Abstract
Privacy is a major concern in the Internet Healthcare of Things (IoHT), where threat actors may intrude systems to access personally identifiable data. Federated Learning (FL) is a well suited Machine Learning (ML) approach to preserve confidentiality, availability, and integrity in such settings during data analysis. In this work, we introduce a Network of Quantum ML (N-QML) approach for IoHT intrusion detection, integrating quantum PCA (QPCA) with Quantum FL (QPCA+QFL), tested on a subset of the data set WUSTL-EHMS-2020 using classical and quantum computing experiments across three seeds, compared against conventional ML (CML) on three feature dimensions. Among CML techniques, the integration of PCA and ANN (PCA+ANN) attained the best mean accuracy, 76.6%, using two features. Among QML techniques, QPCA+QNN achieved the best centralized accuracy, 74.4%, when two features are used, while PCA+SVM outperformed QPCA+QSVM using ten features (70.1% versus 66.9%). As a result of the study, during federation of the quantum model, accuracy was realized to be reduced steadily from 62.9% to 54.7% as dimensionality changed and highest variance attainment occurred at the smallest dimension; this is a pattern that was not previously documented under matched, multi-seed validation. We attribute this to FedAvg interacting with the loss landscape of quantum-derived features on small client partitions, contributing this finding and the framework as groundwork for quantum-aware federated aggregation.
1. Introduction
Conventional Machine Learning (CML) techniques, including but not limited to Artificial Neural Networks (ANN), Support Vector Machine (SVM), and Convolutional Neural Networks (CNN), Fedarated Learning (FL), and Principal Component Analysis (PCA), are widely used in cybersecurity applications [1,2,3]. In particular, ANN and SVM are identified to be effective during intrusion detection system (IDS) analysis [4]. Given the recent advancements in quantum fields, quantum Machine Learning (QML) has also been proactively used in several research areas. In particular, using well established approaches in CML, the newly introduced techniques in QML included Quantum ANN (QNN) [5,6], Quantum CNN (QCNN) [7], Quantum SVM (QSVM) [8,9] and Quantum Supervised Learning [10]. Additionally, feature selection and classification techniques in CML such as Principal Component Analysis (PCA) have been extended to be included in QML as quantum PCA (QPCA) [11]. The QPCA technique used in this work, following [12], refers specifically to a hybrid pipeline combining classical PCA with quantum feature encoding and per-sample measurement and should not be conflated with the canonical quantum PCA algorithm of [11] that relies on quantum phase estimation applied to a density matrix. Network of QML (NQML) is a recent QML development in QML. Such new techniques included Network of QNN (N-QNN) [13], Network of QSVM (N-QSVM) [14], and N-QCNN [15]. Furthermore, QPCA and N-QNN are integrated in [12] with QPCA serving to select the top features while N-QNN serves to further process the top features selected by QPCA in the QNN setting.
In this work, to advance QML applications in cybersecurity, we propose an FL-QPCA as a Federated Learning framework that combines QPCA with QNN for intrusion detection analysis of the WUSTL-EHMS-2020 IoHT dataset [16]. The data in WUSTL-EHMS-2020 is a controlled testbed simulation of an IoHT environment rather than data collected from a real-life clinic, which is important context for interpreting our results; conclusions about deployment-ready performance, including the clinical cost of false negatives, deployment latency, and regulatory compliance. The applications of the ML techniques utilized in this work are case dependent and can be tested by healthcare systems, which is beyond the scope of this study. FL is a convenient method providing data decentralization, in that raw data never leaves the client; however, this is not itself a formal privacy guarantee. Differential privacy is not applied, and federation alone is not presented as sufficient evidence of privacy protection in our work.
The computational results presented in Section 4 followed a three-hospital federated setting using FedAvg aggregation under a sample size matched between classical and quantum experiments and across three independent random seeds, and we compared this QFL pipeline directly against its centralized quantum counterpart as well as classical and federated classical baselines built on the same data. In addition to the analysis using CML and QML evaluations on the data, comparative results are also discussed. The use of PCA for feature selection and evaluation of the selected features using ANN (i.e., PCA+ANN) in the federated classical approach loses at most two to three percentage points of accuracy relative to its centralized version, well within run-to-run variance. Federated QPCA+QNN, by contrast, declines steadily in accuracy as feature dimensionality increases, and its variability across random seeds is highest, not lowest, at the smallest tested dimension. To the best of our knowledge, this is the first paper to evaluate a federated QPCA+QNN framework on a real IoHT dataset that utilizes N-QML under a matched sample size and multi-seed statistical validation, and the first to document dimension-dependent instability, together with its associated computational cost, in Federated Quantum Learning. To support reproducibility, we provide full implementation details, including preprocessing, model architectures, and hyperparameters.
The remainder of this work is structured as follows. Section 2 reviews related work on Federated Learning for IoT and IoHT security and on quantum and federated quantum learning. The Network of Quantum Machine Learning and the associated mathematical framework are explained in Section 3. Section 4 contains information on the dataset, the architecture of the proposed FL-QPCA framework, and the experimental results. The results in the context of the broader literature are discussed, and reflections on the limitations of the proposed approach are covered in Section 5. Section 6 outlines conclusions and possible future directions that can be followed.
2. Related Works
Federated learning has become a convenient Machine Learning application method to resolve analysis of problems that include privacy concerns in IoT anomaly detection [17]. Each device trains locally, and only the model, not the raw data, ever leaves the client, which is exactly the property healthcare deployments need given how strictly patient data needs to be regulated. FL alone is not a complete answer since gradient updates can still leak information [18], but as a starting point for distributed intrusion detection, it has proven itself repeatedly across IoT domains. In this section, we will cover the associated works in both the CML setting and then in the much newer QML applications.
