Federated Learning Framework for Privacy-Preserving Threat Detection in Distributed IT Systems

Authors

  • Mr. Imad Ullah Faculty of Computing, Riphah International University, Islamabad, Pakistan Author https://orcid.org/0000-0002-8669-6998
  • Mr. Ibad Ullah Faculty of Computing, Riphah International University, Islamabad, Pakistan Author
  • Mr. Naseer Ullah Faculty of Computing, Riphah International University, Islamabad, Pakistan Author

DOI:

https://doi.org/10.65080/mijai.v1.CM2601105004

Keywords:

Federated learning, intrusion detection, privacy-preserving machine learning, distributed IT systems, deep neural networks, UNSW-NB15, non-IID data, cybersecurity

Abstract

Introduction: This study investigates the practicality and efficiency of federated learning as a privacy-preserving threat detection approach in distributed IT systems. The research is motivated by the limitations of centralized intrusion detection systems and increasing regulatory constraints on data sharing. The primary aim is to evaluate whether federated learning can achieve competitive detection performance while maintaining strict data privacy.

Methods: An end-to-end federated learning framework was implemented and evaluated using the UNSW-NB15 dataset, consisting of 257,673 network flow records with 36 traffic-related features. A deep neural network model was collaboratively trained across multiple non-IID clients using the Federated Averaging algorithm, ensuring that raw network traffic data remained local to each client. The federated model was compared with centralized deep learning, local-only training, and a centralized Random Forest classifier. In addition to predictive performance, system-level metrics such as communication efficiency, convergence behaviour, and deployment feasibility were analysed.

Results: Experimental results show that the federated model achieved competitive detection performance, closely approaching centralized deep learning while outperforming local-only training. The centralized Random Forest classifier achieved the highest predictive accuracy but required full data aggregation and therefore lacked privacy guarantees. The federated model demonstrated stable convergence within 20 communication rounds, with most performance gains achieved by round 15. Communication overhead remained modest at approximately 10.85 MB, and computational costs were manageable. Although federated training required more time than centralized deep learning, it preserved privacy by ensuring that raw network traffic remained within client environments.

Conclusion: The findings demonstrate that federated learning provides a practical and privacy-aware alternative to centralized intrusion detection systems. It effectively balances detection performance, communication efficiency, and reduced data exposure, making it suitable for deployment in distributed environments with realistic non-IID data conditions.

Author Biographies

  • Mr. Imad Ullah, Faculty of Computing, Riphah International University, Islamabad, Pakistan

    Lecturer, Riphah International University, Islamabad, Pakistan.

  • Mr. Ibad Ullah, Faculty of Computing, Riphah International University, Islamabad, Pakistan

    Lecturer, Riphah International University, Islamabad, Pakistan

  • Mr. Naseer Ullah, Faculty of Computing, Riphah International University, Islamabad, Pakistan

    Lecturer, Riphah International University, Islamabad, Pakistan

References

Albshaier L, Almarri S, Albuali A. Federated learning for cloud and edge security: A systematic review of challenges and AI opportunities. Electronics 2025; 14(5): 1019. https://doi.org/10.3390/electronics14051019

Chen C, et al. Trustworthy federated learning: privacy, security, and beyond. Knowl Inf Syst 2025; 67(3): 2321-2356. https://doi.org/10.1007/s10115-024-02285-2

Bilal G, Meriem B. Federated learning for cybersecurity: Enhancing threat detection across multiple organizations [Thesis]. University of Biskra; 2025. Available from: http://archives.univ-biskra.dz/bitstream/123456789/31490/1/Boussaha_Meriem_Ghamri_Bilal.pdf

Samuel AJ. Optimizing energy consumption through AI and cloud analytics: Addressing data privacy and security concerns. World J Adv Eng Technol Sci 2024; 13(2): 789-806. https://doi.org/10.30574/wjaets.2024.13.2.0609

