cover

PatternIQ Mining (PIQM)

Published by Sahara Digital Publication  •  eISSN: 3006-8894

Federated Graph Neural Pattern Learning Framework for Adaptive Intrusion Detection in Large-Scale IoT Networks

Volume 3, Issue 1 2026
Original Research

Shamsi Lawati and Zainab Mahmood Al Obaidi

Received: 2026-01-12
Accepted: 2026-01-30
Published: 2026-01-30
99 Views 59 Downloads

Abstract

Internet of Things (IoT) systems are a major source of vulnerability for large networks, leaving
them particularly susceptible to distributed denial of service (DDoS) attacks, botnet growth,
spoofing and zero-day attacks. The existing centralized intrusion detection systems (IDSs) are
linked to high communication overhead, privacy leakage, weak scalability and low flexibility to
support heterogeneous IoT environments. In addition, traditional machine learning methods do not
perform well at encapsulating multifaceted spatial relations and evolving patterns of
communication among related IoT devices, resulting in a lower detection rate and slower threat
response. To overcome these shortcomings, the author suggests a Federated Graph Neural Pattern
Learning Framework (FGNPLF) for adaptive intrusion detection in large-scale IoT networks. The
proposed architecture integrates Federated Learning (FL) with Graph Neural Networks (GNNs) to
facilitate large-scale collaborative learning while preserving the privacy of data on the edge devices.
By generating a dynamic communication graph from the IoT traffic, the model is able to detect the
anomalous behavioral patterns in real-time, using graph-based feature aggregation. It also
introduces an adaptive aggregation mechanism to improve robustness against non-IID data
distribution and a changing attack scenario. The framework was tested with the CICIDS2017 and
BoT-IoT datasets. The results of the experiments demonstrate superior performance with an
accuracy of 99.12%, a precision of 98.76%, recall of 98.41%, F1-score of 98.58%, and lower
communication overhead of 31.4% than existing deep learning IDS models. The system also scaled
better and converged quicker with bigger deployments to IoT nodes. The framework is very useful
to maintain privacy, learn the intelligence of the threats, augment detection with low latency and
make efficient use of resources, and is thus well suited for next generation secure IoT
infrastructures.

Download Full Text (PDF)