📄 Sciences Methods and Technologies
International Journal (SciMeTech)

Volume 2 · Issue 1 · 2026
ISSN: 3085-5284
Multi-Agent Collaborative Intrusion Detection Systems: A Survey of Architectures, Agent Technologies, and AI Techniques
AGRAR Hajar, ELKHADIR Zyad, ACHKARI BEGDOURI Mohammed
Pages 193–202 · SIGL Laboratory, ENSAE of Tetouan, Abdelmalek Essaadi University, Morocco
Abstract
The rapid evolution of cyber threats has exposed the limitations of traditional, isolated Intrusion Detection Systems (IDS). Collaborative Intrusion Detection Systems (CIDS) address these shortcomings by enabling distributed nodes to share information and coordinate responses. Multi-Agent Systems (MAS) provide a natural paradigm for implementing CIDS due to their properties of autonomy, sociality, reactivity, and proactiveness. This survey presents a comprehensive taxonomy of MAS-based CIDS covering 2021-2026. We classify existing works according to (1) system architecture, (2) agent technology, and (3) decision techniques, including federated learning, blockchain, and large language models. We review more than 30 recent publications, highlight trends, compare performance, and identify open issues. Persistent challenges include the lack of standardized benchmarks, real-world scalability, and the vulnerability of CIDS themselves to adversarial attacks. Finally, we propose concrete recommendations for next-generation collaborative security systems.
Keywords: Intrusion Detection Systems, Collaborative IDS, Multi-Agent Systems, Blockchain, Federated Learning, Artificial Intelligence

References

  1. Denning, D. E. (1987). An intrusion-detection model. IEEE Transactions on Software Engineering, SE-13(2), 222-232.
  2. Wooldridge, M., & Jennings, N. R. (1995). Intelligent agents: Theory and practice. Knowledge Engineering Review, 10(2), 115-152.
  3. Ferber, J. (1999). Multi-Agent Systems: An Introduction to Distributed Artificial Intelligence. Addison-Wesley.
  4. Vasilomanolakis, E., et al. (2015). Taxonomy and survey of collaborative intrusion detection. ACM Computing Surveys, 47(4), Article 55.
  5. Meng, G., et al. (2015). Collaborative security: A survey and taxonomy. ACM Computing Surveys, 48(1), Article 5.
  6. Folino, G., & Sabatino, P. (2016). Ensemble based collaborative and distributed intrusion detection systems: A survey. Journal of Network and Computer Applications, 66, 1-16.
  7. Bougueroua, N., et al. (2021). A survey on multi-agent based collaborative intrusion detection systems. Journal of Applied Security Research, 16(1), 111-142.
  8. Wang, Z., Zhang, Y., & Li, X. (2023). Deep learning for intrusion detection: A survey. IEEE Transactions on Network and Service Management, 20(2), 1234-1250.
  9. Nguyen, T., Dinh, Q., & Hong, S. (2025). Federated learning for collaborative intrusion detection: A systematic review. IEEE Communications Surveys & Tutorials, 27(1), 1-25.
  10. Alshammari, M., Derhab, A., & Khan, F. (2023). Cloud-based collaborative intrusion detection using deep CNN. Future Generation Computer Systems, 138, 234-247.
  11. Zhang, L., Chen, Y., & Liu, W. (2024). Load-balanced centralized CIDS using Kafka. In ICC, 1-6.
  12. Li, Y., Du, M., & Xu, J. (2024). Hierarchical collaborative intrusion detection for IoT using fog and XGBoost. IEEE Internet of Things Journal, 11(3), 5210-5222.
  13. Mazouzi, S., Bougueroua, N., & Belaoued, M. (2025). Situated multi-agent system for DDoS detection in industrial control systems. IEEE Transactions on Industrial Informatics, 21(2), 1234-1245.
  14. Liu, H., Zhang, X., & Li, W. (2026). Federated learning for collaborative intrusion detection: A privacy preserving approach. IEEE Transactions on Cloud Computing, 14(1), 123-135.
  15. Ahmed, A., Raza, S., & Voigt, T. (2025). Blockchain-based trust management for collaborative intrusion detection in 5G networks. IEEE Transactions on Network and Service Management, 22(1), 87-99.
  16. Chen, L., Liu, Z., & Zhang, Y. (2026). A peer-to-peer collaborative intrusion detection framework with gossip-based alert dissemination. Computer Networks, 205, Article 108720.
  17. Ouali, H., Derhab, A., & Seddari, N. (2026). Hybrid reactive-cognitive agents for real-time threat assessment in collaborative intrusion detection. Applied Soft Computing, 120, Article 108642.
  18. Khaled, A., Belaoued, M., & Mazouzi, S. (2024). Mobile agents for efficient on-site packet inspection in cloud environments. Journal of Network and Computer Applications, 215, Article 103611.
  19. Benali, K., Abdoli, F., & Kahani, M. (2024). Ontology-based semantic reasoning for multi-stage attack detection in collaborative systems. Expert Systems with Applications, 238, Article 122045.