Skip to content
#federated learning Open access

Fed fusion-IDS: a privacy-preserving federated intrusion detection system with multi-objective feature optimization and explainable deep learning

Sep 2026 · Scientific Reports · 0 citations
Network Security and Intrusion Detection

Abstract

Network Intrusion Detection Systems (NIDS) are vital for protecting cybersecurity infrastructures. The existing intrusion detection methodologies that rely on centralization do not offer privacy protection, cannot protect from zero-day attacks, and lack transparency needed to comply with modern cybersecurity policies. In this work, we present FedFusion-IDS, a new privacy-preserving federated framework for intrusion detection. It is based on federated learning, multi-objective feature selection with NSGA-II and SHAP second-level filter, hybrid deep learning architecture with CNN, BiLSTM, and Attention mechanisms, explainability through SHAP and LIME, and zero-day anomalies detection. We perform a thorough evaluation of FedFusion-IDS on the modern TON_IoT dataset with 10 federated clients for 20 communication rounds. During the multi-objective optimization phase, a Pareto-optimal feature subset is selected to decrease dimensionality while retaining important traffic information. The local clients train a CNN-BiLSTM-Attention model with 962,181 parameters, and parameter aggregation is done with conventional FedAvg and F1-weighted adaptive aggregation techniques. From the experiments performed using TON_IoT dataset, global detection accuracy was found to be 66.26%, F1-score was calculated as 0.6524, and ROC-AUC value exceeds 0.99 for all primary attacks (Normal: 0.999, Backdoor: 1.000, DDoS: 0.997, DoS: 0.700, Password.Dual SHAP and LIME explainability mechanisms deliver fine-grained global feature rankings and instance-level explanations, ensuring compliance with legal transparency requirements such as GDPR Article 22 and the EU AI Act. Furthermore, zero-day anomaly detection simulations confirm that FedFusion-IDS effectively identifies out-of-distribution threats without prior signature training. Together, these results provide a practical blueprint for deploying privacy-preserving, explainable intrusion detection across distributed IoT networks.

Read PDF

Similar papers

#machine learning Review Open access Oct 2014

Software development in startup companies: A systematic mapping study

The results indicate that software engineering work practices are chosen opportunistically, adapted and configured to provide value under the constrains imposed by the startup context.

Nicolò Paternoster, Carmine Giardino, M. Unterkalmsteiner et al. · 394 citations · ⚡54
#machine learning Review Open access Jun 2014

Why Early-Stage Software Startups Fail: A Behavioral Framework

This state-of-practice investigation was performed using a literature review followed by a multiple-case study approach and presents how inconsistency between managerial strategies and execution can lead to failure by means of a behavioral framework.

Carmine Giardino, Xiaofeng Wang, P. Abrahamsson · 175 citations · ⚡19
#machine learning Review Open access Oct 2016

“Failures” to be celebrated: an analysis of major pivots of software startups

This study conducts a case survey study based on the secondary data of the major pivots happened in 49 software startups, and demonstrates that customer need pivot is the most common among all pivot types.

Sohaib Shahid Bajwa, Xiaofeng Wang, Anh Nguyen-Duc et al. · 127 citations · ⚡15
#machine learning Review Open access May 2016

Key Challenges in Software Startups Across Life Cycle Stages

It is found that what perceived as biggest challenges by software startups do vary across different life cycle stages, even though its significance decreases when the learning focuses of the startups move from problem to solution and their products mature.

Xiaofeng Wang, Henry Edison, Sohaib Shahid Bajwa et al. · 62 citations · ⚡6

Related blog posts

Microsoft Research Blog Sep 30, 2026

Forecasting space weather risks on power grids

Extreme space-weather events can damage power systems on Earth and degrade GPS accuracy and satellite operations. A new machine learning system can predict where damage is likely to occur 30-60 minutes before a storm arrives. The post Forecasting space weather risks on power grids appeared first on Microsoft Research.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.