Skip to main content

A REVIEW OF PRIVACY-PRESERVING NETWORK INTRUSION IDENTIFICATION THROUGH FEDERATED LEARNING WITH ADAP

Page 1


International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 02 | Feb 2026 www.irjet.net p-ISSN: 2395-0072

A REVIEW OF PRIVACY-PRESERVING NETWORK INTRUSION

IDENTIFICATION THROUGH FEDERATED LEARNING WITH ADAPTIVE

CROSS-NODE

PARAMETER FUSION

1Master of Technology, Computer Science and Engineering, Lucknow Institute of Technology, Lucknow, India

2Assistant Professor, Department of Computer Science and Engineering, Lucknow Institute of Technology, Lucknow, India

Abstract - Therapidproliferationofdistributedcomputing environments, cloud infrastructures, and Internet-of-Things ecosystems has significantly increased the attack surface of modern networks, necessitating robust and intelligent intrusion identification mechanisms. Traditional centralized intrusion detection systems (IDS) face critical challenges related to data privacy, regulatory compliance, and crossorganizational collaboration. Federated Learning (FL) has emergedasapromisingparadigmthatenablescollaborative modeltrainingwithoutrawdataexchange,therebypreserving data locality and confidentiality. This review systematically examines the evolution of privacy-preserving network intrusion identification frameworks based on FL, with particularemphasisonadaptivecross-nodeparameterfusion strategies. The paper analyzes existing architectures, aggregationalgorithms,privacy-enhancingmechanismssuch as differential privacy and secure aggregation, and their impact on detection performance under non-IID data distributions. A comparative taxonomy of state-of-the-art approaches is presented, highlighting trade-offs between privacy guarantees, communication efficiency, and model robustness. Furthermore, open challenges including adversarial threats, model poisoning, scalability constraints, andbenchmarkinginconsistenciesarecriticallydiscussed.The review concludes by outlining future research directions toward resilient, adaptive, and privacy-aware federated intrusion detection systems suitable for real-world deployment.

Key Words: Federated Learning; Network Intrusion Detection; Privacy Preservation; Adaptive Parameter Fusion; Non-IID Data; Secure Aggregation.

1. INTRODUCTION

The exponential growth of interconnected digital infrastructures,includingcloudplatforms,edgecomputing environments,andInternet-of-Things(IoT)ecosystems,has significantly expanded the cyber-attack surface. Network intrusiondetectionsystems(IDS)playafundamentalrolein identifying malicious activities, unauthorized access, and anomaloustrafficpatternswithinsuchenvironments.With theincreasingcomplexityofmodernnetworkarchitectures, conventionalsecuritymechanismsarestrugglingtoprovide

scalable,privacy-compliant,andadaptiveprotection.Recent advances in distributed machine learning, particularly federated learning (FL), offer a promising paradigm for collaborativeyetprivacy-preservingintrusionidentification. Thisreviewcriticallyexaminestheconvergenceofprivacyawarefederatedlearningframeworksandadaptivecrossnode parameter fusion strategies for network intrusion detection.

1.1 Background and Motivation

Theevolutionofcyberthreatshastransitionedfromisolated attackstohighlycoordinated,distributed,andpolymorphic intrusions targeting enterprise and critical infrastructure networks. Machine learning (ML) and deep learning (DL) techniqueshavesignificantlyenhancedIDScapabilitiesby enablinganomalydetectionandbehavioralanalysisbeyond static signature-based approaches (Sommer and Paxson, 2010). However, effective ML-based IDS models require large-scale,diversedatasetsthatoftenresideacrossmultiple organizations or geographically distributed nodes. RegulatoryframeworkssuchastheGeneralDataProtection Regulation(GDPR)furtherrestrictcentralizeddatasharing, creating a tension between collaborative intelligence and privacycompliance.Consequently,thereisstrongmotivation todevelopdecentralizedintrusiondetectionparadigmsthat preserve data locality while enabling global threat intelligence.

1.2 Limitations of Centralized Intrusion Detection

Traditional IDS architectures predominantly rely on centralized data aggregation, where raw traffic logs from distributedsourcesarecollectedandprocessedinacentral server.Althoughthisarchitecturesimplifiesmodeltraining andcoordination,itintroducesseveral critical limitations. First, centralized storage increases vulnerability to data breaches and single-point failures (Garcia-Teodoro et al., 2009). Second, transmitting raw network traffic incurs significantcommunicationoverhead,particularlyinlargescaleIoToredgedeployments.Third,centralizedlearning frameworksstrugglewithheterogeneousdatadistributions, as network traffic characteristics vary across domains. Additionally,privacyrisksassociatedwithsharingsensitive packet-level information hinder cross-organizational

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 02 | Feb 2026 www.irjet.net p-ISSN: 2395-0072

collaboration.Thesestructuralconstraintslimitscalability, resilience, and regulatory compliance, thereby motivating decentralizedalternatives.

Figure-1: Federated Learning–Based IDS Architecture

1.3 Emergence of Federated Learning in Cyber security

Federated Learning, initially introduced to enable collaborative model training without centralized data exchange, has gained significant attention in privacysensitive domains (McMahan et al., 2017). In FL, participatingnodestrainlocalmodelsusingprivatedatasets and share only model updates or gradients with a coordinating server. This decentralized optimization framework reduces data exposure while leveraging distributedknowledge.Withincybersecurity,FLhasbeen increasingly adopted for intrusion detection, malware classification, and anomalydetection tasks, particularlyin environmentscharacterizedbydistributeddataownership (Nguyenetal.,2022).Despiteitsadvantages,FLintroduces newchallenges,includingnon-independentandidentically distributed(non-IID)data,communicationbottlenecks,and susceptibility to adversarial model poisoning. Addressing these issues is essential for robust federated intrusion identification.

