AEGIS-FL: Auditable Federated Threat Detection for Multi-Tenant Cloud-Edge Systems

Main Article Content

Kesavan Sundara Mudaliyar
S. Satish Kumar

Abstract

Multi-tenant hybrid cloud and edge infrastructures generate security telemetry that is individually sparse and collectively informative, but contractual, regulatory, and competitive barriers prevent tenants from pooling it. Federated learning offers a route around this obstacle, yet deployments in adversarial security settings must simultaneously resist model poisoning by participating tenants, provide auditable evidence of what each tenant contributed, bound the information leaked about tenant-local data, and translate detections into containment actions. Existing work addresses these requirements in isolation. We present AEGIS-FL, a four-plane architecture that couples DataOps-oriented governance, privacy-preserving federated training, a permissioned audit ledger, and a reinforcement-learned response controller, and we evaluate the planes jointly rather than separately. The central mechanism is a ledger-anchored aggregation rule in which per-tenant reputation, persisted across rounds on the audit ledger, sets an adaptive screening budget for a geometric (multi-Krum) filter. This removes the dependence on oracle knowledge of the adversary fraction that, we show, silently inflates reported robustness in the standard experimental protocol. On a controlled 100-tenant simulation with label-skewed partitions, AEGIS-FL reaches F₁ = 0.811 ± 0.017 against 0.790 ± 0.048 for FedAvg and 0.259 ± 0.005 for isolated per-tenant training and sustains F₁ = 0.799 under 10% sign-flipping adversaries where FedAvg falls to 0.740. Secure aggregation reconstructs the plaintext mean exactly under 30% tenant dropout at 19.2 kB per tenant per round, and the audit ledger commits at 19.6 kB per round with seven-hash Merkle inclusion proofs. We report three cautionary findings that qualify the deployment envelope. First, client-level differential privacy at this federation scale cannot reach a meaningful budget: ε ≈ 103 costs 4.0 F₁ points, while ε ≈ 7 destroys utility (F₁ = 0.308). Second, contrary to our own hypothesis, reducing model dimensionality does not recover private utility, because capacity losses offset noise reduction. Third, a loss-threshold membership-inference attack achieves AUC = 0.502 even without noise, so the empirical privacy benefit of the noise mechanism is not demonstrable in this regime. We argue these results indicate that participant scale, not noise calibration or model compression, is the binding constraint on private federated security analytics.

Article Details

How to Cite
Mudaliyar, K. S., & Kumar, S. S. (2026). AEGIS-FL: Auditable Federated Threat Detection for Multi-Tenant Cloud-Edge Systems. The Eastasouth Journal of Information System and Computer Science, 4(01), 101–121. https://doi.org/10.58812/esiscs.v4i01.1217
Section
Articles

References

[1] N. Das et al., “A Privacy-Preserving Federated Intrusion Detection System Leveraging Secure Multi-Party Computation Across Collaborative Cloud Tenants,” in International Conference on Computing and Communication Networks, Springer, 2025, pp. 488–504.

[2] N. Das et al., “AI-enhanced privacy preservation using homomorphic federated models,” in 2025 1st International Conference on Advancement in Futuristic Technologies (ICAFT), IEEE, 2025, pp. 1–8.

[3] S. M. Orthi et al., “Federated learning with privacy-preserving big data analytics for distributed healthcare systems,” J. Comput. Sci. Technol. Stud., vol. 7, no. 8, pp. 269–281, 2025.

[4] U. Haldar et al., “Blockchain-driven access control and compliance auditing framework for federated cloud service providers: Architecture, prototype and evaluation,” in International Conference on Computing and Communication Networks, Springer, 2025, pp. 464–487.

[5] P. Chakraborty et al., “Trustworthy data lakehouse design using federated learning and blockchain,” in 2025 1st International Conference on Advancement in Futuristic Technologies (ICAFT), IEEE, 2025, pp. 1–8.

[6] S. N. Hasan et al., “Self-healing cybersecurity systems using RL agents,” in 2025 1st International Conference on Advancement in Futuristic Technologies (ICAFT), IEEE, 2025, pp. 1–8.

[7] A. Shan-A-Alahi et al., “Deep Learning-Based Threat Prediction and Autonomous Response Mechanisms for Containerized Microservices in Hybrid Cloud Deployments,” in International Conference on Computing and Communication Networks, Springer, 2025, pp. 529–554.

