ORCID
Tareef S Alkellezli: https://orcid.org/0009-0004-7938-4007
Nariman A. Khalil: https://orcid.org/0000-0002-0346-3196
Keywords
Advanced persistent threats, Internet of things, Federated learning, BiLSTM, Transformer encoder, Non-IID data, Differential privacy
Article Type
Original Article
Abstract
Advanced persistent threats (APTs) are difficult to detect in heterogeneous Internet of Things (IoT) environments because malicious behavior can unfold across reconnaissance, scanning, command-and-control, denial-of-service, and exfiltration stages. Centralized intrusion-detection pipelines also create privacy, communication, and latency concerns when traffic originates at distributed edge devices. This study presents HAF-BiTrans, a heterogeneity-aware federated BiLSTM-Transformer framework for privacy-preserving detection of multi-stage APT-like behavior. At each client, a bidirectional long short-term memory encoder captures temporal dependencies, a lightweight Transformer models broader contextual relationships, and a class-balanced focal objective addresses class imbalance. At the server, Heterogeneity-Aware Contribution-Trust Aggregation (HACTA) weights client updates using sample support, class-coverage entropy, validation macro-F1, update stability, and differential-privacy reliability. Experiments on CICIoT2023, TON_IoT, and BoT-IoT show marked variation across datasets. HAF-BiTrans + HACTA achieved 89.29% accuracy and 88.93% macro-F1 on TON_IoT and 84.91% accuracy and 84.77% macro-F1 on BoT-IoT. On the more imbalanced CICIoT2023 experiment, centralized HAF-BiTrans reached 25.42% accuracy and 16.88% macro-F1, whereas the federated HACTA configuration reached 20.34% accuracy and 9.59% macro-F1. Thus, the present CICIoT2023 implementation does not outperform a strong tabular baseline and should not be interpreted as a state-of-the-art result. Its practical strength is efficiency: the model occupies approximately 0.052 MB and performs inference in under 0.1 ms per window. These findings position HAF-BiTrans as a compact, edge-oriented federated architecture whose robustness under difficult non-IID conditions still requires further optimization.
How to Cite
Alkellezli, Tareef S and Khalil, Nariman A.
(2026)
"HAF-BiTrans: A Heterogeneity-Aware Federated BiLSTM-Transformer Framework for Privacy-Preserving Detection of Multi-Stage APT Behaviors in IoT Networks,"
Sustainable Machine Intelligence Journal: Vol. 14:
Iss.
3, Article 6.
DOI: https://doi.org/10.63689/3005-3617.1096
Creative Commons License

This work is licensed under a Creative Commons Attribution 4.0 International License.