I Introduction
Modern computer networks support a wide range of critical services, including cloud computing, Internet of Things (IoT) platforms, industrial control systems, intelligent transportation, financial systems, healthcare infrastructure, and defense applications. As these systems become increasingly connected, they also become more exposed to cyber attacks that can disrupt services, compromise sensitive data, or damage physical infrastructure. Intrusion Detection Systems (IDSs) are therefore an essential component of network security. An IDS monitors system activities or network traffic and identifies behaviors that may indicate unauthorized access, malware propagation, denial-of-service attacks, data exfiltration, or other malicious activities. Early IDS research established the foundation for monitoring security-relevant events and detecting abnormal system behaviors [1, 2]. Since then, IDS techniques have evolved from rule-based and signature-based detection toward data-driven approaches based on machine learning (ML) and deep learning (DL). ML-based IDS models can learn complex traffic patterns from historical data and have shown strong performance in both binary attack detection and multi-class attack classification. However, their effectiveness strongly depends on the availability, quality, diversity, and representativeness of training data. In practice, network intrusion datasets are often limited, imbalanced, incomplete, outdated, or collected from restricted environments that do not fully reflect real-world network conditions.
Generative artificial intelligence (AI) provides a promising direction for addressing these data-related limitations. Generative models learn the underlying distribution or structure of observed data and can produce new samples that resemble the original data. In the IDS domain, generative models have been used for synthetic traffic generation, data augmentation, missing-value imputation, anomaly detection, adversarial traffic generation, and explanation of IDS alerts. Representative generative techniques include autoencoders and variational autoencoders, generative adversarial networks, diffusion models, and large language models. These methods offer new opportunities to improve IDS robustness, especially when real attack samples are scarce, minority classes are underrepresented, or data collection is expensive.
At the same time, the deployment of IDS models faces increasing privacy and communication constraints. Traditional centralized IDS training requires collecting network traffic from distributed clients or organizations and transferring it to a central server. This strategy can expose sensitive information and is often impractical for privacy-sensitive environments. Federated Learning (FL) addresses this issue by allowing clients to train models locally and share only model updates with a central server [3]. For IDS, FL is particularly attractive because network traffic is naturally distributed across devices, routers, organizations, and geographic regions. However, FL-based IDS also introduces new challenges, including non-independent and identically distributed (non-IID) client data, communication overhead, client heterogeneity, poisoning attacks, and limited access to realistic FL-based IDS benchmarks.
Although IDS, generative AI, and FL have each been studied extensively, their intersection remains fragmented. Existing studies often focus on a specific model family, a single IDS task, or an isolated FL setting. A systematic review is needed to clarify how generative models are used in IDS, how they can support FL-based IDS, and what technical challenges remain unresolved. Motivated by this need, this survey reviews recent progress in generative AI for IDS and generative AI-embedded FL-based IDS. We organize the literature by IDS research problems, generative model families, application objectives, and FL integration strategies, and we further discuss open challenges and future research directions for building reliable, privacy-preserving, and data-efficient IDS models.
I-A Research Problems
Although IDS has been widely studied, the integration of generative AI and Federated Learning (FL) introduces several open research problems that remain scattered across the literature. This survey focuses on the following questions.
RQ1: How are generative models used to improve IDS? Generative models have been applied to IDS for multiple purposes, including anomaly detection, synthetic traffic generation, data augmentation, data imputation, adversarial traffic generation, and alert explanation. However, these applications are often studied independently. A systematic review is needed to clarify which generative model families are used, what IDS problems they address, and how their assumptions differ.
RQ2: How reliable is synthetic network traffic for IDS training and evaluation? Synthetic data can mitigate limited data availability, class imbalance, and missing records. However, high statistical similarity to real data does not necessarily guarantee realistic network behavior. In IDS, generated traffic should also preserve protocol constraints, temporal dependencies, attack semantics, and network-topology relationships. Therefore, evaluating the quality, usefulness, and realism of synthetic IDS data remains a key challenge.
RQ3: How can generative AI support privacy-preserving and communication-efficient FL-based IDS? FL allows distributed clients to train IDS models without directly sharing raw traffic data. However, FL-based IDS faces non-IID client distributions, communication overhead, client heterogeneity, and vulnerability to poisoning attacks. Generative AI can potentially address these issues by augmenting local data, improving minority-class representation, reducing data heterogeneity, or generating privacy-preserving synthetic samples. The effective integration of generative models into FL-based IDS is still an emerging research direction.
RQ4: What datasets and benchmarks are available for evaluating IDS, generative IDS, and FL-based IDS? Reliable evaluation depends on realistic and representative datasets. However, real network traffic is often sensitive and difficult to release publicly. Existing IDS datasets are useful but may be outdated, centrally collected, or insufficient for evaluating federated and generative settings. This survey therefore summarizes commonly used IDS datasets and discusses the need for more realistic benchmarks for generative AI and FL-based IDS.
