Collaborative privacy-preserving network intrusion detection: A federated multi-agent reinforcement learning approach
Amine Tellache, Abdelaziz Amara Korba, Amdjed Mokhtari, Yacine M. Ghamri-Doudane · Computer Communications · 2026
Machine learning has significantly advanced Intrusion Detection Systems in cybersecurity. However, current ML-based IDS solutions often struggle to keep pace with evolving attack patterns and new types of threats, as most models require complete retraining. Additionally, training these models requires large datasets, which are difficult to obtain due to privacy concerns. Moreover, in real-world environments, attacks occur with varying frequencies across organizations, resulting in non-identically distributed (non-IID) data, diminishing detection effectiveness. To address these challenges, we propose a novel Federated Multi-Agent Reinforcement Learning architecture. This architecture consists of a two-level reinforcement learning framework composed of N independent RL agents at the first level, each trained in a federated manner using a class-level FedAvg aggregation scheme to detect a specific attack type, while the second level features a decision agent that aggregates their outputs for final classification. Each RL agent employs an enhanced Deep Q-Network (DQN) incorporating cost-sensitive learning and a weighted mean square loss function to handle class imbalance and adapt to heterogeneous non-IID data. Reinforcement learning enables adaptation to evolving attack patterns, while federated learning addresses data scarcity and privacy concerns. Additionally, the modular design reduces model bias and enables seamless updates in response to new attacks. Experimental results using the CIC-IDS-2017 dataset confirm FMARL’s robustness, adaptability, and efficiency, achieving 99% accuracy across most configurations, maintaining a minimum of 97% accuracy even in extreme non-IID scenarios, with a notably low false positive rate.