A Hybrid Federated–Incremental Learning Framework for Continuous Authentication in Zero-Trust Networks
Abstract
1. Introduction
- Our federated learning design is integrated into the zero-trust control plane. Here, we were able to delineate the duties and security assumptions of all entities participating in continuous authentication. The proposed dynamic federated aggregation strategy considers both the recency of model updates and the integrity of local contributions. It can mitigate the decrease in performance due to non-independent and identically distributed data and respond to new challenges faster.
- We performed numerous experiments on a dataset that involved both real-world network attack information and synthetic user behavior. The results proved that the scheme we suggest significantly contributes to improving the quality of authentication, especially when an unknown attack is detected early. Also, we measured its real-world performance, especially communication overhead and convergence speed. Initially, we are going to assess the current research position in the field of interest. Next, we will explain the architecture and algorithm design behind the suggested model. After that, we will check how effective the model is by systematically comparing the experimental results. Lastly, we will summarize the findings and provide possible future research directions.
2. Related Research Work
2.1. Dynamic Identity Authentication in Zero-Trust Architecture
2.2. Applications of Federated Learning in Network Security and Identity Authentication
2.3. Incremental Learning Technology for Dynamic Environments
2.4. Summary of Research Status
3. Federated Incremental Identity Authentication Model for Zero Trust (FIL-ZTA Model)
3.1. System Architecture and Threat Model
3.1.1. Participating Entities and Function Definitions
3.1.2. Threat Model and Security Assumptions
3.2. Local Lightweight Authentication Model
3.2.1. Extraction of Discrete–Continuous Hybrid Behavior Features
3.2.2. Structure of the Lightweight Neural Network Model
3.2.3. Local Training Objectives and Addressing Class Imbalance
3.3. Federated Incremental Aggregation Algorithm for Privacy Protection
| Algorithm 1: Federated Incremental Aggregation with Privacy Protection |
| Input: - Global model weights - Set of all clients K - Thresholds: (minimum increment size), (maximum time since last update), τ_reputation (minimum reputation score) - Hyperparameters: β (weight for quality combination), ζ, μ (soft threshold parameters) - Privacy parameters: C (clipping bound), σ (noise scale) - Total communication rounds T for each communication round t = 1 to T do // Server requests participation from all clients Server broadcasts a participation request to all clients in K // Parallel local training and update submission for each client in parallel do Client k trains on its incremental dataset using local loss (Equation (9)) Client k computes model update Client k sends to server: , , timestamp of last update, pre-training loss , post-training loss end for // Stage 1: Dynamic client screening = Ø // candidate set for round t for each client do if and and reputation then end if end for // Stage 2: Contribution-aware weighting for each client do // Quality factor // relative improvement // Compute entropy of normalized absolute update values Let // element-wise absolute value Let // normalize to probability distribution // entropy (ε for numerical stability) // d = dimension of end for // Compute centroid of updates in candidate set for each client do // Consistency factor // cosine similarity // soft threshold function // Aggregation weight α_k end for // Stage 3: Differential privacy protection for each client do // Norm clipping end for // Weighted aggregation with Gaussian noise // Update global model // (Optional) Update client reputations R_k based on their contributions end for |
3.3.1. Design Concept of the Algorithm
3.3.2. Dynamic Client Screening Mechanism
3.3.3. Contribution-Aware Weighted Aggregation Strategy
3.3.4. Privacy-Enhanced Global Model Update
3.4. Dynamic Trust Evaluation and Decision-Making Engine
3.4.1. Multi-Dimensional Dynamic Trust Scoring Model
- : Risks associated with the security status of the device;
- : Network geographical location risk;
- : Time window risk;
- : Sensitivity of the requested resources.
3.4.2. Elastic Policy Mapping Based on Continuous Risk
- (trust): Grant all the requested permissions.
- (low suspicion): Allow permissions but, when it comes to audit log recording implementation, enhance them, and decrease the session validity period.
- (moderate suspicion): Implement a sequential authentication process that involves checking the identity using a second factor, which can be in the form of an SMS code or biometric recognition. On successful authentication, offer limited permissions.
- (highly suspected): Deny access instantly, terminate the session, create an alert for a high-level security incident, and inform the Security Operations Center.
