Full text
Corresponding author: Kigbu Shallom Copyright © 2025 Author(s) retain the copyright of this article. This article is published under the terms of the Creative Commons Attribution Liscense 4.0. Enhancing malware detection using federated learning and explainable AI for privacy-preserving threat intelligence Kigbu Shallom 1, * and Chukwujekwu Damian Ikemefuna 2 1 Department of Computer Science, University of Illinois at Springfield, USA. 2 Department of Cybersecurity, American National University, Kentucky Campus, USA. World Journal of Advanced Research and Reviews, 2025, 27(01), 331-351 Publication history: Received on 18 May 2025; revised on 30 June 2025; accepted on 03 July 2025 Article DOI: https://doi.org/10.30574/wjarr.2025.27.1.2541 Abstract The escalating complexity and frequency of malware attacks pose a significant challenge to conventional cybersecurity frameworks, particularly in scenarios demanding high data privacy and cross-organizational threat intelligence sharing. Traditional centralized machine learning models for malware detection often rely on aggregating data in a central server, thereby increasing the risk of data breaches and limiting the deployment of models in privacy-sensitive environments such as healthcare, finance, and critical infrastructure. To address these limitations, this study explores an integrated approach that combines Federated Learning (FL) with Explainable Artificial Intelligence (XAI) for enhancing malware detection while preserving user privacy and system confidentiality. Federated learning enables the collaborative training of robust malware classifiers across multiple decentralized nodes without sharing raw data, thus maintaining local data sovereignty and complying with data protection regulations. The proposed framework incorporates deep learning architectures such as convolutional neural networks (CNNs) trained in a federated environment using feature vectors extracted from malicious binaries and behavior logs. To ensure transparency and trust in model predictions, explainable AI techniques specifically SHAP (SHapley Additive exPlanations) and LIME (Local Interpretable Model-agnostic Explanations) are integrated, providing actionable insights into the model’s decision-making process. This study also presents a comprehensive evaluation using a benchmark malware dataset distributed across simulated client environments, measuring detection accuracy, communication overhead, privacy leakage, and interpretability performance. Results demonstrate that the FL-XAI approach achieves detection rates comparable to centralized models while ensuring data confidentiality and interpretability. The research contributes to the evolving field of privacy-preserving threat intelligence by offering a scalable and explainable framework suitable for real-time cybersecurity applications. Keywords: Federated Learning; Explainable AI; Malware Detection; Privacy Preservation; Threat Intelligence; Model Interpretability 1. Introduction 1.1. The Evolving Malware Landscape and the Need for Advanced Detection The proliferation of malware has undergone a marked evolution, transitioning from simplistic viruses to sophisticated, polymorphic threats capable of evading traditional detection mechanisms. As global connectivity has expanded, so too has the attack surface, giving rise to malware strains tailored for industrial espionage, ransomware-as-a-service, and autonomous propagation across distributed networks [1]. These threats exploit both technical vulnerabilities and human behavior, embedding themselves in diverse systems, from mobile devices to critical infrastructure platforms.
World Journal of Advanced Research and Reviews, 2025, 27(01), 331-351 332 Recent variants employ advanced evasion techniques, including code obfuscation, sandbox detection avoidance, and behavior masking, which allow them to bypass signature-based defenses [2]. Malware authors are also leveraging machine learning to adapt payload behavior in real-time, making threat detection an increasingly dynamic challenge. This evolving landscape calls for detection systems that not only identify known threats but also anticipate and respond to previously unseen attack vectors. The rapid growth of Internet of Things (IoT) devices and edge computing environments has further exacerbated the challenge. These devices typically lack the processing power and memory to run traditional antivirus software, making them attractive entry points for malware campaigns [3]. Additionally, the use of peer-to-peer propagation models and fileless attack vectors reduces the efficacy of central control systems. Against this backdrop, there is an urgent need for malware detection strategies that integrate distributed intelligence, behavioral profiling, and context-aware anomaly detection. These strategies must operate in near-real time, adapt to system-specific conditions, and scale across diverse network topologies [4]. Consequently, the focus has shifted toward decentralized and federated models of threat detection that leverage collective learning without compromising system autonomy. This evolution sets the stage for rethinking detection architectures, driving a paradigm shift from centralized controls to distributed, intelligent defense mechanisms capable of operating across heterogeneous environments [5]. 1.2. Limitations of Traditional Centralized Malware Detection Approaches Traditional malware detection systems, particularly those based on centralized architectures, are increasingly struggling to address the speed, scale, and sophistication of modern threats. Centralized models rely heavily on continuous data aggregation to a singular control point, where analysis is performed using predefined heuristics or static signatures [6]. While effective in detecting well-known malware strains, such systems often falter when faced with zero-day exploits or polymorphic code that evolves faster than threat databases can be updated. Another critical limitation lies in latency and scalability. The requirement to route large volumes of data to centralized detection engines introduces delay, particularly in geographically dispersed networks [7]. For mission-critical or latency-sensitive applications, this delay can undermine real-time threat mitigation efforts. Additionally, centralized systems may become performance bottlenecks or single points of failure during high-volume attack scenarios or infrastructure outages. Moreover, centralized solutions are ill-suited for edge environments such as IoT networks and mobile ecosystems, where bandwidth is constrained and device diversity is high [8]. The inability to deploy comprehensive security agents on resource-limited devices often results in blind spots, making them prime targets for attackers. Privacy concerns also constrain the viability of centralized malware detection in regulated environments. Aggregating user data, system logs, or telemetry to a central repository often conflicts with data sovereignty and compliance requirements, particularly in sectors like healthcare and finance [9]. These limitations highlight the growing need to reimagine malware detection models—moving toward decentralized frameworks that preserve detection fidelity while addressing latency, scalability, and privacy constraints [10]. 1.3. Objectives, Scope, and Structure of the Study This study aims to explore the efficacy, feasibility, and design considerations of distributed malware detection frameworks tailored for modern enterprise and edge ecosystems. Recognizing the inadequacies of centralized approaches, it seeks to define a holistic model that integrates federated threat intelligence, autonomous anomaly detection, and real-time behavioral analytics in a scalable, privacy-preserving architecture [11]. The core objective is to delineate a comprehensive reference architecture that aligns with evolving operational demands, system heterogeneity, and security policy granularity. By analyzing current research, prototyped systems, and applied use cases, the study provides an evidence-based roadmap for transitioning from monolithic detection engines to agile, distributed systems that can operate seamlessly across cloud, on-premise, and edge layers [12]. In terms of scope, the study spans multiple detection vectors including endpoint behavior analysis, network traffic monitoring, and system call tracing. It incorporates insights from fields such as machine learning, distributed
