American Journal of Advanced Multidisciplinary Innovation and Research

E-ISSN: XXXX-XXXX     Impact Factor: -

A Widely Indexed Open Access Peer Reviewed Multidisciplinary Bi-monthly Scholarly International Journal

Call for Paper Volume 7, Issue 5 (September-October 2026) Submit your research before last 3 days of October to publish your research paper in the issue of September-October.

Federated Cyber-Threat Learning Across Independent Institutions

Author(s) Dr. Samuel J. Rhodes
Country United States
Abstract Independent institutions frequently observe different fragments of the same evolving cyber-threat landscape. Universities may detect credential abuse, healthcare providers may encounter ransomware precursors, municipalities may experience exploitation of internet-facing services, and financial or infrastructure organizations may observe command-and-control or exfiltration behavior. Conventional cyber-threat intelligence sharing allows institutions to exchange indicators and defensive information, but raw security telemetry is often difficult to centralize because it may contain confidential operational information, personal data, proprietary network characteristics, or sensitive incident evidence. Federated learning provides an alternative model in which institutions collaboratively improve machine-learning models while retaining underlying training observations within their own administrative boundaries. Federated learning, however, does not automatically provide privacy or trust. Model updates may disclose information, institutional data may be statistically heterogeneous, malicious participants may poison global models, and privacy-preserving aggregation can complicate the identification of malicious contributions. NIST's privacy-preserving federated-learning work explicitly distinguishes decentralized training from stronger privacy mechanisms such as secure aggregation and output privacy, while recent federated cybersecurity research continues to identify poisoning, Byzantine behavior, inference leakage, and non-IID data as central deployment challenges.
This study proposes a Secure Adaptive Federated Threat Learning Framework for cross-institution cybersecurity collaboration. A synthetic environment representing 12 independent institutions and 144,000 network-event windows was constructed. Four collaboration conditions were modeled: isolated local learning, machine-readable cyber-threat intelligence sharing, conventional cross-silo federated averaging, and secure adaptive federation integrating secure aggregation, institutional trust scoring, robust update screening, local personalization, and structured STIX/TAXII-compatible threat context. The strongest architecture achieved a simulated macro-F1 score of 91.3%, an unseen-threat recall of 84.6%, and a 16-point privacy-exposure index compared with 38 for conventional federated learning. Under a synthetic scenario in which 20% of participating institutional updates were malicious or corrupted, the secure adaptive architecture retained 87.8% macro-F1 compared with 68.9% for unprotected federated averaging.
Keywords federated learning, cyber-threat intelligence, intrusion detection, collaborative cybersecurity, secure aggregation, cross-silo learning, threat intelligence sharing, poisoning attacks, privacy-preserving machine learning, institutional cybersecurity
Field Engineering
Published In Volume 3, Issue 4, July-August 2022
Published On 2022-08-03

Share this