[8] S. M. Orthi et al., “DataOps-oriented big data governance for automated decision pipelines,” in 2025 1st International Conference on Advancement in Futuristic Technologies (ICAFT), IEEE, 2025, pp. 1–8.

[9] B. McMahan, E. Moore, D. Ramage, S. Hampson, and B. A. y Arcas, “Communication-efficient learning of deep networks from decentralized data,” in Artificial intelligence and statistics, Pmlr, 2017, pp. 1273–1282.

[10] T. Li, A. K. Sahu, M. Zaheer, M. Sanjabi, A. Talwalkar, and V. Smith, “Federated optimization in heterogeneous networks,” Proc. Mach. Learn. Syst., vol. 2, pp. 429–450, 2020.

[11] P. Kairouz and H. B. McMahan, “Advances and open problems in federated learning,” Found. trends Mach. Learn., vol. 14, no. 1–2, pp. 1–210, 2021.

[12] K. Bonawitz et al., “Practical secure aggregation for privacy-preserving machine learning,” in proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, 2017, pp. 1175–1191.

[13] P. Paillier, “Public-key cryptosystems based on composite degree residuosity classes,” in International conference on the theory and applications of cryptographic techniques, Springer, 1999, pp. 223–238.

[14] C. Dwork and A. Roth, “The algorithmic foundations of differential privacy,” Found. trends® Theor. Comput. Sci., vol. 9, no. 3–4, pp. 211–487, 2014.

[15] M. Abadi et al., “Deep learning with differential privacy,” in Proceedings of the 2016 ACM SIGSAC conference on computer and communications security, 2016, pp. 308–318.

[16] I. Mironov, “Rényi differential privacy,” in 2017 IEEE 30th computer security foundations symposium (CSF), IEEE, 2017, pp. 263–275.

[17] H. B. McMahan, D. Ramage, K. Talwar, and L. Zhang, “Learning differentially private recurrent language models,” arXiv Prepr. arXiv1710.06963, 2017.

[18] P. Blanchard, E. M. El Mhamdi, R. Guerraoui, and J. Stainer, “Machine learning with adversaries: Byzantine tolerant gradient descent,” Adv. Neural Inf. Process. Syst., vol. 30, 2017.

[19] D. Yin, Y. Chen, R. Kannan, and P. Bartlett, “Byzantine-robust distributed learning: Towards optimal statistical rates,” in International conference on machine learning, Pmlr, 2018, pp. 5650–5659.

[20] M. Castro and B. Liskov, “Practical byzantine fault tolerance,” in OsDI, 1999, pp. 173–186.

[21] R. C. Merkle, “A digital signature based on a conventional encryption function,” in Conference on the theory and application of cryptographic techniques, Springer, 1987, pp. 369–378.

[22] A. Shan-A-Alahi, M. S. Sikder, H. U. Himel, M. T. Bin Ansar, M. K. Tuhin, and H. Kaur, “Resilient Cybersecurity Architectures for Large-Scale Distributed Systems,” in 2026 IEEE International Conference for Convergence in Computing Technology (I3CTCON), IEEE, 2026, pp. 1–8.

[23] K. B. Siddiqa et al., “Assessment of survivability and importance analysis for networks managing intricate traffic flows,” IEEE Commun. Stand. Mag., 2025.

[24] M. R. H. Mahin et al., “Secured and standardized intelligent zero-touch 6G framework for edge-AI applications,” IEEE Commun. Stand. Mag., 2026.

[25] S. R. Varanasi, S. S. S. Valiveti, M. Adnan, M. I. Faruk, M. J. Hossain, and M. M. T. G. Manik, “Cross-Domain standardization and secure edge intelligence for Real-Time digital twin deployments in Next-Generation communication systems,” IEEE Commun. Stand. Mag., 2026.

[26] R. Shokri, M. Stronati, C. Song, and V. Shmatikov, “Membership inference attacks against machine learning models,” in 2017 IEEE symposium on security and privacy (SP), IEEE, 2017, pp. 3–18.

[27] A. Shamir, “gHow to share a secret,• h Commun,” 1979, ACM.

[28] C. J. C. H. Watkins and P. Dayan, “Q-learning,” Mach. Learn., vol. 8, no. 3, pp. 279–292, 1992.