World Journal of Advanced Research and Reviews, 2025, 27(01), 331-351 333 computing, federated learning, and zero trust security models. Emphasis is placed on architectural modularity, interoperability, and response orchestration mechanisms [13]. Structurally, the paper begins with a review of related work and underlying theoretical models, followed by an analysis of key design requirements for distributed detection. Subsequent sections propose a federated detection architecture, present deployment scenarios, and evaluate performance metrics using simulated threat environments. Figure and table inclusions offer visual and comparative support for the core propositions. The conclusion synthesizes strategic recommendations and identifies future research directions [14]. This structure ensures coherence across conceptual foundations, practical implementation, and evaluative insights facilitating both academic inquiry and operational application. 2. Theoretical Foundations 2.1. Overview of Federated Learning in Security Contexts Federated learning (FL) introduces a decentralized model training paradigm that enables multiple clients—ranging from edge devices to distributed enterprise nodes—to collaboratively build machine learning models without sharing raw data. Instead, each client trains a local model on its data and only shares model parameters or gradients with a central aggregator, thus preserving data locality and privacy [6]. In cybersecurity contexts, particularly malware detection, FL offers an innovative solution to the longstanding trade-off between detection effectiveness and data confidentiality. The conventional approach of aggregating user telemetry in centralized repositories for training models is increasingly restricted due to data protection regulations and institutional privacy policies. FL mitigates these limitations by allowing model updates to be exchanged instead of sensitive logs or binary samples [7]. This architecture is particularly valuable in industries such as healthcare, finance, and defense, where threat intelligence must be generated from diverse environments without exposing confidential data. The FL workflow typically follows an iterative cycle: initialization of a global model, local training on decentralized nodes, communication of model updates, aggregation at the server level, and distribution of the updated model. Variants such as FedAvg and FedProx introduce enhancements to ensure stability and fairness across heterogeneous clients with varying computational capacities and data distributions [8]. In malware detection, FL can be applied across multiple endpoints each observing a different spectrum of behavioral patterns and malware signatures. This diversity enriches the learned model while mitigating exposure of proprietary datasets. Moreover, adversarial robustness can be improved through client diversity, as attacks designed for a specific environment may not generalize across all participating nodes [9]. However, FL is not without challenges. Communication overhead, model drift, and vulnerability to poisoning attacks necessitate robust coordination and security layers. Despite these, FL represents a critical step toward democratizing and decentralizing threat detection in a privacy-preserving manner [10]. 2.2. Explainable AI and its Role in Malware Classification Explainable artificial intelligence (XAI) has become an essential component of cybersecurity analytics, offering interpretability to complex machine learning models used for malware classification. While deep learning classifiers such as CNNs and transformers achieve high accuracy, their opaque decision-making processes limit trust and hinder operational deployment in security-critical environments [11]. XAI techniques bridge this gap by making models more transparent and their outputs more understandable to human analysts. Two widely adopted model-agnostic techniques in this context are SHapley Additive exPlanations (SHAP) and Local Interpretable Model-agnostic Explanations (LIME). SHAP assigns a contribution value to each feature in a prediction based on game-theoretic principles, making it ideal for ranking important binary characteristics or behavior-based features indicative of malware [12]. For instance, SHAP can reveal that a particular system call pattern significantly influenced a model's decision to classify a file as malicious, thereby enhancing forensic capabilities. LIME, in contrast, focuses on building local surrogate models around individual predictions to approximate decision boundaries. This is particularly useful when security analysts need to understand why a benign-looking process was
World Journal of Advanced Research and Reviews, 2025, 27(01), 331-351 334 flagged as a threat. By presenting simplified decision rules, LIME facilitates actionable responses and policy adjustments [13]. The benefits of XAI extend beyond interpretability. It enhances compliance with legal frameworks like the GDPR, which emphasize transparency in automated decision-making [14]. Moreover, explainable outputs aid in model debugging, adversarial analysis, and stakeholder confidence-building especially in environments involving non-technical users or risk managers. In malware detection, XAI can identify bias, highlight overfitting, and support the creation of robust, human-in-the-loop systems. Analysts can validate whether models are relying on legitimate behavioral patterns or are being misled by irrelevant correlations. This ensures not just accuracy but also accountability, a critical requirement in threat intelligence workflows [15]. 2.3. Intersection of FL and XAI for Privacy-Preserving Threat Intelligence The convergence of federated learning (FL) and explainable AI (XAI) offers a compelling architecture for malware detection that is both privacy-preserving and interpretable. This integration addresses a long-standing challenge in cybersecurity: building powerful detection systems without compromising user data or obscuring model reasoning. When deployed across decentralized endpoints, FL benefits from XAI’s capacity to demystify local predictions, support differential trust models, and align outputs with operational transparency requirements [16]. At the core of this synergy is the use of localized XAI tools to interpret model behavior on each client node participating in federated training. Since raw data never leaves the device, explainability must be executed locally to provide analysts or automated agents with insights into why a specific file or process is flagged [17]. By embedding lightweight SHAP or LIME modules at the endpoint, each client can independently audit predictions and detect potential biases or anomalies in model evolution. Figure 1 Federated Learning Architecture with Integrated Explainable AI Dashboards Figure 1 illustrates a representative architecture where decentralized clients engage in federated training while maintaining integrated XAI dashboards for human-in-the-loop feedback. These dashboards facilitate model refinement, feature attribution validation, and policy calibration especially critical in dynamically evolving malware environments. Importantly, FL ensures that intelligence gained from local insights is synthesized into a global model, fostering crossorganizational learning without violating data governance norms [18].
