{"id":"https://openalex.org/W7134164736","doi":"https://doi.org/10.5220/0014475900004061","title":"Incremental Federated Learning for Intrusion Detection in IoT Networks under Evolving Threat Landscape","display_name":"Incremental Federated Learning for Intrusion Detection in IoT Networks under Evolving Threat Landscape","publication_year":2026,"publication_date":"2026-01-01","ids":{"openalex":"https://openalex.org/W7134164736","doi":"https://doi.org/10.5220/0014475900004061"},"language":null,"primary_location":{"id":"doi:10.5220/0014475900004061","is_oa":false,"landing_page_url":"https://doi.org/10.5220/0014475900004061","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 12th International Conference on Information Systems Security and Privacy","raw_type":"proceedings-article"},"type":"article","indexed_in":["arxiv","crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2603.10776","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5048947387","display_name":"Muaan Ur Rehman","orcid":"https://orcid.org/0009-0000-2656-0127"},"institutions":[{"id":"https://openalex.org/I111112146","display_name":"Tallinn University of Technology","ror":"https://ror.org/0443cwa12","country_code":"EE","type":"education","lineage":["https://openalex.org/I111112146"]}],"countries":["EE"],"is_corresponding":false,"raw_author_name":"Muaan Rehman","raw_affiliation_strings":["Centre for Digital Forensics and Cyber Security, Department of Software Science, Tallinn University of Technology, Tallinn, Estonia"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Centre for Digital Forensics and Cyber Security, Department of Software Science, Tallinn University of Technology, Tallinn, Estonia","institution_ids":["https://openalex.org/I111112146"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5075157158","display_name":"Hayretdin Bah\u015fi","orcid":"https://orcid.org/0000-0001-8882-4095"},"institutions":[{"id":"https://openalex.org/I111112146","display_name":"Tallinn University of Technology","ror":"https://ror.org/0443cwa12","country_code":"EE","type":"education","lineage":["https://openalex.org/I111112146"]},{"id":"https://openalex.org/I203172682","display_name":"Northern Arizona University","ror":"https://ror.org/0272j5188","country_code":"US","type":"education","lineage":["https://openalex.org/I203172682"]}],"countries":["EE","US"],"is_corresponding":false,"raw_author_name":"Hayretdin Bahsi","raw_affiliation_strings":["Centre for Digital Forensics and Cyber Security, Department of Software Science, Tallinn University of Technology, Tallinn, Estonia","School of Informatics, Computing, and Cyber Systems, Northern Arizona University, U.S.A"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Centre for Digital Forensics and Cyber Security, Department of Software Science, Tallinn University of Technology, Tallinn, Estonia","institution_ids":["https://openalex.org/I111112146"]},{"raw_affiliation_string":"School of Informatics, Computing, and Cyber Systems, Northern Arizona University, U.S.A","institution_ids":["https://openalex.org/I203172682"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5101916839","display_name":"Rajesh Kalakoti","orcid":"https://orcid.org/0000-0001-7390-8034"},"institutions":[{"id":"https://openalex.org/I111112146","display_name":"Tallinn University of Technology","ror":"https://ror.org/0443cwa12","country_code":"EE","type":"education","lineage":["https://openalex.org/I111112146"]}],"countries":["EE"],"is_corresponding":false,"raw_author_name":"Rajesh Kalakoti","raw_affiliation_strings":["Centre for Digital Forensics and Cyber Security, Department of Software Science, Tallinn University of Technology, Tallinn, Estonia"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Centre for Digital Forensics and Cyber Security, Department of Software Science, Tallinn University of Technology, Tallinn, Estonia","institution_ids":["https://openalex.org/I111112146"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":36.0417,"has_fulltext":true,"cited_by_count":2,"citation_normalized_percentile":{"value":0.99527914,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":98,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"97","last_page":"107"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.24169999361038208,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.24169999361038208,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.23890000581741333,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T13918","display_name":"Advanced Data and IoT Technologies","score":0.047600001096725464,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.5699999928474426},{"id":"https://openalex.org/keywords/internet-of-things","display_name":"Internet of Things","score":0.45500001311302185},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.3617999851703644},{"id":"https://openalex.org/keywords/intrusion","display_name":"Intrusion","score":0.2833999991416931},{"id":"https://openalex.org/keywords/field","display_name":"Field (mathematics)","score":0.27810001373291016},{"id":"https://openalex.org/keywords/intrusion-prevention-system","display_name":"Intrusion prevention system","score":0.2689000070095062}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6245999932289124},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.5699999928474426},{"id":"https://openalex.org/C81860439","wikidata":"https://www.wikidata.org/wiki/Q251212","display_name":"Internet