Skip to content
Open access

Decoding the Enigma of Collaborative Intrusion Detection Systems: Ensemble Learning vs Federated Learning in the Battle for Collaborative Anomaly Detection Supremacy

2026 · IEEE Transactions on Network Science and Engineering · Vol 13, pp. 10732-10757 · 0 citations · 88 references
Computer Science

TL;DR

This research examines the comparative effectiveness of EL and FL within CIDS for robust detection of coordinated attacks in heterogeneous network environments and reveals that network heterogeneity significantly influences detection model performance.

Abstract

Coordinated attacks, such as large-scale scanning, worm outbreaks, and Distributed Denial of Service (DDoS) attacks, exhibit distributed cyberattack characteristics that make them challenging to detect with standalone Intrusion Detection Systems (IDS). Collaborative Intrusion Detection Systems (CIDS) address this limitation by aggregating data from multiple network sources and leveraging collective intelligence for anomaly detection, making them more effective in identifying coordinated attacks. CIDS system employs Ensemble Learning (EL) or Federated Learning (FL) to build robust collaborative anomaly detection. EL enhances detection by integrating predictions from multiple models, while FL enables model aggregation from multiple models and preserves privacy. This research examines the comparative effectiveness of EL and FL within CIDS for robust detection of coordinated attacks in heterogeneous network environments. Benchmarking results reveal that network heterogeneity significantly influences detection model performance. Furthermore, this study provides key insights and lessons learned from the comparative analysis, offering a foundation for future research on cyberattack detection using collaborative anomaly detection methods in CIDS.

Read PDF

Similar papers

#software testing Open access Sep 2026

Intelligent DDoS Attack Detection in Software-Defined Networks Using Explainable Machine Learning

The recent trend of Software-Defined Networking (SDN) has posed significant cybersecurity challenges as a result of its centralized control architecture, dynamic traffic behavior, and high programmability. Although these attributes improve network flexibility and management, they also increase vulnerability to Distribu...

J. Malik, N. Naz, Muhammad Saleem et al. · 0 citations
Open access Aug 2026

Intelligent DDOS Attack Detection and Mitigation Using Machine Learning Techniques

An intelligent DDoS detection and mitigation framework that combines classical Machine Learning (ML) classifiers with Deep Learning (DL) architectures to achieve high-fidelity, low-latency attack identification across heterogeneous network topologies is presented.

S. Singh, Alok Kumar · 0 citations
Review Open access Aug 2026

5G Network Intrusion Detection Method Based on Robust Federated Optimization

High-speed, low-latency and massive connectivity have emerged as a result of the rapid development of 5G networks, but so have security threats. Current intrusion detection tools are poorly adapted to the distributed, heterogeneous, and dynamic 5G environment where a flood of real-time information is generated over a s...

C.-J. Wang · 0 citations
Review Open access 2026

Adversarial Evasion in Machine-Learning-Based Network Intrusion Detection: A Systematic Review, Threat Modeling, and Research Roadmap

A Kitchenham-informed systematic literature review methodology, this review synthesizes 186 studies published between 2018 and 2026 and develops a perturbation-realism taxonomy, ranging from feature-level manipulation to executable packet-level attacks, that clarifies when reported success corresponds to deployable ris...

Huda Ali Alatawi · 0 citations
Open access Aug 2026

Explainable Machine Learning for DDoS Attack Detection with Physical Network Validation

Distributed Denial-of-Service (DDoS) attacks remain one of the most disruptive threats to network infrastructure, yet many machine learning (ML)-based detection studies report only offline benchmark performance without verifying whether that performance holds under real network conditions. This study evaluates two expl...

Muhammad Azzam Anshori, R. Amri · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.