Collaborative Federated Learning to Secure 6G-IoT with Deep Convolutional Generative Adversarial Network
Abstract
1. Introduction
- Propose a distributed IDS in 6G-IoT to reduce communication latency based on collaborative FL (IDS-CFL) with three levels, including end devices and fog-cloud.
- Propose a Deep Convolutional Generative Adversarial Network (DCGAN) model to improve accuracy and enable fast processing.
- Evaluate the proposed IDS-CFL using a recent, realistic cybersecurity dataset called Edge-IIoTest with distributed and centralized methods.
2. Related Works
2.1. Centralized Learning Approach
2.2. Distributed Learning Approach
2.3. Collaborative Federated Learning
2.4. Limitations of the Current Solutions
3. Methodology
3.1. Intrusion Detection System Based Collaborative Federated Learning
3.1.1. Cloud-Level FL
3.1.2. Device-Level FL
3.2. Problem Formulation
3.2.1. Detection Time in CFL
- Cloud level:
- Local training: The local training time at device depends on the device’s data size. The local training time is calculated aswhere is the number of CPU cycles required to train one data sample, and is the device CPU frequency.
- Model aggregation: The partial aggregation time at BS consists of the time required to transmit the parameters from the devices that participate in the cloud level under BS’s coverage area. The partial aggregation time at BS is calculated aswhere is the size of global model, it is the same size as local model , is the number of CPU cycles required to aggregate one unit of data, and is the CPU frequency of BS . The aggregation time at the cloud server is calculated aswhere is the bandwidth communication between BS and cloud server, and is the CPU cycle at the cloud server. The aggregation time is affected by the large amount and diversity of data, which makes the system more scalable.
- Parameter transmission: The required time depends on the parameters download at device under BS coverage and is based on the parameter size. The required time for the transmission between the cloud server and BS , and between BS and device , is calculated as
- 2.
- Device level: At the device level, the model parameters can be shared across neighborhood devices, with one device selected as the aggregator. The detection time for the aggregator in one iteration is calculated as
- 3.
- Device selection algorithm: Collaboration across multiple levels can improve detection accuracy but may increase service delivery delays or cause service unavailability in locations far from cloud or fog servers. Therefore, device-level collaboration can minimize time consumption and enable faster detection. Moreover, selecting a device far from the aggregator takes time and adds transmission latency. Therefore, a Gray Wolf Optimizer (GWO) optimization algorithm is used for device selection at the device level. The GWO is a metaheuristic algorithm that mimics the social hierarchy and hunting behaviors of the grey wolves to catch prey in nature. It is used to solve various problems, including global optimization problems because it has fewer parameters, simple principles, and easy implementation [27]. In GWO, five solutions represent the devices in the search space, where alpha (α) is the best solution, beta (β) is the second-best solution, delta (δ) is the third-best solution, and omega (ω) is the rest of the solutions. The wolf represents aggregator A, which is selected randomly, while prey represents neighboring devices . The best three solutions (α, β, δ) are used to guide the other solutions (ω) to improve the search space. The selection steps are described as follows.
- Encircling: Aggregator starts by forming a circle around the neighboring devices when hunting. It is represented mathematically aswhere is the iteration number, is the neighboring device position, is the aggregator position, is used to specify a new position of the aggregator, and and are coefficient vectors that are calculated aswhere and are random vectors in [0, 1], is a vector decreased linearly from 2 to 0 over the iterations, and is calculated as
- Hunting: In this step, the best three solutions (α, β, δ) are obtained. As for the other solutions (ω), they need to update their position by moving towards the average of the three best and known positions, since they have better knowledge about the optimal location of the neighboring device. This step is represented mathematically as
- Attacking: The aggregators finish the hunt by attacking the neighboring device until they stop moving. To model the attacking process, Equation (20) is used, as the parameter balance exploration and exploitation; a decrease linearly from 2 to 0 over iterations. Consequently, parameter takes a random value in the range [] given by Equation (18). When or , aggregators take a random position; when , they are forced to move toward the neighboring device.
