TrustFed-SDN

Federated Learning Software-Defined Networking Verifiable Aggregation

A privacy-preserving, verifiable federated learning framework for SDN-enabled cloud networks

TrustFed-SDN validates cross-tenant threat detection on a real Mininet + OVS + RYU testbed — combining lightweight verifiable aggregation, poisoning-robust training, and adaptive per-tenant differential privacy in a single framework.

Authors
Pritom Kumar Bhowmik MD Naimur Rashid
Supervisor
Saurav Chandra Das Lecturer, Dept. of IRE
Institution
University of Frontier Technology, Bangladesh

Abstract

Why cross-tenant threat detection in SDN needs more than federated averaging.

Software Defined Networking (SDN) enables multi-tenant cloud environments to share physical infrastructure among mutually distrustful tenants, requiring collaborative yet privacy-preserving threat detection. Federated Learning (FL) enables joint model training without raw data sharing, but existing SDN-FL approaches rarely combine a real network testbed, verifiable aggregation, poisoning robustness, and adaptive privacy in one framework.

This work proposes TrustFed-SDN — a federated learning framework validated on a real Mininet+OVS+RYU SDN testbed, providing lightweight verifiable aggregation, trimmed-mean/clustering-based poisoning robustness, and adaptive per-tenant differential privacy for cross-tenant intrusion detection.

Methodology

A multi-tenant SDN testbed feeding a federated learning and trust layer.

TrustFed-SDN system architecture diagram

Each tenant runs an isolated set of virtual machines — an attack source, benign traffic, and a victim/server — behind its own vSwitch and RYU controller instance. Flow features extracted at the switch are trained locally with a GRU model, then passed through an adaptive differential-privacy layer before being committed, verified, and robustly aggregated into a single global model.

  • Genuine hypervisor-level tenant isolation, not a shared-kernel emulation
  • Per-tenant local training on non-IID, top-k selected flow features
  • Hash-commitment verification before any update is aggregated
  • Global model redistributed to every tenant's RYU controller each round

Workflow

TrustFed-SDN end-to-end workflow diagram

One federated round, from raw traffic to a deployed detector.

Every round moves through six stages: flow features are collected from each tenant's SDN switch, reduced to the most relevant per-attack-class features, trained locally on the client side, then privacy-noised and securely aggregated on the server side before the updated global model is verified and pushed back out for evaluation on unseen traffic.

  1. Data collection — flow features from InSDN, CICIDS2017/2019
  2. Preprocessing — per-tenant non-IID partition, top-k selection
  3. Local training — per-tenant GRU, local model update
  4. Privacy & security — adaptive DP, commitment, robust aggregation
  5. Global model update — verified aggregation, redistribution
  6. Evaluation — accuracy, latency, robustness on unseen traffic

References

The prior work TrustFed-SDN builds on and positions itself against. Select any entry to open its DOI.

01 Privacy Protection Optimization Method for Cloud Platforms Based on Federated Learning and Homomorphic Encryption J. Wang & Y. Wang · Sensors, vol. 26, no. 3, p. 890 · 2026 DOI → 02 Federated Learning-Based Solution for DDoS Detection in SDN J. Mateus & G.-A. Lusilao Zodi · Proc. ICNC, Cape Town · 2024 DOI → 03 Privacy-Preserving and Verifiable Federated Learning Framework for Edge Computing H. Zhou, G. Yang, Y. Huang, H. Dai & Y. Xiang · IEEE Trans. Inf. Forensics Secur., vol. 18, pp. 565–580 · 2023 DOI → 04 SDN-Based Federated Learning Approach for Satellite-IoT Framework to Enhance Data Security and Privacy in Space Communication R. Uddin & S. A. P. Kumar · IEEE J. Radio Freq. Identif., vol. 7, pp. 424–440 · 2023 DOI → 05 Low Rate DDoS Detection Using Weighted Federated Learning in SDN Control Plane in IoT Network M. N. Ali, M. Imran, M. S. ud din & B.-S. Kim · Appl. Sci., vol. 13, no. 3, p. 1431 · 2023 DOI → 06 VFChain: Enabling Verifiable and Auditable Federated Learning via Blockchain Systems Z. Peng, J. Xu, X. Chu, S. Gao, Y. Yao, R. Gu & Y. Tang · IEEE Trans. Netw. Sci. Eng., vol. 9, no. 1, pp. 173–186 · 2022 DOI → 07 A Survey on Security and Privacy in Federated Learning-Based Intrusion Detection Systems for 5G and Beyond Networks H. Rezaei, R. Taheri, E. Nowroozi, M. Hajizadeh, S. Shiaeles & T. Bauschert · IEEE Open J. Commun. Soc., vol. 7, pp. 253–300 · 2026 DOI → 08 Collaborative Intrusion Detection Systems in SD-WAN Enterprise Networks with Federated Learning: A Comprehensive Survey W. Almuseelem · J. King Saud Univ. Comput. Inf. Sci., vol. 38, p. 379 · 2026 DOI →

The Team

The people behind TrustFed-SDN.

Pritom Kumar Bhowmik
Researcher

Pritom Kumar Bhowmik

Student ID 2101005

Department of Internet of Things & Robotics Engineering, University of Frontier Technology, Bangladesh.

MD Naimur Rashid
Researcher

MD Naimur Rashid

Student ID 2101042

Department of Internet of Things & Robotics Engineering, University of Frontier Technology, Bangladesh.

Saurav Chandra Das
Supervisor

Saurav Chandra Das

Lecturer, Department of IRE

University of Frontier Technology, Bangladesh — supervising this thesis project.