{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,18]],"date-time":"2026-06-18T19:11:35Z","timestamp":1781809895128,"version":"3.54.5"},"reference-count":79,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2024,10,7]],"date-time":"2024-10-07T00:00:00Z","timestamp":1728259200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2025,1,31]]},"abstract":"<jats:p>Intrusion Detection Systems (IDS) are essential for securing computer networks by identifying and mitigating potential threats. However, traditional IDS face challenges related to scalability, privacy, and computational demands as network data complexity increases. Federated Learning (FL) has emerged as a promising solution, enabling collaborative model training on decentralized data sources while preserving data privacy. Each participant retains local data repositories, ensuring data sovereignty and precluding data sharing. Leveraging the FL framework, participants locally train machine learning models on their respective datasets, subsequently transmitting model updates to a central server for aggregation. The central server then disseminates the aggregated model updates to individual participants, collectively striving to bolster intrusion detection capabilities. This article presents a comprehensive survey of FL applications in IDS, covering core concepts, architectural approaches, and aggregation strategies. We evaluate the strengths and limitations of various FL methodologies for IDS, addressing privacy and security concerns and exploring privacy-preserving techniques and security protocols. Our examination of aggregation strategies within the FL framework for IDS aims to highlight their effectiveness, limitations, and potential enhancements.<\/jats:p>","DOI":"10.1145\/3687124","type":"journal-article","created":{"date-parts":[[2024,8,6]],"date-time":"2024-08-06T11:14:54Z","timestamp":1722942894000},"page":"1-38","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":81,"title":["Survey on Federated Learning for Intrusion Detection System: Concept, Architectures, Aggregation Strategies, Challenges, and Future Directions"],"prefix":"10.1145","volume":"57","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8623-0987","authenticated-orcid":false,"given":"Ansam","family":"Khraisat","sequence":"first","affiliation":[{"name":"Deakin Cyber Research and Innovation Centre, Deakin University, Burwood, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9443-937X","authenticated-orcid":false,"given":"Ammar","family":"Alazab","sequence":"additional","affiliation":[{"name":"Centre for Artificial Intelligence Research and Optimisation (AIRO), Torrens University Australia, Melbourne, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2202-202X","authenticated-orcid":false,"given":"Sarabjot","family":"Singh","sequence":"additional","affiliation":[{"name":"Deakin Cyber Research and Innovation Centre, Deakin University, Burwood, Australia"},{"name":"Centre for Artificial Intelligence Research and Optimisation (AIRO), Torrens University, Melbourne, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3114-8978","authenticated-orcid":false,"given":"Tony","family":"Jan","sequence":"additional","affiliation":[{"name":"Centre for Artificial Intelligence Research and Optimization (AIRO), Torrens University Australia, Sydeny, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-0638-7474","authenticated-orcid":false,"given":"Alfredo","family":"Jr. Gomez","sequence":"additional","affiliation":[{"name":"School of IT &amp; Engineering, Melbourne Institute of Technology, Melbourne, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,10,7]]},"reference":[{"key":"e_1_3_1_2_2","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-021-00077-7"},{"key":"e_1_3_1_3_2","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-019-0038-7"},{"key":"e_1_3_1_4_2","doi-asserted-by":"publisher","DOI":"10.1561\/2200000083"},{"key":"e_1_3_1_5_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jpdc.2022.03.003"},{"key":"e_1_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.3390\/electronics12163382"},{"key":"e_1_3_1_7_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2022.3177512"},{"key":"e_1_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2020.2975749"},{"key":"e_1_3_1_9_2","doi-asserted-by":"publisher","DOI":"10.1145\/3298981"},{"key":"e_1_3_1_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2021.3119038"},{"key":"e_1_3_1_11_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3118642"},{"key":"e_1_3_1_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2021.3058573"},{"key":"e_1_3_1_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/LCOMM.2022.3140273"},{"key":"e_1_3_1_14_2","doi-asserted-by":"publisher","DOI":"10.1109\/TVT.2021.3076780"},{"key":"e_1_3_1_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2020.3023430"},{"key":"e_1_3_1_