Remote job

PhD position H/F - Federated Graph Neural Networks for Intrusion Detection in Industrial IoT Networks

CESI

Source: RecruiteeLocation: Germany onlyPublished: Jun 18, 2026Confirmed active: Sep 11, 2026
Full-timeLogistics

Our assessment

  • 1 more open role from this employer in our index.

This section only: calculated automatically by nomado24, from our own job index and our own reading of the posting text. Not stated by the employer.

Job description

Abstract

Securing industrial IoT infrastructure is no longer a competitive advantage ; it is a prerequisite for resilient, trustworthy, and sustainable Industry 5.0.

Keywords : Industry 5.0, Industrial IoT, Intrusion Detection, Federated Learning, GNN

The rapid proliferation of Industrial Internet of Things (IIoT) devices in manufacturing, energy, and logistics environments has dramatically expanded the cyber attack surface of critical industrial infrastructure. These interconnected cyber-physical systems, while enabling new data-driven automation and intelligent services, introduce severe security vulnerabilities: a single compromised sensor or gateway can propagate threats across the entire production network. In such distributed environments, where multiple industrial stakeholders collaborate without sharing sensitive operational data, security, resilience, and data confidentiality become critical prerequisites for the large-scale adoption of Industry 4.0 and 5.0 technologies.

This doctoral research addresses a core scientific challenge: the collaborative and privacy-preserving detection of cyberattacks and anomalies in IIoT ecosystems. Although deep learning-based intrusion detection systems (IDS) have shown strong performance, their centralized training paradigm raises critical concerns regarding data sovereignty, scalability, and robustness in heterogeneous industrial deployments. This thesis proposes a distributed detection framework combining federated learning and graph neural networks (GNNs), capable of modeling the structural dependencies between IIoT components while keeping sensitive operational data on-premises at each industrial site. Local detection models are trained at the level of edge nodes or industrial gateways and collaboratively aggregated without sharing raw data, enabling collective threat intelligence while preserving industrial confidentiality.

The originality of this work lies in the combined use of federated learning, GNNs, and centrality measures from complex network theory to enhance anomaly detection accuracy, improve robustness in heterogeneous environments, and generalize to novel, unseen attack patterns. Building directly upon prior contributions from the CESI LINEACT team in IoT intrusion detection, federated learning, and graph-based modeling, the proposed framework will be evaluated on realistic IIoT attack scenarios and benchmarked against state-of-the-art methods. The objective is to deliver a generic, distributed, and privacy-preserving methodological building block to strengthen the cybersecurity, operational resilience, and sustainability of future smart industrial systems.

Research Work

Scientific context

The rapid deployment of IIoT devices across manufacturing, smart energy, and logistics sectors has profoundly transformed industrial architectures, giving rise to a new generation of cyber-physical systems (CPS) whose security is critical to operational continuity. Modern IIoT infrastructures embed hundreds of heterogeneous sensors, actuators, and gateways communicating over protocols. The simultaneous growth of remote access interfaces, cloud connectivity, and over-the-air update mechanisms dramatically expands the attack surface of these industrial networks [1, 2].

Network Intrusion Detection Systems (NIDS) have emerged as an essential countermeasure for monitoring IIoT traffic and detecting malicious activity [3]. AI-based NIDS, notably deep learning models, have demonstrated high detection accuracy, but centralizing industrial data on a remote server for training introduces critical scalability, bandwidth, and data sovereignty challenges that are incompatible with real-world industrial deployments [4]. Federated Learning (FL) has been proposed as a solution: each node trains a model locally and only shares model weights with a central aggregator, keeping sensitive data on-premises while enabling collaborative learning at scale [5].

A key limitation of conventional federated approaches is their inability to capture the graph-structured topology inherent to IIoT networks, where devices and communication buses form complex relational graphs. Graph Neural Networks (GNNs) address this gap by modeling nodes and their interactions explicitly. Combined with complex network centrality measures (e.g., degree, betweenness, and modularity-aware centrality), GNNs can identify critical nodes and communication patterns, improving detection accuracy and generalization across heterogeneous industrial deployments [6–9]. This thesis sits at the intersection of federated learning, graph deep learning, and industrial cybersecurity.

Subject

This thesis proposes the design, implementation, and evaluation of a federated GNN-based intrusion detection framework for Industrial IoT networks (IIoT). Its originality lies in the combination of three complementary dimensions: (i) federated learning specifically adapted to the constraints and heterogeneity of industrial …

recruiteeRecherchefulltime fixed termengineering

This role is provided by an external source. Applications are handled on the source website.

New remote jobs like “PhD position” by email

Only when something fitting appears. Free, unsubscribe any time.

You confirm your subscription by email (double opt-in) and can unsubscribe at any time via the link in every email. Our Privacy Policy.

All Remote Jobs in Germany

Prepare your application with AI

Have the AI advisor draft a cover letter, analyze how your profile fits this role, and prep you for the interview.

Sign in & prepare with AI

Free, you'll continue right where you left off after signing in.

Or let us search for you

Matching job categories

Not the right job?