Skip to content
Open access

Decoding the Enigma of Collaborative Intrusion Detection Systems: Ensemble Learning vs Federated Learning in the Battle for Collaborative Anomaly Detection Supremacy

2026 · IEEE Transactions on Network Science and Engineering · Vol 13, pp. 10732-10757 · 0 citations · 88 references
Computer Science

TL;DR

This research examines the comparative effectiveness of EL and FL within CIDS for robust detection of coordinated attacks in heterogeneous network environments and reveals that network heterogeneity significantly influences detection model performance.

Abstract

Coordinated attacks, such as large-scale scanning, worm outbreaks, and Distributed Denial of Service (DDoS) attacks, exhibit distributed cyberattack characteristics that make them challenging to detect with standalone Intrusion Detection Systems (IDS). Collaborative Intrusion Detection Systems (CIDS) address this limitation by aggregating data from multiple network sources and leveraging collective intelligence for anomaly detection, making them more effective in identifying coordinated attacks. CIDS system employs Ensemble Learning (EL) or Federated Learning (FL) to build robust collaborative anomaly detection. EL enhances detection by integrating predictions from multiple models, while FL enables model aggregation from multiple models and preserves privacy. This research examines the comparative effectiveness of EL and FL within CIDS for robust detection of coordinated attacks in heterogeneous network environments. Benchmarking results reveal that network heterogeneity significantly influences detection model performance. Furthermore, this study provides key insights and lessons learned from the comparative analysis, offering a foundation for future research on cyberattack detection using collaborative anomaly detection methods in CIDS.

Read PDF

Similar papers

#software testing Open access Sep 2026

Intelligent DDoS Attack Detection in Software-Defined Networks Using Explainable Machine Learning

An explainable machine learning-based framework for accurate, transparent, and reliable DDoS attack detection in an SDN environment that combines reliable DDoS detection with transparent, analyst-oriented decision support for SDN security monitoring is developed.

J. Malik, N. Naz, Muhammad Saleem et al. · 0 citations
Open access Aug 2026

Intelligent DDOS Attack Detection and Mitigation Using Machine Learning Techniques

An intelligent DDoS detection and mitigation framework that combines classical Machine Learning (ML) classifiers with Deep Learning (DL) architectures to achieve high-fidelity, low-latency attack identification across heterogeneous network topologies is presented.

S. Singh, Alok Kumar · 0 citations

Privacy-Preserving Intrusion Detection Using Federated Learning in Distributed Networks

Evaluated on standard intrusion detection datasets, including NSL-KDD and CICIDS2017, indicates that the proposed model can maintain competitive detection performance while improving privacy protection and supporting deployment across distributed network environments.

R. Chouhan, Kirti Jain, M. Bagwani · 0 citations
Review Open access Aug 2026

5G Network Intrusion Detection Method Based on Robust Federated Optimization

This review provides a detailed study of intrusion detection systems in 5G networks that are federated learning-based, and how the federated learning-based intrusion detection systems can address the challenges mentioned above.

C.-J. Wang · 0 citations
Review Open access 2026

Adversarial Evasion in Machine-Learning-Based Network Intrusion Detection: A Systematic Review, Threat Modeling, and Research Roadmap

A Kitchenham-informed systematic literature review methodology, this review synthesizes 186 studies published between 2018 and 2026 and develops a perturbation-realism taxonomy, ranging from feature-level manipulation to executable packet-level attacks, that clarifies when reported success corresponds to deployable ris...

Huda Ali Alatawi · 0 citations
Open access Aug 2026

Explainable Machine Learning for DDoS Attack Detection with Physical Network Validation

This study evaluates two explainable ML classifiers, XGBoost and Random Forest, for DDoS detection and examines whether their near-perfect offline accuracy translates into reliable physical-network operation, indicating that offline benchmarks alone are insufficient for validating IDS readiness.

Muhammad Azzam Anshori, R. Amri · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.