DOI: 10.3390/fi18100510 ISSN: 1999-5903

CA-AFiD: A Context-Aware Adaptive Federated Intrusion Diagnosis for Heterogeneous IoT–Fog–Cloud Environments

Ashutosh Shankhdhar, Vanitha Murugesan, Thenmozhi Elumalai, Samia Kouki, Sumendra Yogarayan, Prabu Kaliyaperumal

The increasing heterogeneity of Internet of Things (IoT) environments makes intrusion diagnosis challenging because device behaviours, traffic patterns, and attack distributions can vary across deployment conditions, while data-locality requirements limit centralized access to network data. This study proposes CA-AFiD (Context-Aware Adaptive Federated Intrusion Diagnosis), a framework designed to support adaptive and interpretable intrusion diagnosis across IoT–Fog–Cloud environments. CA-AFiD combines behaviour-aware representation learning using Transformer, BiLSTM, and attention mechanisms with a context-aware adaptive ensemble that adjusts learner contributions according to behavioural complexity, attack density, and device context. Federated learning is used to coordinate model updates across distributed Fog nodes without sharing raw traffic data, while attention-based interpretation, SHAP feature attribution, and ATT&CK-oriented contextualization provide explanatory information for diagnostic decisions. The framework was evaluated on the CIC-IoT-DIAD 2024 dataset across device-aware learning, imbalanced attack diagnosis, temporal sensitivity, federated learning, explainability, and operational-efficiency scenarios. Under the controlled homogeneous evaluation, the complete CA-AFiD framework achieved a 99.22% F1-score, while the heterogeneous evaluation achieved an overall 99.03% F1-score across the evaluated attack categories. Across the four evaluated minority attack categories, the average F1-score was 98.79%. Under federated learning, the global model achieved an average device-identification accuracy of 98.90% and an average anomaly-diagnosis F1-score of 98.90% across the participating Fog nodes, while ATT&CK mapping achieved 88–98% coverage. These results demonstrate the potential of CA-AFiD to provide adaptive, data-local, and interpretable intrusion diagnosis for heterogeneous IoT–Fog–Cloud environments.