Federated Learning for Privacy-Preserving Threat Detection in Massive IOT Ecosystems: A Systematic Literature Review

Federated learning (FL) has emerged as a principal architecture for privacy-preserving intrusion detection in Internet of Things (IOT) environments, motivated by the impossibility of transmitting raw device traffic to a centralised server at scale. A rapidly growing body of empirical work applies FL to IOT intrusion detection systems (IDS), yet no PRISMA-compliant synthesis of this literature exists. This systematic review addresses that gap. Sixty-one peer-reviewed journal papers, identified through a PRISMA 2020-compliant search of five electronic databases covering 2018–2026, were subjected to full-text extraction and quality assessment on six dimensions. Four research questions guided the synthesis, organised into four themes. On FL architecture and performance (RQ1), standard FEDAVG and its variants govern aggregation in 65% of papers; two papers exceeded their centralised detection baseline, attributing the gain to data-centric rather than aggregation-level mechanisms. On privacy rigour (RQ2), 80% of papers claim privacy on structural grounds only; a twelve-subcategory privacy taxonomy is established, distinguishing formal differential privacy, cryptographic secure aggregation, and homomorphic encryption from structural-only claims; adaptive noise scheduling reduces the differential privacy accuracy cost from 5.77 percentage points to 0.01 percentage points relative to a non-private baseline. On evaluation realism (RQ3), 85% of papers evaluate on simulation only and 80% use independent and identically distributed data partitioning or do not state it; a 36.5-percentage-point accuracy gap between balanced and imbalanced evaluation conditions quantifies the inflation introduced by default evaluation methodology. On threat and domain coverage (RQ4), 57% of papers address generic multi-class intrusion in unspecified IOT deployment types; healthcare, smart grid, and industrial control systems account for five papers combined. Six research gaps are identified, and four prioritised research directions are proposed.

Keywords: federated learning, intrusion detection system, Internet of Things security, differen-tial privacy, systematic literature review, privacy-preserving machine learning.