Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

PhD position H/F - Federated Graph Neural Networks for Intrusion Detection in Industrial IoT Networks

CESI
CompanyCESI
CategoryScience & Research
LocationLingolsheim
RemoteOn-site (inferred)
EmploymentNot stated
LevelEntry
SalaryNot stated by the employer
First seen14 Jul 2026 (the employer did not state a posting date)
Last verified9 Aug 2026
SourceEmployer ATS (recruitee)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
Abstract Securing industrial IoT infrastructure is no longer a competitive advantage ; it is a prerequisite for resilient, trustworthy, and sustainable Industry 5.0. Keywords : Industry 5.0, Industrial IoT, Intrusion Detection, Federated Learning, GNN The rapid proliferation of Industrial Internet of Things (IIoT) devices in manufacturing, energy, and logistics environments has dramatically expanded the cyber attack surface of critical industrial infrastructure. These interconnected cyber-physical systems, while enabling new data-driven automation and intelligent services, introduce severe security vulnerabilities: a single compromised sensor or gateway can propagate threats across the entire production network. In such distributed environments, where multiple industrial stakeholders collaborate without sharing sensitive operational data, security, resilience, and data confidentiality become critical prerequisites for the large-scale adoption of Industry 4.0 and 5.0 technologies. This doctoral research addresses a core scientific challenge: the collaborative and privacy-preserving detection of cyberattacks and anomalies in IIoT ecosystems. Although deep learning-based intrusion detection systems (IDS) have shown strong performance, their centralized training paradigm raises critical concerns regarding data sovereignty, scalability, and robustness in heterogeneous industrial deployments. This thesis proposes a distributed detection framework combining federated learning and graph neural networks (GNNs), capable of modeling the structural dependencies between IIoT components while keeping sensitive operational data on-premises at each industrial site. Local detection models are trained at the level of edge nodes or industrial gateways and collaboratively aggregated without sharing raw data, enabling collective threat intelligence while preserving industrial confidentiality. The originality of this work lies in the combined use of federated learning, GNNs, and centrality measures from complex network theory to enhance anomaly detection accuracy, improve robustness in heterogeneous environments, and generalize to novel, unseen attack patterns. Building directly upon prior contributions from the CESI LINEACT team in IoT intrusion detection, federated learning, and graph-based modeling, the proposed framework will be evaluated on realistic IIoT attack scenarios and benchmarked against state-of-the-art methods. The objective is to deliver a generic, distributed, and privacy-preserving methodological building block to strengthen the cybersecurity, operational resilience, and sustainability of future smart industrial systems. Research Work Scientific context The rapid deployment of IIoT devices across manufacturing, smart energy, and logistics sectors has profoundly transformed industrial architectures, giving rise to a new generation of cyber-physical systems (CPS) whose security is critical to operational continuity. Modern IIoT infrastructures embed hundreds of heterogeneous sensors, actuators, and gateways communicating over protocols. The simultaneous growth of remote access interfaces, cloud connectivity, and over-the-air update mechanisms dramatically expands the attack surface of these industrial networks [1, 2]. Network Intrusion Detection Systems (NIDS) have emerged as an essential countermeasure for monitoring IIoT traffic and detecting malicious activity [3]. AI-based NIDS, notably deep learning models, have demonstrated high detection accuracy, but centralizing industrial data on a remote server for training introduces critical scalability, bandwidth, and data sovereignty challenges that are incompatible with real-world industrial deployments [4]. Federated Learning (FL) has been proposed as a solution: each node trains a model locally and only shares model weights with a central aggregator, keeping sensitive data on-premises while enabling collaborative learning at scale [5]. A key limitation of conventiona