1.4 Importance of Adaptive Cross-Node Parameter Fusion

Acriticalcomponentoffederatedlearningistheparameter aggregation or fusion mechanism used to combine local modelupdatesintoaglobalmodel.Conventionalalgorithms such as Federated Averaging (FedAvg) apply uniform or data-size-weightedaggregation,whichmaybesuboptimalin heterogeneous network environments (Li et al., 2020). In intrusion detection scenarios, nodes often exhibit diverse traffic patterns and threat profiles, resulting in non-IID distributions that degrade convergence and detection accuracy.Adaptivecross-nodeparameterfusionstrategies aim to address this limitation by dynamically weighting

model contributions based on trust scores, similarity metrics, data quality, or performance indicators. Such adaptivemechanismsenhancerobustnessagainstmalicious participants and improve generalization across heterogeneousnodes.Therefore,adaptivefusionrepresents apivotalresearchdirectionforprivacy-preservingfederated IDSframeworks.

2.FOUNDATIONS AND CONCEPTUAL BACKGROUND

The design of privacy-preserving federated intrusion detection systems requires an interdisciplinary understanding of network security, distributed machine learning,privacyengineering,andaggregationtheory.This section provides the conceptual foundations necessary to contextualizeadaptivecross-nodeparameterfusionwithin federatedintrusionidentificationframeworks.

2.1 Network Intrusion Identification

Network intrusion identification refers to the systematic detection of malicious activities, policy violations, or anomalous behaviors within network traffic. IDS mechanisms have evolved from rule-based systems to sophisticated learning-driven architectures capable of identifyingzero-dayattacksandpolymorphicthreats.

2.1.1 Signature-Based vs Anomaly-Based IDS

Signature-based IDS operate by matching observed traffic patterns against a predefined database of known attack signatures.SystemssuchasSnortexemplifythisapproach, offeringhighprecisionforpreviouslyidentifiedthreatsbut limited capability against novel or obfuscated attacks (Roesch,1999).Incontrast,anomaly-basedIDSestablisha baseline model of normal network behavior and flag deviations as potential intrusions. This paradigm enables detectionofzero-dayattacksbutoftensuffersfromhigher false-positiveratesduetodynamictrafficpatterns(GarciaTeodoro et al., 2009). The shift toward anomaly-based detection laid the foundation for integrating machine learningtechniquesintoIDSframeworks.

2.1.2 Machine Learning-Based IDS

Machinelearning(ML)introducedstatisticalandalgorithmic methodsformodelingcomplextrafficbehaviors.Techniques such as Support Vector Machines (SVM), k-Nearest Neighbors (k-NN), and Random Forests demonstrated improveddetectionperformanceovertraditionalheuristics, particularlyforhigh-dimensionaltrafficfeatures(Bhuyanet al.,2014).ML-basedIDSrelyheavilyonfeatureengineering andlabeleddatasets,andtheireffectivenessdependsonthe representativenessoftrainingdata.However,centralizedML trainingraisesconcernsregardingdatasharing,privacy,and scalabilityindistributedenvironments.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 02 | Feb 2026 www.irjet.net p-ISSN: 2395-0072

2.1.3 Deep Learning Evolution

Deep learning (DL) further enhanced intrusion detection through automatic feature extraction and hierarchical representationlearning.ArchitecturessuchasConvolutional NeuralNetworks(CNN),RecurrentNeuralNetworks(RNN), and Long Short-Term Memory (LSTM) networks have demonstrated strong capability in modeling temporal dependencies and complex traffic structures (Yin et al., 2017).WhileDL-basedIDSachievesuperioraccuracy,they require substantial training data and computational resources, making centralized deployment increasingly impractical in privacy-sensitive and geographically distributedinfrastructures.

2.2 Federated Learning Paradigms

FederatedLearning(FL)isadistributedmachinelearning paradigmthatenablescollaborativemodeltrainingwithout sharingrawdata.Instead,participatingclientscomputelocal updatesthatareaggregatedintoaglobalmodel.

2.2.1

Horizontal Federated Learning

Horizontal Federated Learning (HFL) applies when participating entities share similar feature spaces but differentdatasamples.Forexample,multipleorganizations monitoringnetworktrafficmaycollectcomparablefeatures butfromdistinctuserbases.HFLaggregateslocallytrained modelsacrosstheseentitieswhilemaintainingdatalocality (McMahan et al., 2017). This paradigm is particularly suitableforcross-organizationalintrusiondetection.

2.2.2 Vertical Federated Learning

VerticalFederatedLearning(VFL)isdesignedforscenarios whereparticipantssharethesamesamplespacebutpossess differentfeaturesets.Incybersecuritycontexts,oneentity may hold packet metadata while another maintains behavioral logs. VFL enables joint learning across complementary features without exposing sensitive attributes(Yangetal.,2019).

2.2.3 Hybrid Federated Learning

HybridFLintegratesbothhorizontalandverticalsettings, accommodating complex real-world environments with partiallyoverlappingfeaturesandsamples.Thisapproachis increasingly relevant in IoT and smart infrastructure deploymentswhereheterogeneousdevicesgeneratediverse trafficattributes.

2.2.4 Federated Optimization Algorithms

TheeffectivenessofFLdependsheavilyonitsoptimization strategies.FederatedAveraging(FedAvg)aggregateslocal modelparametersthroughweightedaveragingandservesas thefoundationalalgorithminFLsystems(McMahanetal., 2017). However, FedAvg struggles with non-independent and identically distributed (non-IID) data. FedProx introducesaproximaltermtostabilizeconvergenceunder heterogeneity (Li et al., 2020), while SCAFFOLD mitigates client-driftusingcontrolvariatestocorrectlocalupdatebias (Karimireddy et al., 2020). These optimization advancements are critical for intrusion detection, where trafficdistributionsvarysignificantlyacrossnodes.

2.3 Privacy-Preserving Mechanisms in Federated Learning

Although FL avoids raw data sharing, model updates may still leak sensitive information. Consequently, additional privacy-enhancingmechanismsareintegratedintofederated frameworks.

