Skip to content
Conference

FedShield: A Privacy-Preserving Federated Learning Framework for Behavioral Detection and Mitigation of Zero-Day Attacks

Aug 2026 · International Conference Innovation Engineering and Technology · pp. 1-6 · 0 citations · 17 references

Abstract

Zero-day is a type of attack that targets vulnerabilities unknown to vendors and security experts. Traditional signature-based intrusion detection systems fail to flag such attacks. ML models used to detect attacks require data aggregation, which raises substantial privacy concerns and infringes on an organization’s data sovereignty. To address these difficulties, this study introduces FedShield, a distributed framework for detecting zero-day attacks using federated learning (FL). In the proposed approach, models are locally trained on distributed client nodes, sharing only encrypted model parameters with a central aggregator to maintain data confidentiality. The system incorporates decision fusion, known as an ensemble, to identify behavioral patterns by aggregating the outputs of several specialized models, such as gradient-boosted trees, LSTM networks, and autoencoder-based anomaly detectors. A federated averaging (FedAvg) approach is utilized to combine local updates and build a strong global model while keeping raw data private. The framework demonstrates quick convergence among distributed clients and high resilience against obfuscated and distributed threats. It also includes a response mechanism that maps detection confidence to mitigation actions, such as generating alerts, limiting traffic, or blocking suspicious sources, enabling timely and controlled handling of potential threats.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.