Fed fusion-IDS: a privacy-preserving federated intrusion detection system with multi-objective feature optimization and explainable deep learning
Abstract Network Intrusion Detection Systems (NIDS) are vital for protecting cybersecurity infrastructures. The existing intrusion detection methodologies that rely on centralization do not offer privacy protection, cannot protect from zero-day attacks, and lack transparency needed to comply with modern cybersecurity policies. In this work, we present FedFusion-IDS, a new privacy-preserving federated framework for intrusion detection. It is based on federated learning, multi-objective feature selection with NSGA-II and SHAP second-level filter, hybrid deep learning architecture with CNN, BiLSTM, and Attention mechanisms, explainability through SHAP and LIME, and zero-day anomalies detection. We perform a thorough evaluation of FedFusion-IDS on the modern TON_IoT dataset with 10 federated clients for 20 communication rounds. During the multi-objective optimization phase, a Pareto-optimal feature subset is selected to decrease dimensionality while retaining important traffic information. The local clients train a CNN-BiLSTM-Attention model with 962,181 parameters, and parameter aggregation is done with conventional FedAvg and F1-weighted adaptive aggregation techniques. From the experiments performed using TON_IoT dataset, global detection accuracy was found to be 66.26%, F1-score was calculated as 0.6524, and ROC-AUC value exceeds 0.99 for all primary attacks (Normal: 0.999, Backdoor: 1.000, DDoS: 0.997, DoS: 0.700, Password.Dual SHAP and LIME explainability mechanisms deliver fine-grained global feature rankings and instance-level explanations, ensuring compliance with legal transparency requirements such as GDPR Article 22 and the EU AI Act. Furthermore, zero-day anomaly detection simulations confirm that FedFusion-IDS effectively identifies out-of-distribution threats without prior signature training. Together, these results provide a practical blueprint for deploying privacy-preserving, explainable intrusion detection across distributed IoT networks.
Authors
- Sheetal Reddy
- S. V. N. Santhosh Kumar
Publication Details
- Journal
- Scientific Reports
- Published
- 2026-09-16
- DOI
- https://doi.org/10.1038/s41598-026-70386-9
- Primary Topic
- Network Security and Intrusion Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00