Federated Learning for Privacy-Preserving Cybersecurity: A Review of Distributed Artificial Intelligence for Intrusion Detection
Keywords:
artificial intelligence, cybersecurity, data privacy, federated learning, intrusion detection, privacy preservationAbstract
The increasing volume of cybersecurity data generated by organizations, cloud platforms, Internet of Things devices, and distributed networks has created opportunities for artificial intelligence-based threat detection. Conventional centralized machine learning requires organizations to transfer data to a common repository, which can introduce privacy, security, regulatory, and data-governance concerns. Federated Learning (FL) offers an alternative distributed learning paradigm in which multiple clients collaboratively train a shared model while keeping their raw training data at local sites. This article presents a structured literature review of federated learning for privacy-preserving cybersecurity, with particular attention to intrusion detection, IoT security, distributed anomaly detection, and collaborative threat intelligence. The methodology categorizes the literature according to federated architecture, learning strategy, cybersecurity task, privacy mechanism, and attack resilience. The review indicates that federated learning can facilitate collaborative cybersecurity analytics without requiring direct centralization of raw data, while challenges remain concerning non-independent and non-identically distributed data, communication costs, poisoning attacks, client heterogeneity, model privacy, and trust in aggregation servers. The article proposes a layered framework combining federated learning, secure aggregation, anomaly detection, model validation, and continuous monitoring. The findings indicate that FL is a promising distributed-AI paradigm for cybersecurity, but privacy should not be assumed merely because raw data remain locally stored.