of Things","level":2,"score":0.45500001311302185},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4503999948501587},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.3617999851703644},{"id":"https://openalex.org/C158251709","wikidata":"https://www.wikidata.org/wiki/Q354025","display_name":"Intrusion","level":2,"score":0.2833999991416931},{"id":"https://openalex.org/C9652623","wikidata":"https://www.wikidata.org/wiki/Q190109","display_name":"Field (mathematics)","level":2,"score":0.27810001373291016},{"id":"https://openalex.org/C27061796","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion prevention system","level":3,"score":0.2689000070095062},{"id":"https://openalex.org/C24590314","wikidata":"https://www.wikidata.org/wiki/Q336038","display_name":"Wireless sensor network","level":2,"score":0.25519999861717224},{"id":"https://openalex.org/C93996380","wikidata":"https://www.wikidata.org/wiki/Q44127","display_name":"Server","level":2,"score":0.25279998779296875},{"id":"https://openalex.org/C2776401178","wikidata":"https://www.wikidata.org/wiki/Q12050496","display_name":"Feature (linguistics)","level":2,"score":0.25029999017715454}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.5220/0014475900004061","is_oa":false,"landing_page_url":"https://doi.org/10.5220/0014475900004061","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 12th International Conference on Information Systems Security and Privacy","raw_type":"proceedings-article"},{"id":"pmh:oai:arXiv.org:2603.10776","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2603.10776","pdf_url":"https://arxiv.org/pdf/2603.10776","source":{"id":"https://openalex.org/S4393918464","display_name":"ArXiv.org","issn_l":"2331-8422","issn":["2331-8422"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2603.10776","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2603.10776","pdf_url":"https://arxiv.org/pdf/2603.10776","source":{"id":"https://openalex.org/S4393918464","display_name":"ArXiv.org","issn_l":"2331-8422","issn":["2331-8422"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/13","display_name":"Climate action","score":0.670238733291626}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"The":[0,226],"expansion":[1],"of":[2,4,13,59,123,133,193,249],"Internet":[3],"Things":[5],"(IoT)":[6],"devices":[7],"has":[8],"increased":[9],"the":[10,33,57,129,169,194,209,232,247,255],"attack":[11,175],"surface":[12],"networks,":[14],"necessitating":[15],"a":[16,52,119,147,190,219],"robust":[17],"and":[18,159,185,205,222,238],"adaptive":[19],"intrusion":[20,46,94,195],"detection":[21,34,81,99,196],"systems.":[22],"Machine":[23],"learning":[24,37,126,149,154,164,204,207],"based":[25],"systems":[26,61],"have":[27],"been":[28],"considered":[29],"promising":[30],"in":[31,51,72,127,138,240,258],"enhancing":[32,128],"performance.":[35],"Federated":[36],"settings":[38],"enabled":[39],"us":[40],"to":[41,67,151,188,245],"train":[42],"models":[43,82,137,145],"from":[44,49],"network":[45],"data":[47,73,95,158],"collected":[48],"clients":[50],"privacy":[53],"preserving":[54],"manner.":[55],"However,":[56],"effectiveness":[58],"these":[60],"can":[62,88],"degrade":[63],"over":[64],"time":[65],"due":[66],"concept":[68],"drift,":[69,214],"where":[70],"patterns":[71],"evolve":[74],"as":[75],"attackers":[76],"develop":[77],"new":[78,93,229],"techniques.":[79],"Realistic":[80],"should":[83,111],"be":[84,89],"non-stationary,":[85],"so":[86],"they":[87],"continuously":[90],"updated":[91],"with":[92],"while":[96,215],"maintaining":[97],"their":[98],"capability":[100],"for":[101],"older":[102],"data.":[103],"As":[104],"IoT":[105,139,242,259],"environments":[106],"are":[107],"resource":[108,256],"constrained,":[109],"updates":[110],"consume":[112],"minimal":[113],"computational":[114],"resources.":[115],"This":[116],"study":[117,227],"provides":[118],"comprehensive":[120],"performance":[121,132,212,237],"analysis":[122,192],"incremental":[124,153,203],"federated":[125,148],"long":[130],"term":[131],"non":[134],"stationary":[135],"IDS":[136,252],"networks.":[140],"Specifically,":[141],"we":[142,181],"propose":[143],"LSTM":[144],"within":[146],"setting":[150],"evaluate":[152],"approaches":[155],"that":[156,201],"utilize":[157],"model-based":[160],"measures":[161],"against":[162],"catastrophic":[163],"under":[165,213],"drift":[166],"conditions.":[167],"Using":[168],"CICIoMT2024":[170],"dataset,":[171],"which":[172],"includes":[173],"various":[174],"variants":[176],"across":[177],"five":[178],"major":[179],"categories,":[180],"conduct":[182],"both":[183],"binary":[184],"multiclass":[186],"classification":[187],"provide":[189,208],"granular":[191],"task.":[197],"Our":[198],"results":[199],"show":[200],"cumulative":[202],"representative":[206],"most":[210],"stable":[211],"retention-based":[216],"methods":[217],"offer":[218],"strong":[220],"accuracy":[221],"latency":[223,239],"trade":[224],"off.":[225],"offers":[228],"insights":[230],"into":[231],"interplay":[233],"between":[234],"training":[235],"strategy":[236],"dynamic":[241],"environments,":[243],"aiming":[244],"inform":[246],"development":[248],"more":[250],"resilient":[251],"solutions":[253],"considering":[254],"constraints":[257],"devices.":[260]},"counts_by_year":[{"year":2026,"cited_by_count":2}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-03-09T00:00:00"}