Otoum et al. [19] built a federated transfer learning IDS for the Internet of Medical Things, training a DNN across edge clients and its evaluation on CICIDS2017 data. Rashid et al. [20] paired CNN and RNN to test their effectiveness on Edge-IIoTset with the authors focusing on accuracy and training time rather than any healthcare specific dataset. Friha et al. [21] worked in the same IIoT space by incorporating an additional step and added differentially private gradient exchange to their FL pipeline, also on Edge-IIoTset, and reported strong detection performance. None of these three works focused on a healthcare-specific dataset, which is a gap that has persisted in this literature for a while now.
In an earlier work [22], a federated DNN-based IDS for IoHT devices was developed and evaluated on WUSTL-EHMS-2020 and ECU-IoHT datasets, reaching 91.40% and 98.47% accuracies, respectively. We later extended that framework with Renyi differential privacy using Opacus [23], achieving 95.48% accuracy within an accuracy on ECU-IoHT data. Both of these datasets, WUSTL-EHMS-2020 [16] and ECU-IoHT [24], remained as the two most realistic publicly available IoHT security testbeds, and to the best of our knowledge, no quantum federated learning technique has been applied in either of the sets prior to this work.
Quantum machine learning itself is an independent development from CML and a much newer trending ML application. Using quantum hardware and software, it builds on superposition, entanglement, and interference to represent data in ways that classical models cannot [25], and in the current NISQ era, this means parameterized quantum circuits trained through the parameter shift rule [26]. Frameworks like Qiskit [27,28] and PennyLane [29] have made these circuits accessible via conventional computers, allowing the applicability of hybrid quantum-classical pipelines that are now practical to build and test, even if the hardware itself is still noisy and limited in scale.
Quantum federated learning distributes the training of quantum circuits across clients in the same way conventional FL does as a newer technique. Chen and Yoo [30] laid the associated theoretical framework and flagged the obvious challenges: communication overhead, clients with different numbers of qubits, and the fact that averaging quantum circuit parameters is not the same operation as averaging classical weights. Chehimi and Saad [31] focused specifically on communication efficiency. Both of these works remained at the level of feasibility and convergence without solutions attained for real-life security applications.
A handful of articles that connect QFL to anomaly or intrusion detection exist in the literature that are worth covering. Chen et al. [32] proposed Federated Quantum Kernel Learning for anomaly detection in Industrial IoT time-series data, where quantum edge nodes compute kernel statistics and share summaries with a server; it outperformed classical federated baselines on synthetic IIoT benchmarks, but synthetic data are not the same as a real testbed, and no healthcare dataset was involved. Godavarthi et al. [33] combined quantum-inspired reinforcement learning with FL for dynamic IoT environments where “quantum-inspired” is the operative phrase utilized; the method was not developed using parameterized quantum circuits. These works did not focus on either one of WUSTL-EHMS-2020 or ECU-IoHT, and neither report a privacy budget of any kind.
A smaller and somewhat separate branch of FL focused on UAV and drone networks. Ceviz et al. [34] adapted few-shot federated learning to aerial networks with intermittent connectivity utilization. Heidari et al. [35], in a systematic review of machine learning for the Internet of Drones, confirmed that quantum methods have not been utilized in the solution domain yet. Chen et al. [36] deployed quantum kernels and QNNs on UAV swarm intrusion data without the use of a federated setting. Sahin [37] describes a “quantum-resilient” FL framework for UAV anomaly detection, although the quantum-resilience referred to post-quantum cryptography rather than any actual quantum circuit deployment. UAV security is a different problem from IoHT security. Therefore, this portion of the literature is covered for only QFL content coverage. In these applications, a genuine QFL system has not been developed yet.
QFL and differential privacy are combined directly in a limited number of research articles. Rofougaran et al. [38] trained differentially private hybrid quantum-classical models on binary image classification exceeding 98% Accuracy at . Li et al. [39] used gradient variance for QFL, while Pokharel et al. [40] followed a completely different route, utilizing the depolarizing noise already present in NISQ hardware as a built-in privacy mechanism rather than injecting noise explicitly. All three approaches are useful proofs of concepts for privacy incorporation while implementing QFL; however, none of them cover IoT security, let alone a healthcare dataset.
All in all, the existing limited literature clearly indicates a fairly clear gap. Every IoHT-focused federated learning article remains to use classical approaches. Every QFL paper that covered anomaly or intrusion detection utilized synthetic or generic IoT data rather than a real healthcare testbed. This work contains a unique N-QML approach where we apply a federated quantum learning framework that builds around QPCA and QNN for analysis of the WUSTL-EHMS-2020 dataset. Table 1 contains an overview of the relevant works and their comparisons.
Table 1.
Comparison of this work to other related works.
3. Network of Quantum Neural Networks
The mathematical framework of N-QNN introduced in [13] relied on the neural network design proposed in [6] with the incorporation of a network structure into QNN. In this particular design, each node of the N-QNN consists of a variety and mix of network elements, including qubits, QNN, QSVM, and QCNN, as well as any of the other CML techniques such as SVM, ANN, CNN, etc. Hence, each node of N-QNN gains a subnetwork structure, and each one could consist of a variety of QML and CML techniques as well as qubits. In this network, each (hidden) sublayer consists of subnetworks. Introducing the following notation, furthermore, formulas that structure the N-QNN can be designed [13].
