<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE ArticleSet PUBLIC "-//NLM//DTD PubMed 2.7//EN" "https://dtd.nlm.nih.gov/ncbi/pubmed/in/PubMed.dtd">
<ArticleSet>
<Article>
<Journal>
				<PublisherName>گروه تخصصی محاسبات و سامانه های توزیع شده  انجمن انفورماتیک ایران</PublisherName>
				<JournalTitle>دوفصلنامه محاسبات و سامانه های توزیع شده</JournalTitle>
				<Issn>2645-4416</Issn>
				<Volume>9</Volume>
				<Issue>1</Issue>
				<PubDate PubStatus="epublish">
					<Year>2026</Year>
					<Month>08</Month>
					<Day>23</Day>
				</PubDate>
			</Journal>
<ArticleTitle>TransFeL-NIDS: Federated Latent Zero-Day Signatures using a Memory-Based Transformer for Network Intrusion Detection System</ArticleTitle>
<VernacularTitle>TransFeL-NIDS: Federated Latent Zero-Day Signatures using a Memory-Based Transformer for Network Intrusion Detection System</VernacularTitle>
			<FirstPage>83</FirstPage>
			<LastPage>88</LastPage>
			<ELocationID EIdType="pii">247926</ELocationID>
			
			
			<Language>FA</Language>
<AuthorList>
<Author>
					<FirstName>حمیدرضا</FirstName>
					<LastName>یزدان پناه</LastName>
<Affiliation>دانشکده مهندسی کامپیوتر دانشگاه یزد؛ یزد؛ ایران</Affiliation>

</Author>
<Author>
					<FirstName>مجتبی</FirstName>
					<LastName>متین خواه</LastName>
<Affiliation>دانشکده مهندسی کامپیوتر دانشگاه یزد، یزد، ایران</Affiliation>
<Identifier Source="ORCID">0000-0002-3800-8396</Identifier>

</Author>
<Author>
					<FirstName>علی اکبر</FirstName>
					<LastName>نیکوکار</LastName>
<Affiliation>دانشکده علوم کامپیوتر، دانشگاه یاسوج؛ یاسوج؛ ایران</Affiliation>

</Author>
</AuthorList>
				<PublicationType>Journal Article</PublicationType>
			<History>
				<PubDate PubStatus="received">
					<Year>2026</Year>
					<Month>07</Month>
					<Day>25</Day>
				</PubDate>
			</History>
		<Abstract>Zero-day attacks are a critical challenge for Network Intrusion Detection (NIDS) due to the unknown structure of the attack with no predefined signature. Machine learning (ML) and Deep Learning (DL) models have recently emerged as a promising solution for enhancing IDS capabilities by detecting anomalies. On the other hand, Federated Learning has emerged as a groundbreaking paradigm for distributed applications to enhance privacy and bandwidth efficiency. The standard Federated Learning (FL) approach generally shares model parameters, which cannot effectively transfer knowledge about unseen attack behaviors across clients. This paper introduces TransFeL-NIDS, a novel federated zero-day detection method that allows clients to share the latent zero-day signatures extracted from a memory-based Transformer. The latent signatures encode high-level behavioral semantics without disclosing raw packets or sensitive traffic data. Compared to the standard FL approach, this strategy improves cross-client generalization to detect unseen attacks while preserving privacy and bandwidth efficiency. Additionally, the latent signature updates help mitigate the negative effects of imbalanced and non-IID data distributions in federated learning.</Abstract>
			<OtherAbstract Language="FA">Zero-day attacks are a critical challenge for Network Intrusion Detection (NIDS) due to the unknown structure of the attack with no predefined signature. Machine learning (ML) and Deep Learning (DL) models have recently emerged as a promising solution for enhancing IDS capabilities by detecting anomalies. On the other hand, Federated Learning has emerged as a groundbreaking paradigm for distributed applications to enhance privacy and bandwidth efficiency. The standard Federated Learning (FL) approach generally shares model parameters, which cannot effectively transfer knowledge about unseen attack behaviors across clients. This paper introduces TransFeL-NIDS, a novel federated zero-day detection method that allows clients to share the latent zero-day signatures extracted from a memory-based Transformer. The latent signatures encode high-level behavioral semantics without disclosing raw packets or sensitive traffic data. Compared to the standard FL approach, this strategy improves cross-client generalization to detect unseen attacks while preserving privacy and bandwidth efficiency. Additionally, the latent signature updates help mitigate the negative effects of imbalanced and non-IID data distributions in federated learning.</OtherAbstract>
		<ObjectList>
			<Object Type="keyword">
			<Param Name="value">Federated Learning</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Edge AI</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Transformer</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Latent Signature</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Network Intrusion Detection</Param>
			</Object>
		</ObjectList>
<ArchiveCopySource DocType="pdf">https://www.jdcs.ir/article_247926_9300ddd264e9de1113f7c6a7dac1c403.pdf</ArchiveCopySource>
</Article>
</ArticleSet>