2.3.1 Differential Privacy

Differential Privacy (DP) introduces calibrated noise into model updates to ensure that the contribution of any individualdatapointcannotbeinferredfromtheaggregated model(Dwork,2006).Infederatedintrusiondetection,DP helps protect sensitive network traces but may degrade detectionaccuracyifnoiselevelsareexcessive.

Figure-2: Federated Learning Aggregation
Figure-3: Federated Optimization

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 02 | Feb 2026 www.irjet.net p-ISSN: 2395-0072

2.3.2

Secure Aggregation

Secureaggregationprotocolsensurethatthecentralserver canonlyaccessaggregated model parametersrather than individualclientupdates.Cryptographictechniquesenable secure summation without revealing intermediate values (Bonawitz et al., 2017). This mechanism strengthens confidentialityincollaborativeIDSenvironmentsinvolving semi-trustedparticipants.

2.3.3

Homomorphic Encryption

HomomorphicEncryption(HE)allowscomputationstobe performed directly on encrypted data, preserving confidentialityduringaggregationandoptimization(Gentry, 2009). While HE provides strong privacy guarantees, its computationaloverheadremainsachallengeforlarge-scale federatedintrusiondetection.

2.3.4

Secure Multi-Party Computation

Secure Multi-Party Computation (SMPC) enables multiple participantstojointlycomputeafunctionwithoutrevealing theirindividualinputs(Yao,1982).InFL-basedIDS,SMPC cansupportdecentralizedaggregationwithoutrelianceona trustedcoordinator,thoughscalabilityandlatencyremain concerns.

2.4

Cross-Node Parameter Fusion

Parameterfusionreferstotheaggregationoflocallytrained models into a unified global model. In federated intrusion detection,fusionstrategiesdirectlyinfluenceconvergence, robustness,anddetectionperformance.

2.4.1

Static Aggregation

Static aggregation methods apply fixed averaging rules, typically uniform or data-size weighted averaging. While computationally efficient, static schemes assume homogeneous client behavior and may perform poorly in non-IIDenvironments.

2.4.2

Weighted Aggregation

Weightedaggregationassignsdifferentimportancelevelsto clientsbasedoncriteriasuchasdatasetsize,reliability,or historicalperformance.Thisapproachimprovesfairnessand robustnesscomparedtouniformaveragingbutstillrelieson predefinedweightingschemes.

2.4.3

Similarity-Aware Fusion

Similarity-aware fusion evaluates statistical or behavioral similarity between client updates before aggregation. Distance metrics or clustering techniques identify related nodes,allowingselectiveaggregationtoreducetheadverse effects of heterogeneous traffic distributions. Such approachesareparticularlyrelevantindistributedintrusion

detection,wherenetworksegmentsexhibitdomain-specific patterns.

2.4.4 Adaptive and Dynamic Fusion

Adaptive fusion dynamically adjusts aggregation weights based on trust scores, performance feedback, or anomaly indicators. These methods enhance resilience against adversarial clients and model poisoning attacks by downweighting suspicious updates. Dynamic strategies also address concept drift in evolving network traffic, making them highly suitable for real-world federated IDS deployments.

3. TAXONOMY OF FEDERATED INTRUSION DETECTION SYSTEMS

Astructuredtaxonomyisessentialtodistinguisharigorous scientificreviewfromadescriptivesurvey.Inthecontextof federatedintrusiondetectionsystems(FIDS),classification can be systematically developed along four orthogonal dimensions: learning architecture, privacy enhancement mechanism, parameter fusion strategy, and deployment environment. Such a taxonomy enables comparative analysis,highlightsdesigntrade-offs,andclarifiesresearch gapsinprivacy-preservingcollaborativeintrusiondetection.

3.1 Taxonomy Based on Learning Architecture

Federatedintrusiondetectionsystemsdifferfundamentally in how coordination and communication are organized amongparticipatingnodes.

3.1.1 Centralized Coordination

Incentralizedfederatedarchitectures,acoordinatingserver orchestrates training rounds by distributing the global modeltoclientsandaggregatinglocalupdates.Thisdesign followsthecanonicalfederatedlearningmodelandbenefits from simplified convergence control and global synchronization (Kairouz et al., 2021). For intrusion detection,centralizedcoordinationenablesconsistentglobal threatmodelingacrossorganizations.However,itintroduces partialtrustassumptionstowardthecentralaggregatorand remainsvulnerabletoaggregation-targetedattacksorserver compromise.

3.1.2 Hierarchical Federated Learning

Hierarchical federated learning introduces intermediate aggregationlayersbetween clientsandthecentral server. Local nodes first aggregate updates within clusters (e.g., regional networks or subnetworks) before transmitting them to a higher-level coordinator. This multi-tiered architecturereducescommunicationoverheadandenhances scalability,particularlyinIoTorlargeenterprisenetworks (Liuetal.,2020).Inintrusiondetection,hierarchicalFLcan

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 02 | Feb 2026 www.irjet.net p-ISSN: 2395-0072

reflect network topology, allowing localized anomaly modelingwhilepreservingglobalawareness.

3.1.3 Peer-to-Peer Federated Learning

Peer-to-peer(P2P)federatedlearningeliminatestheneed fora central coordinator by enabling decentralized model exchange among nodes. Distributed consensus or gossipbasedprotocolsareemployedtopropagateupdatesacross thenetwork(Lianetal.,2017).Incybersecurityapplications, P2P architectures enhance resilience and remove single points of failure. Nevertheless, they require robust synchronization mechanisms and are more complex to secureagainstadversarialparticipants.

3.2 Taxonomy Based on Privacy Enhancement

Although federated learning inherently avoids raw data sharing, additional mechanisms are often integrated to strengthen privacy guarantees in intrusion detection scenarios.

3.2.1

Differential Privacy-Based Systems

Differential Privacy (DP)-based federated IDS introduce calibrated noise into local gradients or model parameters beforeaggregationtoboundinformationleakage(Abadiet al., 2016). This approach provides mathematically quantifiable privacy guarantees. However, privacy–utility trade-offs are significant, as excessive perturbation can degradeintrusiondetectionaccuracy,particularlyforrare attackclasses.

