Volume 5
Abstract: Traditional signature- and rule-based Intrusion Detection Systems (IDS) struggle to keep pace with increasingly sophisticated and polymorphic cyberattacks, and existing AI-driven approaches to this problem tend to evaluate detection accuracy in isolation, without addressing the real-world constraints of data privacy or resource-limited deployment. This study addresses that gap by developing and comparing traditional Machine Learning (ML) and Deep Learning (DL) architectures for network intrusion detection, then extending the strongest model into a privacy-preserving Federated Learning (FL) framework suitable for decentralized, resource-constrained environments. Using the NSL-KDD benchmark dataset, we evaluate three ML models (Random Forest, Support Vector Machines, Decision Trees) and three DL models (CNN, LSTM, FNN) across accuracy, latency, and interpretability. Our optimized CNN achieved the highest accuracy (98.4%), outperforming the best ML model (Random Forest, 96.7%) by 1.7 percentage points, while the LSTM model showed the strongest capability for identifying unseen attack variants — a useful proxy for novel-threat detection. To address the privacy limitations of centralized training, we implemented an FL framework across five distributed nodes, achieving accuracy within 1.2% of centralized performance while eliminating the need to share raw data. Together, these findings show that hybrid deep learning architectures combined with federated learning offer a practical path toward accurate, privacy-preserving, real-time intrusion detection, and this paper provides concrete deployment guidelines and benchmarks to support that transition in enterprise environments, with real-world, high-throughput validation identified as a key direction for future work. Download this article: CPPJ - V5 N2 Page 59.pdf Recommended Citation: Sambasivam, S., (2026). Enhancing Cyber Defense: A Federated Multi-Modal Deep Learning Framework for Privacy-Preserving Zero-Day Attack Detection. Cybersecurity Pedagogy and Practice Journal 5(2) pp 59-77. https://doi.org/10.62273/GNXQ6845 | ||||||