Federated AI-Driven Intrusion Detection Framework for DDoS Mitigation in Cloud Networks
Keywords:
Federated Learning, Artificial Intelligence, DDoS Detection, Cloud SecurityAbstract
The rapid expansion of cloud computing infrastructures has intensified exposure to distributed denial-of-service (DDoS) attacks, creating significant challenges for service availability, security resilience, and operational continuity. Traditional centralized intrusion detection approaches often face limitations related to data privacy, communication overhead, scalability, and delayed threat response. This research presents a Federated AI-Driven Intrusion Detection Framework for DDoS Mitigation in Cloud Networks that integrates federated learning principles with intelligent anomaly detection mechanisms to enable decentralized and privacy-preserving security operations. The proposed framework distributes model training across cloud nodes while maintaining local data ownership, allowing collaborative threat intelligence generation without transferring sensitive network information. The research conceptually combines deep learning-based attack recognition, adaptive federated aggregation, and edge-enabled security intelligence for improving real-time DDoS detection capabilities. Existing studies demonstrate the effectiveness of artificial intelligence and federated learning in identifying network anomalies; however, challenges remain regarding communication efficiency, model adaptability, and cross-domain security coordination. The proposed framework addresses these limitations by introducing a collaborative security architecture capable of learning from heterogeneous cloud environments. The analysis highlights that federated AI-based intrusion detection can improve scalability, privacy preservation, and proactive defense against evolving DDoS attack patterns. The framework also aligns with emerging secure edge intelligence paradigms where distributed intelligence supports reliable next-generation communication systems (Varanasi et al., 2026). The findings indicate that federated AI security models provide a promising direction for developing resilient cloud infrastructures with enhanced autonomous threat mitigation capabilities.
References
1. D. M. A. A. Afraji, J. Lloret, and L. Pe ̃nalver, “Deep learning-driven defense strategies for mitigating DDoS attacks in cloud computing environments,” Cyber Secur. Appl., vol. 3, p. 100085, 2025.
2. M. Alauthman, A. Almomani, M. Alarqan, B. Belaton, M. Al-Betar, and V. Arya, “Information theory-based DDoS attack detection in cloud computing: a systematic survey of approaches, challenges, and future directions,” Int. J. Cloud Appl. Comput., vol. 15, no. 1, pp. 1–38, 2025.
3. Y. Alhasawi and S. Alghamdi, “Federated learning for decentralized DDoS attack detection in IoT networks,” IEEE Access, vol. 12, pp. 42357–42368, 2024.
4. M. Asad, S. Shaukat, D. Hu, Z. Wang, E. Javanmardi, J. Nakazato, and M. Tsukada, “Limitations and future aspects of communication costs in federated learning: a survey,” Sensors, vol. 23, no. 17, p. 7358, 2023.
5. F. J. Abdullayeva, “Distributed denial of service attack detection in E-government cloud via data clustering,” Array, vol. 15, p. 100229, 2022.
6. R. Doriguzzi-Corin and D. Siracusa, “FLAD: adaptive federated learning for DDoS attack detection,” arXiv preprint arXiv:2205.06661, 2022.
7. B. Ghimire and D. B. Rawat, “Recent advances in federated learning for cybersecurity and cybersecurity for the internet of things,” IEEE Internet Things J., vol. 9, no. 11, pp. 8229–8249, 2022.
8. G. Kirubavathi, I. R. Sumathi, J. Mahalakshmi, and D. Srivastava, “Detection and mitigation of TCP-based DDoS attacks in cloud environments using a self-attention and intersample attention transformer model,” J. Supercomput., vol. 81, no. 3, p. 474, 2025.
9. S. Kumar, M. Dwivedi, M. Kumar, and S. S. Gill, “A comprehensive review of vulnerabilities and AI-enabled defense against DDoS attacks for securing cloud services,” Comput. Sci. Rev., vol. 53, p. 100661, 2024.
10. M. Ouhssini, K. Afdel, M. Akouhar, E. Agherrabi, and A. Abarda, “Advancements in detecting, preventing, and mitigating DDoS attacks in cloud environments: a comprehensive systematic review of state-of-the-art approaches,” Egypt. Inform. J., vol. 27, p. 100517, 2024.
11. Kishore Subramanya Hebbar, Jaykumar Ambadas Maheshkar, “Intelligent Ml-Based Workload Placement In Hybrid Clouds: Optimizing Cost And Sla In Modernized Systems”, AS, vol. 27, no. 1, pp. 84–101, Dec. 2025, doi: 10.22178/acta.27.1.8
12. S. R. Varanasi, S. S. S. Valiveti, M. Adnan, M. I. Faruk, M. J. Hossain and M. M. T. G. Manik, "Cross-Domain Standardization and Secure Edge Intelligence for Real-Time Digital Twin Deployments in Next-Generation Communication Systems," in IEEE Communications Standards Magazine, doi: 10.1109/MCOMSTD.2026.3662187.