World Journal of Advanced Research and Reviews, 2025, 27(01), 331-351 335 Moreover, XAI mitigates a core limitation of FL: lack of visibility into client-level model behavior. This is crucial in highrisk sectors where endpoint behavior must be audited for compliance and security assurance. Transparency at the local level not only builds trust but also helps in filtering poisoned model updates, a known vulnerability in FL systems [19]. Together, FL and XAI create a distributed threat intelligence framework that is explainable, adaptive, and secure. This positions them as foundational technologies for future-ready cybersecurity architectures, where data privacy, regulatory alignment, and operational clarity are non-negotiable requirements [20]. 3. Malware detection challenges in federated settings 3.1. Heterogeneous Data and Non-IID Distributions A major challenge in deploying federated learning (FL) for malware detection is the heterogeneity of data across participating clients. In real-world environments, devices generate local data that is not independent and identically distributed (non-IID). This disparity arises due to user behavior variability, software ecosystems, regional threat landscapes, and system configurations [11]. Consequently, each node observes a distinct malware profile, leading to skewed learning dynamics. Non-IID distributions can degrade the global model’s generalization ability, as parameter updates may conflict across clients. This is especially critical in malware detection, where differences in file formats, system APIs, and attack vectors produce uneven feature importance across training sites [12]. For instance, a corporate network endpoint might encounter ransomware variants distinct from those seen in personal mobile devices, introducing domain-specific learning biases. To address this, researchers have proposed personalization layers, client clustering, and regularization strategies to smooth the disparities. Methods such as federated multi-task learning aim to tailor global parameters to local contexts, thereby improving convergence without sacrificing generality [13]. Moreover, FL frameworks like FedProx explicitly account for heterogeneity by penalizing client updates that deviate significantly from the global objective. Despite these advances, there remains a trade-off between maintaining a unified detection model and capturing the nuances of distributed threat intelligence. Balancing local specificity with cross-client cohesion remains an open research area. This is further complicated by the dynamic nature of malware evolution, where novel behaviors continuously shift data distributions, exacerbating FL training instability [14]. Understanding and mitigating the impact of non-IID data is thus fundamental to making FL robust, fair, and practically viable for decentralized security infrastructures. This necessitates adaptive aggregation protocols that can dynamically weight client contributions based on their data distributions and observed threat typologies [15]. 3.2. Communication Overhead and Model Drift Communication overhead remains a persistent bottleneck in federated learning (FL) frameworks, particularly in decentralized environments where bandwidth and connectivity are constrained. In malware detection, the frequent exchange of model parameters, gradients, or encrypted representations between edge clients and a central aggregator consumes significant network resources [16]. These constraints become more pronounced in large-scale deployments involving thousands of devices, many of which operate in intermittent or low-bandwidth conditions such as rural or mobile nodes. Model updates are typically transmitted in iterative rounds. The cumulative transmission cost of high-dimensional deep learning models can stall real-time responsiveness, which is essential for malware defense systems. Additionally, asynchronous client participation, a common phenomenon in heterogeneous networks, further complicates the update cycle, leading to staleness and inconsistencies in global model synchronization [17]. To alleviate communication strain, strategies such as update compression, sparsification, and adaptive participation scheduling have been explored. Gradient quantization and dropout techniques reduce data size while preserving model utility [18]. However, these techniques must be balanced against the risk of information loss, which can degrade detection accuracy and increase false positives. Closely related is the issue of model drift, where deviations accumulate over time due to client-specific training on evolving malware datasets. As threats evolve, some clients may learn new attack signatures not present in the shared
World Journal of Advanced Research and Reviews, 2025, 27(01), 331-351 336 model, leading to skewed local updates that diverge from global trends [19]. This drift undermines the stability and predictiveness of the federated model, particularly if drift is not uniform across clients. In Table 1, we summarize the main communication and drift-related challenges encountered in decentralized FL-based malware detection systems. It highlights interrelated bottlenecks across the system lifecycle, including update frequency, drift rate, and resource contention. Table 1 Summary of FL-Related Challenges in Decentralized Malware Detection Environments Challenge Category Description Implications Non-IID Data Distributions Variability in data across clients due to different malware types, sources, and logging schemas. Reduces convergence speed and generalization; increases risk of local bias. Communication Overhead High frequency and volume of model updates during training rounds. Slows down learning and strains bandwidth, especially in resource-limited nodes. Model Drift Client models may evolve inconsistently due to data or environmental dynamics. Leads to inconsistent detection performance and misaligned global model weights. Privacy-Accuracy Trade-off Techniques like differential privacy may reduce model interpretability or detection precision. Must carefully balance regulatory needs with operational accuracy requirements. Explainability Constraints XAI methods struggle with high-dimensional binary or encoded malware features. Reduces analyst trust in predictions; affects regulatory transparency. Hardware and Energy Costs Training deep models locally requires significant computational resources. Barriers to deployment in low-power or mobile edge environments. Mitigating model drift requires robust control measures such as periodic reinitialization, drift detection modules, or weighted aggregation schemes that discount outlier updates [20]. Moreover, combining FL with continual learning strategies may offer a promising path toward long-term stability without increasing communication burdens [21]. 