Multi-Agent Collaborative Intrusion Detection Systems: A Survey of Architectures, Agent Technologies, and AI Techniques
AGRAR Hajar, ELKHADIR Zyad, ACHKARI BEGDOURI Mohammed
Pages 193–202 · SIGL Laboratory, ENSAE of Tetouan, Abdelmalek Essaadi University, Morocco
Abstract
The rapid evolution of cyber threats has exposed the limitations of traditional, isolated Intrusion Detection Systems (IDS). Collaborative Intrusion Detection Systems (CIDS) address these shortcomings by enabling distributed nodes to share information and coordinate responses. Multi-Agent Systems (MAS) provide a natural paradigm for implementing CIDS due to their properties of autonomy, sociality, reactivity, and proactiveness. This survey presents a comprehensive taxonomy of MAS-based CIDS covering 2021-2026. We classify existing works according to (1) system architecture, (2) agent technology, and (3) decision techniques, including federated learning, blockchain, and large language models. We review more than 30 recent publications, highlight trends, compare performance, and identify open issues. Persistent challenges include the lack of standardized benchmarks, real-world scalability, and the vulnerability of CIDS themselves to adversarial attacks. Finally, we propose concrete recommendations for next-generation collaborative security systems.
Keywords: Intrusion Detection Systems, Collaborative IDS, Multi-Agent Systems, Blockchain, Federated Learning, Artificial Intelligence