Netinfo Security ›› 2026, Vol. 26 ›› Issue (6): 944-957.doi: 10.3969/j.issn.1671-1122.2026.06.008

Previous Articles     Next Articles

Deep Active Learning Based Federated Semi-Supervised Intrusion Detection System

ZHANG Hao1,2,3, YE Junwei1,2,3()   

  1. 1 College of Computer and Data Science, Fuzhou University, Fuzhou 350116, China
    2 Fujian Key Laboratory of Network Computing and Intelligent Information Processing, Fuzhou 350116, China
    3 Engineering Research Center of Big Data Intelligence, Chinese Ministry of Education, Fuzhou 350116, China
  • Received:2025-04-15 Online:2026-06-10 Published:2026-07-27
  • Contact: YE Junwei E-mail:xeno73@foxmail.com

Abstract:

With the expansion of network scale, network security issues have become increasingly prominent. Intrusion detection systems face challenges such as high data annotation costs and data transmission delays. Federated learning provides an effective solution for distributed intrusion detection, but it still suffers from the bottleneck of relying on a large amount of labeled data. To reduce annotation costs, active learning is often applied in intrusion detection; however, the query strategies used to select samples for annotation in active learning are often limited by data distribution. This paper proposed a federated semi-supervised intrusion detection system based on deep active learning, combining diversity sampling with a query strategy based on deep model transfer. First, K-Means clustering was used to select diverse samples for annotation. Then, based on transfer learning, a selector was trained using the prediction results of the classifier on the labeled data. The classifier was used for intrusion detection, while the selector was used to identify unlabeled samples that can help improve detection performance for annotation. Finally, the NSL-KDD and UNSW-NB15 datasets selected for experiments. The experimental results show that the proposed scheme reduces the demand for a large amount of labeled data and improves the adaptability of active learning across different data distributions and scenarios.

Key words: network intrusion detection, federated learning, semi-supervisied learning, active learning

CLC Number: