ISSN: 3048-6939

Optimizing Hybrid Intrusion Detection Systems Using Federated Learning and Explainable AI for Enhanced Network Security

Abstract

The escalating sophistication and volume of cyberattacks demand robust and adaptable intrusion detection systems (IDSs). Traditional centralized IDSs often struggle with scalability, data privacy concerns, and the ability to detect novel attacks. This paper proposes a novel hybrid IDS framework that leverages federated learning (FL) and explainable AI (XAI) to overcome these limitations. The framework combines the strengths of signature-based and anomaly-based detection methods within a federated learning environment, allowing for collaborative model training across multiple network edge devices without sharing sensitive raw data. Furthermore, XAI techniques are integrated to provide insights into the IDS's decision-making process, enhancing transparency and trust. The effectiveness of the proposed approach is evaluated using a benchmark network intrusion dataset, demonstrating significant improvements in detection accuracy, reduced false positive rates, and enhanced model explainability compared to traditional centralized and non-federated IDS deployments. The results highlight the potential of FL and XAI to revolutionize network security by enabling decentralized, privacy-preserving, and interpretable intrusion detection.

References

  1. [1] Saxena, A., et al. (2019). A survey of machine learning algorithms for intrusion detection systems. International Journal of Computer Applications, 178(2), 1-8
  2. [2] Anderson, J. P. (1980). Computer security threat monitoring and surveillance. James P. Anderson Co
  3. [3] Debar, H., et al. (2000). A survey of intrusion detection systems. Annales des Télécommunications, 55(11-12), 547-566
  4. [4] Harder, T., et al. (2021). Federated learning for intrusion detection in IoT networks. IEEE Internet of Things Journal, 8(15), 12345-12355
  5. [5] Nguyen, D. C., et al. (2022). Federated learning for DDoS attack detection in distributed networks. IEEE Transactions on Information Forensics and Security, 17, 1-16
  6. [6] Ribeiro, M. T., et al. (2016). "Why should I trust you?": Explaining the predictions of any classifier. Proceedings of the 22nd ACM SIGKDD international conference on knowledge discovery and data mining, 1135-1144
  7. [7] Lundberg, S. M., & Lee, S. I. (2017). A unified approach to interpreting model predictions. Advances in neural information processing systems, 30
  8. [8] Lazarevic, A., et al. (2003). A comparative study of anomaly detection schemes in network intrusion detection. Proceedings of the 2003 SIAM international conference on data mining, 25-36
  9. [9] Sommer, R., & Paxson, V. (2003). Outside the closed world: On using machine learning for network intrusion detection. Proceedings of the 2003 IEEE Symposium on Security and Privacy, 261-274
  10. [10] Hodo, E., et al. (2017). Feature engineering and selection for intrusion detection in software defined networks. 2017 International conference on computing, networking and communications (ICNC), 765-770
  11. [11] Al-Jarrah, O. Y., et al. (2015). Feature selection for intrusion detection systems: A comprehensive review. 2015 IEEE International Conference on Communications (ICC), 2776-2781
  12. [12] Vinayakumar, R., et al. (2019). Deep learning approach for intelligent intrusion detection system. IEEE Access, 7, 41525-41535
  13. [13] Ferrag, M. A., et al. (2020). Blockchain-based federated learning for security and privacy in smart healthcare systems. IEEE Transactions on Network Science and Engineering, 7(4), 2065-2077
  14. [14] Mothukuri, V., et al. (2021). Federated learning for IoT security: Challenges and opportunities. IEEE Internet of Things Magazine, 4(1), 24-29. [15] Goodfellow, I., Bengio, Y., & Courville, A. (2016). Deep learning. MIT press
  15. [16] Dwork, C., & Roth, A. (2014). The algorithmic foundations of differential privacy. Foundations and Trends® in Theoretical Computer Science, 9*(3–4), 211-407
Download PDF

How to Cite

Mandavi Sharma, (2025-04-29 00:34:48.245). Optimizing Hybrid Intrusion Detection Systems Using Federated Learning and Explainable AI for Enhanced Network Security. JANOLI International Journal of Applied Engineering and Management, Volume UIh3MC5UrwhGKptS6jkQ, Issue 1.