Hybrid Federated Learning Framework for APT Attack Chain Detection and Privacy Enhancement

Abstract

To address the issues of cross-domain data privacy protection and collaborative analysis in the detection of Advanced Persistent Threat (APT) attack chains, this paper proposes an APT attack collaborative detection and privacy enhancement method based on hybrid federated learning. This method constructs a two-layer federated learning framework of horizontal cross-organization collaboration and vertical multi-feature fusion, realizing the deep fusion of multi-source threat intelligence under the premise of privacy protection. By designing an adaptive differential privacy mechanism and dynamically optimizing the noise addition strategy, it minimizes the loss of model performance while guaranteeing data security. At the same time, this paper introduces a time-series graph neural network detection model to achieve accurate perception and correlation analysis of multi-stage behaviors of APT attacks. The experimental results demonstrate that HybridFL-APT achieves a macro-averaged F1-score of 0.914 and an attack stage identification accuracy of 0.867. Compared to the standard FedAvg algorithm, the proposed framework reduces the cumulative communication overhead by 30.9% while maintaining robust privacy protection even at a strict privacy budget (ε=0.1).

References

[1] SiJung Kim, DoEun Cho, SangSoo Yeo. Secure model against APT in m-connected SCADA network. International Journal of Distributed Sensor Networks, 2014, 10. DOI: 10.1155/2014/594652

[2] Yazhou Du, Weiwu Ren, Wenjuan Li, et al. GA-ConvE: An APT attack prediction method based on combination of graph attention network and 2D convolution. Neural Networks, 2025: 108216. DOI: 10.1016/j.neunet.2025.108216

[3] Rabia Khan, Noshina Tariq, Muhammad Ashraf, et al. FL-DSFA: Securing RPL-based IoT networks against selective forwarding attacks using federated learning. Sensors, 2024, 24(17). DOI: 10.3390/s24175834

[4] Wudu Bitew Alemayew, Ketema Adere Gemeda. Federated hybrid deep learning for multi-attack detecti

on and classification in RPL-based 6LoWPAN networks. Discover Computing, 2025, 28(1): 1-35. DOI: 10.1007/s10791-025-09852-3

[5] Rashmi Verma, Manisha Jailia. A hybrid metaheuristic federated learning approach-based attack detection system for multi-cloud environment. Journal of Cloud Computing, 2025, 14(1): 1-22. DOI: 10.1186/s13677-025-00797-y

[6] Alessio Sacco, Doriana Monaco, Guido Marchetto, Paolo Montuschi. Dealing with challenged IoT networks in hierarchical federated learning. IEEE Internet of Things Journal, 2025: 12(18):36979-36992. DOI: 10.1109/JIOT.2025.3580627

[7] Xiaoming Wang, Zhiquan Liu, Mingzhen Dai, et al. A verifiable and efficient chained federated learning scheme for privacy protection. Computer Networks, 2025: 111838. DOI: 10.1016/j.comnet.2025.111838

[8] Xiang Chen, Dun Zhang, Zhanqi Cui, et al. DP-Share: Privacy-preserving software defect prediction model sharing through differential privacy. Journal of Computer Science and Technology, 2019, 34(5): 1020-1038. DOI: 10.1007/s11390-019-1958-0

[9] Lixin Cui, Xu Wu. ALDP-FL for adaptive local differential privacy in federated learning. Scientific Reports, 2025, 15(1): 1-18. DOI: 10.1038/s41598-025-12575-6

[10] Debao Wang, Shaopeng Guan. FedFR-ADP: Adaptive differential privacy with feedback regulation for robust model performance in federated learning. Information Fusion, 2025, 116: 102796. DOI: 10.1016/j.inffus.2024.102796

[11] G Hemanth Kumar, Sivananda Lahari Reddy Elicherla, Sugandha Saxena, et al. FL-DPCSA: Federated learning with differential privacy for cache side-channel attack detection in edge-based smart grids. E-PRIME: Advances in Electrical Engineering, 2025. DOI: 10.1016/j.prime.2025.101057

[12] George Alter, Brett Hemenway Falk, Steve Lu, et al. Computing statistics from private data. Data Science Journal, 2018, 17. DOI: 10.5334/dsj-2018-031

[13] Tayyab Rehman, Noshina Tariq, Farrukh Aslam Khan, et al. FFL-IDS: A fog-enabled federated learning-based intrusion detection system to counter jamming and spoofing attacks for the Industrial internet of things. Sensors, 2024, 25(1). DOI: 10.3390/s25010010

[14] Rong Xie, Zhong Chen, Weiguo Cao, et al. Federated self-expanding neural network learning framework for heterogeneous devices. Expert Systems with Applications, 2026: 131199. DOI: 10.1016/j.eswa.2026.131199

