PofoliaShared via Pofolia

Scientific Reports· 2026Q1

Privacy-preserving intrusion detection in mobile edge networks via federated adaptive probabilistic stacking with clan–flock optimisation and explainable AI

Joshitha N., P. Deepanramkumar, A. Helen Sharmila

Short summary

A novel federated intrusion detection system (FedAPS-CFO) achieves F1-scores up to 0.998 across four benchmark datasets (NSL-KDD, UNSW-NB15, CICIDS2017, CIC-IoT2023) while preserving data privacy and providing interpretability.

AI-generated from the title and abstract; the full text is not read.

Key points

  • FedAPS-CFO achieves high F1-scores (0.951-0.998) on NSL-KDD, UNSW-NB15, CICIDS2017, and CIC-IoT2023 datasets.
  • The system uses federated averaging to keep raw traffic local, enhancing privacy.
  • An Adaptive Probabilistic Stacking ensemble fuses multiple models for robust detection.
  • Clan-Flock Optimisation tunes fusion weights and thresholds, proving reliable for heterogeneous data.
  • Explainable AI (SHAP/LIME) is integrated and validated for interpretability.

AI-generated from the title and abstract; the full text is not read.

Abstract

Mobile edge networks require intrusion detection systems (IDS) that are private, accurate and interpretable. We present FedAPS–CFO, a federated IDS coupling four mechanisms: prediction-level federated averaging (FedAvg), so raw traffic never leaves the edge; an Adaptive Probabilistic Stacking (APS) ensemble fusing a stacking meta-learner, Bayesian model averaging and a feature-conditioned ensemble; Clan–Flock Optimisation (CFO), a hybrid metaheuristic that tunes the fusion weights and decision threshold on inner validation splits; and SHapley Additive exPlanations (SHAP) with Local Interpretable Model-agnostic Explanations (LIME), validated quantitatively for stability, fidelity and faithfulness. Under stratified 10-fold cross-validation, FedAPS–CFO attains F1-scores of 0.997 on NSL-KDD, 0.951 on UNSW-NB15, 0.979 on CICIDS2017 and 0.998 on CIC-IoT2023, matching the strongest constituent ensemble on every dataset and significantly surpassing the remaining components (Wilcoxon signed-rank, Holm-corrected). In federations of up to 100 clients with Dirichlet label skew, FedAPS–CFO sustains detection within 1.2 F1 points of its ideal operating point — up to 46 points above its federated base learners — showing that the trained fusion absorbs client heterogeneity. Under matched budgets, CFO is the most reliable optimiser for the tuning task. Adaptive posterior fusion thus offers a practical route to accurate, interpretable, privacy-preserving intrusion detection at the network edge.

The authors' abstract, as published at the source. Scientific Reports, 2026 · DOI ↗

TakeawaysPremium
Ask the paperFree account

Continue with a free account

Ask the paper: 3 free questions a day about this paper; save it, get its citation, new summaries every day for your field. Takeaways are Premium.

Continue free on the web

Sign in with Google or Apple; no card needed. You come back to this paper.

On your phone:

Field: Computer Networks and Communications

Computer Networks and CommunicationsComputer Science