Based on these research problems, this survey reviews IDS background studies, categorizes generative AI techniques for IDS, summarizes existing IDS datasets, and discusses emerging directions in generative AI-embedded FL-based IDS.
| Section I Introduction | |
|---|---|
| Section I-A Research problems | |
| Section I-B Contributions | |
| Table I Structure of our survey | |
| Section II Intrusion detection systems | |
| Section II-A Adversarial Machine Learning for IDS | |
| Section II-B Anomaly-based IDS | |
| Section II-C IDS for IoT | |
| Section II-D Explainable IDS (X-IDS) | |
| Section II-E Datasets for IDS | |
| Section III Generative models | |
| Section III-A Variational Autoencoder | |
| Section III-B GAN in IDS | |
| Section III-C Diffusion in IDS | |
| Section III-D LLM in IDS | |
| Section IV Generative AI Embedded Federated Learning based Intrusion Detection System | |
| Section IV-A VAE embedded FL-IDS | |
| Section IV-B GAN embedded FL-IDS | |
| Section IV-C Diffusion embedded FL-IDS | |
| Section IV-D LLM embedded FL-IDS | |
| Section V Conclusion |
TABLE I: Structure of this survey
I-B Contributions
The main contributions of this survey are summarized as follows:
- We provide a structured review of IDS research from the perspective of data-driven security modeling, covering representative directions including adversarial machine learning for IDS, anomaly-based IDS, IoT-oriented IDS, explainable IDS, and IDS benchmark datasets. This background establishes the technical context for understanding why generative AI and Federated Learning (FL) are increasingly important for modern IDS development.
- We present a taxonomy of generative AI applications in IDS by organizing existing studies according to both model family and task objective. Specifically, we review autoencoder-based models, Generative Adversarial Networks (GANs), diffusion models, and Large Language Models (LLMs), and analyze how they are used for anomaly detection, synthetic traffic generation, data augmentation, data imputation, adversarial traffic generation, and IDS alert explanation.
- We systematically examine the emerging intersection of generative AI and FL-based IDS. Different from conventional IDS surveys that study centralized detection models, this survey highlights how generative models can support privacy-preserving and distributed IDS training by addressing non-IID client data, class imbalance, communication cost, adversarial robustness, and limited local data availability.
- We summarize commonly used IDS datasets and FL-oriented IDS datasets, emphasizing their roles, limitations, and suitability for evaluating generative AI and FL-based IDS. This dataset-level discussion helps clarify current benchmark gaps, especially the shortage of realistic, topology-aware, and federated IDS datasets.
- We identify open challenges and future research directions for generative AI-enabled IDS, including synthetic data reliability, realistic network traffic generation, evaluation of generated samples, privacy-preserving data augmentation, communication-efficient generative FL, and domain-specific LLMs for network security.
I-C Survey Methodology
To assemble the literature reviewed in this survey, we conducted a keyword-based search across Google Scholar and DBLP, supplemented by manual inspection of recent proceedings and articles from major security, networking, and machine learning venues. Our search combined two sets of terms: generative-model keywords (generative AI, VAE, variational autoencoder, GAN, diffusion model, large language model, LLM) and application keywords (intrusion detection, IDS, network security, federated learning, anomaly detection, synthetic traffic, data augmentation). Candidate papers were then selected primarily by relevance rather than by a fixed time window: a study was included if it applied a generative model family to an IDS task, integrated generative models with FL-based IDS, or provided foundational background (e.g., seminal generative architectures, IDS datasets, or evaluation metrics) needed to interpret these works. We excluded papers that used generative models in unrelated domains without transferable methodology and those that did not provide enough methodological detail to assess. Because generative AI is a fast-moving field, the large majority of the application-oriented studies we review were published within roughly the last five to seven years, while a smaller set of older references is retained to establish the technical lineage of each model family (for example, the original VAE, GAN, and diffusion formulations) and the early foundations of intrusion detection. This relevance-driven strategy lets the survey track current practice while preserving the conceptual context required to compare model families and identify open challenges.
Following this methodology, the remainder of this survey is organized as shown in Table I. Section II first provides the background of IDS by reviewing representative research directions, including adversarial machine learning, anomaly-based detection, IoT-oriented IDS, explainable IDS, and commonly used IDS datasets. Section III then reviews generative AI techniques for IDS and categorizes existing studies by model family, including Variational Autoencoders (VAEs), Generative Adversarial Networks (GANs), diffusion models, and Large Language Models (LLMs). Section IV further discusses the integration of generative AI with Federated Learning (FL)-based IDS, focusing on how different generative models can support distributed, privacy-preserving, and data-efficient IDS training. Finally, Section V concludes the survey and summarizes future research opportunities.