| Algorithm 1: Collaborative FL |
| Input: Device , initial global parameter , local patch of device , data size of device , input data Output: Updated global model //Initialization Cloud server initialize for each iteration do //Cloud-Level FL Select a random set of devices Broadcast to all devices participating at the cloud level Receive partial aggregation from the fog level and perform global aggregation using Equation (3) Updated and parameters Send updated to BSs participating in the learning //Fog-Level FL Each device sends its local parameters to BSs Fog server performs partial aggregation using Equation (2) Send to cloud Receive updated from cloud Update parameters and Send to devices participating in the learning //Device-Level FL Select aggregator randomly Aggregator receives from neighboring devices Aggregator performs aggregation using Equation (5) Update parameters and end for |
| Algorithm 2: Device selection using GWO |
| Input: Population size of aggregator devices Output: Optimally aggregator position from Neighboring devices Initialize the aggregator population randomly Initialize , , and Calculate the fitness of each search agent is the best solution is the second-best solution is the third-best solution while do for each aggregator do Initialize and randomly Update current position using Equation (23) end for Update , , and Calculate fitness of each aggregator Update , , and end while return (set of devices participating in device-level FL) |
3.2.2. Deep Convolutional Generative Adversarial Network
| Algorithm 3: DCGAN algorithm |
| Input: Number of epochs (), batch size (), initial generator weight , initial discriminator weight , generator (), discriminator (), training data distribution (), noise distribution , input vector (), noise vector () Output: Optimally trained and //Initialization Initialize and for each epoch from 1 to do Shuffle training data and create minibatches for each batch from 1 to do //Generator training Sample minibatch of noise samples from Sample minibatch of real data samples from Generate synthetic data using Equation (26) Combine synthetic data with to generate combined data Update using Adam: //Discriminator training Evaluate discriminator output using Equation (29) Sample minibatch of noise samples from Generate fake data samples Update using Adam: end for Calculate using Equation (30) Calculate using Equation (31) Save and end for |
4. Data Preparation
4.1. Data Description
4.2. Data Preprocessing
- Feature mapping: The features in IoT data do not consist only of numeric values. Therefore, a mapping technique is required to convert categorical values to numeric values. A common method is One-Hot Encoding (OHE), which converts each distinct value into a binary value.
- Data normalization: Normalization is a scaling method that converts all data features onto a common scale. We removed outliers, such as null values and non-numeric entries in numerical attributes. For a fair comparison, we have normalized the dataset using Min-Max scaling. This popular method facilitates arithmetic processing by linearly mapping each feature’s range to 0–1. It can be calculated as
- 3.
- Feature Selection: It improves predictive quality by selecting relevant features. Feature selection is the process of selecting a subset of features important for solving the detection problem and discarding unneeded features. In this paper, we use a mutual information (MI) technique for feature selection, with selection criteria based on feature dependencies: features with high mutual information are considered the best features. The input–output variables from the training set can be represented as and where . To compute MI, follow these steps.
- 4.
- Class Balancing: To prevent bias toward the majority “Normal” class, the script identifies the minority class size and samples from it. The Synthetic Minority Over-sampling Technique (SMOTE) [29] is applied to handle the imbalanced dataset. It is based on the K-Nearest Neighbors (KNN) model, which takes samples and considers their nearest neighbors in the feature map. If is a sample of a minority class and if its neighbor is selected as , then the data point is synthesized as
5. Experimental Results
5.1. Experiment Setup
5.2. Performance Metrics
5.3. Performance Analysis
- No FL: In this model, centralized learning is performed where each device sends its data to the cloud for model training.
- Fog-level FL: In this model, the traditional FedAvg method is performed at the fog level. The devices send their data to the fog level for model training. After training, the fog servers send the local parameters to the cloud for global model aggregation. After that, the cloud sends the updated parameters to the fog level to update the model.
- Device-level FL: In this model, at each FL iteration, the devices train the model using their data and, instead of sending local model parameters to the cloud or fog, share their parameters. The selected aggregator receives the parameters from neighboring devices and aggregates the model. After that, the aggregator sends the results back to the neighboring devices for attack detection. The aggregator device is selected randomly, and neighboring devices are selected based on the k-means clustering as in [30].
