Gurpreet Singh, Keshav Sood, P. Rajalakshmi, Yong Xiang
Federated learning (FL) offers a privacy-preserving paradigm for distributed machine learning, but its application to intrusion detection systems (IDS) in IoT networks is hindered by severe class imbalance, highly non-IID data, and high communication overhead. These challenges severely degrade the performance of conventional FL methods in real-world network traffic classification. To overcome these limitations, we propose Sentinel, a personalized federated IDS (pFed-IDS) framework that incorporates a dual-model architecture on each client, consisting of a high-capacity personalized teacher and a lightweight globally shared student model. This design balances deep local adaptation with efficient global aggregation while preserving privacy and reducing communication overhead by transmitting only the compact student model. Sentinel integrates three key mechanisms to ensure robust performance: bidirectional knowledge distillation with adaptive temperature scheduling, lightweight multi-level feature alignment between teacher and student representations, and a class-balanced loss to handle highly skewed traffic. On the server side, normalized gradient aggregation with equal client weighting mitigates client drift and improves fairness across clients. Extensive experiments on the IoTID20 and 5GNIDD benchmark datasets demonstrate that Sentinel significantly outperforms state-of-the-art federated baselines under extreme data heterogeneity, while lowering communication overhead.