Abstract
Abstract
The Industrial Internet of Things (IIoT) is increasingly targeted by cyberattacks, making intrusion detection systems (IDS) an essential defensive layer. Federated learning enables distributed clients to collaboratively train IDS models without sharing raw network traffic. However, real-world IIoT traffic is Non-IID and class-imbalanced across clients, which causes client drift and makes a single global model unsuitable, especially for rare attack classes. This paper proposes PAEDDPG (Personalized AutoEncoder--Deep Deterministic Policy Gradient), a personalized federated intrusion detection framework for Non-IID IIoT traffic. Each client jointly trains a shared model with a client-private reconstruction decoder that is never uploaded, preserving on-device privacy while keeping the communication payload identical to standard federated averaging. On the server, a DDPG agent learns probability-simplex aggregation weights from encoder-update statistics and data contribution, guided by a minority-sensitive reward that combines Macro-F1, balanced accuracy, and worst-class recall. Experiments on Edge-IIoTset and NF-ToN-IoT-v3 under IID and Non-IID settings show that PAEDDPG consistently outperforms representative federated and personalized federated baselines, improving the worst-class recall by about 18 percentage points over the best baseline under the strongest Non-IID setting, with the largest gains on rare attack classes and fast, stable convergence.