3.2.2

Cryptographic Systems

Cryptographicapproachesemploytechniquessuchassecure aggregation and encryption-based computation to protect intermediatemodelupdates.Secureaggregationprotocols ensure that individual client contributions remain confidential even from the server (Bonawitz et al., 2017). These systems are particularly relevant for crossorganizationalcollaborationwheremutualtrustislimited. Computational complexity and communication latency, however, may limit real-time deployment in highthroughputnetworks.

3.2.3

Hybrid Privacy Systems

Hybrid systems combine differential privacy with cryptographicsafeguardstoachievelayeredprotection.For instance,encryptedgradientsharingmaybecombinedwith noiseinjectiontomitigatebothinferenceattacksandserverside leakage risks. Such multi-layered defenses aim to address sophisticated adversaries capable of exploiting modelupdates(Truexetal.,2019).Hybridprivacydesigns are increasingly viewed as necessary for high-assurance intrusiondetectionenvironments.

3.3 Taxonomy Based on Fusion Strategy

The parameter aggregation mechanism fundamentally influencesmodelconvergence,robustness,andresilienceto adversarialmanipulation.

3.3.1 Uniform Averaging

Uniform averaging aggregates client updates without weighting adjustments. This strategy underpins classical federatedaveragingalgorithmsandassumeshomogeneous data distributions across nodes (McMahan et al., 2017). While computationally efficient, uniform aggregation performs suboptimally in intrusion detection scenarios characterizedbyheterogeneoustrafficpatterns.

3.3.2 Data-Size Weighted Fusion

Data-size weighted fusion assigns aggregation weights proportional to the volume of local data samples. This method improves representational fairness and enhances convergence in moderately heterogeneous settings. However,itassumesthatlargerdatasetsareinherentlymore reliable,whichmaynotholdifnodesarecompromisedor containnoisylabels.

3.3.3 Trust-Based Fusion

Trust-basedaggregationincorporatesreliabilitymetricsor anomaly detection scores to weight client updates. Nodes exhibitingsuspiciousgradientbehaviormayreceivereduced influenceduringaggregation.Suchstrategiesmitigatemodel poisoningrisksandimproverobustnessagainstmalicious participants(Blanchardetal.,2017).Inintrusiondetection, trust-based fusion aligns well with adversarial threat modeling.

3.3.4 Adaptive Cross-Node Parameter Fusion

Adaptive fusion strategies dynamically adjust aggregation weights based on performance feedback, similarity measures, or statistical divergence among local models. Unlike static weighting schemes, adaptive mechanisms accountfornon-IIDdatadistributionsandconceptdriftin evolving network traffic. By leveraging similarity-aware metricsormeta-learningapproaches,thesesystemsenhance generalizationandresilienceinheterogeneouscybersecurity environments (Li et al., 2020). Adaptive cross-node parameterfusionthusrepresentsacriticaladvancementfor scalableandprivacy-awarefederatedIDSframeworks.

3.4 Taxonomy Based on Deployment Environment

Deployment context significantly influences architectural choices,privacyrequirements,andfusionstrategies.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 02 | Feb 2026 www.irjet.net p-ISSN: 2395-0072

3.4.1

Cloud Environments

Incloud-basedinfrastructures,federatedintrusiondetection mayoperateacrossdistributeddatacentersormulti-tenant platforms. Cloud environments provide substantial computational resources but require strong isolation and compliance mechanisms to prevent cross-tenant data leakage (Zissis and Lekkas, 2012). Centralized or hierarchical FL models are commonly adopted in such contexts.

3.4.2 IoT Networks

IoT networks consist of resource-constrained devices generatingheterogeneoustrafficpatterns.FederatedIDSin IoT environments must address bandwidth limitations, energy efficiency, and highly non-IID data distributions. Lightweight aggregation schemes and hierarchical coordination models are often necessary to maintain scalability.

3.4.3 Edge Computing

Edgecomputingenvironmentsplacecomputationcloserto data sources, reducing latency and improving responsiveness.Federatedlearningnaturallycomplements edge-basedIDSbyenablinglocalizedanomalydetectionwith periodic global synchronization (Shi et al., 2016). Edge deployments benefit from adaptive fusion strategies to handlegeographicallydistributedtrafficvariations.

3.4.4 Industrial Control Systems

IndustrialControlSystems(ICS)andcriticalinfrastructure networks require highly reliable and real-time intrusion detectionduetosafetyandoperationalrisks.FederatedIDS inICSenvironmentsmustsatisfystrictlatencyconstraints andcomplywithindustrialcybersecuritystandards.Privacypreserving collaboration among industrial entities is particularly important to protect proprietary operational datawhilesharingthreatintelligence.

4. COMPARATIVE LITERATURE ANALYSIS

A comparative literature analysis provides critical insight into methodological trends, empirical performance, and open limitations within federated intrusion detection systems (FIDS). Unlike descriptive surveys, this section synthesizesexperimentalfindingsacrossstudiestoevaluate architectural design, privacy enhancement techniques, aggregation strategies, and system-level efficiency. The analysisfocusesoncommonlyreportedevaluationmetrics, includingaccuracy,F1-score,communicationoverhead,and robustnessunderheterogeneousdatadistributions.

4.1 Table of Key Studies

Astructuredcomparisonofkeystudiesistypicallyorganized using standardized evaluation parameters, including publication year, dataset utilized, federated optimization algorithm, privacy-preserving mechanism, aggregation strategy,detectionaccuracy,F1-score,andcommunication cost. Widely used benchmark datasets include NSL-KDD, UNSW-NB15,andCIC-IDS2017,eachofferingdistincttraffic characteristics and attack diversity. For example, early federated IDS implementations primarily relied on Federated Averaging (FedAvg) evaluated on NSL-KDD, reporting competitive accuracy but limited analysis of adversarial resilience (McMahan et al., 2017). Subsequent worksincorporatedmorerealisticdatasetssuchasUNSWNB15 to better reflect contemporary attack patterns (MoustafaandSlay,2015).Morerecentinvestigationshave introducedprivacy-awaremechanismsandheterogeneous data simulation environments, providing improved F1scores under non-IID settings (Nguyen et al., 2022). Comparative tabulation across these studies reveals increasingattentiontowardcommunicationefficiencyand adaptive aggregation methods rather than purely maximizingclassificationaccuracy.