3.4.3. Feedback-Driven Model Calibration Closed-Loop
4. Experimental Validation and Performance Evaluation
4.1. Experimental Setup
4.1.1. Dataset and Environment Configuration
4.1.2. Comparison Methods and Evaluation Indicators
4.2. Comparison of Core Authentication Performance
4.2.1. Authentication Accuracy in a Static Environment
4.2.2. Adaptability to Concept Drift
4.2.3. Detection Effects of Different Types of Attacks
4.3. Analysis of System Efficiency and Communication Overhead
4.3.1. Comparison of Communication Efficiency
4.3.2. Calculation of Resource Consumption
4.4. System Robustness Analysis
4.4.1. Countering Malicious Client Attacks
- Data poisoning attackers: These clients corrupt their local training data by flipping labels (e.g., labeling attack traffic as normal) or injecting adversarial samples. The goal is to degrade the global model’s accuracy or induce targeted misclassifications.
- Model poisoning attackers: These clients manipulate the model updates (gradients) before uploading, e.g., by adding large noise, scaling updates, or sending arbitrary vectors, aiming to disrupt convergence or bias the global model.
- Backdoor attackers: These clients embed a hidden trigger in a small fraction of their local data (e.g., a specific pattern in network traffic) and train the model to associate that trigger with a target label (e.g., normal). The backdoor remains dormant until the trigger appears at inference time, causing the model to misclassify attack traffic as normal.
4.4.2. Ablation Experiment Analysis
4.4.3. Privacy Protection Effect Assessment
4.5. Scalability for Large-Scale Deployment
4.5.1. Scalability of the Number of Clients
4.5.2. Compatibility of Heterogeneous Devices
5. Discussion
5.1. Analysis of the Method’s Advantages
5.2. Limitation Analysis
5.3. Research Implications and Prospects
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
Abbreviations
| GDPR | General Data Protection Regulation |
| CCPA | California Consumer Privacy Act |
| FIL-ZTA | Federated Incremental Identity Authentication Model for Zero Trust |
| PEP | Policy Enforcement point |
| PDP | Policy Decision Point |
| Non-IID | Non-Independent and Identically Distributed |
| EER | Equal Error Rate |
References
- Kim, S.; Cho, D.; Yeo, S. Secure model against APT in m-connected SCADA network. Int. J. Distrib. Sens. Netw. 2014, 10, 594652. [Google Scholar] [CrossRef] [Scilit]
- Du, Y.; Ren, W.; Li, W.; Wang, M.; Wang, W.; Zhang, H.; Xia, M. GA-ConvE: An APT attack prediction method based on combination of graph attention network and 2D convolution. Neural Netw. 2025, 195, 108216. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Khan, R.; Tariq, N.; Ashraf, M.; Khan, F.A.; Shafi, S.; Ali, A. FL-DSFA: Securing RPL-based IoT networks against selective forwarding attacks using federated learning. Sensors 2024, 24, 5834. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Alemayew, W.B.; Gemeda, K.A. Federated hybrid deep learning for multi-attack detection and classification in RPL-based 6LoWPAN networks. Discov. Comput. 2025, 28, 316. [Google Scholar] [CrossRef] [Scilit]
- Verma, R.; Jailia, M. A hybrid metaheuristic federated learning approach based attack detection system for multi-cloud environment. J. Cloud Comput. 2025, 14, 73. [Google Scholar] [CrossRef] [Scilit]
