287","https://openalex.org/W2768174108","https://openalex.org/W2799758613","https://openalex.org/W2899071560","https://openalex.org/W3034606981","https://openalex.org/W3094696138","https://openalex.org/W3132672094","https://openalex.org/W3185153723","https://openalex.org/W3198581335","https://openalex.org/W3209696639","https://openalex.org/W4205915954","https://openalex.org/W4206724648","https://openalex.org/W4288062348","https://openalex.org/W4306827119","https://openalex.org/W4313201775","https://openalex.org/W4365509262","https://openalex.org/W4379472188","https://openalex.org/W4387353472","https://openalex.org/W4387911072","https://openalex.org/W4388052738","https://openalex.org/W4388061054","https://openalex.org/W4399172047","https://openalex.org/W4403600954","https://openalex.org/W4404035300","https://openalex.org/W4408295397","https://openalex.org/W4408331172","https://openalex.org/W4409723463"],"related_works":[],"abstract_inverted_index":{"Botnet":[0],"attacks":[1],"on":[2,27],"Internet":[3],"of":[4,42,169],"Things":[5],"(IoT)":[6],"devices":[7],"are":[8],"escalating":[9],"at":[10],"the":[11,32,71,108,134,196],"5G/6G":[12],"multi-access":[13],"edge,":[14],"yet":[15],"most":[16],"federated":[17],"learning":[18],"frameworks":[19],"for":[20,171,183,205],"IoT":[21],"malware":[22],"detection":[23],"(FL-IMD)":[24],"still":[25],"hinge":[26],"a":[28,39,46,93,100,122,127,159,179],"central":[29],"aggregator,":[30],"enlarging":[31],"attack":[33,138],"surface,":[34],"weakening":[35],"privacy,":[36],"and":[37,67,83,99,118,126,144,199],"creating":[38],"single":[40],"point":[41],"failure.":[43],"We":[44],"propose":[45],"two-tier,":[47],"fully":[48],"decentralized":[49],"FL":[50],"architecture":[51],"aligned":[52],"with":[53,70,111],"MEC\u2019s":[54],"Proximal":[55],"Edge":[56,59],"Server":[57,60],"(PES)/Supplementary":[58],"(SES)":[61],"hierarchy.":[62],"PES":[63],"nodes":[64,76],"train":[65],"locally":[66],"encrypt":[68],"updates":[69],"Cheon\u2013Kim\u2013Kim\u2013Song":[72],"(CKKS)":[73],"scheme;":[74],"SES":[75],"verify":[77],"ECDSA-signed":[78],"provenance,":[79],"homomorphically":[80],"aggregate":[81],"ciphertexts,":[82],"finalize":[84],"each":[85],"round":[86],"via":[87],"an":[88,104,112],"Algorand-style":[89],"committee":[90,184],"that":[91],"writes":[92],"compact,":[94],"tamper-evident":[95],"record":[96],"(update":[97],"digests/URIs":[98],"global-model":[101],"hash)":[102],"to":[103,154],"append-only":[105],"ledger.":[106],"Using":[107],"N-BaIoT":[109],"benchmark":[110],"unsupervised":[113],"autoencoder,":[114],"we":[115],"evaluate":[116],"known-device":[117],"leave-one-device-out":[119],"regimes":[120],"against":[121],"classical":[123],"centralized":[124],"baseline":[125],"cryptographically":[128],"hardened":[129],"but":[130],"server-centric":[131],"variant.":[132],"With":[133],"heavier":[135],"CKKS":[136],"profile,":[137],"sensitivity":[139],"is":[140],"preserved":[141],"(TPR":[142],"\u22650.99),":[143],"specificity":[145],"(TNR)":[146],"declines":[147],"by":[148],"only":[149,178],"0.20":[150],"percentage":[151,167],"points":[152,168],"relative":[153],"plaintext":[155],"in":[156],"both":[157],"regimes;":[158],"lighter":[160],"profile":[161],"maintains":[162],"TPR":[163],"while":[164,186],"trading":[165],"3.5\u20134.8":[166],"TNR":[170],"about":[172],"71%":[173],"smaller":[174],"payloads.":[175],"Decentralization":[176],"adds":[177],"negligible":[180],"per-round":[181],"overhead":[182],"finality,":[185],"homomorphic":[187],"aggregation":[188],"dominates":[189],"latency.":[190],"Overall,":[191],"our":[192],"FL-IMD":[193],"design":[194],"removes":[195],"trusted":[197],"aggregator":[198],"provides":[200],"verifiable,":[201],"ledger-backed":[202],"provenance":[203],"suitable":[204],"trustless":[206],"MEC":[207],"deployments.":[208]},"counts_by_year":[{"year":2025,"cited_by_count":1}],"updated_date":"2026-03-27T05:58:40.876381","created_date":"2025-10-18T00:00:00"}
