Federated Continual Learning for Intrusion Detection: A Drift-Aware Benchmark on the Windows-APT 2025 Dataset

Authors

  • Ilham Achmad Fiqrin School of Computing and Informatics, Universiti Teknologi Brunei, Jalan Tungku Link, Gadong, Bandar Seri Begawan, Brunei Darussalam
  • Taufiq Hidayat Department of Informatics, Faculty of Industrial Technology, Universitas Islam Indonesia Yogyakarta, Indonesia

DOI:

https://doi.org/10.55681/armada.v4i9.3928

Keywords:

Federated Learning, Continual Learning, Intrusion Detection, Drift-Aware Learning, Windows-APT 2025 Dataset, Network Security

Abstract

Federated Learning (FL) enables collaborative intrusion detection among organizations without sharing raw telemetry data. However, existing FL approaches often assume static learning environments, limiting their effectiveness in detecting Advanced Persistent Threats (APTs) with continuously evolving behaviors. This study proposes a Federated Continual Learning (FCL) benchmark for APT technique detection using the Windows-APT 2025 dataset. Following a validation-first paradigm, the dataset characteristics, including client participation, label reliability, and behavioral drift, are analyzed to establish an appropriate evaluation framework. The benchmark evaluates Replay, EWC, and DER++ continual learning methods combined with FedAvg and FedProx optimization strategies, using MLP and 1D-CNN architectures with drift-triggered adaptation. Experimental results show that Replay and EWC achieve up to 23% higher multi-label F1 performance than DER++ under limited local training conditions. FedAvg consistently outperforms FedProx, while MLP surpasses 1D-CNN with approximately one-third of the communication overhead. These findings demonstrate the effectiveness of the proposed benchmark for evaluating drift-aware federated intrusion detection systems.

Downloads

Download data is not yet available.

References

Agrahari, S., & Singh, A. K. (2022). Concept Drift Detection in Data Stream Mining : A literature review. Journal of King Saud University - Computer and Information Sciences, 34(10), 9523–9540. https://doi.org/10.1016/J.JKSUCI.2021.11.006

Agrawal, S., Sarkar, S., Aouedi, O., Yenduri, G., Piamrat, K., Alazab, M., Bhattacharya, S., Maddikunta, P. K. R., & Gadekallu, T. R. (2022). Federated Learning for intrusion detection system: Concepts, challenges and future directions. Computer Communications, 195, 346–361. https://doi.org/10.1016/J.COMCOM.2022.09.012

Andresini, G., Pendlebury, F., Pierazzi, F., Loglisci, C., Appice, A., & Cavallaro, L. (2021). INSOMNIA: Towards Concept-Drift Robustness in Network Intrusion Detection. AISec 2021 - Proceedings of the 14th ACM Workshop on Artificial Intelligence and Security, Co-Located with CCS 2021, 111–122. https://doi.org/10.1145/3474369.3486864

Apruzzese, G., Laskov, P., Montes De Oca, E., Mallouli, W., Brdalo Rapa, L., Grammatopoulos, A. V., & Di Franco, F. (2023). The Role of Machine Learning in Cybersecurity. Digital Threats: Research and Practice, 4(1). https://doi.org/10.1145/3545574/ASSET/C4586A69-4437-435A-9DE6-E5F12828847D/ASSETS/GRAPHIC/DTRAP-2021-0064-F15.JPG

Buzzega, P., Boschini, M., Porrello, A., Abati, D., & CALDERARA, S. (2020). Dark Experience for General Continual Learning: a Strong, Simple Baseline. Advances in Neural Information Processing Systems, 33, 15920–15930. https://github.com/aimagelab/mammoth.

Criado, M. F., Casado, F. E., Iglesias, R., Regueiro, C. V., & Barro, S. (2022). Non-IID data and Continual Learning processes in Federated Learning: A long road ahead. Information Fusion, 88, 263–280. https://doi.org/10.1016/J.INFFUS.2022.07.024

De Lange, M., Aljundi, R., Masana, M., Parisot, S., Jia, X., Leonardis, A., Slabaugh, G., & Tuytelaars, T. (2022). A Continual Learning Survey: Defying Forgetting in Classification Tasks. IEEE Transactions on Pattern Analysis and Machine Intelligence, 44(7), 3366–3385. https://doi.org/10.1109/TPAMI.2021.3057446

Hamedi, P., Razavi-Far, R., & Hallaji, E. (2025). Federated continual learning: Concepts, challenges, and solutions. Neurocomputing, 651, 130844. https://doi.org/10.1016/J.NEUCOM.2025.130844

Han, M., Chen, Z., Li, M., Wu, H., & Zhang, X. (2022). A survey of active and passive concept drift handling methods. Computational Intelligence, 38(4), 1492–1535. https://doi.org/10.1111/COIN.12520