Ullah I, Yaseen MU, Amin NU, Qureshi MR, Ibrahim S. Explainable emotion recognition from heart rate data using deep learning and XGBoost. In: Proc 2025 27th Int Multitopic Conf (INMIC). IEEE; 2025. https://doi.org/10.1109/INMIC65900.2025.11348573

Amin, R., Costanzo, A., Alzabin, L.R. et al. An efficient federated learning-based defense mechanism for software defined network cyber threats through machine learning models. Sci Rep 2025; 15(1): 41390. https://doi.org/10.1038/s41598-025-25345-1

Vyas A, Lin PC, Hwang RH, Tripathi M. Privacy-preserving federated learning for intrusion detection in IoT environments: a survey. IEEE Access. 2024; 12: 127018-127050. https://doi.org/10.1109/ACCESS.2024.3454211

Siddiqui MR. Big data and great privacy challenges in the digital era-A comprehensive study. Innov J Appl Sci 2025; 2(6): 42. https://doi.org/10.70844/ijas.2025.2.42

Rahim T, Ullah I, Nazir A, Tanveer MS, Qureshi MR. A deep learning approach to PCOS diagnosis: Two-stream CNN with transformer attention mechanism. Spectr Eng Sci 2025; 3(7). https://doi.org/10.5281/zenodo.15790016

Liu Y, James J, Kang J, Niyato D, Zhang S. Privacy-preserving traffic flow prediction: A federated learning approach. IEEE Internet Things J 2020; 7(8): 7751-7763. https://doi.org/10.1109/JIOT.2020.2991401

Hasan MM. Federated learning models for privacy-preserving AI in enterprise decision systems. Int J Bus Econ Insights 2025; 5(3): 238-269. https://doi.org/10.63125/ry033286

Gadekallu TR, et al. Federated learning for big data: A survey on opportunities, applications, and future directions. 2021. https://doi.org/10.48550/arXiv.2110.04160

Raza M, Saeed MJ, Riaz MB, Sattar MA. Federated learning for privacy-preserving intrusion detection in software-defined networks. IEEE Access. 2024; 12: 69551-69567. https://doi.org/10.1109/ACCESS.2024.3395997

Quffa A, Abu-Naser SS. A rule-based expert system for cybersecurity threat detection: Evolution, applications, and the hybrid AI paradigm. Int J Acad Eng Res 2025; 9(8): 44-62. Available from: http://ijeais.org/wp-content/uploads/2025/8/IJAER250807.pdf

Hozouri A, Mirzaei A, Effatparvar M. A comprehensive survey on intrusion detection systems with advances in machine learning, deep learning and emerging cybersecurity challenges. Discov Artif Intell 2025; 5(1): 314. https://doi.org/10.1007/s44163-025-00578-1

Sharif F. The role of ensemble learning in strengthening intrusion detection systems: A machine learning perspective. Int J Comput Eng Technol 2024. Available from: https://www.researchgate.net/publication/384366905_The_Role_of_Ensemble_Learning_in_Strengthening_Intrusion_Detection_Systems_A_Machine_Learning_Perspective

Latif N, Ma W, Ahmad HB. Advancements in securing federated learning with IDS: a comprehensive review of neural networks and feature engineering techniques for malicious client detection. Artif Intell Rev 2025; 58(3): 91. https://doi.org/10.1007/s10462-024-11082-w

Alketbi KS, Mehmood A. A comprehensive survey of explainable artificial intelligence techniques for malicious insider threat detection. IEEE Access 2025; 13: 121772-121798. https://doi.org/10.1109/ACCESS.2025.3587114

Chowdhury TK. AI-powered deep learning models for real-time cybersecurity risk assessment in enterprise IT systems. ASRC Procedia Glob Perspect Sci Scholarsh 2025; 1(01): 675-704. https://doi.org/10.63125/137k6y79

Li W, Meng W, Kwok LF. Surveying trust-based collaborative intrusion detection: State-of-the-art, challenges and future directions. IEEE Commun Surv Tutor 2021; 24(1): 280-305. https://doi.org/10.1109/COMST.2021.3139052

