From Machine Learning to Federated Knowledge Systems – Current Challenges and Future Architectural Directions for Cybersecurity Applications
Felix Härer, Noah Agostinis · Frontiers in artificial intelligence and applications · 2025
Machine learning (ML) is foundational to cybersecurity today, underpinning critical applications such as intrusion detection systems. Despite their widespread adoption, however, established ML approaches are beginning to show critical limitations in handling evolving cyberthreats. In this paper, we (1.) conduct a data-driven analysis of ML for intrusion detection to understand and demonstrate current limitations, (2.) discuss the literature and contextualize the findings, and (3.) identify and outline architectural directions for advancing local ML to federated knowledge systems for cybersecurity applications. The analysis results indicate significant challenges within established systems, notably in defining normal behavior, high false alarm rates, and detection rates. These shortcomings highlight intrinsic constraints of localized ML approaches, as exemplified in intrusion detection and beyond. Toward addressing these issues, the properties of a federated knowledge system architecture can provide distributed data inputs rather than siloed sources, data sharing, and federated learning to derive widely distributed, structured knowledge bases.