3.3. Balancing Privacy, Accuracy, and Interpretability The implementation of federated learning (FL) for malware detection involves a triadic optimization challenge: maintaining data privacy, ensuring high detection accuracy, and preserving model interpretability. These three dimensions are often in tension, particularly in complex cyber environments where trade-offs can impact operational security [22]. Data privacy is the cornerstone of FL, as the paradigm was designed to prevent raw telemetry, binary logs, or file samples from leaving client devices. However, recent studies have demonstrated that shared gradients or model updates can still leak sensitive information through inversion or membership inference attacks [23]. Techniques such as differential privacy (DP) and secure multi-party computation (SMPC) have been introduced to mitigate this risk, though they often reduce model fidelity. Accuracy, on the other hand, is essential for threat detection. Malware classifiers must maintain low false negative rates to ensure reliable protection. The use of local data in FL enhances context awareness but may underrepresent rare or emerging threats if clients lack exposure to them. This affects generalizability and necessitates frequent global retraining or synthetic augmentation [24]. Interpretability is increasingly mandated by regulatory and operational requirements. Security analysts require transparent models to understand decisions, perform audits, and validate alerts. While explainable AI (XAI) techniques like SHAP and LIME support this need, they add computational overhead and may not integrate seamlessly with privacypreserving protocols [25]. Ultimately, no single solution fully reconciles all three imperatives. Hybrid approaches that embed local interpretability modules, apply lightweight privacy guards, and leverage adaptive accuracy thresholds may offer practical compromises. An ideal system would integrate real-time, explainable outputs while respecting data governance constraints and
World Journal of Advanced Research and Reviews, 2025, 27(01), 331-351 337 maintaining robust detection efficacy. Continued research is needed to formalize these trade-offs and develop evaluation metrics that account for security, compliance, and operational performance simultaneously [26]. 4. Model architecture and training strategies 4.1. Design of Federated Convolutional Neural Networks (Fed-CNNs) Federated convolutional neural networks (Fed-CNNs) are increasingly applied to malware detection scenarios that require local feature extraction with centralized model coordination. The appeal of CNNs lies in their ability to autonomously learn hierarchical patterns from executable files, dynamic traces, or binary images without handcrafted feature engineering. In the FL setting, each client trains a local CNN on its native dataset and transmits model updates, rather than raw data, to a central server for aggregation [15]. To maintain generalization across heterogeneous clients, Fed-CNN architectures must be lightweight, modular, and tolerant to class imbalance. Popular base architectures include LeNet, MobileNet, and ResNet, each adapted to edge compute environments via pruning or quantization [16]. These models allow for meaningful malware signature detection across clients with divergent resource profiles. In Figure 2, we depict a Fed-CNN architecture integrated with a SHAP-based explainability layer. The local CNNs learn structural and behavioral patterns of malware, while a separate explainer model maps feature importance, ensuring interpretability without central access to raw input [17]. Figure 2 Federated Convolutional Neural Network (Fed-CNN) architecture integrated with SHAP-based explainability Clients may vary in data volume and threat diversity, hence techniques like local batch normalization and adaptive layer freezing are employed to reduce divergence in local updates. Furthermore, split learning approaches where clients retain shallow CNN layers and only forward deep representations can improve privacy guarantees while preserving accuracy [18]. One challenge in Fed-CNN deployment is communication cost, especially for deeper networks with millions of parameters. To address this, gradient sparsification and weight sharing are used to reduce update bandwidth. Still, preserving convergence and stability remains an ongoing challenge, particularly in highly non-IID distributions [19].
World Journal of Advanced Research and Reviews, 2025, 27(01), 331-351 338 Designing effective Fed-CNNs requires a balance between model complexity, interpretability, and adaptability. When appropriately tailored, these networks serve as a strong foundation for privacy-preserving malware detection in diverse environments [20]. 4.2. Optimization Algorithms: FedAvg, FedProx, and Adaptive Variants Optimization in federated learning (FL) hinges on the effective aggregation of model updates from distributed clients with varying data volumes, distributions, and compute capabilities. The foundational algorithm, Federated Averaging (FedAvg), performs weighted averaging of local model parameters across selected clients to update the global model [21]. Though simple and efficient, FedAvg often struggles with convergence in non-IID settings, especially when clients have unbalanced or disjoint data. To address this, FedProx introduces a proximal term to the local objective function, which penalizes updates that deviate significantly from the global model. This regularization enhances stability by aligning local models more closely to a common reference, thus improving convergence under client heterogeneity [22]. Adaptive variants such as FedNova and Scaffold further refine this approach by compensating for local update biases. FedNova normalizes updates by client participation frequency, while Scaffold uses control variates to counteract update variance induced by non-IID data [23]. These methods enable more robust optimization without necessitating structural changes to local models. Table 2 provides a comparative performance evaluation of these optimization algorithms across malware classification tasks. Accuracy, convergence speed, and communication efficiency are considered across simulated decentralized settings with variable threat profiles. Table 2 Comparison of Optimizer Performance in Malware Classification under FL Settings Optimizer Accuracy (%) F1Score Convergence Speed Stability (Variance Across Rounds) Communication Cost Remarks FedAvg 87.2 0.84 Moderate Medium Low Baseline algorithm; performs well with IIDlike distributions. FedProx 88.6 0.86 Moderate High Low Handles non-IID distributions better; slower convergence. FedAdam 90.1 0.88 Fast Low High Superior accuracy and convergence, but higher bandwidth needs. FedYogi 89.7 0.87 Fast Low Moderate Balances speed and generalization in diverse data scenarios. Scaffold 90.3 0.89 Very Fast Very Low Moderate Reduces client drift significantly; best stability observed. Empirical studies have shown that adaptive optimizers significantly outperform FedAvg in scenarios with extreme class imbalance and evolving threat signatures [24]. Furthermore, these optimizers are particularly effective when deployed alongside data augmentation or client resampling techniques, which help mitigate local overfitting. Still, challenges remain. For example, the trade-off between optimization granularity and communication cost is nontrivial, especially for deep models. More frequent global updates yield faster convergence but incur higher bandwidth usage, which may not be feasible in constrained environments [25].
