Home / Current Issue / Paper 1717536
Federated Learning Paradigms for Privacy-Preserving Multi Organizational Threat Intelligence Sharing
Subject area: Science,Engineering and Technology · Area of research: Sciences
DOI: 10.64388/IREV9I10-1717536
Abstract
Cyber threat intelligence sharing is widely recognized as a strategic component for improving early detection of malicious campaigns, correlation of indicators of compromise, and coordinated incident response. Despite this potential, direct exchange of operational data among institutions remains constrained by regulatory, contractual, competitive, and technical barriers, especially when network telemetry, authentication logs, endpoint events, and sensitive artifacts are involved. In this context, federated learning has been investigated as an approach capable of enabling collaborative training without centralizing raw data. This article discusses the main federated learning paradigms applied to multi-organizational cyber threat intelligence sharing, with emphasis on privacy preservation, robustness against adversarial manipulation, statistical heterogeneity across participants, and scalability limitations. It also examines complementary techniques such as secure aggregation, differential privacy, homomorphic encryption, secure multi-party computation, and Byzantine-robust mechanisms. Recent literature suggests that federated learning can improve the generalization capability of detection models when compared with strictly local approaches, although its practical adoption still depends on more mature solutions for inter-organizational trust, semantic interoperability, and technical governance.
Keywords
Federated Learning, Cyber Threat Intelligence, Differential Privacy, Secure Aggregation, Intrusion Detection.
References
[1] McMahan HB, Moore E, Ramage D, Hampson S, Agüera y Arcas B. Communication-efficient learning of deep networks from decentralized data. In: Proceedings of the 20th International Conference on Artificial Intelligence and Statistics. PMLR. 2017;54:1273-82.
[2] Kairouz P, McMahan HB, Avent B, Bellet A, Bennis M, Bhagoji AN, et al. Advances and open problems in federated learning. Found Trends Mach Learn. 2021;14(1-2):1-210.
[3] Bonawitz K, Ivanov V, Kreuter B, Marcedone A, McMahan HB, Patel S, et al. Practical secure aggregation for privacy-preserving machine learning. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security. New York: ACM; 2017. p. 1175-91.
[4] Dwork C, Roth A. The algorithmic foundations of differential privacy. Found Trends Theor Comput Sci. 2014;9(3-4):211-407.
[5] Nguyen T, Thai MT. Preserving privacy and security in federated learning. IEEE/ACM Trans Netw. 2024;32(1):833-43.
[6] Sarhan M, Layeghy S, Moustafa N, Portmann M. Cyber threat intelligence sharing scheme based on federated learning for network intrusion detection. J Netw Syst Manage. 2023;31:1-23.
[7] Sakhare NN. A decentralized approach to threat intelligence using federated learning in privacy-preserving cyber security. J Electr Syst. 2024;20(2):658.
[8] Camalan E, Celiktas B. Privacy-preserving cyber threat intelligence: a framework combining private information retrieval, federated learning, and differential privacy. In: 2025 10th International Conference on Computer Science and Engineering (UBMK). New York: IEEE; 2025. p. 1525-30.
[9] Pandey S, Azath H, Rahman R, Lamkuche H. Privacy-preserving model for cyber threat intelligence sharing across multi-organizational platforms. In: 2025 IEEE 14th International Conference on Communication Systems and Network Technologies (CSNT). New York: IEEE; 2025. p. 437-42.
[10] Mrabet M. TrustFed-CTI: a trust-aware federated learning framework for privacy-preserving cyber threat intelligence sharing across distributed organizations. Future Internet. 2025;17(11):512.
[11] Timofte EM, Dimian M, Puscasu M, et al. Federated learning for cybersecurity: a privacy-preserving approach. Appl Sci. 2025;15(12):6878.
[12] Peng H, Wu C, Xiao Y. FD-IDS: federated learning with knowledge distillation for intrusion detection in non-IID IoT environments. Sensors. 2025;25(14):4309.
[13] Collins E, Wang M. Federated learning: a survey on privacy-preserving collaborative intelligence. arXiv [Preprint]. 2025:arXiv:2504.17703.
[14] Prajapati N. Federated learning for privacy-preserving cybersecurity: a review on secure threat detection. Int J Adv Res Sci Commun Technol. 2025.
[15] Blanchard P, El Mhamdi EM, Guerraoui R, Stainer J. Machine learning with adversaries: Byzantine tolerant gradient descent. In: Advances in Neural Information Processing Systems 30. Red Hook: Curran Associates; 2017. p. 119-29.
[16] Yin D, Chen Y, Kannan R, Bartlett P. Byzantine-robust distributed learning: towards optimal statistical rates. In: Proceedings of the 35th International Conference on Machine Learning. PMLR. 2018;80:5650-9.
[17] OASIS Cyber Threat Intelligence (CTI) Technical Committee. STIX Version 2.1. OASIS Standard; 2021.
[18] Available from: https://docs.oasis-open.org/cti/stix/v2.1/stix-v2.1.html.
How to cite this paper
@article{1717536,
author = {Marcelo Araujo},
title = {Federated Learning Paradigms for Privacy-Preserving Multi Organizational Threat Intelligence Sharing},
journal = {Iconic Research And Engineering Journals},
year = {2026},
volume = {9},
number = {10},
pages = {4280-4284},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1717536.pdf},
abstract = {Cyber threat intelligence sharing is widely recognized as a strategic component for improving early detection of malicious campaigns, correlation of indicators of compromise, and coordinated incident response. Despite this potential, direct exchange of operational data among institutions remains constrained by regulatory, contractual, competitive, and technical barriers, especially when network telemetry, authentication logs, endpoint events, and sensitive artifacts are involved. In this context, federated learning has been investigated as an approach capable of enabling collaborative training without centralizing raw data. This article discusses the main federated learning paradigms applied to multi-organizational cyber threat intelligence sharing, with emphasis on privacy preservation, robustness against adversarial manipulation, statistical heterogeneity across participants, and scalability limitations. It also examines complementary techniques such as secure aggregation, differential privacy, homomorphic encryption, secure multi-party computation, and Byzantine-robust mechanisms. Recent literature suggests that federated learning can improve the generalization capability of detection models when compared with strictly local approaches, although its practical adoption still depends on more mature solutions for inter-organizational trust, semantic interoperability, and technical governance.},
keywords = {Federated Learning, Cyber Threat Intelligence, Differential Privacy, Secure Aggregation, Intrusion Detection.},
month = {April},
doi = {https://doi.org/10.64388/IREV9I10-1717536}
}