EdgeSecure: A Heterogeneous Federated Learning Framework for Lightweight Malware Detection in Resource-Constrained IoT Networks

Authors

  • Baraa Farhan Computer Science Department, College of Education for Pure Sciences, Wasit University, Alkut, Wasit-Iraq

DOI:

https://doi.org/10.71229/ms6rq592

Keywords:

Edge Computing, , Federated Learning,, FedProx,, IoT Security, , Lightweight Deep Learning

Abstract

The rapid expansion of Internet of Things (IoT) devices has intensified security challenges, particularly malware attacks that continue to grow in sophistication while operating under strict resource constraints. Conventional centralized machine learning–based malware detection approaches face significant limitations in IoT environments due to privacy risks, high communication overhead, and computational inefficiency. To overcome these challenges, this paper presents a lightweight federated learning framework tailored for real-time malware detection in resource-constrained IoT systems. The proposed approach employs the Federated Proximal (FedProx) algorithm to effectively address the non-IID data distribution inherent in heterogeneous IoT networks. In parallel, a compact multilayer perceptron (MLP) architecture is designed with fewer than 10,000 parameters, ensuring low computational complexity and energy efficiency suitable for edge devices. The framework also integrates intelligent data preprocessing strategies to mitigate class imbalance and supports automatic binary transformation of multi-class malware detection tasks. Comprehensive experimental evaluations are conducted on two representative IoT security datasets, IoT23 and DNN-EdgeIIoT. Using five federated clients across 50 communication rounds, the proposed framework demonstrates robust and consistent performance. On the IoT23 dataset, it achieves an accuracy of 93.90%, an F1-score of 96.44%, and an AUC of 99.01%. Similarly, on the DNN-EdgeIIoT dataset, the framework attains 99.32% accuracy, a 98.73% F1- score, and a 99.80% AUC. Notably, the model maintains exceptionally high precision, reaching 99.74% on IoT23 and 99.85% on DNN-EdgeIIoT.Overall, the proposed framework addresses three critical research gaps: preserving data privacy without centralized data aggregation, handling non-IID data distributions in IoT networks, and enabling efficient computation for resource-limited devices. The results demonstrate that the federated model achieves performance comparable to or exceeding centralized approaches, while significantly reducing communication overhead, making it a practical and scalable solution for IoT malware detection.

References

[1] A. I. Zreikat, Z. AlArnaout, A. Abadleh, E. Elbasi, and N. Mostafa, "The integration of the internet of things (IoT) applications into 5G networks: a review and analysis," Computers, vol. 14, no. 7, p. 250, 2025. [Online]. Available: https://doi.org/10.3390/computers14070250

[2] V. Pai, B. H. K. Pai, G. S. Sudhiksha, V. Kamath, K. Varsha, and S. Manjunatha, "Systematic approach for malware detection in IoT devices: enhancing security and performance," Int. J. Comput. Intell. Syst., vol. 18, p. 196, 2025. [Online]. Available: https://doi.org/10.1007/s44196-025-00939-9

[3] N. Singh, R. Buyya, and H. Kim, "Securing cloud-based internet of things: challenges and mitigations," Sensors, vol. 25, no. 1, p. 79, 2025. [Online]. Available: https://doi.org/10.3390/s25010079

[4] M. Aggarwal, M. K. Khan, K. Alghathbar, and B. Raza, "Federated learning on internet of things: extensive and systematic review," Comput., Mater. Continua, vol. 79, no. 2, pp. 1795–1834, 2024. [Online]. Available: https://doi.org/10.32604/cmc.2024.049846

[5] E. Dritsas and M. Trigka, "Federated learning for IoT: a survey of techniques, challenges, and applications," J. Sensor Actuator Netw., vol. 14, no. 1, p. 9, 2025. [Online]. Available: https://doi.org/10.3390/jsan14010009

[6] R. Kumar and R. Tripathi, "Privacy-preserving data leakage safeguards in industrial internet of things using blockchain," Comput. Commun., vol. 214, pp. 88–101, 2024. [Online]. Available: https://doi.org/10.1016/j.comcom.2024.01.015

[7] D. Canavese, L. Mannella, L. Regano, and C. Basile, "Security at the edge for resource-limited IoT devices," Sensors, vol. 24, no. 2, p. 590, 2024. [Online]. Available: https://doi.org/10.3390/s24020590

[8] H. S. Alharthi, S. Alshehri, and M. Kalkatawi, "Blockchain-enabled hierarchical federated learning framework for anomaly detection in IoT systems," Appl. Sci., vol. 15, no. 24, p. 13037, 2025. [Online]. Available: https://doi.org/10.3390/app152413037

