Cross-Silo Federated Learning in Security Operations Centers for effective malware detection

2Citations
Citations of this article
17Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Effective malware detection is a key priority for Security Operations Centers (SOC). Machine learning (ML) has emerged as a very powerful tool, widely adopted by many malware detection systems. ML models require extensive and high-quality data to perform well. SOCs are often dependent on their proprietary datasets for training and face challenges to obtain sufficient data, due to privacy and Intellectual Property (IP) concerns, limiting their malware detection capabilities. To address these challenges, this paper introduces the adoption of Cross-Silo Federated Learning (FL), a ML technique that enables different participating SOCs to collaboratively train ML malware detection models without explicitly sharing their private data. The deployment of two distinct FL setups, namely Horizontal Federated Learning (HFL) and Vertical Federated Learning (VFL), is explored to address data sample and feature sharing limitations, respectively. The effectiveness of the proposed architectures is evaluated against two large openly available benchmark datasets and compared to conventional Centralized Learning. Finally, a concrete compelling incentive for SOCs to participate in such federations is provided.

Cite

CITATION STYLE

APA

Xenos, G., & Serpanos, D. (2025). Cross-Silo Federated Learning in Security Operations Centers for effective malware detection. International Journal of Information Security, 24(4). https://doi.org/10.1007/s10207-025-01101-4

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free