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2020.2986024"},{"key":"e_1_3_1_17_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3030072"},{"key":"e_1_3_1_18_2","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2021.3124599"},{"key":"e_1_3_1_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2021.3090430"},{"key":"e_1_3_1_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2021.3075439"},{"key":"e_1_3_1_21_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3077803"},{"key":"e_1_3_1_22_2","doi-asserted-by":"publisher","DOI":"10.1109\/BigDataSE50710.2020.00020"},{"key":"e_1_3_1_23_2","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.011.2000286"},{"key":"e_1_3_1_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3041793"},{"key":"e_1_3_1_25_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2019.00080"},{"key":"e_1_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.1145\/3511285.3511291"},{"key":"e_1_3_1_27_2","doi-asserted-by":"publisher","DOI":"10.1109\/MIS.2020.2988525"},{"key":"e_1_3_1_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/BigData47090.2019.9006280"},{"key":"e_1_3_1_29_2","doi-asserted-by":"publisher","DOI":"10.1109\/tii.2021.3075706"},{"key":"e_1_3_1_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3272338"},{"key":"e_1_3_1_31_2","doi-asserted-by":"publisher","DOI":"10.1109\/MWC.005.2100435"},{"key":"e_1_3_1_32_2","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM42981.2021.9488705"},{"key":"e_1_3_1_33_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE51399.2021.00102"},{"key":"e_1_3_1_34_2","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2020.3041404"},{"key":"e_1_3_1_35_2","doi-asserted-by":"publisher","DOI":"10.1109\/TVT.2023.3246636"},{"key":"e_1_3_1_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/TMC.2022.3200016"},{"key":"e_1_3_1_37_2","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2306.01603"},{"key":"e_1_3_1_38_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3107337"},{"key":"e_1_3_1_39_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3196503"},{"key":"e_1_3_1_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/VTC2023-Spring57618.2023.10200010"},{"key":"e_1_3_1_41_2","doi-asserted-by":"publisher","unstructured":"Zhiyuan Zhang Qi Su and Xu Sun. 2022. Dim-Krum: Backdoor-resistant federated learning for NLP with dimension-wise Krum-based aggregation. arXiv:2210.06894 (2022). DOI:10.48550\/arXiv.2210.06894","DOI":"10.48550\/arXiv.2210.06894"},{"key":"e_1_3_1_42_2","doi-asserted-by":"publisher","unstructured":"Dong Yin Yudong Chen Kannan Ramchandran and Peter Bartlett. 2021. Byzantine-robust distributed learning: Towards optimal statistical rates. arXiv:1803.01498 (2021). DOI:10.48550\/arXiv.1803.01498","DOI":"10.48550\/arXiv.1803.01498"},{"key":"e_1_3_1_43_2","doi-asserted-by":"publisher","DOI":"10.1145\/3510032"},{"key":"e_1_3_1_44_2","doi-asserted-by":"publisher","DOI":"10.23919\/JCC.2020.09.005"},{"key":"e_1_3_1_45_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2883775"},{"key":"e_1_3_1_46_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICTC55196.2022.9952531"},{"key":"e_1_3_1_47_2","doi-asserted-by":"publisher","DOI":"10.1109\/SRDS51746.2020.00011"},{"key":"e_1_3_1_48_2","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2007.14390"},{"key":"e_1_3_1_49_2","article-title":"LEAF: A benchmark for federated settings","author":"Caldas Sebastian","year":"2018","unstructured":"Sebastian Caldas, Sai Meher Karthik Duddu, Peter Wu, Tian Li, Jakub Kone\u010dn\u00fd, H. Brendan McMahan, Virginia Smith, and Ameet Talwalkar. 2018. LEAF: A benchmark for federated settings. arXiv:1812.01097v3 (2018). https:\/\/arxiv.org\/abs\/1812.01097v3","journal-title":"arXiv:1812.01097v3"},{"key":"e_1_3_1_50_2","doi-asserted-by":"publisher","unstructured":"G. Anthony Reina Alexey Gruzdev Patrick Foley Olga Perepelkina Mansi Sharma Igor Davidyuk Ilya Trushkin Maksim Radionov Aleksandr Mokrov Dmitry Agapov Jason Martin Brandon Edwards Micah J. Sheller Sarthak Pati Prakash Narayana Moorthy Shih-Han Wang Prashant Shah and Spyridon Bakas. 2021. OpenFL: An open-source framework for federated learning. arXiv:2105.06413 (2021). DOI:10.1088\/1361-6560\/ac97d9","DOI":"10.1088\/1361-6560\/ac97d9"},{"key":"e_1_3_1_51_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.12"},{"key":"e_1_3_1_52_2","article-title":"FedScale: Benchmarking model and system performance of federated learning at scale","author":"Lai Fan","year":"2021","unstructured":"Fan Lai, Yinwei Dai, Sanjay S. Singapuram, Jiachen Liu, Xiangfeng Zhu, Harsha V. Madhyastha, and Mosharaf Chowdhury. 2021. FedScale: Benchmarking model and system performance of federated learning at scale. arXiv:2105.11367v5 (2021). https:\/\/arxiv.org\/abs\/2105.11367v5","journal-title":"arXiv:2105.11367v5"},{"key":"e_1_3_1_53_2","doi-asserted-by":"crossref","first-page":"341","DOI":"10.1007\/978-3-031-34896-9_20","volume-title":"Towards New e-Infrastructure and e-Services for Developing Countries","author":"Ntantiso Lutho","year":"2023","unstructured":"Lutho Ntantiso, Antoine Bagula, Olasupo Ajayi, and Ferdinand Kahenga-Ngongo. 