[15] Madhuri Gadwal, Atul Negi. A lean discriminative nonlinear federated dictionary learning method. Engineering Applications of Artificial Intelligence, 2026, 167: 113862. DOI: 10.1016/j.engappai.2026.113862

[16] Haoyu Jiang, Xiaoliang Chen, Duoqian Miao, et al. PrivTSAD-FedWGAN: A novel federated learning and WGAN framework for privacy-preserving multivariate time series anomaly detection. Expert Systems with Applications, 2026: 131049. DOI: 10.1016/j.eswa.2025.131049

[17] Jiayuan Chen, Tiantian Zhu, Zhengqiu Weng, et al.SLATSCOG: A secure authentication framework via federated data generation and temporally-enhanced split learning. Knowledge-Based Systems, 2026: 115304. DOI: 10.1016/j.knosys.2026.115304

[18] Jie Niu, Runqi He, Qiyao Zhou, et al. Adaptive differential privacy Cox-MLP model based on federated learning. Mathematics, 2025, 13(7). DOI: 10.3390/math13071096

[19] Sanxiu Jiao, Lecai Cai, Xinjie Wang, et al. A differential privacy federated learning scheme based on adaptive gaussian noise. CMES-Computer Modeling in Engineering & Sciences, 2024, 138(2): 1679-1694. DOI: 10.32604/cmes.2023.030512

[20] Yanjin Cheng, Wenmin Li, Sujuan Qin, et al. Differential privacy federated learning based on adaptive adjustment. CMC-Computers Materials & Continua, 2025, 82(3): 4777-4795. DOI: 10.32604/cmc.2025.060380

[21] Jing Rong, Qiuzhan Zhou, Huinan Wu. A hybrid federated learning framework for enhancing privacy and bobustness in non-intrusive load monitoring. Sensors, 2026. DOI: 10.3390/s26020443

[22] Amjad Rehman, Kamran Ahmad Awan, Amal Al-Rasheed, et al. A novel hybrid fuzzy logic and federated learning framework for enhancing cybersecurity and fraud detection in IoT-enabled metaverse transactions. Egyptian informatics Journal, 2025, 30. DOI: 10.1016/j.eij.2025.100668

[23] Boulkroune, A., Boubellouta, A., Bouzeriba, A. et al. Practical Finite-Time Fuzzy Synchronization of Chaotic Systems with Non-Integer Orders: Two Chatte

ring-Free Approaches. J. Syst. Sci. Syst. Eng. 34, 334

359 (2025). DOI: 10.1007/s11518-024-5635-7

[24] Rigatos, G., Abbaszadeh, M., Busawon, K., Dala, L., Pomares, J., and Zouari, F. (December 6, 2023). "Flatness-Based Control in Successive Loops for Autonomous Quadrotors." ASME. J. Dyn. Sys., Meas., Control. March 2024; 146(2): 024501. DOI: 10.1115/1.4063907

[25] Rigatos, G., Siano, P., Zouari, F. et al. Nonlinear optimal control of autonomous submarines diving. Mar Syst Ocean Technol 15, 57 69 (2020). DOI: 10.1007/s40868-019-00070-3

[26] Rigatos, G. et al. Flatness-based control in successive loops for dual-arm robotic manipulators. 2024 IEEE Conference on Control Technology and Applications (CCTA). IEEE, (2024). DOI: 10.1109/CCTA60707.2024.10666567

[27] G. Rigatos, P. Siano, F. Zouari and S. Ademi, "A nonlinear optimal control methoc for autonomous submarines' diving," 2017 IEEE 26th International Symposium on Industrial Electronics (ISIE), Edinburgh, UK, 2017, pp. 1061-1066, DOI: 10.1109/ISIE.2017.8001393.

[28] Zouari, F., Mahmud, M. (2026). Neural Network-Based Robust Adaptive Output Feedback Control for MIMO Time-Varying Delay Systems. In: Mahmud, M., Pillay, N., Kaiser, M.S. (eds) Applications of Artificial Intelligence and Data Science. AAIDS 2024. Communications in Computer and Information Science, vol 2601. Springer, Cham. DOI: 10.1007/978-3-031-98498-3_5

Authors

  • Jie Ji College of Information Engineering, Yangzhou Polytechnic Institute
  • Shi Qiu Polytechnic Institute, Yangzhou 225127, China
  • Shengpeng Ye Yangzhou Polytechnic Institute, Yangzhou 225127, China
  • Xin Liu Yangzhou Polytechnic Institute, Yangzhou 225127, China

DOI:

https://doi.org/10.31449/inf.v50i2.13646

Downloads

Published

08/04/2026

Issue

Section

Regular papers

How to Cite

Ji, J., Ye, S., & Liu, X. (2026). Hybrid Federated Learning Framework for APT Attack Chain Detection and Privacy Enhancement (S. Qiu, Trans.). Informatica, 50(2). https://doi.org/10.31449/inf.v50i2.13646