Federated Learning in Distributed Cyber Defense
Mohammad Alauthman, Amjad Yousef Aldweesh, Ahmad Al–Qerem, Mouhammd Sharari Alkasassbeh, Saad Alateef, Ammar Almomani · Advances in computational intelligence and robotics book series · 2025
This chapter investigates how Federated Learning (FL) can reshape cyber defense by enabling collaborative model training without consolidating sensitive data, thus safeguarding privacy while enhancing detection and mitigation capabilities. Highlighting the synergy between distributed machine learning and cybersecurity, the discussion compares FL with conventional, centralized solutions that are prone to privacy, scalability, and single-point-of-failure challenges. Key FL architectures, including cross-silo and cross-device systems, are detailed alongside cryptographic tools such as secure aggregation and differential privacy. The chapter also addresses adversarial threats—poisoning and backdoor attacks—and presents robust aggregation techniques as countermeasures. Drawing on real-world examples, it demonstrates how FL can revolutionize threat intelligence, intrusion detection, and malware analysis within privacy- and regulation-conscious contexts.