- k: Subnetwork’s hidden layer quantity
- O: Output
- I: Input
- : Input nodes
- : Output nodes
- : A basis used for the input space
- : Parametrized unitary
- : Layer unitary
- : Completely positive trace map
- : Adjoint channel of
- : QNN quantum circuit where is the output unitary
- : Layers and k are acted on by the i-th perceptron
- : Layer-to-layer transition maps of the Subnetwork
- : Output of the subnetwork
The subnetwork can be designed using the framework
where
The output of each subnetwork consists of completely positive maps’ composition sequence utilizing the perceptrons that act particularly on the sublayer levels k − 1 and k. The unitary can be formed using the basis and parametrized units
that allows subnetwork output to be structured as
By definition, it is possible to use fidelity to measure the closeness of pure quantum states’ closeness that can be used as a measure of cost function between the subnetwork’s output and the expected output averaged over the training data [41]:
The subnetwork training is performed by optimizing the cost function M where the values of M change between 0 and 1. The input and output relationship of the subnetwork nodes can be represented using unitary operation V as follows:
Updating the subnetwork parameter matrix D that is attained for the perceptron unitary components V and step size using the rotational mapping helps to produce subnetwork’s recurrent nature:
During the interaction between subnetworks, subnetwork output is structured by quantum perceptron’s that are acting on qubits in layers k − 1 and k. For each QNN subnetwork, as expected, cost function is aimed to be minimized that relies on the actual and quantum-computed values during the training of the subnetwork. We let
and
The change in the cost function can be stated as the following in a way with the changes in the matrix D components as layers change:
The changes and fine tuning of the matrix M for any three layers of the sub-network can be identified without the need for using the entire quantum circuitry within the local network layers. This approach helps to train the deep neural network to accomplish subnetwork tasks.
The optimization technique used in both quantum and conventional ML techniques could tremendously impact the outcomes. Adam optimizer is one of the most powerful and well-known optimizer [42] while the optimization techniques used in quantum field pose some challenges. For instance, Barren Plateau is recognized as a phenomenon when the gradients of the loss landscape of variational quantum algorithms are exponentially suppressed [43], and there are relevant challenges faced during optimization technique usage for QNN. In the case of ANN development, discriminative and generative approaches [44,45,46,47] are shown to be effective compared to classical ML approaches with training difficulty due to flat optimization landscapes of Barren plateaus [43]. Further developments in QNN included forward and backward propagations.
4. Computational Evaluation of the Theory and Results
In this section, our proposed FL-QPCA framework is compared with both centralized and federated classical baselines, including PCA combined with an ANN, a DNN, and an SVM. We also evaluate two centralized quantum baselines, QPCA+QNN and QPCA+QSVM, to establish structured federated quantum modeling. The dataset WUSTL-EHMS-2020 is used for attaining all experimental results, allowing direct comparison among the classical, quantum, and federated quantum settings under identical preprocessing steps and, critically, under a matched sample size and multi-seed statistical validation.
4.1. Dataset and Experimental Setup
The proposed FL-QPCA framework is evaluated using the WUSTL-EHMS-2020 dataset [16], a publicly available benchmark for IoT electronic health monitoring security. The dataset contains network traffic features alongside physiological sensor readings from wearable devices, reflecting the heterogeneous data environment of real healthcare IoT deployments. The preprocessing applied on the data dropped identifier features such as source and destination addresses, MAC addresses, and port numbers that carry no discriminative signals. The Flgs field is label-encoded, and the target variable is binarized to normal versus attack, collapsing all attack subcategories into a single class. The input features are standardized using StandardScaler, and SMOTE corrects class imbalance for the classical pipeline. Feature selection uses correlation-based ranking against the binary label; the top n features are retained for each dimensionality setting, with n evaluated at two, five, and ten.
After preprocessing, classical and quantum experiments relied on the same matched, stratified sample of 666 records (333 per class), eliminating the sample-size disparity present in earlier versions of this framework, where classical baselines were evaluated on the full 28,544-instance balanced dataset while both CML and QML experiments were restricted to 666 samples for computational tractability. Under an 80/20 stratified split, this yields 532 training and 134 test samples for every model type. Every experiment is repeated across three independent random seeds (42, 7, 13), each governing the sample draw, the train/test split, model initialization, and federated client partitioning; all results are reported using mean ± standard deviation statistics across these three seeds rather than as single point estimates. Table 2 summarizes the experimental configuration.
Table 2.
Experimental configuration.
During the experiments, there was no per-method hyperparameter search performed; all classical and quantum neural architectures share the same activation function (ReLU) and training (500 iterations), and all SVM-based models use the same RBF kernel and default regularization setting, a deliberate choice to avoid confounding architectural differences with unequal tuning effort across methods.
4.2. Classical Baselines
Centralized PCA+ANN and PCA+DNN show a modest decline in accuracy as dimensionality increases. Classical PCA scales its number of components with n exactly as the quantum feature encoding pipeline already does. Using the matched 666-sample dataset, PCA+ANN attained accuracies of 76.6 ± 1.6%, 76.1 ± 2.0%, and 74.6 ± 0.7% at , 5, and 10, respectively, while PCA+DNN attained 75.9 ± 1.9%, 74.1 ± 4.4%, and 71.6 ± 5.2% for the same three dimensions. A modest, roughly 2-4% decline for the neural architectures is consistent with the smaller, matched training set affecting classical and quantum pipelines similarly. The SVM baseline shows a comparatively larger decline of 6.4-points, from 74.6 ± 3.7% at to 68.2 ± 1.9% at , suggesting the RBF kernel makes less effective use of the available feature space than the neural architectures do as dimensionality increases.
The convergence curves in Figure 1 (PCA+ANN) and Figure 2 (PCA+DNN) show stable learning at across the full 500-epoch training, with training and validation accuracy remaining closely coupled and no meaningful sign of overfitting being observed. For , however, a persistent gap occurs between training and validation accuracy for both models: training accuracy climbs to roughly 90–92%, while validation accuracy plateaus in the 70–80% range, indicating mild overfitting once feature dimensionality increases to ten components. In the case when , an intermediate pattern is observed, consistent with the results reported in Table 3.
Figure 1.
Training versus validation accuracy for classical PCA+ANN when (a) . (b) .
Figure 2.
Training versus validation accuracy for classical PCA+DNN when (a) . (b) .
Table 3.
Performance summary of all classical (CML) experiments on the WUSTL-EHMS-2020 dataset, matched to the 666-sample size used for quantum experiments, grouped by feature dimension. Values are mean ± standard deviation across three seeds. All federated experiments use 3 clients and 10 rounds; all centralized classical experiments use 500 iterations.
4.3. Federated Classical Learning
The federated PCA+ANN model, trained across three simulated hospital clients using FedAvg over 10 rounds, tracks its centralized counterpart closely when and but diverges further when . For , federated accuracy is 74.1 ± 3.0% compared to a centralized accuracy of 76.6 ± 1.6%; at , federated accuracy is 73.6 ± 5.3% compared to 76.1 ± 2.0%; when , federated accuracy is 67.4 ± 5.0% compared to 74.6 ± 0.7%, a 7.2 percentage point gap that is larger than at the other two dimensions and only partially explained by seed-to-seed variance. Federation, therefore, introduces a small, largely negligible accuracy cost for the classical model at low dimensionality but a more noticeable one for , a pattern not visible prior to correcting the classical PCA dimensionality-scaling issue described previously. Figure 3 shows the corresponding convergence behavior at and . In both settings, the global model stabilizes within the first several rounds, and training and validation accuracy remain tightly coupled throughout, indicating the aggregated global model generalizes as well as the centralized one, despite the small number of communication rounds available.
Figure 3.
Training versus validation accuracy for federated PCA+ANN over 10 rounds when (a) . (b) .
4.4. Quantum Models
The quantum model deployed in this work is a combination of feature selection by using QPCA that is followed by feeding the selected features to a QML technique. The QPCA we utilized in centralized quantum experiments followed the one used in [12] relying on classical PCA followed by a ZZFeatureMap (linear entanglement), with each sample individually encoded and measured via AerSimulator at 1000 shots, and the resulting measurement probabilities rescaled to before classification. This application of QPCA is different from the one used in the quantum computing literature that relies on quantum phase estimation applied to a density matrix. It is a hybrid classical PCA and quantum feature-encoding pipeline.
As a result of the experimental design, on the matched 666-sample dataset, QPCA+QNN reaches 75.6 ± 2.4% accuracy when , decreases to 68.9 ± 5.0% for , and reaches 69.2 ± 5.7% at . QPCA+QSVM follows a similar accuracy pattern consisting of 72.1 ± 1.6%, 67.9 ± 6.8%, and 67.9 ± 2.7% values, respectively. Both centralized quantum models trail the strongest classical baseline, PCA+ANN, by roughly one to seven percentage points depending on dimension, consistent with the broader difficulty of extracting quantum advantage from near-term hardware on classical tabular data.
Figure 4 demonstrates the convergence behavior when and for a representative seed. At , training accuracy climbs to approximately 84%, while validation accuracy plateaus near 70%, indicating the model’s overfit to the limited training data at higher dimensionality; this training-validation gap is not present in the classical baselines and reflects the added generalization difficulty of quantum kernel methods operating on a small sample during simulation.
Figure 4.
Training versus validation accuracy for centralized QPCA+QNN when (a) . (b) .
4.5. Federated Quantum Learning
The QPCA feature encoding is applied locally at each of three clients before federated training begins as a part of the FL-QPCA framework. Each hospital client transforms its local partition of approximately 177 to 178 samples independently, trains a local QNN with warm_start enabled, and sends weight updates to the server, which aggregates them by FedAvg over 10 rounds.
As a result of the experiments, averaged across three independent seeds, federated QPCA+QNN accuracy is observed to decline steadily with dimension: 62.9 ± 15.8% for , 57.2 ± 9.0% when , and 55.7 ± 2.3% at . Every federated quantum configuration trailed its centralized counterpart by margins of 12.7, 11.7, and 13.4 percentage points, respectively, a materially larger and more consistent federation penalty than the gap observed for the classical model at any dimension. A more striking pattern appears in the variance: standard deviation across seeds is 15.8 percentage points when , roughly 1.7 times greater than the one observed for (9.0 points) and nearly 7 times greater than the one attained for (2.3 points)—a sharp, non-monotonic decline. The lowest-dimensional federated quantum configuration remains the least predictable across random seeds. We attribute this instability to the interaction between FedAvg’s weight averaging and the loss landscape induced by quantum-kernel-derived features, rather than to quantum circuit parameter-space geometry or barren plateaus specifically. The QNN in this framework is a classical MLPClassifier trained on features already transformed by a quantum feature map; FedAvg averages the weights of this classical network, not the parameters of a variational quantum circuit, and we do not have direct evidence of the vanishing-gradient behavior to support the existence of a barren plateau in this application. What is observed instead is that three clients training on small, disjoint partitions of quantum-kernel-transformed data can converge to meaningfully different local optima, particularly at low feature dimensionality where each client’s partition of roughly 177 samples may poorly represent the global decision boundary. Averaging these divergent local models can produce a global model with higher variance and, in some seeds, substantially lower accuracy than any individual client’s local model could achieve alone. The reason for experiencing the strongest effect at rather than experiencing it in higher dimensions is not fully explainable by our current experiments, and we treat this as an open empirical question. Testing this hypothesis directly, for instance, by varying the number of samples available per client independently of feature dimensionality, is left as a part of the future work to be completed.
Figure 5 is a demonstration of the mean test accuracies per round across all three seeds together with a shaded band representing ± one standard deviation range coverage from the mean value. The shaded band attained for is visibly wider than the ones for and throughout all ten rounds, confirming that the elevated variance is not an artifact of any single seed but a consistent property of that configuration.
Figure 5.
Federated QPCA+QNN test accuracy per round, mean ± one standard deviation across three seeds, shown separately by feature dimension.
4.6. Comparative Analysis
A summary of the experimental results is presented in Table 3 for classical models and Table 4 for quantum and federated quantum models, grouped by feature dimensionality and reported as mean ± standard deviation across three seeds. The central empirical finding of this work is an asymmetry in how federation affects classical versus quantum models. For the classical PCA+ANN model, federation costs at most 2 to 3 percentage points of accuracy at any dimension, well within seed-to-seed variance, an essentially free trade for the privacy benefits of not centralizing patient data. For the quantum QPCA+QNN model, federation is both larger in cost, at 10.7 to 15.2 percentage points depending on dimension, and substantially more variable, with standard deviation across seeds reaching 15.2 percentage points at . No comparable instability appears anywhere in the classical results.
Table 4.
Performance summary of all quantum (QML) experiments on the WUSTL-EHMS-2020 dataset, grouped by feature dimension. Values are mean ± standard deviation across three seeds. All federated experiments use 3 clients and 10 rounds; all centralized quantum experiments use 500 iterations.
Computational runtime follows a similar pattern to that observed previously and yields a finding of independent interest for deployment considerations. Federated QPCA+QNN is the most computationally expensive experiment in this study, as it lasted 117.9, 120.4, and 124.5 s on average for , 5, and 10, respectively, exceeding even centralized QPCA+QNN (90.1, 96.4, and 95.9 s). This arises because the quantum feature encoding step that dominates total runtime must be computed independently by each of the three clients in the federated setting, with no sharing of computational results across the clients, unlike the centralized case. Federating this quantum pipeline across k clients increases the quantum encoding cost, while classical federation adds negligible overhead by comparison.
From a comparison standpoint, the classical models remained relatively stronger and more stable performers compared to the quantum techniques utilized in this study; the neural classical models (PCA+ANN, PCA+DNN) stay above 71% mean accuracy at every dimension tested, though PCA+SVM and federated PCA+ANN fall to 68.2% and 67.4%, respectively, when , and federation costs at most 7.2 percentage points relative to the centralized counterpart, concentrated at that dimension. Centralized quantum models (QPCA+QNN and QPCA+QSVM) trail the strongest classical baseline by roughly one to seven percentage points depending on the dimension, consistent with the broader difficulty of extracting quantum advantage from near-term hardware on classical tabular data. Federated quantum performance trails further still at every dimension tested, and its instability, rather than a single failing dimension, is the central and most consistent finding of this evaluation. Figure 6 shows this pattern directly: the classical and federated classical curves sit in a tight, stable band across the full training process, while the federated quantum curves are both lower in accuracy and visibly more erratic across seeds. Figure 7 demonstrates the ten-round centralized curve behavior across the models during the ten rounds of runs.
Figure 6.
Validation accuracy across all centralized and classical models, WUSTL-EHMS-2020 dataset, plotted by training epoch (500 epochs total).
Figure 7.
Validation accuracy across all federated models, WUSTL-EHMS-2020 dataset, plotted by federated round (10 rounds total).
5. Discussion
In this work, a systematic comparison of centralized and federated QPCA+QNN performances is conducted on an IoHT intrusion detection dataset under a matched sample size and multi-seed statistical validation, and to the best of our knowledge, this is the first work on such analysis. The quantum models developed had lower accuracies when compared to the classical ones on the particular dataset utilized. As a result, federated quantum learning in the reduced dataset setting had measurably both less accurate and less predictable outcomes than its centralized counterpart, and that unpredictability is most severe at the lowest tested feature dimensionality rather than the highest. This motivates future work on quantum-aware aggregation strategies and on characterizing the sample-size and dimensionality regimes under which FedAvg remains stable for quantum-kernel-derived features.
Another interesting result is attained when the quantum model is federated. Classical federation stays close to its centralized counterpart at and (within 2.5 percentage points) but widens to a 7.2-point gap at , a larger federation penalty than earlier analysis suggested and one concentrated at the highest tested dimension rather than uniformly small. Federated QPCA+QNN shows a comparable magnitude of accuracy decline: averaged across three random seeds, accuracy falls from 62.9% at to 57.2% at to 55.7% at , trailing its centralized counterpart by 11.7 to 13.5 percentage points at every dimension. The size of the accuracy gap alone, therefore, does not sharply separate federated quantum learning from classical baselines, several of which show declines of similar magnitude. A pooled paired t-test across all nine seed-dimension observations gives , (Wilcoxon ); because the three dimensions within a seed share the same sample and split, these nine observations are not fully independent, and we treat this pooled test as descriptive rather than confirmatory. Per-dimension tests at seeds, the true unit of replication, reach significance only at (), with and not significant (, ) at this seed count. What does distinguish federated quantum learning is variance: standard deviation across seeds is 15.8 percentage points at , more than double the largest variance recorded anywhere else in this study (6.8 points, centralized QPCA+QSVM at ), falling sharply to 9.0 points at and 2.3 points at . Federated quantum training is therefore not simply less accurate at low dimensionality; it is dramatically less consistent from run to run than any classical configuration tested, at any dimension. We attribute this result to the interaction between FedAvg’s weight averaging and the loss landscape induced by quantum-kernel-derived features, not to quantum parameter-space geometry or barren plateaus. Our QNN is a classical MLPClassifier trained on features already transformed by a quantum feature map; FedAvg in our federated experiments averages the weights of this classical network, not the parameters of a variational quantum circuit, and we do not observe the specific optimization pathology that the term ’barren plateau’ exhibits. Our observations rely on three clients’ training on disjoint partitions of roughly 177 to 178 samples with one’s meaningful convergence to different local optima, particularly at low dimensionality where the feature space is small and any single client’s partition may not represent the global decision boundary well; averaging these divergent local models can produce a global model that performs worse, and with substantially higher variance, than any individual client’s local model would. This is consistent with well-documented client drift effects in classical federated learning under small, heterogeneous local datasets, applied here to a feature space with different geometric properties than raw classical features. The reason for this effect to be the strongest at the lowest tested dimension rather than the highest remains an open question that our current experiments do not resolve.
