FedXDDoS: An Explainable Federated Learning Framework for DDoS Attack Detection

Distributed Denial of Service (DDoS) attacks have
emerged as a significant security challenge in software-defined
networking (SDN) environments, where surges in malicious traffic
can disrupt network operations and degrade service availability.
Although deep learning-based intrusion detection systems have
achieved excellent performance in identifying malicious activities,
many existing solutions depend on centralized training and lack
interpretability. To overcome these challenges, This study introduces FedXDDoS, an explainable federated learning framework
for privacy-preserving DDoS attack detection and explanation in
distributed SDN environments. This framework utilizes multiple
deep learning architectures under both FedAvg and FedProx
optimization strategies to facilitate collaborative model training
with no sharing of raw network traffic data. To demonstrate the
effectiveness of the proposed approach, which achieves a best
accuracy of 99. 69% and an F1 score of 99. 67%, the experiments
were conducted on the DDoS-SDN dataset using four federated
clients. Additionally, LIME-based explainability is integrated to
enhance transparency and trustworthiness by offering featurelevel interpretations of model predictions. The results show that
FedXDDoS provides an accurate and interpretable approach for
detecting DDoS attacks in contemporary SDN environments.