FedStackRF: a network intrusion detection framework based on federated and ensemble learning

Zebang Zhang, Xuan Wang, Qiang Yang · IET conference proceedings. · 2025

With the rapid digitalization of society, network intrusion detection has become a critical defense for safeguarding information systems against evolving cyber threats. However, traditional detection methods face significant challenges in handling sophisticated attacks and ensuring data privacy. This paper proposes FedStackRF, a novel framework that combines federated learning with ensemble learning techniques, specifically stacking and Random Forest, to address these challenges. FedStackRF employs a stacking architecture where Random Forest acts as the base model and logistic regression serves as the meta-model. Federated learning is utilized during meta-model training to ensure privacy preservation while effectively handling non-IID data across distributed clients. Experimental results validate the effectiveness of FedStackRF, demonstrating a near-centralized performance with only a marginal AUC difference of 0.0051% compared to the centralized Random Forest model. The framework significantly improves anomaly detection capabilities, achieving an average AUC improvement of 1.53% over local models and a 0.19% improvement over Ensemble Random Forest. Moreover, the framework’s interpretability and low computational cost make it suitable for deployment in resource-constrained edge environments. These findings highlight FedStackRF as a robust and scalable solution for advancing network intrusion detection in privacy-sensitive and distributed scenarios.

Read the paper · More papers on PaperTik