CFA-Optimized Adaptive Trust-Aware FedProx with Feature-Selected CNN-Transformer for High-Accuracy SDN-IoT Intrusion Detection


Dalal S., Choudhary S., Dixit R., Elkiran H., Kaushik J., REŞİT C., ...Daha Fazla

CMES - Computer Modeling in Engineering and Sciences, cilt.148, sa.3, 2026 (SCI-Expanded, Scopus)

  • Yayın Türü: Makale / Tam Makale
  • Cilt numarası: 148 Sayı: 3
  • Basım Tarihi: 2026
  • Doi Numarası: 10.32604/cmes.2026.086995
  • Dergi Adı: CMES - Computer Modeling in Engineering and Sciences
  • Derginin Tarandığı İndeksler: Science Citation Index Expanded (SCI-EXPANDED), Scopus, Aerospace Database, Compendex, INSPEC, zbMATH, Materials Science & Engineering Collection (ProQuest), Technology Collection (ProQuest)
  • Anahtar Kelimeler: catch fish algorithm (CFA), CNN-transformer, federated learning, FedProx optimization, SDN-IoT intrusion detection, trust-aware aggregation
  • İstanbul Medipol Üniversitesi Adresli: Evet

Özet

With the fast development of Software-Defined Networking-enabled Internet of Things (SDN-IoT) environments, the attack surface of modern network infrastructures has been enlarged to a great extent, making efficient and privacy-preserving intrusion detection a critical requirement in cybersecurity. Traditional centralized intrusion detection methods are usually affected by privacy issues, communication overhead, and performance degradation in heterogeneous data distribution. To tackle these problems, this paper presents a distributed SDN-IoT intrusion detection system based on an Adaptive Trust-Aware FedProx framework optimized by the Catch Fish Algorithm (CFA), which is implemented by a Feature-Selected CNN-Transformer architecture. The proposed system combines the following techniques into a single learning environment that respects privacy: (a) feature selection based on mutual information, (b) CNN-Transformer-based traffic classification, (c) adaptive trust-aware federated learning, (d) FedProx regularization, and (e) hyperparameter tuning using the Catch Fish Algorithm (CFA). Feature selection is used to determine the most informative traffic attributes, and the CNN-Transformer model is able to extract both local and long-range traffic connections. The adaptive trust mechanism includes two components: model consistency and detection performance, allowing trust-weighted aggregation and minimizing the impact of unreliable aggregation participants. Moreover, CFA is employed to fine-tune some critical hyperparameters to boost federated convergence and detection accuracy at the same time. The ASEADOS-SDN-IoT dataset consists of 457,044 network traffic records and is evaluated in experimental evaluation for various attack categories. The proposed framework achieved an accuracy of 86.67%, precision of 87.39%, recall of 86.67%, F1-score of 86.43%, MCC of 0.7763, ROC-AUC of 0.9756, and PR-AUC of 0.9121. After 20 communication rounds, the federated learning process decreased the average client loss from 0.9567 to 0.7023 and preserved trust scores ranging from 0.9029 to 1.0000 on the participating clients. Moreover, the system reached 37,005 samples per second throughput and 0.027 ms per sample response time, showing its potential for real-time use. The results validate that the proposed framework can effectively and efficiently detect intrusions in distributed SDN-IoT networks while preserving privacy.