Skip to main navigation Skip to search Skip to main content

Robust federated intrusion detection under statistical heterogeneity

  • Xinran Zheng
  • , Wenhao Wu
  • , Shuo Yang*
  • , Xingjun Wang
  • *Corresponding author for this work
  • Tsinghua University
  • The University of Hong Kong

Research output: Contribution to journalArticlepeer-review

Abstract

Federated learning-based intrusion detection systems (FL-IDS) have emerged as a promising approach for collaborative anomaly detection in distributed networks, providing strong privacy guarantees by enabling model training across decentralized data sources without exposing sensitive information. However, in real-world scenarios, client data are often non-independent and identically distributed (non-i.i.d.), resulting in significant performance degradation and model drift. While sharing subsets of local client data has been proposed to mitigate this issue, such approaches compromise data privacy. In response to these challenges, we propose FedCKD, a federated framework that integrates Contrastive Knowledge Distillation for network intrusion detection. By utilizing a teacher-student model architecture on client devices, FedCKD aligns the feature maps of various models, ensuring consistent feature representation across clients, achieving effective statistical distribution alignment. Furthermore, the incorporation of cluster contrastive learning enhances the separation between anomalous and normal instances, improving the model's discriminative capabilities. We conduct extensive experiments on the NSL-KDD and UNSW-NB15 datasets, demonstrating that FedCKD outperforms existing methods, achieving over 90 % f1-score in non-i.i.d. (an increase of 4.24 %) scenarios. Our approach effectively mitigates performance degradation due to data distribution skewness while maintaining strong privacy protections. These results underscore the potential of FedCKD as a robust and privacy-preserving solution for network intrusion detection.

Original languageEnglish
Article number111904
JournalComputer Networks
Volume275
DOIs
StatePublished - Feb 2026
Externally publishedYes

Keywords

  • Contrastive learning
  • Federated learning
  • Intrusion detection system
  • Knowledge distillation

Fingerprint

Dive into the research topics of 'Robust federated intrusion detection under statistical heterogeneity'. Together they form a unique fingerprint.

Cite this