
doi: 10.2139/ssrn.6371118
The rapid proliferation of encrypted network communication has significantly strengthened data privacy, yet it has simultaneously limited the effectiveness of traditional intrusion detection systems. Zero-day attacks, characterized by previously unseen signatures and evolving behavioral patterns, pose a critical challenge to centralized security architectures. Recent advances in federated learning, introduced by McMahan et al., enable decentralized model training without direct data sharing, preserving privacy while improving collaborative intelligence. Simultaneously, the growing demand for trustworthy artificial intelligence highlights the importance of explainability, as emphasized in the theoretical foundations of Explainable AI by researchers such as Ribeiro et al. and Doshi-Velez and Kim.This study proposes a Federated Explainable Deep Learning Framework for detecting zero-day attacks within encrypted traffic environments. The aim is to design a privacy-preserving, adaptive intrusion detection model capable of identifying anomalous traffic patterns without decrypting payload content. The methodology integrates federated deep neural networks with attention-based architectures for encrypted traffic feature extraction, combined with SHAP-based interpretability mechanisms to enhance transparency and trustworthiness. The framework is evaluated using distributed network datasets to measure detection accuracy, F1-score, robustness against adversarial perturbations, and communication efficiency.Findings indicate that the proposed federated model improves zero-day detection performance while maintaining data confidentiality and interpretability across distributed nodes. The study utilizes federated optimization theory and explainability principles to address limitations in centralized and opaque detection systems. This research contributes to the evolving discourse on privacy-preserving AI-driven cybersecurity, making it particularly relevant in an era of encrypted-by-default communication infrastructures.
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 0 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