5.4. Results
5.4.1. Experiment 1: Effect of Collaboration in CFL
- S1: In S1, there are no devices in No FL involved in learning. In fog-level FL, a high portion of devices is involved in FL (70%), whereas device-level FL involves the lowest portion (30%). This is because 30% of devices have neighbors. CFL has the highest device involvements, at 90% in FL. BSs can cover up to 80% of devices, and devices without BS access can collaborate in FL through their neighboring devices, if available. Also, if a device has no neighbors, it can participate in FL at the fog level if fog infrastructure is available. For our CFL, 10% of devices are not covered by any BS or neighbors.
- 2.
- S2: In S2, the fog servers’ capabilities are available for 90% of devices, whereas 40% of devices have a neighboring. As shown in Figure 5b, there is no significant difference in detection time compared with S1. The time decreases by around 6.6 ms in device-level FL and 7.2 ms in fog-level FL. As shown in Figure 6b, the accuracy and the other metrices are increased in fog-level FL which scored 97.99%. In device-level FL, performance is better than in S1, with 90.06% accuracy when 40% of devices have a neighborhood. Compared with fog-level FL, our CFL reduced communication because it shares parameters across 90%. On the other hand, it outperformed No FL and device-level FL. Table 4 summarized the comparison results.
5.4.2. Experiment 2: Comparing DCGAN with Other Models
5.4.3. Experiment 3: Examine the Scalability with Increasing Number of Devices
6. Conclusions
Author Contributions
Funding
Data Availability Statement
Acknowledgments
Conflicts of Interest
References
- Tera, S.P.; Chinthaginjala, R.; Pau, G.; Kim, T.H. Towards 6G: An Overview of the Next Generation of Intelligent Network Connectivity. IEEE Access 2024, 13, 925–961. [Google Scholar] [CrossRef] [Scilit]
- Nguyen, D.C.; Ding, M.; Pathirana, P.N.; Seneviratne, A.; Li, J.; Niyato, D.; Dobre, O.; Poor, H.V. 6G Internet of Things: A Comprehensive Survey. IEEE Internet Things J. 2021, 9, 359–383. [Google Scholar] [CrossRef] [Scilit]
- Junior, E.E. Systematic Review of 6G-IoT Privacy Risks, Emerging Threats, Mitigation Strategies, and Cybersecurity. SSRN Electron. J. 2025, 19, 180–190. [Google Scholar] [CrossRef] [Scilit]
- Assiri, M. Artificial intelligence-based intrusion detection and secure communication model for sustainable 6G-IoT networks. Sci. Rep. 2026, 16, 12662. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Wu, Y.; Chen, J.; Lei, T.; Yu, J.; Hossain, M.S. Web 3.0 security: Backdoor attacks in federated learning-based automatic speaker verification systems in the 6G era. Future Gener. Comput. Syst. 2024, 160, 433–441. [Google Scholar] [CrossRef] [Scilit]
- Edegbe, G.N.; Acheme, S. A systematic review of centralized and decentralized machine learning models: Security concerns, defenses and future directions. NIPES-J. Sci. Technol. Res. 2024, 6, 161–175. [Google Scholar] [CrossRef]
- Chen, K.; Liu, Y. Toward Privacy-Preserving AI Standards for Federated Learning in 6G-Enabled Digital Twin Environments. IEEE Commun. Stand. Mag. 2025, 10, 265–272. [Google Scholar] [CrossRef] [Scilit]
- de Alwis, C.; Aouedi, O.; Xu, J.; Wang, S.; Siriwardhana, Y.; Hewa, T.; Zeydan, E.; Sandeepa, C.; Liyanage, M. Federated Learning for 6G Security: A Survey on Threats, Solutions, and Research Directions. IEEE Commun. Surv. Tutor. 2026, 28, 4883–4914. [Google Scholar] [CrossRef] [Scilit]
- Tomkos, I.; Klonidis, D.; Pikasis, E.; Theodoridis, S. Toward the 6G network era: Opportunities and challenges. IT Prof. 2020, 22, 34–38. [Google Scholar] [CrossRef] [Scilit]