- Zhou, Q.; Yu, Y.; Ma, J.; Obaidat, M.S.; Chang, X.; Ma, M.; Sun, S. FedPLC: Federated learning with dynamic cluster adaptation for concept drift on Non-IID data. Sensors 2026, 26, 283. [Google Scholar] [CrossRef] [Scilit]
- Wang, X.; Liu, Z.; Dai, M.; Gong, J.; Ni, W. A verifiable and efficient chained federated learning scheme for privacy protection. Comput. Netw. 2025, 274, 111838. [Google Scholar] [CrossRef] [Scilit]
- Chen, X.; Zhang, D.; Cui, Z.Q.; Gu, Q.; Ju, X.L. DP-share: Privacy-preserving software defect prediction model sharing through differential privacy. J. Comput. Sci. Technol. 2019, 34, 1020–1038. [Google Scholar] [CrossRef] [Scilit]
- Cui, L.; Wu, X. ALDP-FL for adaptive local differential privacy in federated learning. Sci. Rep. 2025, 15, 26679. [Google Scholar] [CrossRef] [Scilit]
- Wang, D.; Guan, S. FedFR-ADP: Adaptive differential privacy with feedback regulation for robust model performance in federated learning. Inf. Fusion 2025, 116, 102796. [Google Scholar] [CrossRef] [Scilit]
- Kumar, G.H.; Reddy, S.; Saxena, S.; Swamy, K.A.; Kumar, U.P. FL-DPCSA: Federated learning with differential privacy for cache side-channel attack detection in edge-based smart grids. e-Prime Adv. Electr. Eng. 2025, 13, 101057. [Google Scholar] [CrossRef] [Scilit]
- Alter, G.; Falk, B.H.; Lu, S.; Ostrovsky, R. Computing statistics from private data. Data Sci. J. 2018, 17, 31. [Google Scholar] [CrossRef] [Scilit]
- Rehman, T.; Tariq, N.; Khan, F.A.; Rehman, S.U. FFL-IDS: A fog-enabled federated learning-based intrusion detection system to counter jamming and spoofing attacks for the Industrial internet of things. Sensors 2024, 25, 10. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Xie, R.; Chen, Z.; Cao, W.; Wang, H. Federated self-expanding neural network learning framework for heterogeneous devices. Expert Syst. Appl. 2026, 311, 131199. [Google Scholar] [CrossRef] [Scilit]
- Jiang, H.; Chen, X.; Miao, D.; Zhang, H.; Qin, X.; Du, S.; Lu, P. PrivTSAD-FedWGAN: A novel federated learning and WGAN framework for privacy-preserving multivariate time series anomaly detection. Expert Syst. Appl. 2026, 307, 131049. [Google Scholar] [CrossRef] [Scilit]
- Gao, Q.; Kausar, S.; Zhang, H.X. Incremental-learning-based graph neural networks on edge-forwarding devices for network intrusion detection. Alex. Eng. J. 2025, 126, 81–89. [Google Scholar] [CrossRef] [Scilit]
- Abhishek, R.; Raj RD, A.; Yanamala RM, R.; Pallakonda, A.; Sreenu, S. Federated learning-enhanced Non-IID solar power prediction using multi-layer transformers. Energy Convers. Manag. X 2025, 29, 101446. [Google Scholar]
- Wu, F.; Tan, A.Z.; Feng, S.; Yu, H.; Deng, T.; Zhao, L.; Chen, Y. Federated class-incremental learning via weighted aggregation and distillation. IEEE Internet Things J. 2025, 12, 22489–22503. [Google Scholar] [CrossRef] [Scilit]
- You, Z.; Chu, J.; Li, Z.; Liu, B.; Li, T. Adaptive federated class-incremental learning for reducing catastrophic forgetting. Expert Syst. Appl. 2025, 291, 128442. [Google Scholar] [CrossRef] [Scilit]
- Carillo, R.; Cerasuolo, F.; Bovenzi, G.; Ciuonzo, D.; Pescape, A. Explainable federated class incremental learning for encrypted network traffic classification. Comput. Netw. 2025, 269, 111448. [Google Scholar] [CrossRef] [Scilit]
