A Multi-Agent Federated Learning Framework with Explainable Graph Neural Networks for Real-Time Insider Threat Detection in Zero-Trust Enterprise Networks

Authors

  • M. Hanumanthu, D. Hussenappa Author

DOI:

https://doi.org/10.62643/

Abstract

The rapid adoption of cloud computing, Software-as-a-Service (SaaS), Internet of Things (IoT) devices, remote work environments, and hybrid enterprise infrastructures has significantly increased the complexity of enterprise cybersecurity, making insider threats one of the most difficult attacks to detect. Unlike external attacks, insider threats originate from authorized users whose malicious activities often resemble legitimate behavior, allowing them to evade traditional signature-based intrusion detection systems and centralized machine learning models. To address these challenges, this research proposes A Multi-Agent Federated Learning Framework with Explainable Graph Neural Networks for Real-Time Insider Threat Detection in Zero-Trust Enterprise Networks. The framework deploys intelligent security agents across distributed enterprise environments to monitor user activities, authentication events, endpoint behavior, and network communications while preserving data privacy through Federated Learning. Graph Neural Networks model complex relationships among enterprise entities, and Explainable Artificial Intelligence (XAI) enhances transparency by identifying the behavioral patterns responsible for threat predictions. The proposed architecture also incorporates secure model aggregation, adaptive anomaly scoring, Zero-Trust access verification, and real-time threat response. Experimental evaluation demonstrates improved detection accuracy, precision, recall, and interpretability while reducing false alarms and response time compared to conventional approaches. The framework effectively detects credential misuse, privilege escalation, unauthorized access, lateral movement, and other insider attacks, providing a scalable, privacy-preserving, and explainable cybersecurity solution for modern Zero-Trust enterprise environments

Downloads

Published

23-10-2025

How to Cite

A Multi-Agent Federated Learning Framework with Explainable Graph Neural Networks for Real-Time Insider Threat Detection in Zero-Trust Enterprise Networks. (2025). International Journal of Engineering Research and Science & Technology, 21(4), 950-965. https://doi.org/10.62643/