AEGIS-FL: Auditable Federated Threat Detection for Multi-Tenant Cloud-Edge Systems
Abstract
Multi-tenant hybrid cloud and edge infrastructures generate security telemetry that is individually sparse and collectively informative, but contractual, regulatory, and competitive barriers prevent tenants from pooling it. Federated learning offers a route around this obstacle, yet deployments in adversarial security settings must simultaneously resist model poisoning by participating tenants, provide auditable evidence of what each tenant contributed, bound the information leaked about tenant-local data, and translate detections into containment actions. Existing work addresses these requirements in isolation. We present AEGIS-FL, a four-plane architecture that couples DataOps-oriented governance, privacy-preserving federated training, a permissioned audit ledger, and a reinforcement-learned response controller, and we evaluate the planes jointly rather than separately. The central mechanism is a ledger-anchored aggregation rule in which per-tenant reputation, persisted across rounds on the audit ledger, sets an adaptive screening budget for a geometric (multi-Krum) filter. This removes the dependence on oracle knowledge of the adversary fraction that, we show, silently inflates reported robustness in the standard experimental protocol. On a controlled 100-tenant simulation with label-skewed partitions, AEGIS-FL reaches F₁ = 0.811 ± 0.017 against 0.790 ± 0.048 for FedAvg and 0.259 ± 0.005 for isolated per-tenant training and sustains F₁ = 0.799 under 10% sign-flipping adversaries where FedAvg falls to 0.740. Secure aggregation reconstructs the plaintext mean exactly under 30% tenant dropout at 19.2 kB per tenant per round, and the audit ledger commits at 19.6 kB per round with seven-hash Merkle inclusion proofs. We report three cautionary findings that qualify the deployment envelope. First, client-level differential privacy at this federation scale cannot reach a meaningful budget: ε ≈ 103 costs 4.0 F₁ points, while ε ≈ 7 destroys utility (F₁ = 0.308). Second, contrary to our own hypothesis, reducing model dimensionality does not recover private utility, because capacity losses offset noise reduction. Third, a loss-threshold membership-inference attack achieves AUC = 0.502 even without noise, so the empirical privacy benefit of the noise mechanism is not demonstrable in this regime. We argue these results indicate that participant scale, not noise calibration or model compression, is the binding constraint on private federated security analytics.