2. Hybrid ML/DL models: These architectures combine feature selection with deep networks to obtain higher
performance in anomaly detection in the network.
[10,12]
3. Feature learning from raw inputs using deep models reduces dependency on hand-crafted features, thus
enhancing the system's capability to detect unseen attacks.
[3,6,10,16]
3.3 Federated learning-based IDS
In the last few years, FL has emerged as a methodology for addressing privacy concerns and data silos in
distributed IoT and vehicular networks. The IDS based on FL allows collaborative model training without
transmitting raw traffic logs, as shown in [4,5,12,14]. Applications involve intrusion detection in IoT
environments and the detection of DDoS attacks while Non-IID data distributions are handled efficiently with
reduced communication overhead, as discussed in [5,12,14]. FL has also been combined with deep learning in
hybrid federated architectures for fault detection while ensuring data privacy, as discussed in [4,6,12]. In
summary, FL is a significant step forward toward the realization of distributed, privacy-preserving, and scalable
IDS architectures, as also shown in [4,5,12,14].
3.4 Adversarial Robust IDS
Adversarial robustness is a major concern for machine learning and deep learning-based IDS, which are
continually confronted by evasion and poisoning attacks. Various recent works emphasize robust, autoencoder-
based IDS approaches to detect manipulated traffic patterns.
[2,3,5,15]
Research on adversarial attacks on vehicular
networks and IoT IDS provides beneficial insights into the development of robust models.
[2,11,13]
Further,
adversary sample generation methodologies are discussed for various techniques, such as image augmentation,
filtering, and patching, while practical implications are considered in different case studies, for example, disease
prediction using a prototype chest X-ray imaging system.
[13,14,16]
The shift toward adversarial robustness
supports the performance of IDS, which remains effective under sophisticated and intelligent attack
scenarios.
[2,3,5,15]
3.5 Lightweight IDS for resource-constrained environments
With the proliferation of IoT, unmanned aerial systems, and edge computing infrastructures, there is an
emerging demand for lightweight IDS solutions that would be easily embeddable into resource-constrained
devices. Knowledge distillation and model pruning are common methods to reduce computational and memory
burdens with minimal degradation in detection performance.
[7,9]
Adopting lightweight architectures allows for
real-time threat detection, which can be easily deployed on devices characterized by poor CPU power, memory,
or energy supply.
[7,10]
If combined, these techniques enable scalable and energy-efficient IDS deployment in
heterogeneous networked environments.
[1,7,9,10]
3.6 Explainable AI in IDS
Explainable AI addresses the opaque nature of deep learningbased intrusion detection systems. Feature
selection methods combined with interpretability techniques like SHAP and LIME provide more understandable
explanations of system decisions to network operators. Integration of XAI has been decisive in pushing the
deployment of IDSs in real-world scenarios due to its capacity to help analysts understand why certain instances
of traffic are classified as malicious. XAI is of particular importance when deep learning and federated learning-
based IDS are used in safety critical infrastructures. Finally, the evolution of IDS can be summarized into five
important and somewhat overlapping trends.
[2-16]
Fig. 3 illustrates the projected development of key research
trends in IDS from 2021 to 2025. The plot of relative importance over time reflects the increasing focus of
researchers on various IDS approaches. Deep learning and hybrid approach also stay important, rising from
about 40 in 2021 to over 85 in 2025. This trend indicates the increased reliance of IDS on end-to-end learning
for complex and high-dimensional network traffic problems.
[3-7, 10,12,16]
Federated or privacy-preserving learning
also shows a progressive climb from around 20 in 2021 to roughly 80 in 2025, corresponding to the growing
interest in decentralized IDS with sensitive data protection.
[4,5,12,14]
Adversarial robustness also continuously
rises and reaches about 65 by 2025, indicating an improvement in the robustness of IDSs in resisting evasion
and poisoning attacks.
[2,5,11,13-15]
Lightweight or IoT-focused solutions have a remarkable surge between 2023 and
2024, driven by growing interests in computationally efficient IDS targeting resource-constrained devices, such
as IoT or UAV systems.
[1,7,9,10]
Explainability or XAI starts low, speeding up and almost catching up with other
trends in 2025, reflecting the recent importance of interpretability and operator trust of real-world
deployments.
[8,10,11,16]
These trends are further supported by key references summarized in Table 1, which links
each research direction with representative studies and notable works. For instance, Deep Learning is explored
in [3-7,10,12,16], whereas federated learning approaches can be found in [4,5,12,14]. These trends show a
progressive convergence toward distributed, interpretable, efficient, and robust IDS architectures suitable for
next generation networks.