DOI: 10.3390/s26185911 ISSN: 1424-8220

ARFU-IDS: Robust Federated Unlearning for Transformer-Based Intrusion Detection in IoT and Sensor Networks

Xudong Yang, Zhenyu Zhang, Qiuyan Li, Zhenzhou Jing, Xuyao Lu, Yuxin Zhang, Junwen Chen

Federated intrusion detection systems (FL-IDSs) for IoT and wireless sensor networks (WSNs) must remove client contributions after training when consent changes, devices retire, or compromised nodes are identified. Existing federated unlearning methods are not well aligned with transformer-based IDSs because they use coarse attribution, provide limited trajectory verification, and handle concurrent deletion requests weakly under rare-attack imbalance conditions. This paper proposes ARFU-IDS, a robust federated unlearning framework for transformer-based IoT and sensor-network IDSs. ARFU-IDS combines attention-head attribution, dual-path layer criticality probing, manipulation-resistant iterative verification, and conflict-graph scheduling to remove target-client influence while preserving retained detection utility. Experiments on UNSW-NB15, CICIoT2023, and IoTID20 evaluated detection utility, rare-category recall, adversarial robustness with network-flow feature triggers, and concurrent unlearning. On UNSW-NB15, ARFU-IDS achieves 87.1% Macro-F1 and 77.6% rare-category recall, within 0.2 percentage points of full retraining. Under flow-feature trigger attacks, it reduces attack success rate to 8.2% at f=0.1 and 9.7% at f=0.2. For three concurrent deletion requests, it shortens online unlearning latency by 43.3% relative to sequential processing. These results show that ARFU-IDS offers a practical route to robust and efficient federated unlearning for transformer-based IDSs in IoT and sensor-network deployments.