World Journal of Advanced Research and Reviews, 2025, 27(01), 331-351 339 Ultimately, the selection of an FL optimizer must align with task-specific constraints, including threat complexity, device diversity, and resource availability. Continued algorithmic innovation is essential to make FL scalable and dependable in real-world cybersecurity contexts [26]. 4.3. Integration of Explainability Techniques During and Post-Training As machine learning becomes a cornerstone of malware detection, integrating explainability into federated learning (FL) workflows is crucial for operational transparency, compliance, and trust. Explainable AI (XAI) methods like SHAP (SHapley Additive exPlanations) and LIME (Local Interpretable Model-agnostic Explanations) have been widely adopted in centralized settings, but adapting them to FL presents unique challenges [27]. In decentralized malware detection, SHAP values can be computed locally at each client to highlight which features such as byte sequences, API calls, or entropy patterns contribute most to classification decisions. These local explanations are then aggregated or visualized using differential privacy constraints to ensure anonymity and data protection [28]. Figure 2 illustrates this layered integration of FL and XAI, showing how local explainers interface with a global orchestration layer. During training, model interpretability can be enhanced using attention mechanisms or saliency maps embedded within CNN architectures. This allows clients to generate interpretable signals even without post-hoc analysis. While this adds to computational overhead, it provides real-time insights into model behavior, which is critical for rapid threat response [29]. Post-training, explanation modules can be deployed as diagnostic layers that flag anomalous or low-confidence predictions. These modules can be fine-tuned to reflect evolving threat patterns and client-specific behavior, enabling contextual threat insights without violating data locality principles [30]. Despite their promise, XAI techniques in FL face barriers such as inconsistent feature spaces across clients, computational load on edge devices, and the risk of exposing model vulnerabilities. Researchers are exploring hybrid models that combine interpretable surrogate models (e.g., decision trees) with deep learning for better transparency [31]. Moreover, explainability supports collaborative forensics across institutions, allowing shared understanding of detected malware classes while maintaining data confidentiality. Integrating explainability into FL workflows transforms malware classifiers from black boxes into actionable tools for analysts, auditors, and policymakers alike [32]. 4.4. Data Encoding and Feature Extraction from Executables and Logs The accuracy and robustness of federated malware detection systems depend heavily on how raw data especially executables and log files is encoded into machine-readable features. Malware detection typically uses static, dynamic, or hybrid analysis methods. Static analysis examines features extracted without execution, such as byte entropy, control flow graphs, or import tables. In contrast, dynamic analysis captures runtime behavior such as API call sequences, registry changes, and memory usage patterns [33]. In FL settings, feature extraction must occur locally, and the resulting representations must be compact, privacypreserving, and semantically consistent across clients. Common encoding strategies include byte-level n-grams, opcode sequences, and graph-based embeddings derived from abstract syntax trees or function call graphs [34]. Logs may be tokenized into temporal event vectors or categorical key-value pairs. Effective feature normalization is essential to ensure uniform contribution across clients. Without centralized preprocessing, inconsistencies in feature dimensions, scaling, or format can lead to biased model updates. One approach involves creating a shared feature vocabulary or embedding space agreed upon during the system initialization phase [35]. Advanced encoding also leverages pre-trained embeddings, such as word2vec models trained on malware-specific corpora, which reduce dimensionality while retaining contextual semantics. These embeddings are particularly useful in XAI frameworks, as they preserve interpretability during model introspection [36].
World Journal of Advanced Research and Reviews, 2025, 27(01), 331-351 346 SHAP or LIME further increases memory and runtime costs, especially when generating instance-level explanations for real-time security applications [39]. Network reliability also becomes critical, as intermittent connectivity affects synchronization rounds and delays model convergence. Systems must be equipped with redundancy-aware FL protocols and caching mechanisms to prevent loss of model integrity during connectivity lapses. Thus, FL-XAI adoption necessitates coordinated hardware-software optimization, edge compute provisioning, and robust orchestration frameworks that balance security, performance, and cost at scale [40]. 8. Future directions and strategic recommendations 8.1. Secure Aggregation, Differential Privacy, and Homomorphic Encryption in FL The convergence of federated learning (FL) with privacy-enhancing technologies is critical for trustworthy cybersecurity systems. One of the foundational mechanisms is secure aggregation, which enables model servers to compute an aggregate of client updates without learning any individual contribution [33]. This guarantees that no single client’s model parameters are exposed, mitigating risks of gradient leakage or model inversion. Secure aggregation protocols, such as SecAgg and Prio, operate through cryptographic masking or additive secret sharing, requiring synchronization among clients and a reliable communication infrastructure [34]. Though these protocols ensure confidentiality, they impose latency and memory trade-offs that can hinder scalability in dynamic network environments. Complementing this, differential privacy (DP) introduces noise into updates to athematically guarantee that individual client data cannot be inferred even under repeated queries [35]. In cybersecurity contexts, this ensures that rare malware signatures or regional threat patterns cannot be reverse-engineered from the global model. However, tuning DP parameters like the privacy budget (ε) demands a careful balance between model utility and privacy preservation, especially in non-IID data distributions. Homomorphic encryption (HE) enables computations directly on encrypted data, preserving confidentiality throughout model training and inference. HE schemes like CKKS and Paillier are computationally intensive but valuable in environments with strict regulatory constraints or untrusted infrastructure [36]. Their application in FL is expanding, particularly in cross-border deployments where raw logs or binaries must remain encrypted end-to-end. The synergy of these three tools secure aggregation, differential privacy, and homomorphic encryption creates a multilayered trust model for FL in malware detection systems. Figure 5 illustrates this integration path and highlights potential hardware accelerations, such as trusted execution environments (TEEs), to reduce computational overhead and enable practical deployment at scale [37]. 8.2. Advancing Real-Time Explainability for Operational Deployment For federated learning and explainable AI (FL-XAI) to transition from research to deployment, a pivotal requirement is achieving real-time interpretability without sacrificing detection accuracy or latency. Traditional explainability methods like SHAP and LIME are computationally expensive and often impractical for time-sensitive cybersecurity environments, particularly when models process large feature spaces in malware telemetry [38]. Recent advancements focus on model-integrated explainability, embedding interpretability directly within the architecture. For example, attention-based models can highlight critical system events or memory sequences that drive classification, without the need for post-hoc explanation tools [39]. Similarly, prototype-based learning enables models to compare real-time input against learned malicious archetypes, offering human-readable justifications inline with predictions. Operational explainability demands consistency and robustness. Dynamic environments such as those involving evolving ransomware or obfuscated payloads require XAI methods to remain stable across versions and adapt to concept drift. Integrating continuous explanation validation pipelines helps ensure that model updates preserve interpretability and align with domain knowledge over time [40].
