Fed fusion-IDS: a privacy-preserving federated intrusion detection system with multi-objective feature optimization and explainable deep learning

Abstract Network Intrusion Detection Systems (NIDS) are vital for protecting cybersecurity infrastructures. The existing intrusion detection methodologies that rely on centralization do not offer privacy protection, cannot protect from zero-day attacks, and lack transparency needed to comply with modern cybersecurity policies. In this work, we present FedFusion-IDS, a new privacy-preserving federated framework for intrusion detection. It is based on federated learning, multi-objective feature selection with NSGA-II and SHAP second-level filter, hybrid deep learning architecture with CNN, BiLSTM, and Attention mechanisms, explainability through SHAP and LIME, and zero-day anomalies detection. We perform a thorough evaluation of FedFusion-IDS on the modern TON_IoT dataset with 10 federated clients for 20 communication rounds. During the multi-objective optimization phase, a Pareto-optimal feature subset is selected to decrease dimensionality while retaining important traffic information. The local clients train a CNN-BiLSTM-Attention model with 962,181 parameters, and parameter aggregation is done with conventional FedAvg and F1-weighted adaptive aggregation techniques. From the experiments performed using TON_IoT dataset, global detection accuracy was found to be 66.26%, F1-score was calculated as 0.6524, and ROC-AUC value exceeds 0.99 for all primary attacks (Normal: 0.999, Backdoor: 1.000, DDoS: 0.997, DoS: 0.700, Password.Dual SHAP and LIME explainability mechanisms deliver fine-grained global feature rankings and instance-level explanations, ensuring compliance with legal transparency requirements such as GDPR Article 22 and the EU AI Act. Furthermore, zero-day anomaly detection simulations confirm that FedFusion-IDS effectively identifies out-of-distribution threats without prior signature training. Together, these results provide a practical blueprint for deploying privacy-preserving, explainable intrusion detection across distributed IoT networks.

Authors

Publication Details

Journal
Scientific Reports
Published
2026-09-16
DOI
https://doi.org/10.1038/s41598-026-70386-9
Primary Topic
Network Security and Intrusion Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Fed fusion-IDS: a privacy-preserving federated intrusion detection system with multi-objective feature optimization and explainable deep learning

Sheetal Reddy, S. V. N. Santhosh Kumar
Scientific Reports
Network Security and Intrusion Detection
article

Fed fusion-IDS: a privacy-preserving federated intrusion detection system with multi-objective feature optimization and explainable deep learning

Sheetal Reddy, S. V. N. Santhosh Kumar
article en

Abstract

Abstract Network Intrusion Detection Systems (NIDS) are vital for protecting cybersecurity infrastructures. The existing intrusion detection methodologies that rely on centralization do not offer privacy protection, cannot protect from zero-day attacks, and lack transparency needed to comply with modern cybersecurity policies. In this work, we present FedFusion-IDS, a new privacy-preserving federated framework for intrusion detection. It is based on federated learning, multi-objective feature selection with NSGA-II and SHAP second-level filter, hybrid deep learning architecture with CNN, BiLSTM, and Attention mechanisms, explainability through SHAP and LIME, and zero-day anomalies detection. We perform a thorough evaluation of FedFusion-IDS on the modern TON_IoT dataset with 10 federated clients for 20 communication rounds. During the multi-objective optimization phase, a Pareto-optimal feature subset is selected to decrease dimensionality while retaining important traffic information. The local clients train a CNN-BiLSTM-Attention model with 962,181 parameters, and parameter aggregation is done with conventional FedAvg and F1-weighted adaptive aggregation techniques. From the experiments performed using TON_IoT dataset, global detection accuracy was found to be 66.26%, F1-score was calculated as 0.6524, and ROC-AUC value exceeds 0.99 for all primary attacks (Normal: 0.999, Backdoor: 1.000, DDoS: 0.997, DoS: 0.700, Password.Dual SHAP and LIME explainability mechanisms deliver fine-grained global feature rankings and instance-level explanations, ensuring compliance with legal transparency requirements such as GDPR Article 22 and the EU AI Act. Furthermore, zero-day anomaly detection simulations confirm that FedFusion-IDS effectively identifies out-of-distribution threats without prior signature training. Together, these results provide a practical blueprint for deploying privacy-preserving, explainable intrusion detection across distributed IoT networks.

Scientific Reports
Openalex Percentile: Top 8%
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Fed fusion-IDS: a privacy-preserving federated intrusion detection system with multi-objective feature optimization and explainable deep learning — Sheetal Reddy, S. V. N. Santhosh Kumar · Scientific Reports (2026) | TGRS Research Map | TGRS