- Li, Y.; Wang, H.; Qi, Y.; Liu, W.; Li, R. Re-Fed+: A better replay strategy for federated incremental learning. IEEE Trans. Pattern Anal. Mach. Intell. 2025, 47, 5489–5500. [Google Scholar] [CrossRef] [Scilit]
- Luo, X.; Liang, F.Y.; Liu, J.; Zhan, Y.W.; Chen, Z.D.; Xu, X.S. Federated class-incremental learning with prompting. Expert Syst. Appl. 2025, 297, 129416. [Google Scholar] [CrossRef] [Scilit]
- Criado, M.F.; Casado, F.E.; Iglesias, R.; Regueiro, C.V.; Barro, S. Non-IID data and Continual Learning processes in Federated Learning: A long road ahead. Inf. Fusion 2022, 88, 263–280. [Google Scholar] [CrossRef] [Scilit]
- Liu, D.; Bai, L.; Guo, Y.; Tang, J.; Ruan, Y.; Li, D.; Yu, T. Fed-GCC: Global classifier consensus for conventional/task-free federated class-incremental learning. Knowl.-Based Syst. 2025, 327, 114131. [Google Scholar] [CrossRef] [Scilit]
- Mironov, I. Rényi Differential Privacy. In Proceedings of the 2017 IEEE 30th Computer Security Foundations Symposium (CSF), Santa Barbara, CA, USA, 21–25 August 2017; pp. 263–275. [Google Scholar]










| Method | Application | Handles Concept Drift | Privacy Mechanism | Key Innovation |
|---|---|---|---|---|
| FedAvg [7] | General FL | No | None | Periodic averaging |
| FedProx [8] | Heterogeneous FL | No | None | Proximal term for non-IID data |
| FA-FedAvg [24] | Federated incremental learning | Limited | None | Adaptive aggregation weights |
| Ours (FIL-ZTA) | Zero-trust authentication | Yes (dynamic screening + contribution weighting) | Differential privacy | Closed-loop feedback + robust aggregation |
| Layer | Output Shape | Parameters | FLOPs |
|---|---|---|---|
| Conv1D (32, k = 3) | (1, 32, 108) | 128 | 20,736 |
| MaxPool1D | (1, 32, 54) | 0 | 0 |
| Conv1D (64, k = 3) | (1, 64, 52) | 6208 | 19,968 |
| MaxPool1D | (1, 64, 26) | 0 | 0 |
| Conv1D (128, k = 3) | (1, 128, 24) | 24,704 | 18,432 |
| MaxPool1D | (1, 128, 12) | 0 | 0 |
| Flatten | (1, 1536) | 0 | 0 |
| Fully Connected (256) | (1, 256) | 393,472 | 786,432 |
| Fully Connected (128) | (1, 128) | 32,896 | 65,536 |
| Output Layer (Softmax) | (1, 2) | 258 | 512 |
| Total | 457,666 (~0.46 M) | ~0.91 M |
| Method | EER (%) | FAR (%) | FRR (%) | AUC | Rounds | Single-Round Time |
|---|---|---|---|---|---|---|
| Centralized CNN | 1.52 | 1.48 | 1.56 | 0.992 | 50 | 45.2 |
| FedAvg | 4.89 | 4.95 | 4.83 | 0.972 | 38 | 12.3 |
| FedProx | 3.71 | 3.65 | 3.77 | 0.985 | 32 | 12.8 |
| FA-FedAvg | 3.02 | 2.97 | 3.07 | 0.988 | 26 | 13.1 |
| FIL-ZTA | 2.15 | 2.08 | 2.22 | 0.991 | 18 | 14.5 |
| Attack Type | Number of Samples | FedAvg | FedProx | FA-FedAvg | FIL-ZTA |
|---|---|---|---|---|---|
| Brute force attack | 12,500 | 95.3 | 96.1 | 96.8 | 97.5 |
| DDoS | 8700 | 92.7 | 93.5 | 94.2 | 95.1 |
| Web attack | 10,200 | 88.5 | 90.2 | 91.3 | 93.6 |
| Port scanning | 6800 | 96.2 | 96.8 | 97.1 | 97.9 |
| New Attack D | 5300 | 76.4 | 81.2 | 87.5 | 94.2 |
| New Attack E | 4900 | 72.8 | 78.6 | 85.3 | 92.7 |
| Attack Type | Precision (%) | Recall (%) | F1-Score (%) | PR-AUC (%) |
|---|---|---|---|---|
| Brute Force Attack | 97.8 | 97.2 | 97.5 | 98.1 |
| DDoS | 95.4 | 94.8 | 95.1 | 96.0 |
| Web Attack | 94.1 | 93.0 | 93.5 | 94.7 |
| Port Scanning | 98.2 | 97.6 | 97.9 | 98.5 |
| New Attack D | 94.8 | 93.6 | 94.2 | 95.3 |
| New Attack E | 93.5 | 91.9 | 92.7 | 94.0 |
