A Federated Heterogeneous Ensemble Framework for Detecting Low-Rate Distributed Denial-of-Service Attacks

Authors

  • Rikie Kartadie Department of Computer Engineering, Universitas Teknologi Digital Indonesia, Yogyakarta, Indonesia https://orcid.org/0000-0003-1947-353X
  • Danny Kriestanto Department of Informatics Engineering, Universitas Teknologi Digital Indonesia, Yogyakarta, Indonesia https://orcid.org/0009-0009-0480-1132
  • Yagus Cahyadi Department Master of Information Technology, Universitas Teknologi Digital Indonesia, Yogyakarta, Indonesia https://orcid.org/0009-0001-4406-4642

DOI:

https://doi.org/10.5753/jbcs.2026.7824

Keywords:

Federated Learning, Low-Rate Distributed Denial-of-Service Detection, Heterogeneous Model Ensemble, Network Intrusion Detection Systems, Non-IID Data in Distributed Networks

Abstract

Detecting low-rate distributed denial-of-service (LR-DDoS) attacks remains challenging because their traffic profiles closely resemble legitimate network activity, making them difficult to identify using conventional intrusion detection systems. This study proposes a federated heterogeneous ensemble framework for LR-DDoS detection under non-IID data conditions. Five local classifiers, Logistic Regression, Random Forest, SVM, Gradient Boosting, and MLP, are trained on locally partitioned datasets generated through Dirichlet-based distribution, and their probabilistic outputs are combined via a softmax-weighted aggregation mechanism. Experiments using the CICDDoS2019 dataset with a 70/15/15 train-validation-test split and results averaged over 10 independent seeds show that local model accuracy ranges from 0.664 to 0.917 under non-IID conditions. The proposed federated ensemble achieves a mean accuracy of 0.925 0.008 and F1-score of 0.910 0.009, outperforming all individual models and two alternative aggregation strategies. These results indicate that combining heterogeneous model architectures with adaptive prediction-level aggregation improves detection robustness in distributed intrusion detection systems

Downloads

Download data is not yet available.

References

Allouah, Y., Dhasade, A., Guerraoui, R., Gupta, N., Kermarrec, A.-M., Pinot, R., Pires, R., and Sharma, R. (2024). Revisiting ensembling in one-shot federated learning. arXiv preprint. DOI: 10.48550/arXiv.2411.07182.

Daalen, F., Ippel, L., Dekker, A., and Bermejo, I. (2022). Federated ensembles: a literature review. Research Square. DOI: 10.21203/rs.3.rs-2350540/v1.

Doriguzzi-Corin, R., Sabel, P., Cretti, S., and Ranise, S. (2025). Federated learning in the wild: A comparative study for cybersecurity under non-IID and unbalanced settings. arXiv preprint. DOI: 10.48550/arXiv.2509.17836.

G, D. M. J. et al. (2024). Non-IID data in federated learning: A survey with taxonomy, metrics, methods, frameworks and future directions. arXiv preprint. DOI: 10.48550/arxiv.2411.12377.

Han, J., Kamber, M., and Pei, J. (2011). Data Mining: Concepts and Techniques. Morgan Kaufmann, 3rd edition. DOI: 10.5860/choice.49-3305.

Hsu, T.-M. H., Qi, H., and Brown, M. (2019). Measuring the effects of non-identical data distribution for federated visual classification. arXiv preprint arXiv:1909.06335. DOI: 10.48550/arxiv.1909.06335.

Konečný, J., McMahan, H. B., Yu, F. X., Richtárik, P., Suresh, A. T., and Bacon, D. (2016). Federated learning: Strategies for improving communication efficiency. arXiv preprint. DOI: 10.48550/arXiv.1610.05492.

Lavaur, L., Costé, B., Pahl, M.-O., Busnel, Y., and Autrel, F. (2022). Federated learning as enabler for collaborative security between not fully-trusting distributed parties. Available at:[link].

Lin, T., Kong, L., Stich, S. U., and Jaggi, M. (2020). Ensemble distillation for robust model fusion in federated learning. Available at arXiv:2006.07242. DOI: 10.48550/arxiv.2006.07242.

Luo, X., Chang, R. K., et al. (2005). On a new class of pulsing denial-of-service attacks and the defense. In NDSS. Available at:[link].

McMahan, H. B., Moore, E., Ramage, D., Hampson, S., and Arcas, B. A. Y. (2016). Communication-efficient learning of deep networks from decentralized data. arXiv preprint. DOI: 10.48550/arXiv.1602.05629.

Pedregosa, F., Varoquaux, G., Gramfort, A., Michel, V., Thirion, B., Grisel, O., Blondel, M., Prettenhofer, P., Weiss, R., Dubourg, V., Vanderplas, J., Passos, A., Cournapeau, D., Brucher, M., Perrot, M., and Duchesnay, E. (2011). Scikit-learn: Machine learning in Python. Journal of Machine Learning Research, 12:2825-2830. DOI: 10.48550/arxiv.1201.0490.

Sharafaldin, I., Lashkari, A. H., Hakak, S., and Ghorbani, A. A. (2019). Developing realistic distributed denial of service (ddos) attack dataset and taxonomy. In 2019 International Carnahan Conference on Security Technology (ICCST), pages 1-8. DOI: 10.1109/CCST.2019.8888419.

Shevtekar, A., Anantharam, K., and Ansari, N. (2005). Low rate tcp denial-of-service attack detection at edge routers. IEEE Communications Letters, 9(4):363-365. DOI: 10.1109/lcomm.2005.1413635.

Talukder, M. A. et al. (2024). Machine learning-based network intrusion detection for big and imbalanced data using oversampling, stacking feature embedding and feature extraction. Journal of Big Data, 11(1). DOI: 10.1186/s40537-024-00886-w.

Yurochkin, M., Agarwal, M., Ghosh, S., Greenewald, K., Hoang, N., and Khazaeni, Y. (2019). Bayesian nonparametric federated learning of neural networks. In International Conference on Machine Learning (ICML), pages 7252-7261. PMLR. DOI: 10.48550/arxiv.1905.12022.

Zaidi, S. A. N. (2024). Mitigating DDoS attacks on IoT networks: Strategies and solutions. International Journal for Research in Applied Science and Engineering Technology, 12(6):1387-1394. DOI: 10.22214/ijraset.2024.63246.

Zhu, H., Xu, J., Liu, S., and Jin, Y. (2021). Federated learning on non-IID data: A survey. Neurocomputing, 465:371-390. DOI: 10.1016/j.neucom.2021.07.098.

Downloads

Published

2026-09-01

How to Cite

Kartadie, R., Kriestanto, D., & Cahyadi, Y. (2026). A Federated Heterogeneous Ensemble Framework for Detecting Low-Rate Distributed Denial-of-Service Attacks. Journal of the Brazilian Computer Society, 32(1), 2242–2251. https://doi.org/10.5753/jbcs.2026.7824

Issue

Section

Regular Issue