A factor that played a significant role during computational experiment results’ attainment is the dataset size. Our experiments for both classical and quantum computations relied on a matched sample size of 666 records rather than the much larger classical dataset used in earlier studies within the dataset. This was a deliberate choice made to compare the benchmark values on such a small-sized structured database. This specific data set reduction was selected to implement a fair comparison between classical and quantum methods. The original dataset was not utilized due to the runtime challenges that would be faced during quantum-driven computational experiment results’ attainment. As discussed earlier, classical model accuracy remained relatively stable across different dimensions while quantum accuracy declined; that contrast was an artifact of an inconsistency in how classical PCA’s component count was set relative to the reported dimension, not a genuine finding, and changing this factor, with classical PCA now scaling its number of components with dimension exactly as the quantum feature encoding does, classical accuracy also declines moderately across dimensions two, five, and ten (by 2.0 points for PCA+ANN and up to 6.4 points for PCA+SVM), a pattern consistent with the smaller, matched sample size affecting every model type rather than being unique to the quantum pipeline.
Another factor that played a significant role in the experimental result attainment of this study is the federated client setting itself. We used three simulated clients with client partitions remaining approximately equal in size and independently and identically distributed. Noting this factor, at the same total matched sample size, there was a limited number of samples available to each client with approximately 177 to 178 data points’ partitioning to each one of them. Therefore, non-IID partitions, unbalanced client sizes, and a larger number of clients are not tested in this study. We leave such a real-life multi-hospital deployment of the models introduced in this work as a future work to be implemented, as computational time deployment of the quantum models is currently challenging. Another future work is the identification of the reason(s) for showing the highest variance.
Overall, none of the above-mentioned arguments are against pursuing QFL for healthcare IoT security. It is well known that quantum technologies give the ability to increase security during communications by detecting communication interferences by outsiders. Additional testing and different technique utilization may result in stronger computational QML results that needs to be tested using end-to-end network testing on real-life networks.
6. Conclusions
In this work, we proposed FL-QPCA as a new ML approach, a federated quantum learning framework that combines Quantum PCA with a quantum neural network for intrusion detection on the WUSTL-EHMS-2020 IoHT dataset. This technique is evaluated using the centralized and federated classical baselines and centralized quantum baselines, across three feature dimensions, using the same sample size for both classical and quantum experiments, and across three independent random seeds.
Federated classical learning remained close to the centralized training when and (within 2.5 percentage points) but showed a larger (7.2-point) gap at . Federated quantum learning accuracy decreased steadily with dimensionality: accuracy dropped from 62.9% at to 57.2% at and then to 55.7% at , trailing its centralized counterpart by 11.7 to 13.5 percentage points at every dimension, a pattern not previously documented, to our knowledge, for a real intrusion detection dataset under matched sample sizes and multi-seed validation. The more distinctive finding is variance: standard deviation across seeds was 15.8 percentage points when , more than double the largest variance recorded for any other configuration in this study (6.8 points), falling sharply and non-monotonically to 9.0 points at and 2.3 points at . We attribute this instability to the interaction between FedAvg’s parameter averaging and the loss landscape induced by quantum-kernel-derived features on small, disjoint client partitions, although the exact mechanism and why is the most volatile setting rather than the least remain an open question.
Overall, measurable results indicated the best performance attainment by PCA+ANN, having an accuracy of 76.6% at , compared to a ceiling closer to 74% for any quantum variant tested for the same dimension. Every model type evaluated, classical and quantum alike, showed some decline in accuracy as dimension increased from 2 to 10; what distinguished federated quantum learning was not the size of this decline, comparable in magnitude to that of the classical SVM baseline, but its variance, which was several times larger in magnitude than that of any classical or centralized-quantum configuration tested. Our contribution in this work is the developed framework itself, evaluated end-to-end on a matched dataset under multi-seed statistical validation, and the empirical finding that federated aggregation affects quantum and classical models in fundamentally different and, for quantum models, unpredictable ways. This is a useful finding contributing to the field of applications that needs to be carefully investigated by other researchers.
Future work falls into three areas. First, the sample-size hypothesis needs to be tested properly, with a quantum dataset large enough to vary per-client sample counts systematically and independently of feature dimensionality, rather than relying on a single fixed split. Second, quantum-aware aggregation strategies, the ones that account for the geometry of the loss landscape induced by quantum feature encoding rather than treating quantum-derived weights as if they were ordinary classical ones, are worth exploring as a direct response to the instability we observed. Third, the federated setting itself needs to be tested under genuinely non-IID client partitions, unbalanced client sizes, and a larger number of clients, since our current three-client, near-identically distributed setup does not yet reflect realistic multi-hospital deployment conditions and may itself be a contributing factor to the instability reported here.
Author Contributions
Conceptualization, E.T.; methodology, E.T.; software, F.M.; formal analysis, F.M. All authors have read and agreed to the published version of the manuscript.
Funding
This research received no external funding.
Data Availability Statement
The dataset used in this study, WUSTL-EHMS-2020, is publicly available and is cited in the manuscript. The source code developed for this study is not publicly available at this time. Requests for further information about the implementation may be directed to the corresponding author.
Conflicts of Interest
The authors declare no conflicts of interest.
References
- Algethami, S.A.; Alshamrani, S.S. A deep learning-based framework for strengthening cybersecurity in internet of health things (IoHT) environments. Appl. Sci. 2024, 14, 4729. [Google Scholar] [CrossRef] [Scilit]
- Muthupandian, S.; Manoj Kumar, D. CNN-BiLSTM-Based Hybrid Deep Learning for Multi-Metric Anomaly Detection and Mitigation in Secure IoMT Healthcare WBANs. Sensors 2026, 26, 3849. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Bhasker, B.; Rao, P.M.; Saraswathi, P.; Patro, S.G.K.; Bhutto, J.K.; Islam, S.; Kareemullah, M.; Emma, A.F. Blockchain framework with IoT device using federated learning for sustainable healthcare systems. Sci. Rep. 2025, 15, 26736. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Tokgoz, E. Artificial Bee Colony Optimization Techniques’ Utilization for Intrusion Detection Systems’ Analysis. In Proceedings of the 4th IEEE International Conference on AI in Cybersecurity (ICAIC) Proceedings, Houston, TX, USA, 5–7 February 2025; Available online: https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=10848880 (accessed on 5 September 2026).
