The increasing adoption of distributed infrastructure systems, cloud computing, Internet of Things (IoT) technologies, and edge-based architectures has significantly expanded the cybersecurity attack surface and introduced increasingly sophisticated cyber threats. Conventional centralized intrusion detection approaches often face challenges related to scalability, data privacy, communication overhead, and limited transparency in artificial intelligence-driven decision-making processes. To address these limitations, this study proposes a Cognitive Threat Intelligence and Explainable Federated Security Analytics framework for distributed infrastructure systems. The proposed framework integrates Federated Learning (FL), Explainable Artificial Intelligence (XAI), and cognitive cybersecurity analytics to enable collaborative and privacy-preserving cyber threat detection across distributed network environments. Instead of transmitting sensitive raw network traffic data to centralized servers, local security models are independently trained at distributed nodes, where only encrypted model parameters and updates are shared through a federated aggregation mechanism. This decentralized learning architecture improves privacy protection while reducing communication dependency and centralized security risks. To enhance intelligent threat analysis, the framework incorporates machine learning and deep learning algorithms including Random Forest, XGBoost, Autoencoder
翻译:随着分布式基础设施系统、云计算、物联网(IoT)技术以及边缘架构的广泛采用,网络安全攻击面显著扩大,同时引入了日益复杂的网络威胁。传统的集中式入侵检测方法在扩展性、数据隐私、通信开销以及人工智能驱动决策过程中的透明度不足等方面面临挑战。为解决这些局限性,本研究提出了一种面向分布式基础设施系统的认知威胁情报与可解释联邦安全分析框架。该框架融合了联邦学习(FL)、可解释人工智能(XAI)和认知网络安全分析技术,能够在分布式网络环境中实现协作式且隐私保护的网络威胁检测。原始敏感网络流量数据无需传输至集中服务器,而是由分布式节点独立训练本地安全模型,仅通过联邦聚合机制共享加密后的模型参数与更新。这种去中心化学习架构在减少通信依赖与集中式安全风险的同时,提升了隐私保护能力。为增强智能威胁分析性能,本框架整合了机器学习与深度学习算法,包括随机森林、XGBoost与自编码器。