Get Started
Home
Topics
Search
Library
Research questionHow can organizations detect coordinated cyberattack campaigns from fragmented local evidence without sharing sensitive telemetry or indicators?Each organization may observe only part of an active attack campaign and hold different indicators, making cross-organizational correlation difficult when telemetry cannot cross institutional or national boundaries.
AI
Machine Learning
Research Paper
Statistical Machine Learning
Technology
Latest papersRecent research connected to this question, newest first.Federated Attack Campaign Detection via Contrastive Encoding of Threat Indicators in Gradient UpdatesThe evidence covers FedIoC evaluated on two public threat-detection benchmarks distributed across federated-learning clients. Clients observe campaign fragments and disjoint indicator sets; the server recovers campaign cohorts from cosine similarity between gradient updates. The results identify non-IID gradient structure as a key driver, but the evidence is limited to these benchmark settings.research paper · Sep 4, 2026
Related questions
How can live-streaming risk detectors connect recurring behavior across sessions without sacrificing real-time response?How can cooperative perception fuse independently trained detectors without pre-deployment coordination?How can we detect multivariate IoT traffic anomalies across deployments without labels or raw-feature sharing?How can autonomous LLM agents detect attacks whose evidence accumulates across loop iterations?