Impact Factor: 7.883
Submit Paper
Volume 12, Issue 9 (September 2026)

A Privacy-preserving Federated Learning Framework With Dual Explainability For Hybrid Cnn–lstm Based Anomaly Detection In Iot Network Traffic

Impact Factor
7.883
Call For Paper
Volume 12 Issue 10

October 2026

Download Paper Format
Copyright Form
Share on:

Author(s)

Lakshya Kumar Tiwari Prof. Jai Mungi Dr. Komal Tahiliani

Abstract

Intrusion Detection Systems (IDS) For The Internet Of Things Face A Three-way Tension: Deep Models Detect Attacks Accurately But Behave As Opaque Black Boxes, Centralised Training Pipelines Require Raw Traffic To Be Exported From Every Device In Violation Of Data-protection Expectations, And Lightweight Edge Hardware Cannot Host Heavyweight Detectors. This Paper Proposes A Framework That Resolves All Three Constraints Simultaneously. A Hybrid One-dimensional Convolutional And Long Short-term Memory (CNN–LSTM) Network Captures Both The Spatial Structure Of Individual Flow Records And The Temporal Signature Of Multi-stage Attacks. The Model Is Trained Under A Federated Learning Protocol In Which Distributed IoT Clients Perform Local Optimisation And Exchange Only Weight Updates, Aggregated At A Central Server With The FedAvg Rule, So Raw Traffic Never Leaves Its Point Of Capture. On Top Of The Converged Global Model, A Dual Explainability Layer Couples SHAP, Which Supplies Global Feature-attribution Rankings, With LIME, Which Produces An Instance-level Rationale For Every Alert Raised. The Framework Is Evaluated On The CIC-IoT2023 Benchmark, Whose 46.7 Million Flow Records From 105 Real Devices Are Grouped Into Eight Classes Spanning DDoS, DoS, Reconnaissance, Web-based, Brute-force, Spoofing And Mirai Activity Alongside Benign Traffic. Under A Ten-client Federated Deployment The Proposed Detector Attains 99.21% Binary And 97.86% Eight-class Accuracy With A Macro F1-score Of 97.42%, Remaining Within Half A Percentage Point Of Its Centralised Counterpart While Eliminating Raw-data Centralisation, And Inter-arrival Time, Transmission Rate And TCP-flag Statistics Emerge As The Dominant Explanatory Features. The Results Indicate That Privacy, Accuracy And Interpretability Need Not Be Traded Against One Another In IoT Intrusion Detection.


Keywords

Internet Of Things; Intrusion Detection; Federated Learning; CNN–LSTM; Explainable Artificial Intelligence; SHAP; LIME; CIC-IoT2023; FedAvg; Privacy Preservation.

Paper ID

IJSARTV12I9105900

Publication Date

September 19, 2026

Research Area

Computer Science And Engineering

Submit Your Paper to IJSART

Join the global research community with IJSART. Submit your paper, share your work, and gain worldwide recognition!