Abstract
Federated learning-based intrusion detection systems (FL-IDS) have emerged as a promising approach for collaborative anomaly detection in distributed networks, providing strong privacy guarantees by enabling model training across decentralized data sources without exposing sensitive information. However, in real-world scenarios, client data are often non-independent and identically distributed (non-i.i.d.), resulting in significant performance degradation and model drift. While sharing subsets of local client data has been proposed to mitigate this issue, such approaches compromise data privacy. In response to these challenges, we propose FedCKD, a federated framework that integrates Contrastive Knowledge Distillation for network intrusion detection. By utilizing a teacher-student model architecture on client devices, FedCKD aligns the feature maps of various models, ensuring consistent feature representation across clients, achieving effective statistical distribution alignment. Furthermore, the incorporation of cluster contrastive learning enhances the separation between anomalous and normal instances, improving the model's discriminative capabilities. We conduct extensive experiments on the NSL-KDD and UNSW-NB15 datasets, demonstrating that FedCKD outperforms existing methods, achieving over 90 % f1-score in non-i.i.d. (an increase of 4.24 %) scenarios. Our approach effectively mitigates performance degradation due to data distribution skewness while maintaining strong privacy protections. These results underscore the potential of FedCKD as a robust and privacy-preserving solution for network intrusion detection.
| Original language | English |
|---|---|
| Article number | 111904 |
| Journal | Computer Networks |
| Volume | 275 |
| DOIs | |
| State | Published - Feb 2026 |
| Externally published | Yes |
Keywords
- Contrastive learning
- Federated learning
- Intrusion detection system
- Knowledge distillation
Fingerprint
Dive into the research topics of 'Robust federated intrusion detection under statistical heterogeneity'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver