OER·harvester

← Back to the library
arXiv HTML resource

Generative AI and Federated Learning for Intrusion Detection Systems: A Survey

Intrusion Detection Systems (IDSs) are essential for monitoring network traffic and identifying malicious activities in modern cyber-physical, Internet of Things (IoT), enterprise, and distributed network environments. However, developing reliable IDS models remains challenging because attack behaviors evolve over time, realistic datasets are difficult to obtain, traffic records may be incomplete, attack classes are…

Licence
OPEN CC-BY-4.0
Authors
Jiefei Liu, Abu Saleh Md Tayeen, Pratyay Kumar, Qixu Gong, Wenbin Jia…
Published
2026-07-01 · arXiv
Language
en
Length
20383 words
Type
narrative text

Cites 94 works

inferred
Open original ↗

V Conclusion

This survey examined the intersection of generative AI, Federated Learning (FL), and Intrusion Detection Systems (IDSs). We reviewed representative IDS research directions—adversarial machine learning, anomaly-based detection, IoT-oriented IDS, explainable IDS, and benchmark datasets—organized generative AI applications in IDS by four model families (VAEs, GANs, diffusion models, and LLMs) and task objectives, and analyzed how these models are being integrated into FL-based IDS. We now return to the four research questions posed in Section I-A and summarize what the reviewed literature indicates.

RQ1 (How are generative models used to improve IDS?) The reviewed studies show that generative models address IDS along two complementary axes: model family and task objective. VAEs are used primarily for reconstruction-based anomaly detection, latent representation learning, data generation, and augmentation. GANs are most often applied to tabular flow generation, class-imbalance mitigation, data imputation, and, on the offensive side, adversarial traffic generation. Diffusion models are an emerging alternative for synthetic data generation, adversarial purification, and robustness improvement, and tend to offer more stable training than GANs at higher sampling cost. LLMs introduce capabilities the other families lack, including traffic-log analysis, natural-language alert explanation, and knowledge-guided tabular generation. These families also differ in their assumptions: VAEs and GANs operate on fixed feature representations, diffusion models trade computation for stability, and LLMs require traffic to be encoded into model-readable formats. Across all families, the dominant motivation is the same: compensating for limited, imbalanced, incomplete, or non-shareable IDS data.

RQ2 (How reliable is synthetic network traffic for IDS training and evaluation?) The literature indicates that statistical fidelity is necessary but not sufficient. Distribution-level metrics such as KL and JS divergence, Wasserstein distance, FID, and MMD can quantify similarity to real data, but high similarity does not guarantee that generated traffic preserves protocol constraints, temporal dependencies, attack semantics, or network-topology relationships. Several studies report that synthetic data improves some downstream detectors while degrading others, and that low-quality samples can distort decision boundaries. We therefore conclude that synthetic IDS traffic remains only conditionally reliable, and that IDS-specific evaluation—measuring both statistical realism and network-level validity—is still an open requirement rather than a solved problem.

RQ3 (How can generative AI support privacy-preserving and communication-efficient FL-based IDS?) The reviewed FL studies show that generative models can augment local datasets, generate minority-class samples, reduce non-IID skew, and produce privacy-preserving synthetic data without sharing raw traffic. Autoencoder- and VAE-based methods additionally support communication reduction through compact latent representations, and diffusion-based federated methods have shown that high-quality generation can be compatible with reduced communication cost. At the same time, this capability is dual-use: GAN- and diffusion-generated traffic can poison local updates or evade detection, and because the server observes only model updates, such manipulation is harder to detect in FL than in centralized settings. The integration of generative AI into FL-based IDS is thus promising but still early, supported by relatively few primary studies and an open need for robust aggregation and communication-efficient generative sharing.

RQ4 (What datasets and benchmarks are available?) We surveyed widely used IDS datasets (Table II), spanning traditional network intrusion detection, DDoS, IoT, and in-vehicle settings. Most are centrally collected and were not designed to capture client-level heterogeneity, network topology, temporal drift, or organization-specific attack patterns. FLNET2023 is, to our knowledge, the principal dataset that explicitly supports federated evaluation. We therefore conclude that current benchmarks are adequate for centralized generative IDS research but insufficient for federated and topology-aware evaluation, which is one of the most concrete gaps the field faces.

Taken together, these answers point to a small set of priorities for future work. First, more realistic and explicitly federated IDS benchmarks are needed, since artificially partitioned centralized datasets do not reflect real deployment. Second, synthetic traffic generation should become protocol- and topology-aware, and should be evaluated for network-level validity rather than statistical similarity alone. Third, communication-efficient generative FL methods are required so that the cost of sharing generative models does not offset the privacy and efficiency benefits of FL. Fourth, network-domain-specific LLMs, adapted through parameter-efficient tuning and grounded in verified traffic behavior, deserve focused study for IDS data generation, alert explanation, and response recommendation. Finally, because generative models are inherently dual-use, FL-based IDS should be evaluated not only on detection accuracy but also on robustness to adversarial generation, privacy leakage, and communication cost. Building reliable generative AI-enabled IDS will ultimately require combining accurate detection, realistic data generation, privacy preservation, communication efficiency, and security-aware evaluation within a single framework.