[9] S. Garcia, A. Parmisano, and M. J. Erquiaga, IoT-23: a labeled dataset with malicious and benign IoT network traffic, Zenodo, 2020. [Online]. Available: https://doi.org/10.5281/zenodo.4743746

[10] M. A. Ferrag, O. Friha, D. Hamouda, L. Maglaras, and H. Janicke, "Edge-IIoTset: a new comprehensive realistic cyber security dataset of IoT and IIoT applications for centralized and federated learning," IEEE Access, vol. 10, pp. 40281–40306, 2022. [Online]. Available: https://doi.org/10.1109/ACCESS.2022.3165809

[11] C. S. G and S., "A comprehensive survey on deep learning based malware detection techniques," Comput. Sci. Rev., vol. 47, p. 100529, 2022. [Online]. Available: https://doi.org/10.1016/j.cosrev.2022.100529

[12] S. U. Qureshi et al., "Systematic review of deep learning solutions for malware detection and forensic analysis in IoT," J. King Saud Univ. - Comput. Inf. Sci., vol. 36, no. 8, p. 102164, 2024. [Online]. Available: https://doi.org/10.1016/j.jksuci.2024.102164

[13] V. Vasilev, V. Shterev, and M. Nenova, "Optimizing activation function for parameter reduction in CNNs on CIFAR-10 and CINIC-10," Appl. Sci., vol. 15, no. 8, p. 4292, 2025. [Online]. Available: https://doi.org/10.3390/app15084292

[14] M. Noble et al., "Decentralized model training and privacy preservation in federated learning systems," IEEE Trans. Neural Netw. Learn. Syst., vol. 35, no. 4, pp. 1120–1132, 2024. [Online]. Available: https://doi.org/10.1109/TNNLS.2024.104231

[15] A. Asiri et al., "Closing the performance gap between centralized and federated learning in edge networks," J. Netw. Comput. Appl., vol. 221, p. 103850, 2025. [Online]. Available: https://doi.org/10.1016/j.jnca.2025.103850

[16] J. V. S. Souza, C. B. Vieira, G. D. C. Cavalcanti, and R. M. O. Cruz, "Imbalanced malware classification: an approach based on dynamic classifier selection," arXiv preprint arXiv:2504.00041, 2025. [Online]. Available: https://doi.org/10.48550/arxiv.2504.00041

[17] O. Elharrouss, N. Almaadeed, S. Al-Maadeed, and Y. Akbari, "Task-based loss functions in computer vision: a comprehensive review," arXiv preprint arXiv:2504.04242, 2025. [Online]. Available: https://doi.org/10.48550/arxiv.2504.04242

[18] Y. Zhang et al., "Adam-mini: use fewer learning rates to gain more," arXiv preprint arXiv:2406.16793, 2024. [Online]. Available: https://doi.org/10.48550/arXiv.2406.16793

[19] R. Lu et al., "Adaptive asynchronous federated learning," Future Gener. Comput. Syst., vol. 152, pp. 193–206, 2023. [Online]. Available: https://doi.org/10.1016/j.future.2023.11.001

[20] F. J. Piran, Z. Chen, M. Imani, and F. Imani, "Privacy-preserving federated learning with differentially private hyperdimensional computing," Comput. Electr. Eng., vol. 123, p. 110261, 2025. [Online]. Available: https://doi.org/10.1016/j.compeleceng.2025.110261

[21] Y. Li, J. Lai, R. Zhang, and M. Sun, "Secure and efficient multi-key aggregation for federated learning," Inf. Sci., vol. 654, p. 119830, 2023. [Online]. Available: https://doi.org/10.1016/j.ins.2023.119830

[22] R. U. Z. Wani and O. Can, "FED-EHR: a privacy-preserving federated learning framework for decentralized healthcare analytics," Electronics, vol. 14, no. 16, p. 3261, 2025. [Online]. Available: https://doi.org/10.3390/electronics14163261

[23] A. Gokcen and A. Boyaci, "Robust federated learning with confidence-weighted filtering and GAN-based completion under noisy and incomplete data," arXiv preprint arXiv:2505.09733, 2025. [Online]. Available: https://doi.org/10.48550/arxiv.2505.09733

fig 4

Downloads

Published

2026-09-10

Issue

Section

Original Articles

How to Cite

EdgeSecure: A Heterogeneous Federated Learning Framework for Lightweight Malware Detection in Resource-Constrained IoT Networks. (2026). Al-Noor Journal of Engineering Management and Computer Science, 2(4), 256-273. https://doi.org/10.71229/ms6rq592

Similar Articles

31-40 of 49

You may also start an advanced similarity search for this article.