Experimental evaluation demonstrates traffic-constrained split learning achieves high botnet detection accuracy in IoT networks, indicating viable privacy and resource trade-offs.
Key Points
To evaluate whether a traffic-constrained multi-client split-learning framework can balance high botnet detection accuracy with low client communication, energy usage, and raw data exposure.
Evaluated traffic-constrained split learning across eight IoT clients and one edge server on the BoT-IoT, N-BaIoT, and CIC-IDS2017 datasets.
Profiled candidate cut layers (L1–L6) under communication budgets, exchanging activations and gradients while keeping raw data local.
Benchmarked split learning against centralized learning, federated learning, and SplitFed-v1 using matched partitions and fixed 10-epoch optimization workloads.
Split learning achieved macro F1 scores of 98.88% (BoT-IoT), 98.42% (N-BaIoT), and 97.51% (CIC-IDS2017) with a mean of 98.27%, compared to 98.52% for centralized learning and 97.84% for federated learning.
The selected L4 cut consumed 95 MB per epoch (0.95 GB total) versus 405 MB per epoch (4.05 GB total) for federated learning, with early splits minimizing client energy at 248 J and middle splits minimizing system energy at 780 J.
Moving from cut layer L1 to L6 increased reconstruction NRMSE from 0.18 to 0.71, reduced membership-inference AUC from 0.71 to 0.53, lowered inversion success from 75% to 20%, and reduced poisoning degradation from 6.8 to 3.9 percentage points.