World Journal of Advanced Research and Reviews, 2025, 27(01), 331-351 347 Visualization plays a key role in enabling SOC (Security Operations Center) analysts to act on FL-XAI outputs. Streamlined dashboards that translate SHAP scores or attention weights into visual narratives such as code flow diagrams or anomaly trees help reduce alert fatigue and enhance investigative efficiency [41]. These tools are being embedded into SIEM platforms to facilitate seamless security decision-making. Figure 5 situates these innovations along a maturity curve from offline explainability to fully integrated, real-time operational feedback systems. The convergence of efficient algorithms, GPU acceleration, and intelligent UI/UX design will determine the success of XAI in field-ready federated malware detection systems [42]. 8.3. Policy and Governance for Inter-Organizational Threat Intelligence Sharing Federated learning’s promise in cybersecurity hinges not only on technological sophistication but also on robust policy frameworks that enable data collaboration without undermining privacy, trust, or compliance. Effective interorganizational threat intelligence sharing under FL requires clearly articulated governance mechanisms to manage participation, data use, liability, and dispute resolution [43]. Figure 5 Maps these policy and governance layers alongside technical components, envisioning a fully integrated future FL ecosystem. Legal harmonization, contractual SLAs, and cross-border regulatory sandboxes will be pivotal in mainstreaming FL-XAI deployments for global cyber resilience [47] Governments, critical infrastructure operators, and private cybersecurity vendors often face diverging legal, reputational, and economic incentives when contributing data. To align these interests, multi-stakeholder consortia are emerging to define FL governance charters, addressing aspects such as data retention policies, contribution transparency, and audit rights [44]. These charters serve as binding agreements for model usage, versioning, and retraining criteria. Compliance with existing frameworks like the NIST Privacy Framework, GDPR, and sector-specific regulations (e.g., HIPAA, PCI-DSS) is essential. These policies should be extended to cover federated contributions ensuring that model outputs and metadata cannot inadvertently leak protected information or trigger legal liabilities [45]. Trust anchors, such as third-party verifiers or neutral aggregators, may be needed to coordinate FL participation across sectors. Public key infrastructures (PKI), hardware attestation, and remote attestation protocols ensure that only validated entities contribute to or access FL models [46]. These mechanisms uphold model integrity and deter collusion or poisoning attacks. 9. Conclusion This study explored the intersection of federated learning (FL) and explainable artificial intelligence (XAI) as a foundation for secure, privacy-preserving malware detection in increasingly complex digital ecosystems. With malware
World Journal of Advanced Research and Reviews, 2025, 27(01), 331-351 348 evolving in sophistication and frequency, the cybersecurity community must overcome the dual challenge of building accurate threat classifiers while ensuring user privacy and operational trust. Centralized approaches, though historically dominant, have struggled to meet these demands due to data centralization risks, scalability limitations, and regulatory pressures. In contrast, FL offers a decentralized framework where learning is distributed across client endpoints, ensuring that raw data never leaves its origin. Coupled with XAI techniques, such systems can deliver not only robust threat detection but also interpretability crucial for decision-making in real-world deployments. Throughout the analysis, it became evident that implementing FL in malware detection is not without challenges. Key bottlenecks such as non-IID data distributions, communication overhead, model drift, and explainability constraints in high-dimensional feature spaces pose significant hurdles. Moreover, privacy-enhancing technologies like secure aggregation, differential privacy, and homomorphic encryption, while promising, require careful orchestration to balance computational costs with performance efficiency. Nevertheless, recent advancements in federated convolutional neural networks, adaptive optimization algorithms, and embedded interpretability have shown tangible progress toward making FL-XAI architectures viable for security-sensitive contexts. One of the core contributions of this research is the design and evaluation of a federated malware detection framework capable of adapting across various sectors including financial institutions, healthcare networks, and governmental infrastructures without compromising on data sovereignty or threat response agility. Empirical evaluations across multiple datasets demonstrated that federated models can outperform traditional and siloed alternatives when configured with fine-tuned aggregation and explainability layers. Visualizations of model decision-making offered by SHAP and attention-based architectures enhanced analyst trust and operational transparency. Furthermore, this work emphasized the critical role of privacy-respecting collaboration. In a landscape where threats often transcend organizational and geographic boundaries, isolated security operations are no longer sustainable. FL enables a paradigm shift from data hoarding to knowledge sharing where insights from dispersed nodes can be aggregated securely and scalably. This collaborative intelligence is vital for detecting low-frequency, high-impact threats such as zero-day attacks or advanced persistent threats (APTs), which rarely manifest in isolated systems but show discernible patterns when viewed collectively. However, collaboration must be framed within governance structures that ensure