- Schuld, M.; Sinayskiy, I.; Petruccione, F. The quest for a quantum neural network. Quantum Inf. Process. 2014, 13, 2567–2586. [Google Scholar] [CrossRef] [Scilit]
- Beer, K.; Bondarenko, D.; Farrelly, T.; Osborne, T.J.; Salzmann, R.; Scheiermann, D.; Wolf, R. Training deep quantum neural networks. Nat. Commun. 2020, 11, 808. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Cong, I.; Choi, S.; Lukin, M.D. Quantum convolutional neural networks. Nat. Phys. 2019, 15, 1273–1278. [Google Scholar] [CrossRef] [Scilit]
- Rebentrost, P.; Mohseni, M.; Lloyd, S. Quantum support vector machine for big data classification. Phys. Rev. Lett. 2014, 113, 130503. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Park, S.; Park, D.K.; Rhee, J.K.K. Variational quantum approximate support vector machine with inference transfer. Sci. Rep. 2023, 13, 3288. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Aïmeur, E.; Brassard, G.; Gambs, S. Quantum speed-up for unsupervised learning. Mach. Learn. 2013, 90, 261. [Google Scholar] [CrossRef] [Scilit]
- Lloyd, S.; Mohseni, M.; Rebentrost, P. Quantum principal component analysis. Nat. Phys. 2014, 10, 631–633. [Google Scholar] [CrossRef] [Scilit]
- Tokgoz, E.; Baah, L. An Integrated Quantum PCA and Network of Quantum Neural Network Approach with an Application to Kidney Cancer. In Proceedings of the AIR-RES’26 Conference; Springer Nature: Berlin/Heidelberg, Germany, 2026. [Google Scholar]
- Tokgoz, E.; Desiboyina, S. Network of Quantum Neural Networks. In Proceedings of the 2025 CSCI Conference’s Research Track on Artificial Intelligence; Springer Nature: Berlin/Heidelberg, Germany, 2025. [Google Scholar]
- Tokgoz, E.; Desiboyina, S. Network of Quantum Support Vector Machines & Red Wine Quality Analysis. In Proceedings of the ICEQT’26 Conference Proceedings; Springer Nature: Berlin/Heidelberg, Germany, 2026. [Google Scholar]
- Tokgoz, E.; Desiboyina, S. Network of Quantum Convolutional Neural Networks. In Proceedings of the CAC’26 Conference Proceedings; Springer Nature: Berlin/Heidelberg, Germany, 2026. [Google Scholar]
- Hady, A.A.; Ghubaish, A.; Salman, T.; Unal, D.; Jain, R. Intrusion detection system for healthcare systems using medical and network data: A comparison study. IEEE Access 2020, 8, 106576–106584. [Google Scholar] [CrossRef] [Scilit]
- Kairouz, P.; McMahan, H.B.; Avent, B.; Bellet, A.; Bennis, M.; Bhagoji, A.N.; Bonawitz, K.; Charles, Z.; Cormode, G.; Cummings, R.; et al. Advances and open problems in federated learning. Found. Trends Mach. Learn. 2021, 14, 1–210. [Google Scholar] [CrossRef] [Scilit]
- Yang, H.; Ge, M.; Xue, D.; Xiang, K.; Li, H.; Lu, R. Gradient leakage attacks in federated learning: Research frontiers, taxonomy and future directions. IEEE Netw. 2023, 38, 247–254. [Google Scholar] [CrossRef] [Scilit]
- Otoum, Y.; Wan, Y.; Nayak, A. Federated transfer learning-based IDS for the Internet of Medical Things (IoMT). In Proceedings of the 2021 IEEE Globecom Workshops (GC Wkshps), Madrid, Spain, 7 –11 December 2021; pp. 1–6. [Google Scholar]
- Rashid, M.M.; Khan, S.U.; Eusufzai, F.; Redwan, M.A.; Sabuj, S.R.; Elsharief, M. A federated learning-based approach for improving intrusion detection in Industrial Internet of Things networks. Network 2023, 3, 158–179. [Google Scholar] [CrossRef] [Scilit]
- Friha, O.; Ferrag, M.A.; Benbouzid, M.; Berghout, T.; Kantarci, B.; Choo, K.K.R. 2DF-IDS: Decentralized and differentially private federated learning-based intrusion detection system for industrial IoT. Comput. Secur. 2023, 127, 103097. [Google Scholar] [CrossRef] [Scilit]
- Mosaiyebzadeh, F.; Pouriyeh, S.; Parizi, R.M.; Han, M.; Batista, D.M. Intrusion Detection System for IoHT Devices using Federated Learning. In Proceedings of the IEEE INFOCOM 2023—IEEE International Conference on Computer Communications (INFOCOM), Hoboken, NJ, USA, 20 May 2023. [Google Scholar] [CrossRef] [Scilit]
- Mosaiyebzadeh, F.; Pouriyeh, S.; Han, M.; Liu, L.; Xie, Y.; Zhao, L.; Batista, D.M. Privacy-Preserving Federated Learning-Based Intrusion Detection System for IoHT Devices. Electronics 2024, 14, 67. [Google Scholar] [CrossRef] [Scilit]
- Ahmed, M.; Byreddy, S.; Nutakki, A.; Sikos, L.F.; Haskell-Dowland, P. ECU-IoHT: A dataset for analyzing cyberattacks in Internet of Health Things. Ad Hoc Netw. 2021, 122, 102621. [Google Scholar] [CrossRef] [Scilit]
- Biamonte, J.; Wittek, P.; Pancotti, N.; Rebentrost, P.; Wiebe, N.; Lloyd, S. Quantum machine learning. Nature 2017, 549, 195–202. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Cerezo, M.; Arrasmith, A.; Babbush, R.; Benjamin, S.C.; Endo, S.; Fujii, K.; McClean, J.R.; Mitarai, K.; Yuan, X.; Cincio, L.; et al. Variational quantum algorithms. Nat. Rev. Phys. 2021, 3, 625–644. [Google Scholar] [CrossRef] [Scilit]
- Treinish, M. Qiskit/Qiskit-Metapackage: Qiskit 0.44, Zenodo. 2023. Available online: https://zenodo.org/records/8190968 (accessed on 11 September 2026).
