Intrusion Detection Systems (IDSs) are essential for protecting connected IoT devices from attacks that threaten network and device integrity, confidentiality, and availability. Machine learning (ML) models are increasinglyadopted for IDSs due to their ability to process large volumes of traffic and detect complex threats. However, traditional ML approaches typically rely on centralized data collection, raising privacy and scalability concerns. Federated learning (FL) addresses these issues by enabling collaborative model training across distributed clients without requiring raw data exchange. While much of the existing research on FL-based IDSs focuses on improving accuracy and detection rates, the equally critical aspect of model uncertainty has received little attention. Reliable uncertainty estimation, often achieved through proper model calibration, is crucial for trustworthy decision-making in safety-critical applications such as intrusion detection. This paper proposes a novel federated calibration framework that enables clients to collaboratively train a calibration module while preserving data privacy. Calibration is performed without sharing any local calibration datasets, using a lightweight and efficient method compatible with the classical FL workflow. Experimental results demonstrate that our approach improves model’s confidence estimation, while maintaining high predictive performance, making it particularly well-suited for trustworthy IDS deployments in IoT networks.
Talpini, J., Civiero, N., Sartori, F., Savi, M. (In corso di stampa). A Federated Calibration Framework for ML-Based Intrusion Detection Systems. In Agents and Artificial Intelligence 17th International Conference, ICAART 2025, Porto, Portugal, February 23–25, 2025, Revised Selected Papers, Part III (pp.524-541). Springer Science and Business Media Deutschland GmbH [10.1007/978-3-032-25035-3_25].
A Federated Calibration Framework for ML-Based Intrusion Detection Systems
Talpini J.;Sartori F.;Savi M.
In corso di stampa
Abstract
Intrusion Detection Systems (IDSs) are essential for protecting connected IoT devices from attacks that threaten network and device integrity, confidentiality, and availability. Machine learning (ML) models are increasinglyadopted for IDSs due to their ability to process large volumes of traffic and detect complex threats. However, traditional ML approaches typically rely on centralized data collection, raising privacy and scalability concerns. Federated learning (FL) addresses these issues by enabling collaborative model training across distributed clients without requiring raw data exchange. While much of the existing research on FL-based IDSs focuses on improving accuracy and detection rates, the equally critical aspect of model uncertainty has received little attention. Reliable uncertainty estimation, often achieved through proper model calibration, is crucial for trustworthy decision-making in safety-critical applications such as intrusion detection. This paper proposes a novel federated calibration framework that enables clients to collaboratively train a calibration module while preserving data privacy. Calibration is performed without sharing any local calibration datasets, using a lightweight and efficient method compatible with the classical FL workflow. Experimental results demonstrate that our approach improves model’s confidence estimation, while maintaining high predictive performance, making it particularly well-suited for trustworthy IDS deployments in IoT networks.| File | Dimensione | Formato | |
|---|---|---|---|
|
Talpini-2026-ICAART 2025-preprint.pdf
accesso aperto
Tipologia di allegato:
Submitted Version (Pre-print)
Licenza:
Creative Commons
Dimensione
1.01 MB
Formato
Adobe PDF
|
1.01 MB | Adobe PDF | Visualizza/Apri |
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.


