Federated learning and autoencoder-based hybrid framework for DDoS detection

Abstract Distributed Denial-of-Service (DDoS) attacks can overwhelm network resources and disrupt the availability of cloud services, enterprise systems, and critical infrastructure. Machine-learning-based intrusion detection can help identify malicious traffic from network-flow characteristics. However, conventional centralized training requires data from multiple environments to be collected and stored in a central location, which can be challenging when organizations face confidentiality and data-sharing restrictions. This study presents a hybrid federated framework for DDoS detection that combines a Federated Averaging (FedAvg) multilayer perceptron (MLP) with an autoencoder trained on benign traffic. Traffic from the CICIDS2017 and CICDDoS2019 datasets is cleaned, deduplicated, and aligned using common flow-level features before being distributed across federated clients. The FedAvg MLP acts as the primary classifier, while the autoencoder provides additional anomaly information through reconstruction error. A confidence-gated cascading mechanism activates the autoencoder only when the MLP predicts benign traffic with low confidence, particularly for samples close to the decision boundary. This enables potentially missed attacks to be reassessed without unnecessarily altering confident predictions. The proposed framework is evaluated against a centralized MLP baseline using standard detection metrics, along with an analysis of recovered attacks and additional false positives. Because raw traffic remains on the participating clients, the framework supports collaborative DDoS detection across distributed network environments without requiring organizations to directly share their underlying traffic data.

Authors

Publication Details

Journal
Scientific Reports
Published
2026-09-25
DOI
https://doi.org/10.1038/s41598-026-72638-0
Primary Topic
Network Security and Intrusion Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Federated learning and autoencoder-based hybrid framework for DDoS detection

H. M. Anitha, G. Srujana, K. S. Harshita, Harshitha Shetty et al.
Scientific Reports
Network Security and Intrusion Detection
article

Federated learning and autoencoder-based hybrid framework for DDoS detection

H. M. Anitha, G. Srujana, K. S. Harshita, Harshitha Shetty, Nalina V., N. Jhansi
article en

Abstract

Abstract Distributed Denial-of-Service (DDoS) attacks can overwhelm network resources and disrupt the availability of cloud services, enterprise systems, and critical infrastructure. Machine-learning-based intrusion detection can help identify malicious traffic from network-flow characteristics. However, conventional centralized training requires data from multiple environments to be collected and stored in a central location, which can be challenging when organizations face confidentiality and data-sharing restrictions. This study presents a hybrid federated framework for DDoS detection that combines a Federated Averaging (FedAvg) multilayer perceptron (MLP) with an autoencoder trained on benign traffic. Traffic from the CICIDS2017 and CICDDoS2019 datasets is cleaned, deduplicated, and aligned using common flow-level features before being distributed across federated clients. The FedAvg MLP acts as the primary classifier, while the autoencoder provides additional anomaly information through reconstruction error. A confidence-gated cascading mechanism activates the autoencoder only when the MLP predicts benign traffic with low confidence, particularly for samples close to the decision boundary. This enables potentially missed attacks to be reassessed without unnecessarily altering confident predictions. The proposed framework is evaluated against a centralized MLP baseline using standard detection metrics, along with an analysis of recovered attacks and additional false positives. Because raw traffic remains on the participating clients, the framework supports collaborative DDoS detection across distributed network environments without requiring organizations to directly share their underlying traffic data.

Scientific Reports
Industry, innovation and infrastructure
Openalex Percentile: Top 9%
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Federated learning and autoencoder-based hybrid framework for DDoS detection — H. M. Anitha, G. Srujana, et al. · Scientific Reports (2026) | TGRS Research Map | TGRS