4.2 Performance Trends and Observations

Acrosstheliterature,aconsistenttrendshowsthatfederated intrusiondetectionmodelsachieveperformancecomparable to centralized baselines when data distributions are moderately homogeneous. Deep neural network architectures, particularly CNN- and LSTM-based models, oftendemonstratesuperiorrecallforcomplexattackclasses duetoenhancedfeatureabstractioncapabilities(Yinetal., 2017). However, empirical results indicate that naive aggregationstrategiesmaysufferfromslowerconvergence in heterogeneous deployments. Studies incorporating proximal optimization or variance correction methods demonstrateimprovedstabilityindistributedenvironments (Karimireddyetal.,2020).Anotherobservabletrendisthe shiftfromreportingonlyaccuracytoemphasizingF1-score andrecall,recognizingclassimbalanceasacriticalissuein intrusion datasets. Furthermore, communication-efficient update compression and partial client participation have emerged as optimization priorities in large-scale deployments.

4.3 Impact of Non-IID Data on Detection Accuracy

Non-independentandidenticallydistributed(non-IID)data significantly influence federated model convergence and generalization.Inintrusiondetection,trafficpatternsdiffer across geographic locations, network roles, and organizationalpolicies,leadingtoskewedclassdistributions. Researchdemonstratesthat standardFedAvgexperiences performancedegradationundersevereheterogeneitydueto client drift and biased local gradients (Li et al., 2020). Empirical evaluations reveal reduced recall for minority

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 02 | Feb 2026 www.irjet.net p-ISSN: 2395-0072

attack classes when data imbalance is not explicitly addressed.Techniquessuchasclientclustering,similarityawareaggregation,andpersonalizedfederatedlearninghave been proposed to mitigate these effects (Hanzely and Richtárik, 2020). Overall, non-IID data remains one of the most critical challenges in achieving robust federated intrusiondetection.

4.4 Privacy–Utility–Communication Trade-offs

The integration of privacy-enhancing mechanisms introduces measurable trade-offs among detection performance,communicationefficiency,andconfidentiality guarantees. Differential privacy, while offering formal privacybounds,oftenresultsinreducedmodelprecisiondue to gradient perturbation (Abadi et al., 2016). Secure aggregationprotocolsenhanceconfidentialitybutincrease computationalandcommunicationoverhead,particularlyin high-frequency training rounds (Bonawitz et al., 2017). Communicationcompressiontechniques,suchasgradient sparsification or quantization, reduce bandwidth consumptionbutmayslowconvergenceoraffectminorityclassdetectionaccuracy(Konečnýetal.,2016).Comparative analysis across studies indicates that achieving optimal balance requires adaptive tuning of privacy budgets, aggregation frequency, and update granularity. Consequently, privacy–utility–communication trade-offs representamultidimensionaloptimizationproblemcentral tothedesignofscalablefederatedIDSframeworks.

5. SECURITY THREATS IN FEDERATED IDS

Whilefederatedlearningenhancesprivacybyavoidingraw datacentralization,itintroducesanewattacksurfaceatthe model-updatelevel.Infederatedintrusiondetectionsystems (FIDS),adversariesmaymanipulatetrainingdynamics,inject malicious updates, or extract sensitive information from shared parameters. Unlike traditional centralized IDS, federatedenvironmentsmustdefendagainstbothexternal cyber threats and internal adversarial participants. This sectionexaminesprincipalattackcategoriesanddiscusses aggregation-level defenses relevant to privacy-preserving federatedIDSframeworks.

5.1 Model Poisoning Attacks

Model poisoning attacks occur when malicious clients intentionallymanipulatelocaltrainingupdatestodegrade globalmodelperformanceorbiaspredictions.Infederated IDS,acompromisednodemayaltergradientvaluesorinject adversarial perturbations that skew attack classification boundaries.Suchattacksareparticularlyeffectivebecause thecentralservertypicallyassumesthatlocalupdatesare benign and aggregates them without direct access to raw data. Byzantine-resilient attack models demonstrate that even a small fraction of malicious participants can significantly distort convergence in distributed learning (Blanchard et al., 2017). Empirical evidence shows that

poisoning can reduce detection recall for critical attack classeswhilemaintainingoverallaccuracy,therebymasking degradationinintrusiondetectioneffectiveness(Bhagojiet al., 2019). The decentralized nature of federated IDS amplifies this risk, especially in cross-organizational deploymentswheretrustrelationshipsarelimited.

5.2 Backdoor Attacks

Backdoor attacks represent a specialized form of model poisoninginwhichadversariesembedhiddentriggersinto the global model. In intrusion detection scenarios, a malicious client may train its local model to misclassify specificattacksignatureswhenapredefinedtrafficpattern appears.Theglobalaggregationprocesstheninadvertently incorporates this backdoor behavior. Unlike general poisoning, backdoor attacks aim to preserve overall performancewhileenablingtargetedevasion.Studieshave shown that model replacement techniques can allow adversaries to scale malicious updates to dominate aggregationroundswithout detection(Bagdasaryanet al., 2020). In federated IDS environments, such attacks are particularly dangerous because they may enable stealthy bypass of security monitoring systems while remaining statisticallyinconspicuous.