| Method | Convergence Rounds | Single-Round Communication Volume (MB) | Cumulative Communication Volume (MB) | AUC at Convergence | Bandwidth Utilization Rate (%) |
|---|---|---|---|---|---|
| FedAvg | 38 | 12.0 | 456.0 | 0.972 | 73.2 |
| FedProx | 32 | 12.0 | 384.0 | 0.985 | 78.5 |
| FA-FedAvg | 26 | 12.0 | 312.0 | 0.988 | 82.1 |
| FIL-ZTA | 18 | 12.0 | 216.0 | 0.991 | 88.7 |
| Method | Single-Round Training Time (s) | Total Training Time (s) | Peak Memory (MB) | Average Energy Consumption (J) | Energy Consumption Efficiency (Samples/J) |
|---|---|---|---|---|---|
| FedAvg | 12.3 | 467.4 | 1250 | 1842 | 461.5 |
| FedProx | 12.8 | 409.6 | 1280 | 1635 | 519.9 |
| FA-FedAvg | 13.1 | 340.6 | 1310 | 1428 | 595.2 |
| FIL-ZTA | 14.5 | 261.0 | 1353 | 1313 | 647.5 |
| Experimental Configuration | EER (%) | FAR (%) | FRR (%) | AUC | Performance Degradation (%) |
|---|---|---|---|---|---|
| Complete FIL-ZTA | 3.98 | 3.85 | 4.11 | 0.986 | 0.0 |
| No dynamic screening | 9.85 | 9.72 | 9.98 | 0.952 | 147.5 |
| No contribution weighting | 6.72 | 6.58 | 6.86 | 0.971 | 68.5 |
| No differential privacy | 4.33 | 4.20 | 4.46 | 0.984 | 8.8 |
| Variant | EER (%) | FAR (%) | FRR (%) | AUC |
|---|---|---|---|---|
| Uniform weighting (baseline) | 6.72 | 6.58 | 6.86 | 0.971 |
| Quality factor only | 5.51 | 5.38 | 5.64 | 0.978 |
| Consistency factor only | 5.24 | 5.11 | 5.37 | 0.980 |
| Full combination | 3.98 | 3.85 | 4.11 | 0.986 |
| Number of Clients | FIL-ZTA EER (%) | Convergence Rounds | Single-Round Time(s) | Cumulative Communication (GB) | Performance Retention Rate (%) |
|---|---|---|---|---|---|
| 10 | 2.15 | 18 | 14.5 | 0.216 | 100.0 |
| 50 | 2.08 | 21 | 22.3 | 0.504 | 103.4 |
| 200 | 2.02 | 25 | 31.6 | 0.900 | 106.4 |
| 500 | 2.11 | 29 | 39.8 | 1.392 | 101.9 |
| 1000 | 2.21 | 32 | 46.2 | 1.728 | 97.3 |
| Clients | Synchronous (for Reference) | Asynchronous (θ = 0.8) | Speedup |
|---|---|---|---|
| 10 | 4.3 min | 4.1 min | 1.05× |
| 50 | 9.8 min | 8.0 min | 1.23× |
| 200 | 15.2 min | 11.3 min | 1.34× |
| 500 | 24.6 min | 16.2 min | 1.52× |
| 1000 | 38.7 min | 20.5 min | 1.89× |
| Device Type | Computing Power | Network Bandwidth | EER (%) | Training Time (s) | Memory Occupancy (MB) | Model Size (MB) |
|---|---|---|---|---|---|---|
| High-performance server | High | 1 Gbps | 2.15 | 14.5 | 1353 | 12.0 |
| Edge gateway | Medium | 100 Mbps | 2.41 | 28.7 | 842 | 8.2 |
| Internet of Things devices | Low | 10 Mbps | 2.89 | 72.3 | 512 | 4.1 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Ji, J.; Qiu, S.; Ye, S.; Liu, X. A Hybrid Federated–Incremental Learning Framework for Continuous Authentication in Zero-Trust Networks. Future Internet 2026, 18, 154. https://doi.org/10.3390/fi18030154
Ji J, Qiu S, Ye S, Liu X. A Hybrid Federated–Incremental Learning Framework for Continuous Authentication in Zero-Trust Networks. Future Internet. 2026; 18(3):154. https://doi.org/10.3390/fi18030154
Chicago/Turabian StyleJi, Jie, Shi Qiu, Shengpeng Ye, and Xin Liu. 2026. "A Hybrid Federated–Incremental Learning Framework for Continuous Authentication in Zero-Trust Networks" Future Internet 18, no. 3: 154. https://doi.org/10.3390/fi18030154
APA StyleJi, J., Qiu, S., Ye, S., & Liu, X. (2026). A Hybrid Federated–Incremental Learning Framework for Continuous Authentication in Zero-Trust Networks. Future Internet, 18(3), 154. https://doi.org/10.3390/fi18030154

