Scientific Reports· 2026Q1
Federated learning and autoencoder-based hybrid framework for DDoS detection
- 0citations
- Q1SCImago
- 2026year
Short summary
A hybrid federated learning framework combining Federated Averaging (FedAvg) MLP and an autoencoder detects DDoS attacks without sharing raw traffic data, achieving improved accuracy by re-evaluating low-confidence predictions.
AI-generated from the title and abstract; the full text is not read.
Key points
- A hybrid federated framework combines FedAvg MLP and an autoencoder for DDoS detection.
- The autoencoder is activated via a confidence-gated mechanism to reassess low-confidence MLP predictions.
- Raw network traffic data remains on participating clients, ensuring data privacy.
- The framework was evaluated against a centralized MLP baseline using standard detection metrics.
AI-generated from the title and abstract; the full text is not read.
Abstract
Abstract Distributed Denial-of-Service (DDoS) attacks can overwhelm network resources and disrupt the availability of cloud services, enterprise systems, and critical infrastructure. Machine-learning-based intrusion detection can help identify malicious traffic from network-flow characteristics. However, conventional centralized training requires data from multiple environments to be collected and stored in a central location, which can be challenging when organizations face confidentiality and data-sharing restrictions. This study presents a hybrid federated framework for DDoS detection that combines a Federated Averaging (FedAvg) multilayer perceptron (MLP) with an autoencoder trained on benign traffic. Traffic from the CICIDS2017 and CICDDoS2019 datasets is cleaned, deduplicated, and aligned using common flow-level features before being distributed across federated clients. The FedAvg MLP acts as the primary classifier, while the autoencoder provides additional anomaly information through reconstruction error. A confidence-gated cascading mechanism activates the autoencoder only when the MLP predicts benign traffic with low confidence, particularly for samples close to the decision boundary. This enables potentially missed attacks to be reassessed without unnecessarily altering confident predictions. The proposed framework is evaluated against a centralized MLP baseline using standard detection metrics, along with an analysis of recovered attacks and additional false positives. Because raw traffic remains on the participating clients, the framework supports collaborative DDoS detection across distributed network environments without requiring organizations to directly share their underlying traffic data.
The authors' abstract, as published at the source. Scientific Reports, 2026 · DOI ↗
Continue with a free account
Ask the paper: 3 free questions a day about this paper; save it, get its citation, new summaries every day for your field. Takeaways are Premium.
Continue free on the webSign in with Google or Apple; no card needed. You come back to this paper.
On your phone:
Field: Computer Networks and Communications
Computer Networks and CommunicationsComputer Science