/System For Privacy-preserving Zero-day Threat Detection In Encrypted Traffic Using Federated Graph Neural Networks
Abstract

A system and method for privacy-preserving real-time zero-day threat detection in encrypted network traffic using federated temporal graph neural networks with integrated explainable artificial intelligence is disclosed. The system comprises a network interface controller configured to receive encrypted packet streams, a metadata extraction unit configured to derive non-payload attributes without decrypting packet contents, and a temporal graph construction unit configured to generate a dynamic graph representation of communication entities and their time-varying interactions. A plurality of distributed graph processing devices perform iterative message passing operations on the temporal graph, and a federated coordination processor aggregates locally computed model parameter updates using a secure aggregation unit without accessing raw data. An inference processor applies the aggregated model to detect anomalous communication patterns indicative of zero-day threats, while an explainability processor determines contribution scores of graph components to generate interpretable outputs.

Full Text

What is claimed is:

A system and method for privacy-preserving real-time zero-day threat detection in encrypted network traffic using federated temporal graph neural networks with integrated explainable artificial intelligence is disclosed. The system comprises a network interface controller configured to receive encrypted packet streams, a metadata extraction unit configured to derive non-payload attributes without decrypting packet contents, and a temporal graph construction unit configured to generate a dynamic graph representation of communication entities and their time-varying interactions. A plurality of distributed graph processing devices perform iterative message passing operations on the temporal graph, and a federated coordination processor aggregates locally computed model parameter updates using a secure aggregation unit without accessing raw data. An inference processor applies the aggregated model to detect anomalous communication patterns indicative of zero-day threats, while an explainability processor determines contribution scores of graph components to generate interpretable outputs.
Timeline
Filed
04/20/2026
Published
08/27/2026
Granted
Not Available
IPC Codes(1)
H04L 9/40:Network security protocols