Purpose – This study evaluates reinforcement learning (RL)-based adaptive threshold optimization for binary Internet of Things (IoT) network anomaly detection in a federated sequence-to-sequence (Seq2Seq) reconstruction model. Reconstruction-based detectors require a threshold to convert anomaly scores into benign-or-attack decisions, and a fixed threshold may not provide the most suitable operating point in federated non-IID settings.Methods – An LSTM Seq2Seq autoencoder was implemented using a controlled CICIoT2023 subset with 182,829 records and 39 numerical traffic features. Three scenarios were compared: centralized Seq2Seq with static threshold, federated Seq2Seq with static threshold, and federated Seq2Seq with RL-based adaptive threshold. Federated learning used five simulated clients, Dirichlet non-IID partitioning with α = 0.5, three local epochs, ten communication rounds, and weighted FedAvg aggregation. The RL component was implemented as an offline validation-based threshold optimizer and selected a single final threshold after federated training. Findings – Compared with federated static thresholding, the RL-based adaptive threshold improved accuracy from 92.97% to 95.71%, recall from 91.60% to 98.21%, and F1-score from 94.98% to 97.08%. FNR decreased from 8.40% to 1.79%, while FPR increased from 3.40% to 10.95%.Research implications – Threshold optimization should be treated as a decision-layer component in federated reconstruction-based IDS. The proposed pipeline may also support vocational informatics and cybersecurity education as a case study on federated learning, anomaly detection, and threshold-based IDS trade-offs.Originality – This study positions RL-based threshold adaptation as a decision-layer component in federated reconstruction-based IoT anomaly detection.
Copyrights © 2026