Kirkpatrick, J., Pascanu, R., Rabinowitz, N., Veness, J., Desjardins, G., Rusu, A. A., Milan, K., Quan, J., Ramalho, T., Grabska-Barwinska, A., Hassabis, D., Clopath, C., Kumaran, D., & Hadsell, R. (2017). Overcoming catastrophic forgetting in neural networks. Proceedings of the National Academy of Sciences of the United States of America, 114(13), 3521–3526. https://doi.org/10.1073/PNAS.1611835114/SUPPL_FILE/PNAS.201611835SI.PDF

Korycki, Ł., & Krawczyk, B. (2023). Adversarial concept drift detection under poisoning attacks for robust data stream mining. Machine Learning, 112(10), 4013–4048. https://doi.org/10.1007/S10994-022-06177-W/METRICS

Lavaur, L., Pahl, M. O., Busnel, Y., & Autrel, F. (2022). The Evolution of Federated Learning-Based Intrusion Detection and Mitigation: A Survey. IEEE Transactions on Network and Service Management, 19(3), 2309–2332. https://doi.org/10.1109/TNSM.2022.3177512

Mat, N. I. C., Jamil, N., Yusoff, Y., & Kiah, M. L. M. (2024). A systematic literature review on advanced persistent threat behaviors and its detection strategy. Journal of Cybersecurity, 10(1). https://doi.org/10.1093/CYBSEC/TYAD023

Mozaffari, M., Yazdinejad, A., & Dehghantanha, A. (2026). Windows-APT 2025: A dataset for APT-inspired attack scenarios on windows systems. Data in Brief, 65, 112569. https://doi.org/10.1016/J.DIB.2026.112569

Sun, H., Zhang, W., Zhang, R., Xu, L., Guan, H., Zhao, H., Zhang, B., Yang, S., & Yu, X. (2025). Federated Continual Learning Based on Weakly Supervised Diffusion Models for Disease Diagnosis. IEEE Internet of Things Journal, 12(22), 45958–45971. https://doi.org/10.1109/JIOT.2025.3535628

Susanto, A. K. S., Fiqrin, I. A., Patchmuthu, R. K., Tajuddin, S. T. B. H., Waruwu, D. S., & Laia, O. (2025). Performance Comparison Analysis of Conventional and Advanced Machine Learning Algorithms for APT Malware Detection. 2025 7th International Conference on Applied Computational Intelligence in Information Systems: Intelligent and Resilient Digital Innovations for Sustainable Living, ACIIS 2025 - Proceedings. https://doi.org/10.1109/ACIIS66255.2025.11402962

Susanto, A. K. S., Fiqrin, I. A., Patchmuthu, R. K., Tajuddin, S. T. B. H., & Zai, M. S. P. (2025). A Comparison of Deep Learning Algorithms for APT Malware Detection. 2025 7th International Conference on Applied Computational Intelligence in Information Systems (ACIIS), 1–6. https://doi.org/10.1109/ACIIS66255.2025.11402960

Wang, L., Zhang, X., Su, H., & Zhu, J. (2024). A Comprehensive Survey of Continual Learning: Theory, Method and Application. IEEE Transactions on Pattern Analysis and Machine Intelligence, 46(8), 5362–5383. https://doi.org/10.1109/TPAMI.2024.3367329

Wang, Z. I., Wu, F., Yu, F., Zhou, Y., Hu, J., Min, G., & Wang, Z. (2024). Federated Continual Learning for Edge-AI: A Comprehensive Survey. ACM Computing Surveys, 1. https://doi.org/XXXXXXX.XXXXXXX

Zhong, Z., Bao, W., Wang, J., Chen, J., Lyu, L., & Yang Bryan Lim, W. (2025). SacFL: Self-Adaptive Federated Continual Learning for Resource-Constrained End Devices. IEEE Transactions on Neural Networks and Learning Systems, 36(9), 17169–17183. https://doi.org/10.1109/TNNLS.2025.3565827

Zhu, H., Xu, J., Liu, S., & Jin, Y. (2021). Federated learning on non-IID data: A survey. Neurocomputing, 465, 371–390. https://doi.org/10.1016/J.NEUCOM.2021.07.098

Downloads

Published

2026-09-30

How to Cite

Ilham Achmad Fiqrin, & Taufiq Hidayat. (2026). Federated Continual Learning for Intrusion Detection: A Drift-Aware Benchmark on the Windows-APT 2025 Dataset. ARMADA : Jurnal Penelitian Multidisiplin, 4(9), 5385–5394. https://doi.org/10.55681/armada.v4i9.3928