Powered by OpenAIRE graph
Found an issue? Give us feedback
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/ ZENODOarrow_drop_down
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/
ZENODO
Other literature type . 2026
License: CC BY
Data sources: ZENODO
SSRN Electronic Journal
Article . 2026 . Peer-reviewed
Data sources: Crossref
versions View all 2 versions
addClaim

Federated Explainable Deep Learning Framework for Zero-Day Attack Detection in Encrypted Traffic Environments

Authors: Ghimire, Anushrut;

Federated Explainable Deep Learning Framework for Zero-Day Attack Detection in Encrypted Traffic Environments

Abstract

The rapid proliferation of encrypted network communication has significantly strengthened data privacy, yet it has simultaneously limited the effectiveness of traditional intrusion detection systems. Zero-day attacks, characterized by previously unseen signatures and evolving behavioral patterns, pose a critical challenge to centralized security architectures. Recent advances in federated learning, introduced by McMahan et al., enable decentralized model training without direct data sharing, preserving privacy while improving collaborative intelligence. Simultaneously, the growing demand for trustworthy artificial intelligence highlights the importance of explainability, as emphasized in the theoretical foundations of Explainable AI by researchers such as Ribeiro et al. and Doshi-Velez and Kim.This study proposes a Federated Explainable Deep Learning Framework for detecting zero-day attacks within encrypted traffic environments. The aim is to design a privacy-preserving, adaptive intrusion detection model capable of identifying anomalous traffic patterns without decrypting payload content. The methodology integrates federated deep neural networks with attention-based architectures for encrypted traffic feature extraction, combined with SHAP-based interpretability mechanisms to enhance transparency and trustworthiness. The framework is evaluated using distributed network datasets to measure detection accuracy, F1-score, robustness against adversarial perturbations, and communication efficiency.Findings indicate that the proposed federated model improves zero-day detection performance while maintaining data confidentiality and interpretability across distributed nodes. The study utilizes federated optimization theory and explainability principles to address limitations in centralized and opaque detection systems. This research contributes to the evolving discourse on privacy-preserving AI-driven cybersecurity, making it particularly relevant in an era of encrypted-by-default communication infrastructures.

  • BIP!
    Impact byBIP!
    selected citations
    These citations are derived from selected sources.
    This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    0
    popularity
    This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
    Average
    influence
    This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    Average
    impulse
    This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
    Average
Powered by OpenAIRE graph
Found an issue? Give us feedback
selected citations
These citations are derived from selected sources.
This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Citations provided by BIP!
popularity
This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
BIP!Popularity provided by BIP!
influence
This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Influence provided by BIP!
impulse
This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
BIP!Impulse provided by BIP!
0
Average
Average
Average
Green