AI-Driven Intrusion Detection for the Internet of Things: A Scoping Review of Federated Learning, Privacy-Preserving Architectures, and Edge Deployability

Federated learning has emerged as the dominant architectural response to the privacy and communication constraints of centralised intrusion detection in Internet of Things environments, yet the field lacks a synthesis that maps the concurrent state of architecture diversity, privacy-preservation rigour, and edge deployability. This scoping review synthesises 99 empirical studies published between 2020 and 2026, drawn from two thematic extraction categories: federated learning-based intrusion detection for Internet of Things networks (61 studies) and deep learning-based intrusion detection with blockchain-enabled tamper-proof logging (43 studies, one shared). Following the Preferred Reporting Items for Systematic Reviews and Meta-Analyses extension for scoping reviews, the review maps twelve confirmed architecture families, a twelve-branch privacy mechanism taxonomy, and classifies all included studies by edge evaluation type. Three gap clusters are identified. An empirical gap in deployment evaluation is the most operationally consequential: 88 per cent of included studies evaluate on server simulation only, and the study that quantifies the cost of this deferral reports a 36.5 percentage-point accuracy degradation on real-world imbalanced data. A practical-knowledge and evidence gap in privacy claims separates formal guarantees from predominant practice: 41 of 61 federated learning studies assert privacy through the federated paradigm alone, without differential privacy, homomorphic encryption, or secure aggregation. A methodological gap in evaluation reproducibility arises from incomplete federated learning configuration reporting, persistent reliance on a 2009 benchmark dataset, and unnamed datasets in recent papers. The findings provide a structured evidence base for primary research that targets these gaps.

Keywords: Edge deployment; Federated learning; Internet of Things; Intrusion detection systems; Privacy-preserving machine learning; Scoping review.