- Creswell, A.; White, T.; Dumoulin, V.; Arulkumaran, K.; Sengupta, B.; Bharath, A.A. Generative adversarial networks: An overview. IEEE Signal Process. Mag. 2024, 35, 53–65. [Google Scholar] [CrossRef] [Scilit]
- Wu, Y.; Nie, L.; Wang, S.; Ning, Z.; Li, S. Intelligent Intrusion Detection for Internet of Things Security: A Deep Convolutional Generative Adversarial Network-enabled Approach. IEEE Internet Things J. 2021, 10, 3094–3106. [Google Scholar] [CrossRef] [Scilit]
- Saeed, M.M.; Saeed, R.A.; Gaid, A.S.A.; Mokhtar, R.A.; Khalifa, O.O.; Ahmed, Z.E. Attacks Detection in 6G Wireless Networks Using Machine Learning; IGI Global: Hershey, PA, USA, 2023; pp. 6–11. [Google Scholar] [CrossRef] [Scilit]
- Rao, V.A.; Rao, R.; Hota, C. Anomaly detection in wireless body area networks using generative adversarial networks. In Proceedings of the 2024 IEEE International Conference on Industry 4.0, Artificial Intelligence, and Communications Technology (IAICT), Bali, Indonesia, 4–6 July 2024. [Google Scholar]
- Lin, C.-Y.; Chen, C.-Z. Inpainting-based anomaly detection system with self-supervised learning. In Proceedings of the 2024 IEEE International Conference on Industry 4.0, Artificial Intelligence, and Communications Technology (IAICT), Bali, Indonesia, 4–6 July 2024. [Google Scholar]
- Hinojosa-Palafox, E.A.; Rodríguez-Elías, O.M.; Pacheco-Ramírez, J.H.; Hoyo-Montaño, J.A.; Pérez-Patricio, M.; Espejel-Blanco, D.F. A Novel Unsupervised Anomaly Detection Framework for Early Fault Detection in Complex Industrial Settings. IEEE Access 2024, 12, 181823–181845. [Google Scholar] [CrossRef] [Scilit]
- Zhang, J.; Luo, C.; Jiang, Y.; Min, G. Decentralized Federated Learning for Intrusion Detection in 6G-based UxV Networks. IEEE Veh. Technol. Mag. 2025, 20, 83–93. [Google Scholar] [CrossRef] [Scilit]
- Garroppo, R.G.; Giardina, P.G.; Landi, G.; Ruta, M. Trustworthy AI and Federated Learning for Intrusion Detection in 6G-Connected Smart Buildings. Future Internet 2025, 17, 191. [Google Scholar] [CrossRef] [Scilit]
- Korba, A.A.; Sebaa, S.; Mabrouki, M.; G-Doudane, Y.; Benatchba, K. A Life-long Learning Intrusion Detection System for 6G-Enabled IoV. In Proceedings of the 2024 International Wireless Communications and Mobile Computing (IWCMC); IEEE: New York, NY, USA, 2024; pp. 1773–1778. [Google Scholar] [CrossRef] [Scilit]
- Ma, X.; Hu, J.; Liang, S.; Wu, Y. Federated Learning and Resource-Aware Graph Neural Network for Intrusion Detection in 6G-IoT Driven Healthcare System. IEEE Internet Things J. 2025, 13, 7749–7761. [Google Scholar] [CrossRef] [Scilit]
- Jayarajan, J.; Mahalingam, N.; Seng, Y.K. Empowering Smart Grid Security: Towards Federated Learning in 6G-Enabled Smart Grids using Cloud. Res. Sq. 2024; preprint. [CrossRef] [Scilit] [PubMed]
- Prathiba, S.B.; Raja, G.; Anbalagan, S.; Gurumoorthy, S.; Kumar, N.; Guizani, M. Cybertwin-Driven Federated Learning Based Personalized Service Provision for 6G-V2X. IEEE Trans. Veh. Technol. 2022, 71, 4632–4641. [Google Scholar] [CrossRef] [Scilit]
- Alatawi, M.N. SAFEL-IoT: Secure Adaptive Federated Learning with Explainability for Anomaly Detection in 6G-Enabled Smart Industry 5.0. Electronics 2025, 14, 2153. [Google Scholar] [CrossRef] [Scilit]
- Kianpisheh, S.; Taleb, T. Collaborative Federated Learning for 6G With a Deep Reinforcement Learning Based Controlling Mechanism: A DDoS Attack Detection Scenario. IEEE Trans. Netw. Serv. Manag. 2024, 21, 4731–4749. [Google Scholar] [CrossRef] [Scilit]
- Sedjelmaci, H.; Kheir, N.; Boudguiga, A.; Kaaniche, N. Cooperative and smart attacks detection systems in 6G-enabled Internet of Things. In Proceedings of the ICC 2022-IEEE International Conference on Communications, Seoul, Republic of Korea, 16–20 May 2022; Available online: https://ieeexplore.ieee.org/abstract/document/9838338/ (accessed on 21 September 2023).
