{"id":"https://openalex.org/W7135030530","doi":"https://doi.org/10.48550/arxiv.2603.10776","title":"Incremental Federated Learning for Intrusion Detection in IoT Networks under Evolving Threat Landscape","display_name":"Incremental Federated Learning for Intrusion Detection in IoT Networks under Evolving Threat Landscape","publication_year":2026,"publication_date":"2026-03-11","ids":{"openalex":"https://openalex.org/W7135030530","doi":"https://doi.org/10.48550/arxiv.2603.10776"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2603.10776","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.10776","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2603.10776","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5048947387","display_name":"Muaan Ur Rehman","orcid":"https://orcid.org/0009-0000-2656-0127"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Rehman, Muaan Ur","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5075157158","display_name":"Hayretdin Bah\u015fi","orcid":"https://orcid.org/0000-0001-8882-4095"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Bahsi, Hayretdin","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5101916839","display_name":"Rajesh Kalakoti","orcid":"https://orcid.org/0000-0001-7390-8034"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Kalakoti, Rajesh","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12761","display_name":"Data Stream Mining Techniques","score":0.4921000003814697,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12761","display_name":"Data Stream Mining Techniques","score":0.4921000003814697,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.14990000426769257,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.07500000298023224,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.7633000016212463},{"id":"https://openalex.org/keywords/latency","display_name":"Latency (audio)","score":0.5187000036239624},{"id":"https://openalex.org/keywords/internet-of-things","display_name":"Internet of Things","score":0.46889999508857727},{"id":"https://openalex.org/keywords/federated-learning","display_name":"Federated learning","score":0.4643000066280365},{"id":"https://openalex.org/keywords/concept-drift","display_name":"Concept drift","score":0.4399000108242035},{"id":"https://openalex.org/keywords/adaptive-learning","display_name":"Adaptive learning","score":0.4050000011920929},{"id":"https://openalex.org/keywords/resource","display_name":"Resource (disambiguation)","score":0.38029998540878296},{"id":"https://openalex.org/keywords/big-data","display_name":"Big data","score":0.34150001406669617},{"id":"https://openalex.org/keywords/intrusion","display_name":"Intrusion","score":0.33379998803138733}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.835099995136261},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.7633000016212463},{"id":"https://openalex.org/C82876162","wikidata":"https://www.wikidata.org/wiki/Q17096504","display_name":"Latency (audio)","level":2,"score":0.5187000036239624},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.5011000037193298},{"id":"https://openalex.org/C81860439","wikidata":"https://www.wikidata.org/wiki/Q251212","display_name":"Internet of Things","level":2,"score":0.46889999508857727},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.46650001406669617},{"id":"https://openalex.org/C2992525071","wikidata":"https://www.wikidata.org/wiki/Q50818671","display_name":"Federated learning","level":2,"score":0.4643000066280365},{"id":"https://openalex.org/C60777511","wikidata":"https://www.wikidata.org/wiki/Q3045002","display_name":"Concept drift","level":3,"score":0.4399000108242035},{"id":"https://openalex.org/C125014702","wikidata":"https://www.wikidata.org/wiki/Q4680749","display_name":"Adaptive learning","level":2,"score":0.4050000011920929},{"id":"https://openalex.org/C206345919","wikidata":"https://www.wikidata.org/wiki/Q20380951","display_name":"Resource (disambiguation)","level":2,"score":0.38029998540878296},{"id":"https://openalex.org/C75684735","wikidata":"https://www.wikidata.org/wiki/Q858810","display_name":"Big data","level":2,"score":0.34150001406669617},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.33719998598098755},{"id":"https://openalex.org/C158251709","wikidata":"https://www.wikidata.org/wiki/Q354025","display_name":"Intrusion","level":2,"score":0.33379998803138733},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.3334999978542328},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.3305000066757202},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.3149000108242035},{"id":"https://openalex.org/C67186912","wikidata":"https://www.wikidata.org/wiki/Q367664","display_name":"Data modeling","level":2,"score":0.30709999799728394},{"id":"https://openalex.org/C46637626","wikidata":"https://www.wikidata.org/wiki/Q6693015","display_name":"Low latency (capital markets)","level":2,"score":0.30140000581741333},{"id":"https://openalex.org/C2986087404","wikidata":"https://www.wikidata.org/wiki/Q15946010","display_name":"Online