A HYBRID MACHINE LEARNING FRAMEWORK WITH HOMOMORPHIC ENCRYPTION FOR IOT NETWORK INTRUSION DETECTION AND PRIVACY-PRESERVING CLASSIFICATION
Author
Ashish Shukla, Dr. F Rahman
Abstract
This paper presents the design and implementation of a novel hybrid machine learning framework for IoT network intrusion detection, combining Random Forest (RF) and Feed-Forward Neural Networks (FFNN) in a layered classification pipeline. The framework is evaluated on the UNSW-NB15 dataset enriched with IoT sensor data, targeting nine attack categories including DoS, backdoors, worms, fuzzers, and exploits. The proposed RF-FFNN hybrid achieves 98.76% accuracy and 98.57% F1-score, outperforming standalone Logistic Regression (87.42%), Decision Trees (92.67%), MLP (95.14%), and XGBoost (96.71%) baselines. Additionally, this work integrates federated learning (FL) with CKKS-based homomorphic encryption (HE) to enable privacy-preserving collaborative model training across distributed healthcare IoT environments. Federated HE configurations achieve 97.45% accuracy with high privacy guarantees, demonstrating a practical accuracy-privacy trade-off. Feature importance analysis using recursive feature elimination identifies the top-15 discriminating features, including source/destination byte counts, protocol type, and connection state indicators. Comparative analysis validates the proposed framework against contemporary state-of-the-art methods, demonstrating superior performance across all standard evaluation metrics.
Keywords
IoT intrusion detection; Random Forest; feed-forward neural network; federated learning; homomorphic encryption; UNSW-NB15; cyber attack classification; privacy-preserving machine learning
Full Text:
References
[1] Smmarwar, S.K., Gupta, G.P., & Kumar, S. (2025). Smart deep learning model for enhanced IoT intrusion detection. Scientific Reports, 15, 20577.
[2] Rahman, M.M., Shakil, S.A., & Mustakim, M.R. (2025). A survey on intrusion detection system in IoT networks. Cyber Security and Applications, 3, 100082.
[3] Wu, Y., et al. (2025). Improved model for intrusion detection in the Internet of Things. Scientific Reports, 15, 21547.
[4] Seyedi, B. & Postolache, O. (2025). Securing IoT communications via anomaly traffic detection: Synergy of genetic algorithm and ensemble method. Sensors, 25(13), 4098.
[5] Bhattacharjee, D. (2025). FedHealthcare: Federated learning and lightweight additive homomorphic encryption-based privacy-preserving healthcare. Security and Privacy, 8(6), e70116.
[6] Jayaweera, R., Agrawal, H., & Karie, N.M. (2025). Federated security for privacy preservation of healthcare data in edge-cloud environments. Sensors, 25(16), 5108.
[7] Firdaus, M., Larasati, H.T., & Hyune-Rhee, K. (2025). Blockchain-based federated learning with homomorphic encryption for privacy-preserving healthcare data sharing. Internet of Things, 31, 101579.
[8] Kumbhar, H.R. & Srinivasa Rao, S. (2025). Federated learning enabled multi-key homomorphic encryption. Expert Systems with Applications, 268, 126197.
[9] Ji, R., Selwal, A., Kumar, N., & Padha, D. (2025). Cascading bagging and boosting ensemble methods for intrusion detection in cyber-physical systems. Security and Privacy, 8(1), e497.
[10] Subramaniam, T. et al. (2024). Enhancing IoT security: Optimizing anomaly detection through machine learning. Electronics, 13(11), 2148.
[11] Talukder, M.A., et al. (2025). Evaluating large transformer models for anomaly detection of resource-constrained IoT devices. Scientific Reports, 15.
[12] Saheed, Y.K., et al. (2024). GA-mADAM-IIoT: A new lightweight threats detection in the industrial IoT via genetic algorithm with attention mechanism and LSTM. Sensors International, 6, 100297.
[13] Saheed, Y.K., Misra, S., & Chockalingam, S. (2024). Modified genetic algorithm and fine-tuned LSTM network for intrusion detection in the IoT networks with edge capabilities. Applied Soft Computing, 155, 111434.
[14] Sinha, S. & Tomar, D.S. (2024). A comprehensive empirical analysis of datasets, regression-based feature selectors and linear SVM classifiers for intrusion detection. IEEE Internet of Things Journal.
[15] Ji, R., Kumar, N., & Padha, D. (2024). CNN-GWO-voting & hybrid: ensemble learning inspired intrusion detection for cyber-physical systems. Proceedings of the Indian National Science Academy, 1–15.
[16] Albinali, H. & Azzedin, F. (2025). Replay attacks in RPL-based Internet of Things: Comparative and empirical study. Computer Networks, 257, 110996.
[17] Soni, V., Bhatt, D.P., & Yadav, N.S. (2025). HAIS-IDS: A hybrid artificial immune system model for intrusion detection in IoT. Bulletin of the Polish Academy of Sciences, e152211.
[18] Maheswari, K.G., et al. (2025). Machine learning-inspired intrusion detection system for IoT: Security issues and future challenges. Computers & Electrical Engineering.
[19] Xie, Q., et al. (2024). Efficiency optimization techniques in privacy-preserving federated learning with homomorphic encryption: A brief survey. IEEE Internet of Things Journal.
[20] Babar, M., Qureshi, B., & Koubaa, A. (2024). Review on federated learning for digital transformation in healthcare through big data analytics. Future Generation Computer Systems, 160, 14–28.
[21] Shahid, B., et al. (2023). Enhancing IoT network security through deep learning-powered intrusion detection system. Internet of Things, 24, 100936.
[22] Sharma, B., Sharma, L., Lal, C., & Roy, S. (2023). Anomaly based network intrusion detection for IoT attacks using deep learning technique. Computers & Electrical Engineering, 107, 108626.
[23] Abusitta, A., et al. (2023). Deep learning-enabled anomaly detection for IoT systems. Internet of Things, 21, 100656.
[24] Almowsawi, A.A.H.D. (2024). Deep guard-IoT: A systematic review of AI-based anomaly detection frameworks for next-generation IoT security (2020–2024). Wasit Journal for Pure Sciences, 3, 70–77.
[25] Bhardwaj, R., et al. (2025). Machine learning and artificial intelligence for detecting cyber security threats in IoT environment. Natural Language Processing for Software Engineering, 1–14.