From Network Intrusion Detection to Blockchain-Backed Endpoint Detection and Response: Mapping the Landscape of Decentralized Detection-and-Response Architectures
Authors: Yahya Shahsavari, Sara Rouhani, Kaiwen Zhang
Organizations: Dept. of Software and IT Engineering ´Ecole de technologie sup´erieure ( ´ETS) Montr´eal, Qu´ebec, Canada · Dept. of Computer Science University of Calgary Calgary, Alberta, Canada
While the literature on blockchain-assisted intrusion detection and prevention systems (IDS/IPS) for Internet of Things (IoT) and Industrial Internet of Things (IIoT) networks is mature, existing systematic reviews suffer from two critical limitations: they overlook the structural shift toward modern Endpoint Detection and Response (EDR) and Extended Detection and Response (XDR) architectures, and they conflate blockchain's distinct functional roles into a single monolithic category. This Systematization of Knowledge (SoK) addresses these gaps by proposing a three-axis taxonomy that classifies proposals by detection-system class (NIDS, HIDS, EDR/XDR), blockchain functional role, and response-automation maturity. Synthesizing research published in high-impact venues between 2019 and 2026, we provide a rigorous gap analysis exposing why a genuine per-endpoint blockchain-anchored response loop remains nearly nonexistent due to latency, deployment, and community mismatches. Furthermore, we evaluate structural, cross-cutting challenges persisting across the literature, including consensus latency on constrained devices, post-quantum cryptographic vulnerability, smart-contract attack surfaces, and the adversarial vulnerability of evolving LLM-based detection engines. Finally, we outline a comprehensive research agenda centered on hybrid on-chain/off-chain orchestration to bridge the gap between decentralized trust and rapid response automation.
Figures & tables
Primitive
Taxonomy mapping
Immutable ledgers
Axis 2: Role L (evidentiary/audit)
Consensus protocols
Axis 2: Role T (trust/consensus)
Incentive layers
Axis 2: Role I (incentive)
FL integrity assurance
Axis 2: Role F (FL-integrity)
Smart contracts
Cross-cutting: implements Axis 3
(R2/R3 response automation) atop L/T/I/F
TABLE I: Mapping of Blockchain Primitives (Sec. II-B ) to Taxonomy Axes (Sec. IV )
Fig. 1: Schematic view of the three-axis taxonomy (Section IV ). Points are representative systems from Table II , positioned by detection-system class (x-axis) and response-automation maturity (y-axis); point color/fill loosely indicates dominant blockchain functional role. The dashed region marks the largely unoccupied EDR/XDR × R2/R3 cell that motivates Sections VI and IX.
PoFQ consensus for decentralized threat hunting [ 33 ]
NIDS
T
R1–R2
Novel consensus protocol, trustless setting
Securing FL with blockchain + XAI, IoT [ 39 ]
NIDS (IoT)
F
R1
Explainability layer added to FL-IDS
CyberNFTs reward-driven IDS [ 23 ]
NIDS
I, T
R0–R1
Conceptual; incentive layer is the core contribution
TABLE II: Three-Axis Taxonomy Applied to Representative Surveyed Systems
Fig. 2: Proposed hybrid on-chain/off-chain response architecture (Section IX.A). The fast path (solid red) executes containment locally within an EDR-realistic latency budget, without waiting on consensus. The slow path (dashed blue) asynchronously commits a tamper-evident audit record to the ledger, where consensus latency is acceptable. The optional feedback loop (gray) represents the R3 closed-loop ideal, which no surveyed system currently implements at the individual-endpoint level.
The rise of IoT devices and the uptake of cloud computing have informed a new era of data-driven intelligence. Traditional centralized machine learning models that require a large volume of data to be stored in a single location have therefore become more susceptible to data breaches, privacy violations, and regulatory non-compliance. This report presents a thorough examination of the merging of Federated Learning (FL) and blockchain technology in a cloud-edge setting, demonstrating it as an effective solution to the stated concerns. We are proposing a detailed four-dimensional architectural categorization that meticulously assesses coordination frameworks, consensus algorithms, data storage practices, and trust models that are significant to these integrated systems. The manuscript presents a comprehensive comparative examination of two cutting-edge frameworks: the Multi-Objectives Reinforcement Federated Learning Blockchain (MORFLB), which is designed for intelligent transportation systems, and the Federated Blockchain-IoT Framework for Sustainable Healthcare Systems (FBCI-SHS), elucidating their distinctive contributions and inherent limitations. Lastly, we engage in a thorough evaluation of the literature that integrates a comparative perspective on current frameworks to discern the singular nature of this research within existing knowledge systems. The manuscript culminates in delineating the principal challenges and offering a strategic framework for prospective research trajectories, emphasizing the advancement of adaptive, resilient, and standardized BCFL systems across diverse application domains.
Saloni Garg, Amit Sagtani, Kamal Kant Hiran
Adobe Research San Jose, USA · San Francisco State University San Francisco, USA · Sir Padampat Singhania University Udaipur, India
Machine-learning Network Intrusion Detection Systems (IDS) depend on substantial labeled datasets and task-specific training, whereas Large Language Models (LLMs) detection can analyze flow records directly but incurs higher inference cost and latency, with less constrained outputs. This paper presents JEV-IDS, an open experimental general NIDS based on the Jev System One Model (SOM) to detect zero day intrusions Under label scarcity. JEV-IDS serializes one flow per request and asks JEV two questions: a binary attack probability and a finite-choice traffic category. Our results show that, at k=1, JEV was 4.8 times faster and 3.8 times cheaper than GPT-5.6 Luna, with 1.5 times higher novel-attack recall; it also produced 15 times fewer false alarms than a low-data Random Forest. Across 5,400 decisions on a 300-flow NSL-KDD pilot split, JEV achieved F1-Score 0.859, precision 0.941, recall 0.790, and novel-attack recall 0.838. Increasing k to 2 reduced its F1-Score to 0.839.
Paulo Severo, Silvio E. Quincozes, Amanda Dias
Graduate Program in Software Engineering, Federal University of Pampa (UNIPAMPA), Alegrete, Rio Grande do Sul, Brazil
Enterprise intrusion response still depends on static playbooks and analyst-driven triage, creating delay between alert generation and containment. We present Agentra, a supervisable multi-agent Intrusion Response System (IRS) framework that converts alerts from IDS, EDR, and XDR platforms into structured incident response plans grounded in MITRE ATT&CK, MITRE D3FEND, and NIST CSF 2.0. Agentra decomposes response reasoning across role-scoped agents, validates proposed plans through a bounded Planner--Validator review loop, screens retrieved threat intelligence through a Moderator security gateway, gates actions through an Action Catalog and risk score, and records decisions in an append-only audit log. We evaluate Agentra against a static OASIS CACAO v2.0 cyber-playbook baseline on a 120-event corpus drawn from ThreatHunter-Playbook, Splunk BOTSv3, and DARPA OpTC. The strongest configuration improves FP-aware IRS F1 from 0.61 to 0.84 and restores the projected harmful-action rate to the static baseline level of 0.0% after Planner-only configurations introduce unsafe overreaction. These results indicate that multi-agent response planning can improve ontology-grounded IRS coverage while preserving analyst approval and auditability.
Raj Patel, Shaswata Mitra, Michele Guida +3
The University of Alabama, Alabama, USA · Roma Tre University, Rome, Italy