IP Library Granted Patent US 12,452,265
Granted Patent B2
US 12,452,265 · App. 18/510,105 · Granted Oct 21, 2025

Intrusion detection system for IoT networks using blockchain-enabled federated learning and operating method thereof

Inventors: Ki Ryong Kwon (Busan, KR); Mamunur Rashid Md (Busan, KR)
Assignee: PUKYONG NATIONAL UNIVERSITY INDUSTRY-UNIVERSITY COOPERATION FOUNDATION
H04L63/1416G06N3/045G06N3/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,452,265
App. No.
18/510,105
Granted
Oct 21, 2025
Kind
B2
Abstract

An intrusion detection system for an IoT network using blockchain-enabled federated learning (FL) and an operating method thereof are described. The intrusion detection system for the IoT network includes a plurality of local clients configured to be each interconnected with a plurality of Internet of Things (IoT) device groups to establish an individual IoT network, and a central server configured to be interconnected with the plurality of local clients and implemented on a blockchain network, wherein each of the plurality of local clients includes a local neural network model for intrusion detection, and updates a current local neural network model based on a global neural network model transmitted from the central server.

Claims (23)

1. An intrusion detection system for an Internet of Things (IoT) network, comprising:

a plurality of local clients, each configured to be interconnected with a corresponding one of a plurality of IoT device groups to establish an individual IoT network; and

a central server configured to be interconnected with the plurality of local clients and implemented on a blockchain network,

wherein at a beginning of operation, the central server is configured to:

generate an initial global neural network model by using data held by the central server, and

transmit the generated global neural network model to each of the plurality of local clients,

wherein each of the plurality of local clients is configured to:

input data collected from a IoT device group interconnected with each of the plurality of local clients into the initial global neural network model to train the initial global neural network model, and

generate an initial local neural network model, and

wherein each of the plurality of local clients includes a local neural network model for intrusion detection, and is further configured to update a current local neural network model based on an updated global neural network model transmitted from the central server.

2. The intrusion detection system of claim 1 , wherein each of the plurality of local clients trains the current local neural network model by using data collected from the IoT device group interconnected with each of the plurality of local clients as input, and transmits learning content to the central server.

3. The intrusion detection system of claim 1 , wherein the central server generates a global neural network model updated by combining learning content transmitted from each of the plurality of local clients, and transmits the updated global neural network model to each of the plurality of local clients.

4. The intrusion detection system of claim 1 , wherein the central server includes a plurality of nodes implemented on the blockchain network, and the plurality of nodes generate an updated global neural network model based on learning content transmitted from a local client among the plurality of local clients and learning content transmitted from other nodes.

5. An operating method of an intrusion detection system for an Internet of Things (IoT) network, the system detecting an intrusion into an IoT network established by interconnecting each of a plurality of IoT device groups with a corresponding one of a plurality of local clients, each of the plurality of local clients including a local neural network model for intrusion detection, the method comprising:

generating, by a central server implemented on a blockchain network, an initial global neural network model by using data stored by the central server at a beginning of operation;

transmitting, by the central server, the generated initial global neural network model to each of the plurality of local clients;

inputting, by each of the plurality of local clients, data collected from a IoT device group interconnected with each of the plurality of local clients into the initial global neural network model to train the initial global neural network model;

generating, by each of the plurality of local clients, an initial local neural network model;

training, by each of the plurality of local clients, a current local neural network model by using data collected from the IoT device group interconnected with each of the plurality of local clients as input and transmitting learning content to the central server;

generating, by the central server, a global neural network model updated by combining the learning content transmitted from each of the plurality of local clients, and transmitting the generated global neural network model to each of the plurality of local clients; and

updating, by each of the plurality of local clients, the current local neural network model based on the updated global neural network model.

6. The operating method of claim 5 , wherein the central server includes a plurality of nodes implemented on the blockchain network, and

wherein the generating, by the central server, the updated global neural network model includes generating, by the plurality of nodes, the global neural network model updated by combining the learning content transmitted from a local client among the plurality of local clients and learning content transmitted from other nodes.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2023
From: KWON, KI RYONG; RASHID MD, MAMUNUR
To: PUKYONG NATIONAL UNIVERSITY INDUSTRY-UNIVERSITY COOPERATION FOUNDATION
Reel/Frame 065574/0536 →
Priority Claims (1)
KR 10-2022-0156591 · Nov 21, 2022 · national
Continuity (1)
Related Publication 20240171599A1 · May 23, 2024
References Cited (23)
US 7523502B1 · Kennedy · 2009 [cited by examiner]
US 20020032871A1 · Malan · 2002 [cited by examiner]
US 20130283374A1 · Zisapel · 2013 [cited by examiner]
US 20170331853A1 · Kawakita · 2017 [cited by examiner]
US 20200267146A1 · Nambiar · 2020 [cited by examiner]
US 20210258328A1 · Appel · 2021 [cited by examiner]
US 20210374617A1 · Chu · 2021 [cited by examiner]
US 20220043920A1 · Zhang · 2022 [cited by examiner]
US 20220044117A1 · Song · 2022 [cited by examiner]
US 20220044162A1 · Zhang · 2022 [cited by examiner]
US 20220156368A1 · Spyridopoulos · 2022 [cited by examiner]
US 20220215256A1 · Song · 2022 [cited by examiner]
US 20220318412A1 · Guo · 2022 [cited by examiner]
US 20230087863A1 · Gong · 2023 [cited by examiner]
US 20230169350A1 · Louizos · 2023 [cited by examiner]
US 20230259812A1 · Jagyasi · 2023 [cited by examiner]
US 20230319094A1 · Bakman · 2023 [cited by examiner]
US 20230336436A1 · Zhang · 2023 [cited by examiner]
US 20240177063A1 · Aizaki · 2024 [cited by examiner]
US 20240250975A1 · Pourahmadi · 2024 [cited by examiner]
Thien Duc Nguyen, D″IoT: A Federated Self-learning Anomaly Detection System for IoT, (2019) IEEE. pp. 756-767 (Year: 2019). [cited by examiner]
Eman Ashraf, “FIDChain: Federated Intrusion Detection System for Blockchain-Enabled IoT Healthcare Applications” (Jun. 2022) (Year: 2022). [cited by examiner]
Mohanad Sarhan, “HBFL:A hierarchical blockchain-based federated learning frame work for collaborative IoT intrusion detection” University of Queensland, Sep. 2022 (Year: 2022). [cited by examiner]