A trust-aware privacy-preserving federated learning framework for secure threat intelligence sharing using blockchain
Abstract
Collaborative threat intelligence sharing has become essential for defending distributed enterprise and smart city infrastructures against increasingly sophisticated cyber threats. However, organizations remain reluctant to share raw security data due to privacy, regulatory, and trust concerns. Federated Learning (FL) has emerged as a promising solution by enabling collaborative model training without exposing local data. Nevertheless, traditional FL-based intrusion detection frameworks remain vulnerable to model poisoning, Byzantine attacks, and lack transparent accountability mechanisms for cross-organization collaboration. This paper proposes an engineering framework for privacy-preserving federated threat intelligence sharing that integrates trust-aware robust aggregation with blockchain-based integrity anchoring. The proposed architecture introduces a dynamic reputation mechanism that evaluates participant reliability across communication rounds and assigns adaptive aggregation weights to mitigate malicious updates. To enhance transparency and non-repudiation, model update hashes and trust evolution records are anchored on a permissioned blockchain through smart contracts, ensuring immutable auditability without exposing sensitive parameters. The framework is evaluated using a non-IID partition of the ToN-IoT dataset across multiple simulated organizations. Experimental results demonstrate significant robustness improvements under adversarial environments. Under Byzantine attacks with 20% malicious clients, the proposed trust-aware aggregation mechanism achieves approximately 95% Accuracy and 95% F1-macro, compared with approximately 89% obtained using conventional FedAvg. Furthermore, under highly adversarial conditions involving 40% malicious participants, the proposed framework maintains approximately 95% Accuracy and F1-macro, whereas FedAvg degrades to approximately 78% Accuracy and 77% F1-macro. These results confirm the effectiveness of the proposed trust-aware aggregation mechanism in mitigating malicious updates while preserving stable convergence and reliable intrusion detection performance.