In federated learning-based network intrusion detection systems, model structural heterogeneity and class-imbalanced data distributions often coexist, making it difficult for conventional parameter aggregation or simple knowledge distillation methods to simultaneously achieve high global model performance and strong local adaptability. To address this issue, this study investigates efficient knowledge fusion under heterogeneous federated learning settings and proposes a federated class-wise bidirectional knowledge distillation method for network intrusion detection, termed FedCKD. During the global aggregation stage on the server, a class-wise learnable weight matrix is introduced to perform weighted distillation of client model predictions across different attack categories, enabling fine-grained fusion of heterogeneous model outputs. During the local update stage on the clients, an attention-based distillation mechanism constructed from class-wise F1-scores is employed to enhance feature learning for minority and hard-to-classify classes under the guidance of the global model, thereby alleviating the impact of class imbalance on model performance. Experimental results on the public CICIDS2017 and CIDDS-001 network intrusion detection datasets show that, compared with FedAvg, FedMD, FedHe, and HFedCKD, FedCKD improves the macro-average F1-score of the global model by approximately 0.012 to 0.045, and increases the F1-score of minority attack classes in local client models by approximately 0.030 to 0.086, while maintaining stable convergence behavior and acceptable computational overhead. The results indicate that FedCKD enables effective modeling of multi-class attacks in heterogeneous federated learning environments without requiring unified model architectures, and is applicable to network intrusion detection tasks characterized by model heterogeneity and class imbalance.
XUJiuqiang, ZHOUYangyang, WANGJinfa, et al. Anomaly detection of network traffic based on flow time influence domain[J]. Journal of Northeastern University(Natural Science), 2019, 40(1): 26-31.(in Chinese)
[7]
YEM, FANGX W, DUB, et al. Heterogeneous federated learning: State-of-the-art and research challenges[J]. ACM Computing Surveys, 2024, 56(3): 1-44.
[8]
ZHANGL, SHENL, DINGL, et al. Fine-tuning Global Model Via Data-Free Knowledge Distillation For Non-Iid Federated Learning[C]//2022 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), 2022: 10164-10173.
[9]
MCMAHANH B, MOOREE, RAMAGED, et al. Communication-efficient learning of deep networks from decentralized data[C]//20th International Conference on Artificial Intelligence and Statistics, 2017: 1273-1282.
[10]
BAGUIS, LIK Q. Resampling imbalanced data for network intrusion detection datasets[J]. Journal of Big Data, 2021, 8(1): 6.
[11]
LID L, WANGJ P. FedMD: Heterogeneous federated learning via model distillation[DB/OL].(2019-10-08)[2025-08-22].
[12]
QIP H, ZHOUX Y, DINGY L, et al. FedBKD: Heterogeneous federated learning via bidirectional knowledge distillation for modulation classification in IoT-edge system[J]. IEEE Journal of Selected Topics in Signal Processing, 2023, 17(1): 189-204.
[13]
ZHENGY T, LINB H, CHENJ Q, et al. HFedCKD: Toward robust heterogeneous federated learning via data-free knowledge distillation and two-way contrast[DB/OL].(2025-03-09)[2025-08-22].
[14]
CHANY H, NGAIE C H. FedHe: Heterogeneous Models and Communication Efficient Federated Learning [C]//17th International Conference on Mobility, Sensing and Networking (MSN), 2021: 207-214.
[15]
YAOD Z, PANW N, DAIY T, et al. FedGKD: Toward heterogeneous federated learning via global knowledge distillation[J]. IEEE Transactions on Computers, 2024, 73(1): 3-17.
[16]
HANJ G, SHANC F, ZHANGJ Q. FedGMKD: An efficient prototype federated learning framework through knowledge distillation and discrepancy-aware aggregation[J]. Advances in Neural Information Processing Systems, 2024, 37: 118326-118356.
[17]
WUC H, WUF Z, LÜL J, et al. Communication-efficient federated learning via knowledge distillation[J]. Nature Communications, 2022, 13(1): 2032.
[18]
HUC H, CHENZ, LARSSONE G. Scheduling and aggregation design for asynchronous federated learning over wireless networks[J]. IEEE Journal on Selected Areas in Communications, 2023, 41(4): 874-886.