IDEAS home Printed from https://ideas.repec.org/a/gam/jftint/v18y2026i6p306-d1960879.html

Secure Federated Intrusion Detection for Resource-Constrained IoT Devices Using Lightweight Cryptography: A Hardware-Validated Study

Author

Listed:
  • Yerlan Tursynbek

    (Institute of Automation and Information Technologies, Satbayev University, Satbayev Str., 22, Almaty 050013, Kazakhstan)

  • Nurtay Albanbay

    (Institute of Automation and Information Technologies, Satbayev University, Satbayev Str., 22, Almaty 050013, Kazakhstan)

  • Djamel Djenouri

    (School of Computing and Creative Technology, University of the West of England, Bristol BS16 1QY, UK)

  • Shahid Latif

    (School of Computing and Creative Technology, University of the West of England, Bristol BS16 1QY, UK)

  • Ainur Akhmediyarova

    (Institute of Automation and Information Technologies, Satbayev University, Satbayev Str., 22, Almaty 050013, Kazakhstan)

  • Zhibek Alibiyeva

    (Institute of Automation and Information Technologies, Satbayev University, Satbayev Str., 22, Almaty 050013, Kazakhstan)

  • Janna Alimkulova

    (Department of Computer Engineering, Turan University, Almaty 050013, Kazakhstan)

  • Dina Oralbekova

    (Institute of Information and Computational Technologies, Almaty 050010, Kazakhstan)

Abstract

Federated learning (FL) enables distributed model training in IoT environments while keeping raw data on local devices. However, protecting model-update exchange is difficult on microcontroller-class devices due to strict latency, memory, and energy constraints. Existing studies often evaluate lightweight cryptography outside complete FL pipelines or on more powerful hardware, leaving its practical overhead on MCU-class devices insufficiently explored. This paper presents an end-to-end, hardware-validated secure framework for exchanging model updates in federated learning on resource-constrained IoT microcontrollers. Implemented on ESP32-based edge devices, the framework combines lightweight block ciphers (SPECK, SIMON, and PRESENT), HMAC-SHA256 for integrity verification, and ECDH-HKDF for session-key establishment. The evaluation assessed latency, throughput, RAM/ROM footprint, and energy consumption. Results show that SPECK provides the lowest overhead (0.13 µs/byte, 8.68 MB/s, 138.3 mJ), SIMON offers intermediate performance (0.41 µs/byte, 1.96 MB/s, 184.9 mJ), and PRESENT incurs the highest computational cost (89.37 µs/byte, 0.011 MB/s, 446.2 mJ). In the CICIoT2023 federated intrusion-detection evaluation, the secure model maintained stable convergence and achieved 85.43% accuracy after 20 rounds, remaining close to the centralized baseline. These findings demonstrate the practical feasibility of secure model-update exchange in FL on real IoT microcontrollers and provide hardware-grounded guidance for cipher selection under tight resource budgets.

Suggested Citation

  • Yerlan Tursynbek & Nurtay Albanbay & Djamel Djenouri & Shahid Latif & Ainur Akhmediyarova & Zhibek Alibiyeva & Janna Alimkulova & Dina Oralbekova, 2026. "Secure Federated Intrusion Detection for Resource-Constrained IoT Devices Using Lightweight Cryptography: A Hardware-Validated Study," Future Internet, MDPI, vol. 18(6), pages 1-30, June.
  • Handle: RePEc:gam:jftint:v:18:y:2026:i:6:p:306-:d:1960879
    as

    Download full text from publisher

    File URL: https://www.mdpi.com/1999-5903/18/6/306/pdf
    Download Restriction: no

    File URL: https://www.mdpi.com/1999-5903/18/6/306/
    Download Restriction: no
    ---><---

    More about this item

    Keywords

    ;
    ;
    ;
    ;
    ;
    ;
    ;
    ;

    JEL classification:

    Statistics

    Access and download statistics

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:gam:jftint:v:18:y:2026:i:6:p:306-:d:1960879. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    We have no bibliographic references for this item. You can help adding them by using this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: MDPI Indexing Manager The email address of this maintainer does not seem to be valid anymore. Please ask MDPI Indexing Manager to update the entry or send us the correct address (email available below). General contact details of provider: https://www.mdpi.com .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.