5.3 Inference Attacks (Membership and Model Inversion)

Inference attacks exploit shared model updates to extract sensitiveinformationaboutlocaltrainingdata.Membership inference attacks aim to determine whether specific data samples were part of a client’s training set, potentially revealingconfidentialnetworktrafficpatterns(Shokrietal., 2017).Modelinversionattacksgofurtherbyreconstructing approximations of original training inputs from gradient information (Zhu et al., 2019). In federated intrusion detection, exposure of traffic metadata or behavioral signatures through such attacks could compromise organizationalprivacyorrevealoperationalvulnerabilities. Althoughfederatedlearningreducesdirectdataexposure, gradient leakage remains a documented risk, particularly when privacy-preserving mechanisms are not rigorously implemented.

5.4 Robust Aggregation Countermeasures

To mitigate adversarial threats, robust aggregation mechanismshavebeendevelopedtodetectandneutralize maliciousupdates.Byzantine-resilientaggregationmethods, such as Krum and trimmed-mean algorithms, attempt to filter anomalous gradients before global model updates (Blanchard et al., 2017). Median-based or norm-clipping strategiesfurtherreducetheinfluenceofextremeparameter deviations. More advanced defenses incorporate anomaly detection at the update level, evaluating statistical divergenceortrustscoresbeforeaggregation(Pillutlaetal., 2022). In privacy-preserving federated IDS, combining

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 02 | Feb 2026 www.irjet.net p-ISSN: 2395-0072

robust aggregation with differential privacy and secure aggregation protocolscanenhance resilienceagainst both poisoning and inference attacks. However, defensive mechanisms often introduce additional computational overheadandmayslowconvergence,highlightingtheneed foradaptiveandefficientcountermeasurestailoredtocyber securitycontexts.

6. EMERGING RESEARCH DIRECTIONS

The evolution of federated intrusion detection systems (FIDS) is increasingly shaped by advances in distributed optimization,adaptiveintelligence,andsecurecoordination mechanisms. While foundational federated learning frameworks have demonstrated feasibility in privacypreservingintrusiondetection,emergingresearchdirections aim to enhance robustness, scalability, and regulatory alignment. This section synthesizes key forward-looking paradigmsthatareexpectedtoinfluencethenextgeneration ofadaptivecross-nodefederatedIDSarchitectures.

6.1 Graph-Based Federated Aggregation

Traditionalfederatedaggregationassumesastar-topology communicationstructurewhereclientsinteractonlywitha central coordinator. However, real-world network infrastructuresoftenexhibitgraph-likerelationshipsamong nodes.Graph-basedfederatedaggregationleveragesgraph neural networks (GNNs) or topology-aware optimization strategies to model inter-client relationships during parameterfusion.Byincorporatingstructuralsimilarityor communicationproximityintoaggregationweights,graphbasedmethodsimproveconvergenceunderheterogeneous conditions (Scarselli et al., 2009). In intrusion detection, graph-based aggregation enables clustering of nodes with similar traffic distributions, thereby reducing the adverse effects of non-IID data. Furthermore, topology-aware aggregationcanenhanceresilienceagainstmaliciousnodes byisolatinganomalousparticipantswithingraphpartitions.

6.2 Meta-Learning for Dynamic Fusion

Meta-learning, often described as “learning to learn,” provides a framework for adaptive model generalization acrossheterogeneousenvironments.InfederatedIDS,metalearning techniques can dynamically adjust aggregation parameters or initialization weights to optimize performance under varying traffic distributions. ModelAgnostic Meta-Learning (MAML) and related approaches allowrapidadaptationtonewattackpatternswithminimal localretraining(Finnetal.,2017).Integratingmeta-learning into federated aggregation facilitates personalized or cluster-specificmodels,addressingclientdriftandconcept evolution in distributed networks. This direction is particularly relevant for adaptive cross-node parameter fusion,whereaggregationrulescanthemselvesbeoptimized throughmeta-objectives.

6.3 Block chain-Assisted Federated IDS

Blockchain technology offers decentralized trust management and tamper-resistant record-keeping, which can complement federated learning in adversarial environments.InfederatedIDS,blockchaincanbeemployed tosecurelylogmodelupdates,verifyparticipantintegrity, and enforce smart-contract-based aggregation policies (Zhangetal.,2020).Thisintegrationreducesrelianceona fully trusted central server and enhances transparency in collaborativecybersecuritysettings.However,blockchainassisted federated systems must address scalability constraints and consensus latency, especially in highthroughputintrusiondetectionscenarios.Theconvergence ofblockchainandfederatedlearningrepresentsapromising pathwaytowarddecentralized,auditablethreatintelligence sharing.

6.4 Federated Continual Learning

Network environments are dynamic, with evolving attack vectors and shifting traffic patterns. Federated continual learningextendsstandardFLbyenablingincrementalmodel updates without catastrophic forgetting of previously learnedattacksignatures.Continuallearningmechanisms, suchasregularization-basedmemoryretentionandreplay strategies, have been proposed to preserve historical knowledgewhileincorporatingnewthreatdata(Parisietal., 2019).In federatedIDS, continual learning supportslongtermadaptabilityacrossdistributednodes,allowingsystems toremainresponsivetoemergingcyberthreats.Combining continuallearningwithadaptiveaggregationstrategiescan further mitigate performance degradation under concept driftconditions.

6.5 AI Governance and Regulatory Compliance

As federated intrusion detection systems are deployed across jurisdictions and industries, compliance with regulatory frameworks becomes increasingly critical. AI governance principles emphasize transparency, accountability, and explain ability in machine learning systems(Floridietal.,2018).Incybersecurityapplications, explainablefederatedIDSmodelscanimprovetrustamong collaborating entities and support forensic investigations. Additionally, privacy-preserving mechanisms must align withlegalstandardssuchasGDPRandsector-specificcyber security regulations. Emerging research focuses on embedding compliance-aware constraints into federated optimization processes and establishing standardized evaluation protocols for privacy guarantees. GovernancealignedfederatedIDSarchitecturesare expectedtoplay a central role in responsible and sustainable cyber security collaboration.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 02 | Feb 2026 www.irjet.net p-ISSN: 2395-0072