- Luo, Y.; Chen, X.; Sun, H.; Li, X.; Ge, N.; Feng, W.; Lu, J. Securing 5G/6G IoT Using Transformer and Personalized Federated Learning: An Access-Side Distributed Malicious Traffic Detection Framework. IEEE Open J. Commun. Soc. 2024, 5, 1325–1339. [Google Scholar] [CrossRef] [Scilit]
- El Houda, Z.A.; Naboulsi, D.; Kaddoum, G. A Privacy-Preserving Collaborative Jamming Attacks Detection Framework Using Federated Learning. IEEE Internet Things J. 2024, 11, 12153–12164. [Google Scholar] [CrossRef] [Scilit]
- Faris, H.; Aljarah, I.; Al-Betar, M.A.; Mirjalili, S. Grey wolf optimizer: A review of recent variants and applications. Neural Comput. Appl. 2017, 30, 413–435. [Google Scholar] [CrossRef] [Scilit]
- Ferrag, M.A.; Friha, O.; Hamouda, D.; Maglaras, L.; Janicke, H. Edge-IIoTset: A New Comprehensive Realistic Cyber Security Dataset of IoT and IIoT Applications for Centralized and Federated Learning. IEEE Access 2022, 10, 40281–40306. [Google Scholar] [CrossRef] [Scilit]
- Abunada, M.; Belhaouari, S.B.; Bensmail, H. Synthetic Minority Oversampling for Imbalanced Time Series Classification Based on Path Signature. Appl. Sci. 2026, 16, 4451. [Google Scholar] [CrossRef] [Scilit]
- Trindade, S.; da Fonseca, N.L.S. Multicriteria Scoring for Cluster and Client Selection in Heterogeneous Hierarchical Federated Learning. IEEE Internet Things J. 2026, 13, 16763–16779. [Google Scholar] [CrossRef] [Scilit]
- Kaur, R. Generative Adversarial Network (GANs) for Image Generation or Data Augmentation. Int. J. Sci. Archit. Technol. Environ. 2025, 3, 509–517. [Google Scholar] [CrossRef] [Scilit]









| Ref | Work | Learning Model | Dataset | Limitations |
|---|---|---|---|---|
| [12] | Attack detection in 6G (AD6Gs) | RF and SVM | CICDDoS2019 | It is difficult to identify new threats |
| [13] | GAN-WBAN to detect anomalies | CNN | MIMIC | It is not practical with a large number of points |
| [14] | Anomaly detection system | SSL | MVTec | High transmission overhead |
| [15] | Anomaly detection framework in industrial environment | ML | 2015 PHM Data Challenge | Using unsupervised learning lacks to detect anomalies, especially those that significantly deviate from previously observed patterns |
| [16] | Decentralized FL for intrusion detection in UxVs | ML | AWID-3 | It is not practical with complex attacks |
| [17] | FL-IDS to detect attacks in smart buildings | CNN | ToN-IoT | There is no clear correlation between the impact of attacks on network and telemetry data |
| [18] | Intrusion detection system in IoV | MLP | 5G-NIDD | It is not effective when the number of clients increases |
| [19] | FLARE for intrusion detection in 6G-IoT driven healthcare system | LLM | CICIDS2017 and UNSW-NB15 | The training time is high for real-time applications such as healthcare systems |
| [20] | A hierarchical FL approach in smart grid for 6G network to detect DDoS attacks | CNN | CICDDoS2019 | It is suitable only for a small number of clients |
| [21] | FLCC to provide security in 6G-V2X | DRL | CIFAR10 | It is not practical with complex attacks |
