Decoding the Enigma of Collaborative Intrusion Detection Systems: Ensemble Learning vs Federated Learning in the Battle for Collaborative Anomaly Detection Supremacy
2026· IEEE Transactions on Network Science and Engineering· Vol 13, pp. 10732-10757· 0 citations· 88 references
Computer Science
TL;DR
This research examines the comparative effectiveness of EL and FL within CIDS for robust detection of coordinated attacks in heterogeneous network environments and reveals that network heterogeneity significantly influences detection model performance.
Abstract
Coordinated attacks, such as large-scale scanning, worm outbreaks, and Distributed Denial of Service (DDoS) attacks, exhibit distributed cyberattack characteristics that make them challenging to detect with standalone Intrusion Detection Systems (IDS). Collaborative Intrusion Detection Systems (CIDS) address this limitation by aggregating data from multiple network sources and leveraging collective intelligence for anomaly detection, making them more effective in identifying coordinated attacks. CIDS system employs Ensemble Learning (EL) or Federated Learning (FL) to build robust collaborative anomaly detection. EL enhances detection by integrating predictions from multiple models, while FL enables model aggregation from multiple models and preserves privacy. This research examines the comparative effectiveness of EL and FL within CIDS for robust detection of coordinated attacks in heterogeneous network environments. Benchmarking results reveal that network heterogeneity significantly influences detection model performance. Furthermore, this study provides key insights and lessons learned from the comparative analysis, offering a foundation for future research on cyberattack detection using collaborative anomaly detection methods in CIDS.
The recent trend of Software-Defined Networking (SDN) has posed significant cybersecurity challenges as a result of its centralized control architecture, dynamic traffic behavior, and high programmability. Although these attributes improve network flexibility and management, they also increase vulnerability to Distribu...
J. Malik, N. Naz, Muhammad Saleem et al.· Italian National Conference...· 0 citations
An intelligent DDoS detection and mitigation framework that combines classical Machine Learning (ML) classifiers with Deep Learning (DL) architectures to achieve high-fidelity, low-latency attack identification across heterogeneous network topologies is presented.
S. Singh, Alok Kumar· International Journal of Com...· 0 citations
High-speed, low-latency and massive connectivity have emerged as a result of the rapid development of 5G networks, but so have security threats. Current intrusion detection tools are poorly adapted to the distributed, heterogeneous, and dynamic 5G environment where a flood of real-time information is generated over a s...
A Kitchenham-informed systematic literature review methodology, this review synthesizes 186 studies published between 2018 and 2026 and develops a perturbation-realism taxonomy, ranging from feature-level manipulation to executable packet-level attacks, that clarifies when reported success corresponds to deployable ris...
Distributed Denial-of-Service (DDoS) attacks remain one of the most disruptive threats to network infrastructure, yet many machine learning (ML)-based detection studies report only offline benchmark performance without verifying whether that performance holds under real network conditions. This study evaluates two expl...
Muhammad Azzam Anshori, R. Amri· Journal of Computer Science...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.