Federated Attack Campaign Detection via Contrastive Encoding of Threat Indicators in Gradient Updates
Researchers propose FedIoC, a federated learning framework detecting cross-organization attack campaigns from threat-indicator structure in gradient updates without sharing IoCs.
The paper introduces FedIoC, a modular federated learning framework in which clients encode locally matched indicators of compromise into gradient updates using a supervised contrastive loss over IoC-matched flows. The server clusters client updates by cosine similarity to recover global attack-campaign patterns without any direct IoC transmission across organizational or national boundaries. Evaluations on two public threat-detection benchmarks, distributed across clients holding only fragments of each campaign and disjoint indicator sets, show the server recovers cross-organizational campaign cohorts from gradient geometry alone. The authors identify non-IID gradient structure as the main driver of recovery and define open problems for encoder design.