Marran Al Qwaid, Gobbi Ramasamy, Md Sabbir Hossen
The rapid deployment of Internet of Things (IoT)-enabled electric vehicle (EV) charging infrastructures introduces cybersecurity challenges due to distributed operation, communication dependency, and exposure to malicious cyberattacks. Existing anomaly detection approaches mainly rely on centralized learning architectures that require raw charging data, creating privacy concerns, scalability limitations, and reduced robustness against stealth cyberattacks that mimic legitimate charging behavior. To address these issues, this paper proposes a privacy-preserving federated cybersecurity framework for IoT-based EV charging infrastructures using distributed anomaly detection. The framework integrates cybersecurity-aware feature engineering, aggressive and stealth cyberattack simulation, centralized anomaly detection, and federated learning without raw charging session sharing. A real-world EV charging dataset is utilized to model legitimate and malicious charging behavior using operational and engineered features, including charging ratio and power consistency. Experimental evaluation compares Isolation Forest, centralized LSTM autoencoder, and federated LSTM anomaly detection under aggressive and stealth cyberattack scenarios. The results show that aggressive cyberattacks are more easily separable, where Isolation Forest achieves an attack F1-score of 0.85 and AUC of 0.86, while stealth cyberattacks reduce detection performance, lowering the F1-score to 0.61. The centralized LSTM autoencoder demonstrates superior detection performance, whereas the federated LSTM preserves privacy and achieves competitive results with 0.86 accuracy, 0.67 attack F1-score, and 0.81 AUC without transmitting raw charging data. These findings demonstrate federated anomaly detection as a promising privacy-preserving solution for secure EV charging infrastructures.