7. CONCLUSION

This review has systematically examined the evolving landscape of privacy-preserving network intrusion identification through federated learning with adaptive cross-node parameter fusion. By synthesizing existing research across architectural paradigms, privacyenhancement mechanisms, aggregation strategies, and deployment contexts, the study highlights the transition fromconventionalcentralizedintrusiondetectionsystems toward collaborative and decentralized intelligence frameworks. The analysis demonstrates that federated learningeffectivelymitigatesrawdataexposureriskswhile maintainingcompetitivedetectionperformance.However, thesuccessoffederatedintrusiondetectionsystems(FIDS) largelydependsonrobustaggregationmechanismscapable of handling non-IID data, adversarial manipulation, and dynamic network conditions. Adaptive cross-node parameterfusion emergesasa critical enabler, improving convergencestability,resilienceagainstpoisoningattacks, and generalization across heterogeneous environments. Furthermore, emerging directions such as graph-based aggregation,federatedcontinuallearning,andgovernancealigned AI frameworks indicate a maturation of the field toward scalable and regulation-compliant deployment. Overall,privacy-awarefederatedIDSrepresentapromising paradigm for secure collaborative cyber security, though further advancements in robustness, standardization, and real-worldvalidationremainnecessary.

7.1. Limitations of This Review

Despiteprovidingastructuredtaxonomyandcomparative synthesis, this review has certain limitations. First, the analysisreliesonpublishedacademicliterature,whichmay notfullycaptureproprietaryorindustry-deployedfederated intrusiondetectionimplementations.Second,variationsin experimentalsetups,datasets,andevaluationmetricsacross studieslimitdirectquantitativecomparability.Third,rapidly evolving federated optimization and adversarial defense techniques may render some observations temporally constrained.Additionally,whileprivacy–utilitytrade-offsare discussed conceptually, a formal meta-analysis was not conductedduetoinconsistentreportingofcommunication overhead and privacy budgets. Finally, the review emphasizes adaptive cross-node parameter fusion within federated frameworks, potentially underrepresenting alternativedecentralizedlearningparadigmsthatcouldalso supportprivacy-preservingintrusiondetection.

REFERENCES

1. Abadi, M., Chu, A., Goodfellow, I., McMahan, H.B., Mironov, I., Talwar, K. and Zhang, L. (2016) ‘Deep learningwithdifferentialprivacy’,Proceedingsofthe ACM Conference on Computer and Communications Security(CCS),pp.308–318.

2. Bagdasaryan, E., Veit, A., Hua, Y., Estrin, D. and Shmatikov, V. (2020) ‘How to backdoor federated learning’,ProceedingsoftheInternationalConference onArtificialIntelligenceandStatistics(AISTATS),pp. 2938–2948.

3. Bhagoji, A.N., Chakraborty, S., Mittal, P. and Calo, S. (2019) ‘Analyzing federated learning through an adversarial lens’, Proceedings of the International ConferenceonMachineLearning(ICML),pp.634–643.

4. Bhuyan, M.H., Bhattacharyya, D.K. and Kalita, J.K. (2014)‘Networkanomalydetection:Methods,systems andtools’,IEEECommunicationsSurveys&Tutorials, 16(1),pp.303–336.

5. Blanchard, P., El Mhamdi, E.M., Guerraoui, R. and Stainer,J.(2017)‘Machinelearningwithadversaries: Byzantine tolerant gradient descent’, Advances in Neural Information Processing Systems, 30, pp. 119–129.

6. Bonawitz, K., Ivanov, V., Kreuter, B., Marcedone, A., McMahan,H.B.,Patel,S.,Ramage,D.,Segal,A.andSeth, K. (2017) ‘Practical secure aggregation for privacypreservingmachinelearning’,ProceedingsoftheACM CCS,pp.1175–1191.

7. Dwork,C.(2006)‘Differentialprivacy’,Proceedingsof theInternationalColloquiumonAutomata,Languages andProgramming(ICALP),pp.1–12.

8. Finn, C., Abbeel, P. and Levine, S. (2017) ‘Modelagnostic meta-learning for fast adaptation of deep networks’,ProceedingsofICML,pp.1126–1135.

9. Floridi, L., Cowls, J., Beltrametti, M., Chatila, R., Chazerand, P., Dignum, V., Luetge, C., Madelin, R., Pagallo,U.,Rossi,F.,Schafer,B.,Valcke,P.andVayena, E.(2018)‘AI4People Anethicalframeworkforagood AIsociety’,MindsandMachines,28(4),pp.689–707.

10. Garcia-Teodoro,P.,Diaz-Verdejo,J.,Maciá-Fernández, G. and Vázquez, E. (2009) ‘Anomaly-based network intrusion detection: Techniques, systems and challenges’,Computers&Security,28(1–2),pp.18–28.

11. Gentry,C.(2009)‘Fullyhomomorphicencryptionusing ideallattices’,ProceedingsoftheACMSymposiumon TheoryofComputing(STOC),pp.169–178.

12. Hanzely,F.andRichtárik,P.(2020)‘Federatedlearning ofamixtureofglobalandlocalmodels’,arXivpreprint arXiv:2002.05516.

13. Kairouz,P.,McMahan,H.B.,Avent,B.,Bellet,A.,Bennis, M.,Bhagoji,A.N.,Bonawitz,K.,Charles,Z.,Cormode,G., Cummings,R.,D’Oliveira,R.,Eichner,H.,ElRouayheb, S.,Evans,D.,Gardner,J.,Garrett,Z.,Gascón,A.,Ghazi,B.,

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 02 | Feb 2026 www.irjet.net p-ISSN: 2395-0072

Gibbons, P.B., Green, M., Harchaoui, Z., He, Y., He, T., Huo, Z., Jaggi, M., Javidi, T., Joshi, G., Kale, S., Karimireddy,S.P.,Konecny,J.,Koushanfar,F.,Koyejo,O., Li,T.,Liu,Y.,Mohri,M.,Nock,R.,Pappas,G.,Qi,Y.,Reddi, S.,Richtárik,P.,Singhal,K.,Smith,V.,Suresh,A.T.,Su,J., Sun,H.,Talwalkar,A.,Wang,H.,Wu,L.,Xu,S.,Yang,Q., Yu, F.X., Yuan, M., Zaheer, M., Zhang, K. and Zhao, Z. (2021) ‘Advances and open problems in federated learning’,FoundationsandTrendsinMachineLearning, 14(1–2),pp.1–210.

