PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
February 5, 2026Discover Internet of Things3 citationsOpen Access

Explainable federated learning through causal reasoning for intrusion detection in IoT

View Full Paper
FAFatima Asiri

Key Points

  • The aim is to enhance the explainability of intrusion detection within IoT through causal reasoning in federated learning.
  • Developed a framework integrating causal reasoning into federated learning for intrusion detection.
  • Distributed IoT clients perform local causal discovery and send causal summaries to a central server.
  • The central server creates a global causal graph from the causal summaries provided.
  • Achieved a prediction accuracy of approximately 98.5%.
  • Demonstrated effective scaling with 10, 25, and 50 clients.
  • Provided stable, transparent explanations based on causal analysis.

Abstract

Abstract The rapid growth of Internet of Things (IoT) devices has significantly increased the cyber-attack surface, rendering traditional centralized Intrusion Detection Systems (IDSs) impractical due to privacy concerns and communication bottlenecks. Federated Learning (FL) has become a privacy-preserving alternative, but most FL-based IDSs function as “black boxes, " relying on correlation-based explainability methods that do not reveal the underlying causal mechanisms of attacks. These limitations impede root-cause analysis and the creation of reliable security solutions. This paper introduces a new framework, Causal Explainable Federated Learning for IoT Intrusion Detection (Causal-FL-ID), which integrates causal reasoning directly into the FL process. In this setup, distributed IoT clients perform local causal discovery and send lightweight, privacy-preserving causal summaries to a central server. The server combines these summaries to create a global causal graph, providing deep insights into the causes of an intrusion. This method enables counterfactual reasoning, allowing security analysts to simulate interventions and assess their potential impact on threat mitigation. Extensive experiments on the IDSIoT2024 dataset demonstrate that the proposed framework achieves high prediction accuracy around 98. 5\% and scales effectively with 10, 25, and 50 clients. The results confirm that Causal-FL-ID not only delivers strong performance with manageable communication costs but also offers stable, transparent, and causally grounded explanations, marking a significant step toward more interpretable and resilient security systems for complex IoT environments.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Fatima Asiri (2026) studied this question.

synapsesocial.com/papers/6984359ef1d9ada3c1fb49e0https://doi.org/10.1007/s43926-026-00292-z
Ask AI
Helpful
Bookmark
Share
View Full Paper