Intrusion Detection Systems (IDSs) are essential for protecting connected IoT devices from attacks that threaten network and device integrity, confidentiality, and availability. Machine learning (ML) models are increasinglyadopted for IDSs due to their ability to process large volumes of traffic and detect complex threats. However, traditional ML approaches typically rely on centralized data collection, raising privacy and scalability concerns. Federated learning (FL) addresses these issues by enabling collaborative model training across distributed clients without requiring raw data exchange. While much of the existing research on FL-based IDSs focuses on improving accuracy and detection rates, the equally critical aspect of model uncertainty has received little attention. Reliable uncertainty estimation, often achieved through proper model calibration, is crucial for trustworthy decision-making in safety-critical applications such as intrusion detection. This paper proposes a novel federated calibration framework that enables clients to collaboratively train a calibration module while preserving data privacy. Calibration is performed without sharing any local calibration datasets, using a lightweight and efficient method compatible with the classical FL workflow. Experimental results demonstrate that our approach improves model’s confidence estimation, while maintaining high predictive performance, making it particularly well-suited for trustworthy IDS deployments in IoT networks.

Talpini, J., Civiero, N., Sartori, F., Savi, M. (In corso di stampa). A Federated Calibration Framework for ML-Based Intrusion Detection Systems. In Agents and Artificial Intelligence 17th International Conference, ICAART 2025, Porto, Portugal, February 23–25, 2025, Revised Selected Papers, Part III (pp.524-541). Springer Science and Business Media Deutschland GmbH [10.1007/978-3-032-25035-3_25].

A Federated Calibration Framework for ML-Based Intrusion Detection Systems

Talpini J.;Sartori F.;Savi M.
In corso di stampa

Abstract

Intrusion Detection Systems (IDSs) are essential for protecting connected IoT devices from attacks that threaten network and device integrity, confidentiality, and availability. Machine learning (ML) models are increasinglyadopted for IDSs due to their ability to process large volumes of traffic and detect complex threats. However, traditional ML approaches typically rely on centralized data collection, raising privacy and scalability concerns. Federated learning (FL) addresses these issues by enabling collaborative model training across distributed clients without requiring raw data exchange. While much of the existing research on FL-based IDSs focuses on improving accuracy and detection rates, the equally critical aspect of model uncertainty has received little attention. Reliable uncertainty estimation, often achieved through proper model calibration, is crucial for trustworthy decision-making in safety-critical applications such as intrusion detection. This paper proposes a novel federated calibration framework that enables clients to collaboratively train a calibration module while preserving data privacy. Calibration is performed without sharing any local calibration datasets, using a lightweight and efficient method compatible with the classical FL workflow. Experimental results demonstrate that our approach improves model’s confidence estimation, while maintaining high predictive performance, making it particularly well-suited for trustworthy IDS deployments in IoT networks.
paper
Federated Learning; Machine Learning; Model Calibration; Network Intrusion Detection;
English
17th International Conference, ICAART 2025 - February 23–25, 2025
2025
van den Herik, HJ; Rocha, AP; Steels, L
Agents and Artificial Intelligence 17th International Conference, ICAART 2025, Porto, Portugal, February 23–25, 2025, Revised Selected Papers, Part III
9783032250346
2-lug-2026
In corso di stampa
16518
524
541
https://link.springer.com/chapter/10.1007/978-3-032-25035-3_25
open
Talpini, J., Civiero, N., Sartori, F., Savi, M. (In corso di stampa). A Federated Calibration Framework for ML-Based Intrusion Detection Systems. In Agents and Artificial Intelligence 17th International Conference, ICAART 2025, Porto, Portugal, February 23–25, 2025, Revised Selected Papers, Part III (pp.524-541). Springer Science and Business Media Deutschland GmbH [10.1007/978-3-032-25035-3_25].
File in questo prodotto:
File Dimensione Formato  
Talpini-2026-ICAART 2025-preprint.pdf

accesso aperto

Tipologia di allegato: Submitted Version (Pre-print)
Licenza: Creative Commons
Dimensione 1.01 MB
Formato Adobe PDF
1.01 MB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/10281/622544
Citazioni
  • Scopus 0
  • ???jsp.display-item.citation.isi??? ND
Social impact