Research Article

Continual Federated Learning for Network Intrusion Detection: An Open-Index Systematic Map

Authors

  • Daryoosh Mansoory MSc – Master of Science in Computer Science, Department of Information Technology, Faculty of Computer Science, Herat University, Herat, Afghanistan
  • Ahmad Wali Noori MSc – Master of Science in Computer Engineering- Software, Faculty of Education, Farah University, Farah, Afghanistan
  • Mohammad Peeroz Qaderi MSc – Master of Science in Computer Science- Computer Networks, Faculty of Education, Farah University, Farah, Afghanistan

Abstract

Purpose: Continual federated learning (FCL) combines decentralized model updating with sequential adaptation, but network-intrusion studies use incompatible definitions of drift, retention, and evaluation. This open-index systematic map examines how such systems operationalize non-stationarity, preserve earlier knowledge, and report empirical and reproducibility evidence. Method: Eight queries were executed in OpenAlex, Crossref, and DBLP on 26 July 2026. The interfaces returned 8,819 records within documented result limits; deduplication left 3,075 unique records. The initial concept-block rule excluded 2,865 records. A rule-based sensitivity audit reclassified two false negatives, yielding 2,863 automatic exclusions and 212 records for title/abstract screening. Thirty-one database-derived and nine supplementary reports were sought; 24 were not retrieved. Sixteen full texts were assessed, two were excluded, and 14 primary studies were mapped. Results: The corpus comprised three studies from 2023, six from 2024, one from 2025, and four from the partial 2026 search year. Nine studies tested retention after later tasks or classes; five reported adaptation without a prior-task retention outcome. Within the nine retention-tested studies, replay-based designs most often reported favorable within-study stability results, but heterogeneous scenarios and comparators do not establish cross-study superiority. Only two studies reported standardized forgetting or backward transfer, two supplied study-specific code, and one tested malicious clients. Conclusion: The accessible open-index evidence supports FCL as a prototype strategy under constructed benchmark sequences. It does not establish cross-network robustness, formal privacy, or deployment-scale reliability. A targeted supplementary update on 27 July 2026 found no additional eligible, accessible full text. Interpretation is constrained by capped interfaces, single-reviewer screening, and 24 unretrieved reports.

Article information

Journal

Journal of Computer Science and Technology Studies

Volume (Issue)

8 (8)

Pages

364-386

Published

2026-08-15

How to Cite

Daryoosh Mansoory, Noori, A. W., & Mohammad Peeroz Qaderi. (2026). Continual Federated Learning for Network Intrusion Detection: An Open-Index Systematic Map. Journal of Computer Science and Technology Studies, 8(8), 364-386. https://doi.org/10.32996/jcsts.2026.8.8.27

Publication History

  1. Submitted
  2. Published

Peer Review

This article has been peer reviewed.

Downloads

Views

49

Downloads

27

Keywords:

continual federated learning; network intrusion detection; concept drift; catastrophic forgetting; systematic mapping