Survey of Federated Learning for Cyber Threat Intelligence in Industrial IoT: Techniques, Applications and Deployment Models

The Industrial Internet of Things (IIoT) is transforming industrial operations through connected devices and real-time automation but also introduces significant cybersecurity risks. Cyber threat intelligence (CTI) is critical for detecting and mitigating such threats, yet traditional centralized CT...

وصف كامل

التفاصيل البيبلوغرافية
الحاوية / القاعدة:Future Internet
المؤلفون الرئيسيون: Abin Kumbalapalliyil Tom, Ansam Khraisat, Tony Jan, Md Whaiduzzaman, Thien D. Nguyen, Ammar Alazab
التنسيق: مقال
اللغة:الإنجليزية
منشور في: MDPI AG 2025-09-01
الموضوعات:
الوصول للمادة أونلاين:https://www.mdpi.com/1999-5903/17/9/409
الوصف
الملخص:The Industrial Internet of Things (IIoT) is transforming industrial operations through connected devices and real-time automation but also introduces significant cybersecurity risks. Cyber threat intelligence (CTI) is critical for detecting and mitigating such threats, yet traditional centralized CTI approaches face limitations in latency, scalability, and data privacy. Federated learning (FL) offers a privacy-preserving alternative by enabling decentralized model training without sharing raw data. This survey explores how FL can enhance CTI in IIoT environments. It reviews FL architectures, orchestration strategies, and aggregation methods, and maps their applications to domains such as intrusion detection, malware analysis, botnet mitigation, anomaly detection, and trust management. Among its contributions is an empirical synthesis comparing FL aggregation strategies—including FedAvg, FedProx, Krum, ClippedAvg, and Multi-Krum—across accuracy, robustness, and efficiency under IIoT constraints. The paper also presents a taxonomy of FL-based CTI approaches and outlines future research directions to support the development of secure, scalable, and decentralized threat intelligence systems for industrial ecosystems.
تدمد:1999-5903