Loading... Loading...
Grenze Logo
GRENZE International Journal of Engineering and Technology Vol. 12 (2026), Issue 1

Federated Learning-Enhanced Graph Neural Networks for Privacy-Preserving Cybersecurity Threat Detection

Authors

Durgashree N, Ranjan, Devraj MM, V. Srinivasan, Jayanthi R

Abstract

In today’s digital age, the landscape of cyber threats is growing increasingly complex and sophisticated, demanding innovative and secure methods for detecting malicious activities. Conventional Intrusion Detection Systems (IDS) typically rely on centralized models, which, while effective to some extent, pose significant risks to user data privacy and often struggle to adapt swiftly to novel attack patterns. To overcome these limitations, we propose a Federated Learning-Enhanced Graph Neural Network (FL-GNN) framework that combines the strengths of decentralized learning and graph-based anomaly detection. This approach allows for model training across distributed data sources without the need to share sensitive raw data, thus preserving user privacy. In our architecture, Graph Neural Networks (GNNs) are utilized to analyze the structural and relational aspects of network traffic, enabling more accurate identification of abnormal patterns. We incorporate differential privacy techniques to safeguard individual data contributions during federated model updates, ensuring a strong layer of privacy protection. Additionally, adversarial training is implemented to improve the model’s resilience against evasion tactics employed by attackers. We evaluate our framework using well-established datasets—CICIDS2017 and NSL-KDD—and demonstrate significant improvements in detection accuracy (94%) and a substantial reduction in false positives (4%). Our study further investigates the trade-off between privacy and model performance by analyzing the impact of different privacy budgets. Comparative analysis with traditional IDS methods shows that our FL-GNN framework not only enhances detection capability but also achieves scalability, robustness, and privacy preservation, making it a compelling choice for real-world cybersecurity deployments.