fairness, accountability, and interoperability. Institutional readiness, legacy system integration, and cross-sector alignment remain essential factors in advancing the adoption of FL-XAI in practice. Public-private partnerships, contractual governance models, and international policy harmonization will be required to scale these systems ethically and sustainably. In conclusion, the path forward lies in building AI-driven threat-sharing ecosystems rooted in federated architectures and fortified with real-time interpretability. These ecosystems must be agile enough to accommodate rapidly evolving threats, robust enough to withstand adversarial attacks, and inclusive enough to unify diverse stakeholders in a common security mission. By aligning technological innovation with policy reform and human-centered design, the cybersecurity community can transition from reactive defense to proactive, collaborative resilience. This research sets the stage for future deployments where intelligent, privacy-preserving AI systems form the backbone of digital defense infrastructures across industries and borders. Compliance with ethical standards Disclosure of conflict of interest No conflict of interest to be disclosed. References [1] Vyas A, Lin PC, Hwang RH, Tripathi M. Privacy-Preserving Federated Learning for Intrusion Detection in IoT Environments: A Survey. IEEE Access. 2024 Sep 4. [2] Ejedegba Emmanuel Ochuko. Advancing green energy transitions with eco-friendly fertilizer solutions supporting agricultural sustainability. Int Res J Mod Eng Technol Sci. 2024 Dec;6(12):1970. Available from: https://www.doi.org/10.56726/IRJMETS65313
World Journal of Advanced Research and Reviews, 2025, 27(01), 331-351 349 [3] Chukwunweike J. Design and optimization of energy-efficient electric machines for industrial automation and renewable power conversion applications. Int J Comput Appl Technol Res. 2019;8(12):548–560. doi: 10.7753/IJCATR0812.1011. [4] Torre D, Chennamaneni A, Jo J, Vyas G, Sabrsula B. Toward Enhancing Privacy Preservation of a Federated Learning CNN Intrusion Detection System in IoT: Method and Empirical Study. ACM Transactions on Software Engineering and Methodology. 2025 Feb 12;34(2):1-48. [5] Odeniran OM. Exploring the Potential of Bambara Groundnut Flour as an Alternative for Diabetic and Obese Patients in the USA: A Comprehensive Review. Cureus. 2025 Jan 30;17(1). [6] Asiri M, Khemakhem MA, Alhebshi RM, Alsulami BS, Eassa FE. Rpfl: A reliable and privacy-preserving framework for federated learning-based iot malware detection. Electronics. 2025 Mar 10;14(6):1089. [7] Darkwah E. Developing spatial risk maps of PFAS contamination in farmlands using soil core sampling and GIS. World Journal of Advanced Research and Reviews. 2023;20(03):2305–25. doi: https://doi.org/10.30574/wjarr.2023.20.3.2305. [8] Ejedegba Emmanuel Ochuko. Synergizing fertilizer innovation and renewable energy for improved food security and climate resilience. Int J Res Publ Rev. 2024 Dec;5(12):3073–88. Available from: https://doi.org/10.55248/gengpi.5.1224.3554 [9] Chukwunweike Joseph, Salaudeen Habeeb Dolapo. Advanced Computational Methods for Optimizing Mechanical Systems in Modern Engineering Management Practices. International Journal of Research Publication and Reviews. 2025 Mar;6(3):8533-8548. Available from: https://ijrpr.com/uploads/V6ISSUE3/IJRPR40901.pdf [10] Juliet C Igboanugo, Uchenna Uzoma Akobundu. Evaluating the Resilience of Public Health Supply Chains During COVID-19 in Sub-Saharan Africa. Int J Comput Appl Technol Res. 2020;9(12):378–93. Available from: https://doi.org/10.7753/IJCATR0912.1008 [11] Olaoye G. AI-Driven Intrusion Detection and Prevention Systems (IDPS) for Cloud Security. Available at SSRN 5129525. 2025 Feb 8. [12] Alkaeed M, Qayyum A, Qadir J. Privacy preservation in Artificial Intelligence and Extended Reality (AI-XR) metaverses: A survey. Journal of Network and Computer Applications. 2024 Aug 2:103989. [13] Bandi A. A Taxonomy of AI techniques for security and privacy in cyber–physical systems. Journal of computational and cognitive engineering. 2024 Jan 17;3(2):98-111. [14] Sharma DP, Habibi Lashkari A, Firoozjaei MD, Mahdavifar S, Xiong P. Defense Methods for Adversarial Attacks and Privacy Issues in Secure AI. InUnderstanding AI in Cybersecurity and Secure AI 2025 (pp. 159-195). Springer, Cham. [15] Chibogwu Igwe-Nmaju. Organizational communication in the age of APIs: integrating data streams across departments for unified messaging and decision-making. International Journal of Research Publication and Reviews. 2024 Dec;5(12):2792–2809. Available from: https://ijrpr.com/uploads/V5ISSUE12/IJRPR36937.pdf [16] Iyengar SS, Nabavirazavi S, Hariprasad Y, HB P, Mohan CK. Cyber Threat Intelligence and Security for Federated Learning in Digital Forensics. InArtificial Intelligence in Practice 2025 (pp. 177-199). Springer, Cham. [17] Aidoo EM. Community based healthcare interventions and their role in reducing maternal and infant mortality among minorities. International Journal of Research Publication and Reviews. 2024 Aug;5(8):4620–36. Available from: https://doi.org/10.55248/gengpi.6.0325.1177 [18] Ullah S, Li J, Ullah F, Chen J, Ali I, Khan S, Ahad A, Leung VC. The revolution and vision of explainable AI for android malware detection and protection. Internet of Things. 2024 Aug 6:101320. [19] Joseph Kumbankyet. The AI Revolution in Finance: Building a Sustainable Future. February 2025. ISBN: 9798310623071. [20] Achuthan K, Ramanathan S, Srinivas S, Raman R. Advancing cybersecurity and privacy with artificial intelligence: current trends and future research directions. Frontiers in Big Data. 2024 Dec 5;7:1497535. [21] Emmanuel Ochuko Ejedegba. INTEGRATED STRATEGIES FOR ENHANCING GLOBAL FOOD SECURITY AMID SHIFTING ENERGY TRANSITION CHALLENGES. International Journal of Engineering Technology Research and Management (ijetrm). 2024Dec16;08(12).
