Indexed metadata

Privacy-Aware and Resource-Efficient Split Learning for IoT Botnet Detection: A Multi-Dataset Experimental and Systems Evaluation

Mohammad Alja’afreh, Ali Karime, Aziz Oukaira

Source record

Source: Crossref

Published: Aug 3, 2026

DOI: 10.20944/preprints202608.0075.v1

Open original source ↗

Source abstract

Internet of Things (IoT) botnet detection requires high predictive performance, low client-side resource demands, and limited exposure of raw traffic data. This paper presents a traffic-constrained multi-client split-learning (TC-SL) intrusion-detection system evaluated on BoT-IoT, N-BaIoT, and CIC-IDS2017 using eight clients and one edge server. TC-SL profiles candidate cut layers, selects the highest-performing feasible cut under a communication budget, and trains by exchanging smashed activations and cut-layer gradients while raw records remain local. Centralized, federated, split-learning, and SplitFed-v1 models were compared with matched partitions and optimization budgets. Split learning achieved macro F1 scores of 98.88%, 98.42%, and 97.51% on the three datasets, respectively, with a mean macro F1 of 98.27%, compared with 98.52% for centralized learning, 97.84% for federated learning, and 98.39% for SplitFed. Its pooled ROC-AUC and average precision were 0.985 and 0.980. The selected L4 cut required 95 MB of normalized bidirectional communication per epoch in the systems evaluation and 0.95 GB across the complete 10-epoch systems run, compared with 405 MB per epoch and 4.05 GB per run for federated learning. The early split minimized cumulative client energy at 248 J, whereas the middle split minimized total-system energy at 780 J. Across L1–L6, reconstruction NRMSE increased from 0.18 to 0.71, membership-inference AUC decreased from 0.71 to 0.53, label- and attribute-inference success decreased from 0.84 and 0.76 to 0.55 and 0.54, inversion success decreased from 75% to 20%, and poisoning-induced macro-F1 degradation decreased from 6.8 to 3.9 percentage points. The results identify a practical accuracy–communication–energy–privacy operating point for constrained IoT clients.

Evidence graph

No public relationships recorded yet.

Integrity note: This page is a factual metadata record created by deterministic ingestion. It is not a claim that the work moves a mathematical frontier or has been independently verified.