Federated Learning Framework for Privacy-Preserving Threat Detection in Distributed IT Systems
DOI:
https://doi.org/10.65080/mijai.v1.CM2601105004Keywords:
Federated learning, intrusion detection, privacy-preserving machine learning, distributed IT systems, deep neural networks, UNSW-NB15, non-IID data, cybersecurityAbstract
Introduction: This study investigates the practicality and efficiency of federated learning as a privacy-preserving threat detection approach in distributed IT systems. The research is motivated by the limitations of centralized intrusion detection systems and increasing regulatory constraints on data sharing. The primary aim is to evaluate whether federated learning can achieve competitive detection performance while maintaining strict data privacy.
Methods: An end-to-end federated learning framework was implemented and evaluated using the UNSW-NB15 dataset, consisting of 257,673 network flow records with 36 traffic-related features. A deep neural network model was collaboratively trained across multiple non-IID clients using the Federated Averaging algorithm, ensuring that raw network traffic data remained local to each client. The federated model was compared with centralized deep learning, local-only training, and a centralized Random Forest classifier. In addition to predictive performance, system-level metrics such as communication efficiency, convergence behaviour, and deployment feasibility were analysed.
Results: Experimental results show that the federated model achieved competitive detection performance, closely approaching centralized deep learning while outperforming local-only training. The centralized Random Forest classifier achieved the highest predictive accuracy but required full data aggregation and therefore lacked privacy guarantees. The federated model demonstrated stable convergence within 20 communication rounds, with most performance gains achieved by round 15. Communication overhead remained modest at approximately 10.85 MB, and computational costs were manageable. Although federated training required more time than centralized deep learning, it preserved privacy by ensuring that raw network traffic remained within client environments.
Conclusion: The findings demonstrate that federated learning provides a practical and privacy-aware alternative to centralized intrusion detection systems. It effectively balances detection performance, communication efficiency, and reduced data exposure, making it suitable for deployment in distributed environments with realistic non-IID data conditions.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Imad Ullah, Ibad Ullah, Naseer Ullah (Author)

This work is licensed under a Creative Commons Attribution 4.0 International License.