World Journal of Advanced Research and Reviews, 2025, 27(01), 331-351 350 [22] Timofte EM, Dimian M, Graur A, Potorac AD, Balan D, Croitoru I, Hrițcan DF, Pușcașu M. Federated Learning for Cybersecurity: A Privacy-Preserving Approach. Applied Sciences. 2025 Jun 18;15(12):6878. [23] Ugwueze VU, Chukwunweike JN. Continuous integration and deployment strategies for streamlined DevOps in software engineering and application delivery. Int J Comput Appl Technol Res. 2024;14(1):1–24. doi:10.7753/IJCATR1401.1001. [24] Sani Zainab Nimma. Integrating AI in Pharmacy Pricing Systems to Balance Affordability, Adherence, and Ethical PBM Operations. Global Economics and Negotiation Journal. 2025;6(05):Article 19120. doi: https://doi.org/10.55248/gengpi.6.0525.19120. [25] Chukwunweike Joseph Nnaemeka, Kadiri Caleb, Williams Akudo Sylveria, Oluwamayowa Akinsuyi, Samson Akinsuyi. Applying AI and machine learning for predictive stress analysis and morbidity assessment in neural systems: A MATLAB-based framework for detecting and addressing neural dysfunction. World Journal of Advanced Research and Reviews. 2024;23(03):063–081. doi:10.30574/wjarr.2024.23.3.2645. Available from: https://doi.org/10.30574/wjarr.2024.23.3.2645 [26] Adeyeye OJ, Akanbi I, Emeteveke I, Emehin O. Leveraging secured AI-driven data analytics for cybersecurity: Safeguarding information and enhancing threat detection. International Journal of Research and Publication and Reviews. 2024;5(10):3208-23. [27] Hakeem SA, Kim H. Advancing Intrusion Detection in V2X Networks: A Comprehensive Survey on Machine Learning, Federated Learning, and Edge AI for V2X Security. IEEE Transactions on Intelligent Transportation Systems. 2025 May 23. [28] SAI M, RAMESH P, REDDY DS. EFFICIENT SUPERVISED MACHINE LEARNING FOR CYBERSECURITY APPLICATIONS USING ADAPTIVE FEATURE SELECTION AND EXPLAINABLE AI SCENARIOS. Journal of Theoretical and Applied Information Technology. 2025 Mar 31;103(6). [29] Salim S, Moustafa N, Almorjan A. Responsible Deep Federated Learning-based Threat Detection for Satellite Communications. IEEE Internet of Things Journal. 2025 Jan 20. [30] Kavitha D, Thejas S. Ai enabled threat detection: Leveraging artificial intelligence for advanced security and cyber threat mitigation. IEEE Access. 2024 Nov 8. [31] Amiri-Zarandi M, Karimipour H, Dara RA. A federated and explainable approach for insider threat detection in IoT. Internet of Things. 2023 Dec 1;24:100965. [32] Ejedegba Emmanuel Ochuko. Innovative solutions for food security and energy transition through sustainable fertilizer production techniques. World J Adv Res Rev. 2024;24(3):1679–95. Available from: https://doi.org/10.30574/wjarr.2024.24.3.3877 [33] Namakshenas D, Yazdinejad A, Dehghantanha A, Parizi RM, Srivastava G. IP2FL: Interpretation-based privacypreserving federated learning for industrial cyber-physical systems. IEEE Transactions on Industrial CyberPhysical Systems. 2024 Jul 30. [34] Chukwunweike Joseph Nnaemeka, Emeh Chinonso, Kehinde QS Husseini Musa, Kadiri Caleb. Advancing precision in pipeline analog-to-digital converters: Leveraging MATLAB for design and analysis in next-generation communication systems. World Journal of Advanced Research and Reviews. 2024;23(01):2333–2383. doi:10.30574/wjarr.2024.23.1.2172. Available from: https://doi.org/10.30574/wjarr.2024.23.1.2172 [35] Chen C, Liu J, Tan H, Li X, Wang KI, Li P, Sakurai K, Dou D. Trustworthy federated learning: privacy, security, and beyond. Knowledge and Information Systems. 2025 Mar;67(3):2321-56. [36] Ejeofobiri CK, Victor-Igun OO, Okoye C. AI-driven secure intrusion detection for Internet of Things (IoT) networks. Am J Comput Model Optim Res. 2024;31(4):40–55. doi:10.56557/ajomcor/2024/v31i48971. [37] Nuwasiima Mackline, Ahonon Metogbe Patricia, Kadiri Caleb. The Role of Artificial Intelligence (AI) and machine learning in social work practice. World Journal of Advanced Research and Reviews. 2024;24(01):080–097. doi:10.30574/wjarr.2024.24.1.2998. Available from: https://doi.org/10.30574/wjarr.2024.24.1.2998 [38] GK SK, Muniyal B, Rajarajan M. Explainable Federated Framework for Enhanced Security and Privacy in Connected Vehicles Against Advanced Persistent Threats. IEEE Open Journal of Vehicular Technology. 2025 Jun 4.
World Journal of Advanced Research and Reviews, 2025, 27(01), 331-351 351 [39] Chukwunweike J, Lawal OA, Arogundade JB, Alade B. Navigating ethical challenges of explainable AI in autonomous systems. International Journal of Science and Research Archive. 2024;13(1):1807–19. doi:10.30574/ijsra.2024.13.1.1872. Available from: https://doi.org/10.30574/ijsra.2024.13.1.1872. [40] Kumar KS, Nair SA, Roy DG, Rajalingam B, Kumar RS. Security and privacy-aware artificial intrusion detection system using federated machine learning. Computers and Electrical Engineering. 2021 Dec 1;96:107440. [41] Fatema K, Anannya M, Dey SK, Su C, Mazumder R. Securing Networks: A Deep Learning Approach with Explainable AI (XAI) and Federated Learning for Intrusion Detection. InInternational Conference on Data Security and Privacy Protection 2024 Oct 18 (pp. 260-275). Singapore: Springer Nature Singapore. [42] Dorgbefu EA. Innovative real estate marketing that combines predictive analytics and storytelling to secure longterm investor confidence. Int J Sci Res Arch. 2020;1(1):209–227. doi: https://doi.org/10.30574/ijsra.2020.1.1.0049 [43] Raza A. Secure and privacy-preserving federated learning with explainable artificial intelligence for smart healthcare system. University of Kent (United Kingdom); 2023. [44] Fatema K, Dey SK, Anannya M, Khan RT, Rashid MM, Su C, Mazumder R. Federated XAI IDS: An Explainable and Safeguarding Privacy Approach to Detect Intrusion Combining Federated Learning and SHAP. Future Internet. 2025 May 26;17(6):234. [45] Ragab M, Ashary EB, Alghamdi BM, Aboalela R, Alsaadi N, Maghrabi LA, Allehaibi KH. Advanced artificial intelligence with federated learning framework for privacy-preserving cyberthreat detection in IoT-assisted sustainable smart cities. Scientific Reports. 2025 Feb 6;15(1):4470. [46] Ejeofobiri CK, Adelere MA, Shonubi JA. Developing adaptive cybersecurity architectures using Zero Trust models and AI-powered threat detection algorithms. Int J Comput Appl Technol Res. 2022;11(12):607–621. doi:10.7753/IJCATR1112.1024. [47] Gwassi OA, Uçan ON, Navarro EA. Cyber-XAI-Block: an end-to-end cyber threat detection and fl-based risk assessment framework for iot enabled smart organization using xai and blockchain technologies. Multimedia Tools and Applications. 2024 Sep 11:1-42.