2023. A review of federated learning: Algorithms, frameworks and applications. In Towards New e-Infrastructure and e-Services for Developing Countries, Rashid A. Saeed, Abubakar D. Bakari, and Yahya Hamad Sheikh (Eds.). Springer Nature Switzerland, Cham, 341\u2013357."},{"key":"e_1_3_1_54_2","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2207.10308"},{"key":"e_1_3_1_55_2","doi-asserted-by":"publisher","unstructured":"Zilong Zhao Robert Birke Aditya Kunar and Lydia Y. Chen. 2021. Fed-TGAN: Federated learning framework for synthesizing tabular data. arXiv:2108.07927 (2021). DOI:10.48550\/arXiv.2108.07927","DOI":"10.48550\/arXiv.2108.07927"},{"key":"e_1_3_1_56_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jksuci.2023.101575"},{"key":"e_1_3_1_57_2","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2107.10996"},{"key":"e_1_3_1_58_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3037194"},{"key":"e_1_3_1_59_2","doi-asserted-by":"publisher","DOI":"10.1109\/MCE.2019.2959108"},{"key":"e_1_3_1_60_2","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-021-00105-6"},{"key":"e_1_3_1_61_2","doi-asserted-by":"publisher","unstructured":"Gergely Daniel Nemeth Miguel Angel Lozano Novi Quadrianto and Nuria Oliver. 2023. Addressing membership inference attack in federated learning with model compression. arXiv:2311.17750 (2023). DOI:10.48550\/arXiv.2311.17750","DOI":"10.48550\/arXiv.2311.17750"},{"key":"e_1_3_1_62_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2023.3288886"},{"key":"e_1_3_1_63_2","doi-asserted-by":"publisher","unstructured":"Jahid Hasan. 2023. Security and privacy issues of federated learning. arXiv:2307.12181 (2023). DOI:10.48550\/arXiv.2307.12181","DOI":"10.48550\/arXiv.2307.12181"},{"key":"e_1_3_1_64_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103205"},{"key":"e_1_3_1_65_2","doi-asserted-by":"publisher","DOI":"10.3390\/electronics12214463"},{"key":"e_1_3_1_66_2","doi-asserted-by":"publisher","DOI":"10.1109\/TEM.2022.3155353"},{"key":"e_1_3_1_67_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2020.3039941"},{"key":"e_1_3_1_68_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.2988575"},{"key":"e_1_3_1_69_2","doi-asserted-by":"publisher","DOI":"10.3233\/IA-200075"},{"key":"e_1_3_1_70_2","doi-asserted-by":"publisher","DOI":"10.1145\/3442381.3449851"},{"key":"e_1_3_1_71_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE53745.2022.00077"},{"key":"e_1_3_1_72_2","doi-asserted-by":"publisher","DOI":"10.1109\/TWC.2020.3003744"},{"key":"e_1_3_1_73_2","doi-asserted-by":"publisher","DOI":"10.33166\/AETiC.2021.05.025"},{"key":"e_1_3_1_74_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS47774.2020.00032"},{"key":"e_1_3_1_75_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2017.11"},{"key":"e_1_3_1_76_2","doi-asserted-by":"publisher","unstructured":"Wenyuan Yang Yuguo Yin Gongxi Zhu Hanlin Gu Lixin Fan Xiaochun Cao and Qiang Yang. 2023. FedZKP: Federated model ownership verification with zero-knowledge proof. arXiv:2305.04507 (2023). DOI:10.48550\/arXiv.2305.04507","DOI":"10.48550\/arXiv.2305.04507"},{"key":"e_1_3_1_77_2","doi-asserted-by":"publisher","DOI":"10.23919\/INDIACom54597.2022.9763109"},{"key":"e_1_3_1_78_2","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2019.8737464"},{"key":"e_1_3_1_79_2","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2020.3015777"},{"key":"e_1_3_1_80_2","article-title":"Federated learning for intrusion detection system: Concepts, challenges and future directions","author":"Agrawal Shaashwat","year":"2021","unstructured":"Shaashwat Agrawal, Sagnik Sarkar, Ons Aouedi, Gokul Yenduri, Kandaraj Piamrat, Sweta Bhattacharya, Praveen Reddy, and Thippa Gadekallu. 2021. Federated learning for intrusion detection system: Concepts, challenges and future directions. Computer Communications. Published Online, June 16, 2021.","journal-title":"Computer Communications."}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3687124","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3687124","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:10:21Z","timestamp":1750295421000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3687124"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,10,7]]},"references-count":79,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2025,1,31]]}},"alternative-id":["10.1145\/3687124"],"URL":"https:\/\/doi.org\/10.1145\/3687124","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,10,7]]},"assertion":[{"value":"2023-09-08","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-08-01","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-10-07","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}