Federated Explainable Deep Learning Framework for Zero-Day Attack Detection in Encrypted Traffic Environments
Description
The rapid proliferation of encrypted network communication has significantly strengthened data privacy, yet it has simulta- neously limited the effectiveness of traditional intrusion detection systems. Zero-day attacks, characterized by previously unseen signatures and evolving behavioral patterns, pose a critical challenge to centralized security architectures. Recent advances in fed- erated learning, introduced by McMahan et al., enable decentralized model training without direct data sharing, preserving privacy while improving collaborative intelligence. Simultaneously, the growing demand for trustworthy artificial intelligence highlights the importance of explainability, as emphasized in the theoretical foundations of Explainable AI by researchers such as Ribeiro et al. and Doshi-Velez and Kim.This study proposes a Federated Explainable Deep Learning Framework for detecting zero-day attacks within encrypted traffic environments. The aim is to design a privacy-preserving, adaptive intrusion detection model capable of identifying anomalous traffic patterns without decrypting payload content. The methodology integrates federated deep neural networks with attention-based architectures for encrypted traffic feature extraction, combined with SHAP-based interpretability mechanisms to enhance transparency and trustworthiness. The framework is evaluated using distributed network datasets to measure detection accuracy, F1-score, robustness against adversarial perturbations, and communication efficiency.Findings indicate that the proposed federated model improves zero-day detection performance while maintaining data confidentiality and interpretability across distributed nodes. The study utilizes federated optimization theory and explainability principles to address limitations in centralized and opaque detection systems. This research contributes to the evolving discourse on privacy-preserving AI-driven cybersecurity, making it particularly relevant in an era of encrypted-by-default communication infrastructures.
Files
FEDLF.pdf
Files
(219.3 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:d3946970881b67245124f5d395c0b90a
|
219.3 kB | Preview Download |
Additional details
Dates
- Copyrighted
-
2026-04-22