| [22] | SAFEL-IoT for anomaly detection | AE | SKAB | The adaptive aggregation mechanisms remain limited, and formal proofs under non-convex optimization settings are necessary to establish robust guarantees |
| [23] | Collaborative FL to detect DDoS attacks | GRU | CICDDoS2019 | Some accuracy loss might be experienced due to the issue of more locality in constructing the parameters of the model |
| [24] | Cooperative FL to detect attacks in 6G-Enabled IoT | ML | UNSW-NB15 | It suffers from high communication latency |
| [25] | Personalized FL-based collaborative algorithm for attack detection | Transformer | N-BaIoT | The global detection ability is not accurate, and it is not effective when the clients are highly distributed |
| [26] | Collaborative FL to enable privacy-aware distributed learning | CNN | WSN-DS | The response time and communication latency are high |
| Parameter | Value |
|---|---|
| No. of devices | 50 |
| No. of BSs | 5 |
| Data rate | 10 Mbps |
| Fog CPU frequency | 2.5 GHz |
| Device CPU frequency | from 1.5 to 2.4 |
| Transmission bandwidth | 100 MHz |
| Learning rate | 0.01 |
| Batch size | 128 |
| Epochs | 10 |
| Optimizer | Adam |
| Method | Total Involved Device Ratio in FL | Device-Level Collaboration Ratio | Fog-Level Collaboration Ratio |
|---|---|---|---|
| No FL | 0 | 0 | 0 |
| Fog-level FL | S1: 70%, S2: 90% | 0 | 100% |
| Device-level FL | S1: 30%, S2: 40% | 100% | 0 |
| CFL | 90% | 25% | 75% |
| Method/Metrics | Accuracy (%) | Recall (%) | F1 (%) | AUC (%) | DT (ms) |
|---|---|---|---|---|---|
| No FL | 75.02 | 73.11 | 74.05 | 77.13 | 3.8 |
| Fog-level FL | 94.80 | 92.99 | 93.52 | 95.03 | 8.3 |
| Device-level FL | 85.09 | 82.12 | 84.19 | 85.03 | 7.5 |
| Proposed CFL | 96.20 | 94.10 | 95.90 | 97.05 | 4.5 |
| Model/Metrics | Accuracy (%) | Recall (%) | F1 (%) | AUC (%) | DT (ms) |
|---|---|---|---|---|---|
| CNN | 80.14 | 76.99 | 79.56 | 81.17 | 3.5 |
| GAN | 94.32 | 92.16 | 92.98 | 94 | 4.1 |
| DCGAN | 96.20 | 94.10 | 95.90 | 97.05 | 4.5 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Almarshdi, R.; Alrashidi, B.; Alamr, A. Collaborative Federated Learning to Secure 6G-IoT with Deep Convolutional Generative Adversarial Network. Computers 2026, 15, 644. https://doi.org/10.3390/computers15100644
Almarshdi R, Alrashidi B, Alamr A. Collaborative Federated Learning to Secure 6G-IoT with Deep Convolutional Generative Adversarial Network. Computers. 2026; 15(10):644. https://doi.org/10.3390/computers15100644
Chicago/Turabian StyleAlmarshdi, Rasha, Bedour Alrashidi, and Abrar Alamr. 2026. "Collaborative Federated Learning to Secure 6G-IoT with Deep Convolutional Generative Adversarial Network" Computers 15, no. 10: 644. https://doi.org/10.3390/computers15100644
APA StyleAlmarshdi, R., Alrashidi, B., & Alamr, A. (2026). Collaborative Federated Learning to Secure 6G-IoT with Deep Convolutional Generative Adversarial Network. Computers, 15(10), 644. https://doi.org/10.3390/computers15100644

