Decoding the Enigma of Collaborative Intrusion Detection Systems: Ensemble Learning vs Federated Learning in the Battle for Collaborative Anomaly Detection Supremacy
Abstract
Coordinated attacks, such as large-scale scanning, worm outbreaks, and Distributed Denial of Service (DDoS) attacks, exhibit distributed cyberattack characteristics that make them challenging to detect with standalone Intrusion Detection Systems (IDS). Collaborative Intrusion Detection Systems (CIDS) address this limitation by aggregating data from multiple network sources and leveraging collective intelligence for anomaly detection, making them more effective in identifying coordinated attacks. CIDS system employs Ensemble Learning (EL) or Federated Learning (FL) to build robust collaborative anomaly detection. EL enhances detection by integrating predictions from multiple models, while FL enables model aggregation from multiple models and preserves privacy. This research examines the comparative effectiveness of EL and FL within CIDS for robust detection of coordinated attacks in heterogeneous network environments. Benchmarking results reveal that network heterogeneity significantly influences detection model performance. Furthermore, this study provides key insights and lessons learned from the comparative analysis, offering a foundation for future research on cyberattack detection using collaborative anomaly detection methods in CIDS.