learning","level":2,"score":0.30070000886917114},{"id":"https://openalex.org/C93996380","wikidata":"https://www.wikidata.org/wiki/Q44127","display_name":"Server","level":2,"score":0.2840999960899353},{"id":"https://openalex.org/C123201435","wikidata":"https://www.wikidata.org/wiki/Q456632","display_name":"Information privacy","level":2,"score":0.2809000015258789},{"id":"https://openalex.org/C2780735816","wikidata":"https://www.wikidata.org/wiki/Q28324931","display_name":"Incremental learning","level":2,"score":0.27379998564720154},{"id":"https://openalex.org/C120314980","wikidata":"https://www.wikidata.org/wiki/Q180634","display_name":"Distributed computing","level":1,"score":0.26820001006126404},{"id":"https://openalex.org/C27061796","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion prevention system","level":3,"score":0.2653000056743622},{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.26350000500679016},{"id":"https://openalex.org/C61797465","wikidata":"https://www.wikidata.org/wiki/Q1188986","display_name":"Term (time)","level":2,"score":0.2612000107765198},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.2581999897956848},{"id":"https://openalex.org/C2776576444","wikidata":"https://www.wikidata.org/wiki/Q303569","display_name":"Attack surface","level":2,"score":0.25200000405311584},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.251800000667572},{"id":"https://openalex.org/C65856478","wikidata":"https://www.wikidata.org/wiki/Q3991682","display_name":"Attack model","level":2,"score":0.2500999867916107}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2603.10776","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.10776","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2603.10776","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.10776","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"The":[0,226],"expansion":[1],"of":[2,4,13,59,123,133,193,249],"Internet":[3],"Things":[5],"(IoT)":[6],"devices":[7],"has":[8],"increased":[9],"the":[10,33,57,129,169,194,209,232,247,255],"attack":[11,175],"surface":[12],"networks,":[14],"necessitating":[15],"a":[16,52,119,147,190,219],"robust":[17],"and":[18,159,185,205,222,238],"adaptive":[19],"intrusion":[20,46,94,195],"detection":[21,34,81,99,196],"systems.":[22],"Machine":[23],"learning":[24,37,126,149,154,164,204,207],"based":[25],"systems":[26,61],"have":[27],"been":[28],"considered":[29],"promising":[30],"in":[31,51,72,127,138,240,258],"enhancing":[32,128],"performance.":[35],"Federated":[36],"settings":[38],"enabled":[39],"us":[40],"to":[41,67,151,188,245],"train":[42],"models":[43,82,137,145],"from":[44,49],"network":[45],"data":[47,73,95,158],"collected":[48],"clients":[50],"privacy":[53],"preserving":[54],"manner.":[55],"However,":[56],"effectiveness":[58],"these":[60],"can":[62,88],"degrade":[63],"over":[64],"time":[65],"due":[66],"concept":[68],"drift,":[69,214],"where":[70],"patterns":[71],"evolve":[74],"as":[75],"attackers":[76],"develop":[77],"new":[78,93,229],"techniques.":[79],"Realistic":[80],"should":[83,111],"be":[84,89],"non-stationary,":[85],"so":[86],"they":[87],"continuously":[90],"updated":[91],"with":[92],"while":[96,215],"maintaining":[97],"their":[98],"capability":[100],"for":[101],"older":[102],"data.":[103],"As":[104],"IoT":[105,139,242,259],"environments":[106],"are":[107],"resource":[108,256],"constrained,":[109],"updates":[110],"consume":[112],"minimal":[113],"computational":[114],"resources.":[115],"This":[116],"study":[117,227],"provides":[118],"comprehensive":[120],"performance":[121,132,212,237],"analysis":[122,192],"incremental":[124,153,203],"federated":[125,148],"long":[130],"term":[131],"non":[134],"stationary":[135],"IDS":[136,252],"networks.":[140],"Specifically,":[141],"we":[142,181],"propose":[143],"LSTM":[144],"within":[146],"setting":[150],"evaluate":[152],"approaches":[155],"that":[156,201],"utilize":[157],"model-based":[160],"measures":[161],"against":[162],"catastrophic":[163],"under":[165,213],"drift":[166],"conditions.":[167],"Using":[168],"CICIoMT2024":[170],"dataset,":[171],"which":[172],"includes":[173],"various":[174],"variants":[176],"across":[177],"five":[178],"major":[179],"categories,":[180],"conduct":[182],"both":[183],"binary":[184],"multiclass":[186],"classification":[187],"provide":[189,208],"granular":[191],"task.":[197],"Our":[198],"results":[199],"show":[200],"cumulative":[202],"representative":[206],"most":[210],"stable":[211],"retention-based":[216],"methods":[217],"offer":[218],"strong":[220],"accuracy":[221],"latency":[223,239],"trade":[224],"off.":[225],"offers":[228],"insights":[230],"into":[231],"interplay":[233],"between":[234],"training":[235],"strategy":[236],"dynamic":[241],"environments,":[243],"aiming":[244],"inform":[246],"development":[248],"more":[250],"resilient":[251],"solutions":[253],"considering":[254],"constraints":[257],"devices.":[260]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-03-13T00:00:00"}
