The increasing adoption of Internet of Things (IoT) devices in smart-home environments has introduced new challenges for network monitoring, cybersecurity and digital forensics. In forensic scenarios, IoT devices can act as digital witnesses, since their network traffic may help reconstruct events after an incident. However, smart-home ecosystems are highly heterogeneous, including different device types, vendors, protocols, configurations and user behaviors. For this reason, machine learning models require large and diverse traffic datasets, whose centralized collection may expose sensitive information about users and their private environments. Federated Learning addresses this limitation by enabling collaborative model training while keeping raw data local. This thesis investigates Zigbee IoT device classification by comparing centralized XGBoost with Federated XGBoost. Zigbee is considered a relevant case study because its low-power mesh networks include devices with different roles and traffic behaviors, which make classification challenging. The experimental evaluation is based on Zigbee packet captures transformed into statistical network-flow features, using existing Zigbee datasets and a newly acquired dataset collected in a real smart-home environment. Federated XGBoost is evaluated with three aggregation strategies: gradient aggregation, cyclic aggregation and bagging. The results show that centralized XGBoost achieves the best overall performance. On CMU-Smarthome, it reaches 0.8525 accuracy, 0.7750 Macro F1 and 0.8510 Weighted F1, while the best federated configuration, based on gradient aggregation, reaches 0.7862, 0.7485 and 0.7746 respectively. On the more heterogeneous ZBIOT* group, the gap is much smaller: centralized XGBoost obtains 0.8700 accuracy, 0.6643 Macro F1 and 0.8685 Weighted F1, while Federated XGBoost reaches 0.8644, 0.6556 and 0.8644. These findings show that Federated XGBoost is a promising privacy-aware alternative for Zigbee IoT device classification, although further improvements are needed to better handle heterogeneous and imbalanced traffic.

La crescente diffusione dei dispositivi Internet of Things (IoT) negli ambienti smart home introduce nuove sfide per il monitoraggio delle reti, la cybersecurity e la digital forensics. In ambito forense, i dispositivi IoT possono agire come testimoni digitali, poiché il traffico di rete da essi generato può supportare la ricostruzione degli eventi dopo un incidente. Tuttavia, gli ecosistemi smart home sono altamente eterogenei e includono diversi tipi di dispositivi, produttori, protocolli, configurazioni e comportamenti degli utenti. Per questo motivo, i modelli di machine learning richiedono dataset di traffico ampi e diversificati, la cui raccolta centralizzata può però esporre informazioni sensibili sugli utenti e sui loro ambienti privati. Il Federated Learning affronta questa limitazione permettendo l’addestramento collaborativo di un modello condiviso mantenendo i dati grezzi localmente. Questa tesi analizza la classificazione di dispositivi IoT Zigbee confrontando XGBoost centralizzato con Federated XGBoost. Zigbee rappresenta un caso di studio rilevante perché le sue reti mesh a basso consumo includono dispositivi con ruoli e comportamenti di traffico differenti, rendendo la classificazione complessa. La valutazione sperimentale si basa su catture di pacchetti Zigbee trasformate in feature statistiche di flusso, utilizzando dataset Zigbee esistenti e un nuovo dataset acquisito in un ambiente smart home reale. Federated XGBoost viene valutato con tre strategie di aggregazione: gradient aggregation, cyclic aggregation e bagging. I risultati mostrano che XGBoost centralizzato ottiene le migliori prestazioni complessive. Su CMU-Smarthome raggiunge 0.8525 di accuracy, 0.7750 di Macro F1 e 0.8510 di Weighted F1, mentre la migliore configurazione federata, basata su gradient aggregation, raggiunge rispettivamente 0.7862, 0.7485 e 0.7746. Sul gruppo ZBIOT*, più eterogeneo, il divario è molto più ridotto: XGBoost centralizzato ottiene 0.8700 di accuracy, 0.6643 di Macro F1 e 0.8685 di Weighted F1, mentre Federated XGBoost raggiunge 0.8644, 0.6556 e 0.8644. Questi risultati mostrano che Federated XGBoost è una promettente alternativa privacy-aware per la classificazione di dispositivi IoT Zigbee, sebbene siano necessari ulteriori miglioramenti per gestire meglio traffico eterogeneo e sbilanciato.

First steps towards Zigbee IoT device classification with Federated XGBoost

Caminati, Lorenzo
2025/2026

Abstract

The increasing adoption of Internet of Things (IoT) devices in smart-home environments has introduced new challenges for network monitoring, cybersecurity and digital forensics. In forensic scenarios, IoT devices can act as digital witnesses, since their network traffic may help reconstruct events after an incident. However, smart-home ecosystems are highly heterogeneous, including different device types, vendors, protocols, configurations and user behaviors. For this reason, machine learning models require large and diverse traffic datasets, whose centralized collection may expose sensitive information about users and their private environments. Federated Learning addresses this limitation by enabling collaborative model training while keeping raw data local. This thesis investigates Zigbee IoT device classification by comparing centralized XGBoost with Federated XGBoost. Zigbee is considered a relevant case study because its low-power mesh networks include devices with different roles and traffic behaviors, which make classification challenging. The experimental evaluation is based on Zigbee packet captures transformed into statistical network-flow features, using existing Zigbee datasets and a newly acquired dataset collected in a real smart-home environment. Federated XGBoost is evaluated with three aggregation strategies: gradient aggregation, cyclic aggregation and bagging. The results show that centralized XGBoost achieves the best overall performance. On CMU-Smarthome, it reaches 0.8525 accuracy, 0.7750 Macro F1 and 0.8510 Weighted F1, while the best federated configuration, based on gradient aggregation, reaches 0.7862, 0.7485 and 0.7746 respectively. On the more heterogeneous ZBIOT* group, the gap is much smaller: centralized XGBoost obtains 0.8700 accuracy, 0.6643 Macro F1 and 0.8685 Weighted F1, while Federated XGBoost reaches 0.8644, 0.6556 and 0.8644. These findings show that Federated XGBoost is a promising privacy-aware alternative for Zigbee IoT device classification, although further improvements are needed to better handle heterogeneous and imbalanced traffic.
ING - Scuola di Ingegneria Industriale e dell'Informazione
22-lug-2026
2025/2026
La crescente diffusione dei dispositivi Internet of Things (IoT) negli ambienti smart home introduce nuove sfide per il monitoraggio delle reti, la cybersecurity e la digital forensics. In ambito forense, i dispositivi IoT possono agire come testimoni digitali, poiché il traffico di rete da essi generato può supportare la ricostruzione degli eventi dopo un incidente. Tuttavia, gli ecosistemi smart home sono altamente eterogenei e includono diversi tipi di dispositivi, produttori, protocolli, configurazioni e comportamenti degli utenti. Per questo motivo, i modelli di machine learning richiedono dataset di traffico ampi e diversificati, la cui raccolta centralizzata può però esporre informazioni sensibili sugli utenti e sui loro ambienti privati. Il Federated Learning affronta questa limitazione permettendo l’addestramento collaborativo di un modello condiviso mantenendo i dati grezzi localmente. Questa tesi analizza la classificazione di dispositivi IoT Zigbee confrontando XGBoost centralizzato con Federated XGBoost. Zigbee rappresenta un caso di studio rilevante perché le sue reti mesh a basso consumo includono dispositivi con ruoli e comportamenti di traffico differenti, rendendo la classificazione complessa. La valutazione sperimentale si basa su catture di pacchetti Zigbee trasformate in feature statistiche di flusso, utilizzando dataset Zigbee esistenti e un nuovo dataset acquisito in un ambiente smart home reale. Federated XGBoost viene valutato con tre strategie di aggregazione: gradient aggregation, cyclic aggregation e bagging. I risultati mostrano che XGBoost centralizzato ottiene le migliori prestazioni complessive. Su CMU-Smarthome raggiunge 0.8525 di accuracy, 0.7750 di Macro F1 e 0.8510 di Weighted F1, mentre la migliore configurazione federata, basata su gradient aggregation, raggiunge rispettivamente 0.7862, 0.7485 e 0.7746. Sul gruppo ZBIOT*, più eterogeneo, il divario è molto più ridotto: XGBoost centralizzato ottiene 0.8700 di accuracy, 0.6643 di Macro F1 e 0.8685 di Weighted F1, mentre Federated XGBoost raggiunge 0.8644, 0.6556 e 0.8644. Questi risultati mostrano che Federated XGBoost è una promettente alternativa privacy-aware per la classificazione di dispositivi IoT Zigbee, sebbene siano necessari ulteriori miglioramenti per gestire meglio traffico eterogeneo e sbilanciato.
File allegati
File Dimensione Formato  
2026_07_Caminati.pdf

accessibile in internet per tutti

Dimensione 11.46 MB
Formato Adobe PDF
11.46 MB Adobe PDF Visualizza/Apri

I documenti in POLITesi sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/10589/261566