TrustCloud-FL: A Self-Healing and Privacy-Preserving Architecture for Secure Analytics Across Multi-Tenant Hybrid Clouds
Abstract
Cloud platforms let organizations share computing capacity, data services, and machine-learning tools across many business units, regions, and providers. The same flexibility also creates a difficult security problem: raw records may cross tenant boundaries, model updates may be poisoned, automated responses may interrupt legitimate workloads, and audit evidence may be scattered across services. This paper presents TrustCloud-FL, a self-healing and privacy-preserving architecture for secure analytics across multi-tenant hybrid clouds. The design joins six capabilities that are often treated separately: tenant-local data processing, secure federated aggregation, risk fusion across identity and service signals, policy-bounded automated response, ledger-backed audit evidence, and edge-aware service recovery. A design-science method translates gaps in twelve focal recent studies, interpreted alongside independent journal literature, into coherent architecture and a transparent evaluation plan. The proposed design is tested through 50 Monte Carlo replications of three threat scenarios: credential abuse with lateral movement, poisoned model updates with insider activity, and traffic bursts with regional service degradation. It is compared with a conventional centralized baseline and a federated-detection baseline. In the simulation, TrustCloud-FL achieved the highest attack-detection rate, the lowest false-positive rate, the shortest containment and recovery times, and the most complete audit record. These gains required about nine milliseconds of added decision latency, which makes the trade-off visible rather than hiding it. An ablation study further showed that no single module produced the full benefit: secure aggregation primarily protected tenant data, adaptive response reduced containment time, DataOps validation limited false alarms, and edge survivability improved availability. The results support a practical conclusion: trustworthy cloud security depends on coordinated controls and measured automation, not on one detection model alone.