2026/06/18 by Jorge Robalino-Díaz, Alejandro Cabrera‐Andrade, Sergio Luján‐Mora +1 · 1 voice
Computer Science · Engineering · #Advanced Malware Detection Techniques #Anomaly Detection Techniques and Applications #Smart Grid Security and Resilience
paper · pdf · doi:10.3389/frai.2026.1825067
openalex publication_date 2026/06/18 · openalex created_date 2026/06/19 · openalex updated_date 2026/07/23
The expansion of Internet of Things (IoT) and Internet of Medical Things (IoMT) infrastructures has increased the generation of multivariate sensor streams that reflect complex operational behaviors in industrial and clinical environments. Centralized anomaly detection approaches face limitations in IoMT due to privacy constraints, latency, and device heterogeneity. Federated learning (FL) enables distributed model training without data centralization; however, its behavior under highly non-Independent and Identically Distributed (non-IID) conditions remains insufficiently understood. This study proposes a trace-level behavioral modeling approach combined with federated training via FedAvg to analyze the impact of non-IID heterogeneity on anomaly detection. An Integrated Hybrid Dataset (IHD) comprising 71,980 behavioral traces, with 22,698 used for evaluation, was constructed from Edge-IIoTset, TONIoT, and IoMT data. The centralized model achieved F 1 = 0.981 and Recall = 0.993, while the federated model preserved discriminative capacity (AUC-ROC = 0.995) but reduced Recall to 0.530. Degradation is concentrated in IoMT (Recall = 0.290), with increased Brier Score and Expected Calibration Error, showing that preserved discrimination does not ensure operational effectiveness.