PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
April 1, 2026Electronics2 citationsOpen Access

Federated Retrieval-Augmented Generation for Cybersecurity in Resource-Constrained IoT and Edge Environments: A Deployment-Oriented Scoping Review

View Full Paper
HHHangyu HeThe University of SydneyXYXin YuanCommonwealth Scientific and Industrial Research OrganisationKWKai WuKing University

Key Points

  • This review aims to explore the deployment of federated retrieval-augmented generation (FedRAG) systems in enhancing cybersecurity for IoT and edge environments under resource constraints.
  • Conducted a scoping review following PRISMA-ScR guidance.
  • Synthesized findings from 82 studies published between 2020 and 2026.
  • Developed a taxonomy clarifying the components of federated systems and their deployment.
  • Mapped the RAG+FL attack surface and summarized practical defenses for deployment.
  • Identified trade-offs in robustness, privacy, latency, and maintainability.
  • Distinguished key components and challenges in FedRAG architecture.
  • Highlighted open research priorities for effective implementation in real-world settings.

Abstract

Cybersecurity operations in IoT and edge environments require fast, evidence-grounded decisions under strict resource and trust constraints. While large language models can support triage and incident analysis, their parametric knowledge may be outdated and prone to hallucination. Retrieval-augmented generation (RAG) improves grounding by conditioning responses on retrieved evidence, but also introduces new risks such as knowledge-base poisoning, indirect prompt injection, and embedding leakage. Federated learning enables collaborative adaptation without centralizing sensitive data, motivating federated RAG (FedRAG) architectures for distributed cybersecurity deployments. This study presents a deployment-oriented scoping review of FedRAG for cybersecurity. The review follows PRISMA-ScR reporting guidance and synthesizes 82 studies published between 2020 and 2026, identified through keyword search and citation snowballing over OpenAlex, arXiv, and Crossref. We develop a taxonomy that clarifies the components of federated systems, deployment locations, trust boundaries, and protected assets. We further map the combined RAG+FL attack surface, summarize practical defenses and system patterns, and distill actionable guidance for secure, privacy-preserving, and efficient FedRAG deployment in real-world IoT and edge scenarios. Our synthesis highlights recurring trade-offs among robustness, privacy, latency, communication overhead, and maintainability, and identifies open research priorities in benchmark design, governance mechanisms, and cross-silo evaluation protocols for practical deployment.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

He et al. (2026) studied this question.

synapsesocial.com/papers/69ccb69d16edfba7beb88534https://doi.org/10.3390/electronics15071409
Ask AI
Helpful
Bookmark
Share
View Full Paper