NeuralFortress-XFL: Privacy-Preserving Federated Explainable Learning for Cyber Threat Intelligence
Abstract
Collaborative cyber threat intelligence sharing is becoming a crucial part of contemporary security practices but is still limited by privacy risks and the need to retain confidence within and between organizations due to the heterogeneous nature of the information. NeuralFortress-XFL attempts to alleviate these issues by using a federated and explainable learning architecture that is capable of detecting threats with high fidelity, without revealing raw data or model explanations. The structure incorporates a Dynamic Privacy-Efficient Mechanism (DPEM), which dynamically adapts differential privacy budgets based on local data sensitivity and a lightweight explanation-embedding component that preserves both interpretability and privacy. An experiment conducted using CTI-Sharing-2024 dataset, which contains 15 organizations consisting of financial and healthcare industries, indicates that NeuralFortress-XFL provides the same level of detection as the centralized training accommodations, with significantly lower communication overhead. NeuralFortress-XFL maintains robust performance against up to 40% independent malicious participants (87.4% accuracy with label flipping, 84.3% backdoor detection rate). Against coordinated collusion, robustness degrades proportionally with coalition size: coalitions of five or more clients (33% of 15 organizations) achieve 67.3% attack success, a limitation that is explicitly addressed in the paper, and a trust-weighted aggregation process maintains global model consistency despite adversarial client updates. The framework is also able to offer consistent and sound explanations, which can support real-world analyst workflows. As a whole, NeuralFortress-XFL is a solid security solution for sharing privacy-sensitive cyber threat intelligence in a deployable and balanced way that satisfies all of the following criteria: it is accurate, it is interpretable, it communicates well, and it exhibits adversarial resilience in a multi-organizational real-world setting.