Federated Learning–Driven Intrusion Detection in Cloud–IoT Settings: A Security- Centric Survey
Summary
The integration of Cloud–IoT ecosystems has accelerated automation and intelligent decisionmakingbut simultaneously introduced critical vulnerabilities that traditional intrusion detectionsystems (IDS) struggle to address. Centralized IDS approaches suffer from scalabilitylimitations, privacy risks, and single points of failure, making them inadequate for highlydistributed IoT environments. Federated Learning (FL) has emerged as a promising paradigmto enhance IDS by enabling collaborative model training without sharing raw data, therebypreserving privacy, reducing communication overhead, and improving detection accuracy. Thissurvey provides a comprehensive review of FL-driven IDS for Cloud–IoT networks, examiningarchitectures, datasets, evaluation metrics, and current methodologies. It discusses state-of-theartsolutions, including cloud–IoT collaboration, hybrid federated frameworks, and privacypreservingmechanisms such as differential privacy and secure aggregation. Key challenges areidentified, including poisoning and inference attacks, client heterogeneity, non-IID data, andthe absence of standardized benchmarks. Future research directions highlight the integration ofFL with edge intelligence, 6G, explainable AI, energy-efficient protocols, and blockchain tobuild robust, transparent, and scalable IDS. Ultimately, FL is positioned as a cornerstone forsecuring next-generation Cloud–IoT infrastructures by balancing performance, privacy, andadaptability.