Mankotia S, de Leon DC, Rimal BP. FedPrIDS: privacy-preserving federated learning for collaborative network intrusion detection in IoT. J Cybersecur Priv. 2026; 6(1): 10. https://doi.org/10.3390/jcp6010010

Khalil U, Malik OA, Uddin M, Chen CL. A comparative analysis on blockchain versus centralized authentication architectures for IoT-enabled smart devices in smart cities: a comprehensive review, recent advances, and future research directions. Sensors 2022; 22(14): 5168. https://doi.org/10.3390/s22145168

Alqattan DSM. Security of distributed and federated deep learning systems [thesis]. Newcastle University; 2025. http://hdl.handle.net/10443/6614

Ji, S, Tan, Y, Saravirta, T. et al. Emerging trends in federated learning: From model fusion to federated x learning. Int J Mach Learn Cybern 2024; 15(9): 3769-3790. https://doi.org/10.1007/s13042-024-02119-1

Zhao Z, et al. Federated learning with non-IID data in wireless networks. IEEE Trans Wirel Commun 2021; 21(3): 1927-1942. https://doi.org/10.1109/TWC.2021.3108197

Bouacida N, Mohapatra P. Vulnerabilities in federated learning. IEEE Access 2021; 9: 63229-63249. https://doi.org/10.1109/ACCESS.2021.3075203

Taheri R, Jafari R, Gegov A, Arabikhan F, Ichtev A. Explainable AI for federated learning-based intrusion detection systems in connected vehicles. Electronics 2025; 14(22): 4508. https://doi.org/10.3390/electronics14224508

Baich M, Sael N. A federated learning-based intrusion detection system using dynamic ensemble aggregation for IoT networks. IEEE Access 2025; 13: 205826-205839. https://doi.org/10.1109/ACCESS.2025.3640521

Hernandez-Ramos JL, et al. Intrusion detection based on federated learning: A systematic review. ACM Comput Surv 2025; 57(12): 1-65. https://doi.org/10.1145/3731596

Albanbay N, et al. Federated learning-based intrusion detection in IoT networks: Performance evaluation and data scaling study. J Sens Actuator Netw 2025; 14(4): 78. https://doi.org/10.3390/jsan14040078

Moualla S, Khorzom K, Jafar A. Improving the performance of machine learning-based network intrusion detection systems on the UNSW-NB15 dataset. Comput Intell Neurosci 2021; 2021(1): 5557577. https://doi.org/10.1155/2021/5557577

Jouhari M, Benaddi H, Ibrahimi K. Efficient intrusion detection: Combining x2 feature selection with CNN-BiLSTM on the UNSW-NB15 dataset. Proc 2024 11th Int Conf Wirel Netw Mob Commun (WINCOM). IEEE 2024: 1-6. https://doi.org/10.1109/WINCOM62286.2024.10658099

Pinheiro JMH, et al. The impact of feature scaling in machine learning: Effects on regression and classification tasks. IEEE Access 2025; 13: 199903-199931. Available from: https://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=11261543

Shebl A, Elsedimy EI, Ismail A, Salama AA, Herajy M. DCNN: A novel binary and multi-class network intrusion detection model via deep convolutional neural network. EURASIP J Inf Secur 2024; 2024(1): 36. https://doi.org/10.1186/s13635-024-00184-1

Efthymiadis F, Karras A, Karras C, Sioutas S. Advanced optimization techniques for federated learning on non-IID data. Future Internet 2024; 16(10): 370. https://doi.org/10.3390/fi16100370

Downloads

Published

2026-05-26

Issue

Section

Articles

How to Cite

Federated Learning Framework for Privacy-Preserving Threat Detection in Distributed IT Systems. (2026). Majestic International Journal of AI Innovations, 1, 1-16. https://doi.org/10.65080/mijai.v1.CM2601105004