Evidence map›Paper›PMID 42249052›Full record

ArticleScientific reports2026

Non-IID and aware federated intrusion detection with PBFT with secured model aggregation for multi institutional healthcare internet of things networks.

Sudhakar Sengan, Chin-Shiuh Shieh

Abstract read
In one paragraph

Article in Scientific reports, 2026. The graph could read no effect estimate from its abstract, so it casts no vote on the map. Not yet cited in PubMed.

0numbers the graph read from it
0cells of the map it votes in
0citing papers in PubMed
–field-weighted citation impact
1 · What the graph read from it

What it found

Each row is one number read from the abstract, on the scale the paper reported it, with its interval. Left of the dashed line favours the treatment, right favours the comparator. Under each row is the sentence it came from. New to these charts? A ten-minute tutorial.

The abstract states no effect estimate the extractor could read, or names no intervention and outcome on the map, so this paper lights no cell and moves no belief. It is still indexed, cited and linked below.

2 · The registry

The trial behind it

Trials whose registry record cites this paper, or whose number appears in the abstract. A trial that started after this paper was published is citing it as background, not reporting it.

Neither the registry nor the abstract names a trial number. If this is a trial report, that itself is worth knowing.

3 · Its place in the literature

Who cites it

0 citing papers in PubMed.

No citing paper in PubMed yet.

4 · The record

Corrections and comments

PubMed lists nothing against this paper. Absence here is not a guarantee, only a check that was made.

5 · Who and what money

Authors and funding

2 authors.

Sudhakar SenganDepartment of Computer Science and Engineering, PSN College of Engineering and Technology, Tirunelveli, Tamil Nadu, 627152, India. sudhakarsengan@psncet.ac.in.
Chin-Shiuh ShiehDepartment of Electronic Engineering, Research Institute of IoT Cybersecurity, National Kaohsiung University of Science and Technology, Kaohsiung, Taiwan.

Funding

No grant is acknowledged in the PubMed record.

6 · The paper itself

Abstract

Multi-institutional healthcare Internet of Things (IoT) networks face a core challenge between combined intrusion detection and patient data privacy. Raw traffic records cannot be shared across institutional boundaries, yet local models trained on institution-specific data alone generalize poorly to attack distributions that differ from those practical in real healthcare IoT deployments. Federated Learning (FL) addresses privacy constraints by storing data locally at each institution, but it introduces statistical heterogeneity across institutions. Local data at each institution are non-independent and non-identically distributed due to clinical specialization, protocol diversity, and deployment-scale asymmetry. Standard federated averaging cannot handle this non-IID condition, and detection performance lowers significantly as a result. Existing Federated Intrusion Detection Systems (FIDS) implied that all participating institutions were honest. But this hypothesis cannot hold in real multi-institutional consortia, because Byzantine participants can corrupt the global model by submitting manipulated gradient updates. In this work, a Non-IID-Aware Federated Intrusion Detection System (N-IID-AFIDS) is proposed for multi-institutional healthcare IoT networks and is designed to address both challenges simultaneously. A cluster-weighted aggregation mechanism is used in this N-IID-AFIDS, grouping institutions by distributional similarity through spectral clustering of a Wasserstein-based affinity matrix and applying gradient divergence correction to submitted updates before aggregation. Protocol-aware Deep Sparse Autoencoder (DSAE) adaptation is also part of this model, and it uses local feature normalization based on an institutional protocol mixture and a distribution alignment regularizer. This regularizer operates without raw data exchange across institutions. This work extends practical Byzantine Fault Tolerance (PBFT) consensus from event logging for detection to model update validation. Geometric median-based Byzantine filtering, together with reputation-based participation control, is also added to this model. The proposed model is evaluated on the IoT-Flock and CICIoT2023 datasets across three non-IID severity levels, based on combined skew in quantity, labels, and features. It achieved non-IID detection accuracies of 93.17% on IoT-Flock and 89.84% on CICIoT2023. And this model is the only federated method in the comparison that reports non-IID performance on both datasets simultaneously. It also retains 83.61% accuracy with four Byzantine participants and meets a 16 ms clinical real-time detection constraint, converging in 29-67 rounds, faster than other federated baselines.

Indexed as

Computer SecurityInternet of ThingsAlgorithmsComputer Communication NetworksDelivery of Health CareFederated LearningHumansBlockchainByzantine ResilienceFederated LearningHealthcare IoT SecurityIntrusion DetectionNon-IID DataPBFT Consensus

Identifiers

PMID42249052
PMCPMC13415842

What OpenQuestion holds

Textmetadata
LicenceCC BY-NC-ND
Read underepoch 390

Registered trials

None linked

Read under generation 80e0d062 · epoch 390. Bibliography from PubMed, PubMed Central and OpenAlex; grants from NIH RePORTER; trial links from ClinicalTrials.gov; estimates, votes and beliefs from the OpenQuestion graph.