14. Karimireddy,S.P.,Kale,S.,Mohri,M.,Reddi,S.,Stich,S.U. and Suresh, A.T. (2020) ‘SCAFFOLD: Stochastic controlled averaging for federated learning’, ProceedingsofICML,pp.5132–5143.

15. Konečný, J., McMahan, H.B., Yu, F.X., Richtárik, P., Suresh,A.T.andBacon,D.(2016)‘Federatedlearning: Strategies for improving communication efficiency’, arXivpreprintarXiv:1610.05492.

16. Li, T., Sahu, A.K., Talwalkar, A. and Smith, V. (2020) ‘Federated optimization in heterogeneous networks’, ProceedingsofMLSys,pp.429–450.

17. Lian,X.,Zhang,C.,Zhang,H.,Hsieh,C.J.,Zhang,W.and Liu,J.(2017)‘Candecentralizedalgorithmsoutperform centralizedalgorithms?Acasestudyfordecentralized parallel stochastic gradient descent’, Advances in NeuralInformationProcessingSystems,30,pp.5330–5340.

18. Liu,Y.,Kang,Y.,Xing,C.,Chen,T.andYang,Q.(2020)‘A secure federated transfer learning framework’, IEEE IntelligentSystems,35(4),pp.70–82.

19. McMahan,B.,Moore,E., Ramage,D.,Hampson, S.and Arcas,B.A.(2017)‘Communication-efficientlearningof deepnetworksfromdecentralizeddata’,Proceedingsof AISTATS,pp.1273–1282.

20. Moustafa, N. and Slay, J. (2015) ‘UNSW-NB15: A comprehensivedatasetfornetworkintrusiondetection systems’, Military Communications and Information SystemsConference,pp.1–6.

21. Nguyen,T.D.,Marchal,S.,Miettinen,M.,Fereidooni,H. and Asokan, N. (2022) ‘Deep federated learning for intrusiondetectioninIoTnetworks’,IEEEInternetof ThingsJournal,9(7),pp.5625–5638.

22. Parisi,G.I.,Kemker,R.,Part,J.L.,Kanan,C.andWermter, S. (2019) ‘Continual lifelong learning with neural networks:Areview’,NeuralNetworks,113,pp.54–71.

23. Pillutla,K.,Kakade,S.andHarchaoui,Z.(2022)‘Robust aggregationforfederatedlearning’,IEEETransactions onSignalProcessing,70,pp.1142–1154.

24. Roesch, M. (1999) ‘Snort: Lightweight intrusion detectionfornetworks’,ProceedingsofLISA,pp.229–238.

25. Scarselli,F.,Gori,M.,Tsoi,A.C.,Hagenbuchner,M.and Monfardini, G. (2009) ‘The graph neural network model’,IEEETransactionsonNeuralNetworks,20(1), pp.61–80.

26. Shi,W.,Cao,J.,Zhang,Q.,Li,Y.andXu,L.(2016)‘Edge computing: Vision and challenges’, IEEE Internet of ThingsJournal,3(5),pp.637–646.

27. Shokri, R., Stronati, M., Song, C. and Shmatikov, V. (2017)‘Membershipinferenceattacksagainstmachine learning models’, IEEE Symposium on Security and Privacy,pp.3–18.

28. Sommer,R.andPaxson,V.(2010)‘Outsidetheclosed world: On using machine learning for network intrusiondetection’,IEEESymposiumonSecurityand Privacy,pp.305–316.

29. Truex,S.,Liu,L.,Chow,K.H.,Gursoy,M.E.andWei,W. (2019) ‘Hybrid federated learning: Algorithms and implementation’,IEEEInternationalConferenceonBig Data,pp.3378–3387.

30. Yang,Q.,Liu,Y.,Chen,T.andTong,Y.(2019)‘Federated machine learning: Concept and applications’, ACM Transactions on Intelligent Systems and Technology, 10(2),pp.1–19.

31. Yao, A.C. (1982) ‘Protocols for secure computations’, ProceedingsofFOCS,pp.160–164.

32. Yin,C.,Zhu,Y.,Fei,J.andHe,X.(2017)‘Adeeplearning approachforintrusiondetectionusingrecurrentneural networks’,IEEEAccess,5,pp.21954–21961.

33. Zhang, Y., Kasahara, S., Shen, Y., Jiang, X. and Wan, J. (2020) ‘Smart contract-based access control for the Internet of Things’, IEEE Internet of Things Journal, 6(2),pp.1594–1605.

34. Zhu,L.,Liu,Z.andHan, S.(2019)‘Deepleakage from gradients’,AdvancesinNeuralInformationProcessing Systems,32,pp.14774–14784.

35. Zissis, D. and Lekkas, D. (2012) ‘Addressing cloud computing security issues’, Future Generation ComputerSystems,28(3),pp.583–592.

36. Bhagoji, A.N., Chakraborty, S., Mittal, P. and Calo, S., 2019. Analyzing federated learning through an adversariallens.Proceedingsofthe36thInternational ConferenceonMachineLearning(ICML),pp.634–643.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 02 | Feb 2026 www.irjet.net p-ISSN: 2395-0072

37. Cao,X.,Fang,M.,Liu,J.andGong,N.Z.,2021.FLTrust: Byzantine-robust federated learning via trust bootstrapping. Proceedings of the Network and DistributedSystemSecuritySymposium(NDSS).

Turn static files into dynamic content formats.

Create a flipbook
A REVIEW OF PRIVACY-PRESERVING NETWORK INTRUSION IDENTIFICATION THROUGH FEDERATED LEARNING WITH ADAP by IRJET Journal - Issuu