- Qiskit Machine Learning Developers. Qiskit Machine Learning. 2023. Available online: https://github.com/qiskit-community/qiskit-machine-learning (accessed on 5 September 2026).
- Pennylane Software. 2026. Available online: https://pennylane.ai/ (accessed on 5 September 2026).
- Chen, S.Y.C.; Yoo, S. Federated quantum machine learning. Entropy 2021, 23, 460. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Chehimi, M.; Saad, W. Quantum federated learning with quantum data. In Proceedings of the 2022 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), Singapore, 22–27 May 2022. [Google Scholar]
- Chen, K.C.; Chen, S.Y.C.; Liu, C.Y.; Leung, K.K. Federated quantum kernel learning for anomaly detection in multivariate IoT time-series. In 2025 IEEE Annual Congress on Artificial Intelligence of Things (AIoT); IEEE: New York, NY, USA, 2025; pp. 278–285. Available online: https://ieeexplore.ieee.org/abstract/document/11415725 (accessed on 5 September 2026).
- Godavarthi, D.; Rekapalli, V.C.S.; Mohanty, S.; Jaswanth, J.V.; Polisetty, D.; Dash, B.B.; Moreira, F. Federated quantum-inspired anomaly detection using collaborative neural clients. Front. Artif. Intell. 2025, 8, 1648609. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Ceviz, O.; Sen, S.; Sadioglu, P. Distributed intrusion detection in dynamic networks of UAVs using few-shot federated learning. In International Conference on Security and Privacy in Communication Systems; Springer: Berlin/Heidelberg, Germany, 2024; pp. 131–153. [Google Scholar]
- Heidari, A.; Navimipour, N.J.; Unal, M.; Zhang, G. Machine learning applications in internet-of-drones: Systematic review. ACM Comput. Surv. 2023, 55, 1–45. [Google Scholar] [CrossRef] [Scilit]
- Chen, K.C.; Chen, S.Y.C.; Li, T.Y.; Liu, C.Y.; Leung, K.K. Quantum machine learning for uav swarm intrusion detection. In 2025 IEEE Globecom Workshops (GC Wkshps); IEEE: New York, NY, USA, 2025; pp. 921–926. Available online: https://ieeexplore.ieee.org/abstract/document/11590964 (accessed on 5 September 2026).
- Batur Sahin, C. Quantum-resilient federated learning for multi-layer cyber anomaly detection in UAV systems. Sensors 2026, 26, 509. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Rofougaran, R.; Yoo, S.; Tseng, H.H.; Chen, S.Y.C. Federated quantum machine learning with differential privacy. In Proceedings of the ICASSP 2024—2024 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), Seoul, Republic of Korea, 14–19 April 2024. [Google Scholar]
- Li, C.; Kumar, N.; Song, Z.; Chakrabarti, S.; Pistoia, M. Privacy-preserving quantum federated learning via gradient hiding. Quantum Sci. Technol. 2024, 9, 035028. [Google Scholar] [CrossRef] [Scilit]
- Pokharel, A.; Rahman, R.; Shaon, S.; Morris, T.; Nguyen, D.C. Differentially private federated quantum learning via quantum noise. In 2025 IEEE International Conference on Quantum Computing and Engineering (QCE); IEEE: New York, NY, USA, 2025; Volume 1, pp. 1559–1565. Available online: https://ieeexplore.ieee.org/abstract/document/11250199 (accessed on 5 September 2026).
- Devadas, R.M.; Sowmya, T. Quantum machine learning: A comprehensive review of integrating AI with quantum computing for computational advancements. MethodsX 2025, 14, 103318. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Kinga, D.; Adam, J.B. A method for stochastic optimization. In Proceedings of the International Conference on Learning Representations (ICLR), San Diego, CA, USA, 7–9 May 2015; Volume 5, p. 1. [Google Scholar]
- McClean, J.R.; Boixo, S.; Smelyanskiy, V.N.; Babbush, R.; Neven, H. Barren plateaus in quantum neural network training landscapes. Nat. Commun. 2018, 9, 4812. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Huang, H.L.; Du, Y.; Gong, M.; Zhao, Y.; Wu, Y.; Wang, C.; Li, S.; Liang, F.; Lin, J.; Xu, Y.; et al. Experimental quantum generative adversarial networks for image generation. Phys. Rev. Appl. 2021, 16, 024051. [Google Scholar] [CrossRef] [Scilit]
- Mitarai, K.; Negoro, M.; Kitagawa, M.; Fujii, K. Quantum circuit learning. Phys. Rev. A 2018, 98, 032309. [Google Scholar] [CrossRef] [Scilit]
- Zeng, J.; Wu, Y.; Liu, J.G.; Wang, L.; Hu, J. Learning and inference on generative adversarial quantum circuits. Phys. Rev. A 2019, 99, 052306. [Google Scholar] [CrossRef] [Scilit]
- Hamilton, K.E.; Dumitrescu, E.F.; Pooser, R.C. Generative model benchmarks for superconducting qubits. Phys. Rev. A 2019, 99, 062323. [Google Scholar] [CrossRef] [Scilit]
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.






