{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T01:43:17Z","timestamp":1780623797226,"version":"3.54.1"},"reference-count":39,"publisher":"MDPI AG","issue":"7","license":[{"start":{"date-parts":[[2025,7,3]],"date-time":"2025-07-03T00:00:00Z","timestamp":1751500800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Hanoi University of Science and Technology","award":["T2023-PC-038"],"award-info":[{"award-number":["T2023-PC-038"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>Domain Generation Algorithms (DGAs) remain a persistent technique used by modern malware to establish stealthy command-and-control (C&amp;C) channels, thereby evading traditional blacklist-based defenses. Detecting such evolving threats is especially challenging in decentralized environments where raw traffic data cannot be aggregated due to privacy or policy constraints. To address this, we present FedSAGE, a security-aware federated intrusion detection framework that combines Variational Autoencoder (VAE)-based latent representation learning with unsupervised clustering and resource-efficient client selection. Each client encodes its local domain traffic into a semantic latent space using a shared, pre-trained VAE trained solely on benign domains. These embeddings are clustered via affinity propagation to group clients with similar data distributions and identify outliers indicative of novel threats without requiring any labeled DGA samples. Within each cluster, FedSAGE selects only the fastest clients for training, balancing computational constraints with threat visibility. Experimental results from the multi-zones DGA dataset show that FedSAGE improves detection accuracy by up to 11.6% and reduces energy consumption by up to 93.8% compared to standard FedAvg under non-IID conditions. Notably, the latent clustering perfectly recovers ground-truth DGA family zones, enabling effective anomaly detection in a fully unsupervised manner while remaining privacy-preserving. These foundations demonstrate that FedSAGE is a practical and lightweight approach for decentralized detection of evasive malware, offering a viable solution for secure and adaptive defense in resource-constrained edge environments.<\/jats:p>","DOI":"10.3390\/fi17070299","type":"journal-article","created":{"date-parts":[[2025,7,3]],"date-time":"2025-07-03T06:01:33Z","timestamp":1751522493000},"page":"299","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Detecting Emerging DGA Malware in Federated Environments via Variational Autoencoder-Based Clustering and Resource-Aware Client Selection"],"prefix":"10.3390","volume":"17","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-3329-2529","authenticated-orcid":false,"given":"Ma Viet","family":"Duc","sequence":"first","affiliation":[{"name":"School of Electrical and Electronic Engineering, Hanoi University of Science and Technology, Hanoi 100000, Vietnam"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-0177-0151","authenticated-orcid":false,"given":"Pham Minh","family":"Dang","sequence":"additional","affiliation":[{"name":"School of Electrical and Electronic Engineering, Hanoi University of Science and Technology, Hanoi 100000, Vietnam"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-0571-1962","authenticated-orcid":false,"given":"Tran Thu","family":"Phuong","sequence":"additional","affiliation":[{"name":"School of Electrical and Electronic Engineering, Hanoi University of Science and Technology, Hanoi 100000, Vietnam"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-6054-7555","authenticated-orcid":false,"given":"Truong Duc","family":"Truong","sequence":"additional","affiliation":[{"name":"School of Electrical and Electronic Engineering, Hanoi University of Science and Technology, Hanoi 100000, Vietnam"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2880-4417","authenticated-orcid":false,"given":"Vu","family":"Hai","sequence":"additional","affiliation":[{"name":"School of Electrical and Electronic Engineering, Hanoi University of Science and Technology, Hanoi 100000, Vietnam"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7354-1524","authenticated-orcid":false,"given":"Nguyen Huu","family":"Thanh","sequence":"additional","affiliation":[{"name":"School of Electrical and Electronic Engineering, Hanoi University of Science and Technology, Hanoi 100000, Vietnam"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,7,3]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1016\/j.jnca.2012.09.004","article-title":"Intrusion detection system: A comprehensive review","volume":"36","author":"Liao","year":"2013","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"46","DOI":"10.1109\/MSP.2016.76","article-title":"A taxonomy of domain-generation algorithms","volume":"14","author":"Sood","year":"2016","journal-title":"IEEE Secur. Priv."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"1430","DOI":"10.1109\/TIFS.2017.2668361","article-title":"Stealthy domain generation algorithms","volume":"12","author":"Fu","year":"2017","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Minh, N.N., Hieu, P.T., Hai, V., and Thanh, N.H. (2024, January 17\u201319). DGA-based Intrusion Detection System using Federated Learning Method on Edge Devices. Proceedings of the 2024 International Conference on Information Networking (ICOIN), Ho Chi Minh City, Vietnam.","DOI":"10.1109\/ICOIN59985.2024.10572165"},{"key":"ref_5","unstructured":"McMahan, B., Moore, E., Ramage, D., Hampson, S., and Arcas, B.A. (2017, January 20\u201322). Communication-efficient learning of deep networks from decentralized data. Proceedings of the Artificial Intelligence and Statistics, PMLR, Fort Lauderdale, FL, USA."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Aouedi, O., Piamrat, K., Muller, G., and Singh, K. (2022, January 8\u201311). FLUIDS: Federated Learning with semi-supervised approach for Intrusion Detection System. Proceedings of the 2022 IEEE 19th annual consumer communications & networking conference (CCNC), Las Vegas, NV, USA.","DOI":"10.1109\/CCNC49033.2022.9700632"},{"key":"ref_7","unstructured":"Duc, M.V., Luan, N.T., Tai, N.T., Hieu, N.P.T., Minh, N.N., Hieu, P.T., Hai, V., and Thanh, N.H. (2024, January 9). On the Impact of Heterogeneity on Federated Learning at the Edge with DGA Malware Detection. Proceedings of the Asian Internet Engineering Conference 2024, Sydney, Australia."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"20243","DOI":"10.1109\/JIOT.2022.3175149","article-title":"WSCC: A weight-similarity-based client clustering approach for non-IID federated learning","volume":"9","author":"Tian","year":"2022","journal-title":"IEEE Internet Things J."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Bo, L., Ping, Z.Y., and Cai, L.Q. (2023, January 21\u201324). FedPVD: Clustered Federated Learning with NoN-IID Data. Proceedings of the 2023 IEEE 6th International Conference on Electronic Information and Communication Technology (ICEICT), Qingdao, China.","DOI":"10.1109\/ICEICT57916.2023.10245600"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Shih, C.H., Kuo, J.J., and Sheu, J.P. (2023, January 4\u20138). Information-Exchangeable Hierarchical Clustering for Federated Learning with Non-IID Data. Proceedings of the GLOBECOM 2023\u20142023 IEEE Global Communications Conference, Kuala Lumpur, Malaysia.","DOI":"10.1109\/GLOBECOM54140.2023.10436834"},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"109","DOI":"10.1109\/OJCS.2023.3262203","article-title":"Flis: Clustered federated learning via inference similarity for non-iid data distribution","volume":"4","author":"Morafah","year":"2023","journal-title":"IEEE Open J. Comput. Soc."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Li, Q., Shao, S., Yang, C., Chen, J., Qi, F., and Guo, S. (2024, January 8\u201310). Communication-efficient Federated Learning Framework with Parameter-Ordered Dropout. Proceedings of the 2024 27th International Conference on Computer Supported Cooperative Work in Design (CSCWD), Tianjin, China.","DOI":"10.1109\/CSCWD61410.2024.10580559"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Alsamiri, J., and Alsubhi, K. (2023). Federated learning for intrusion detection systems in internet of vehicles: A general taxonomy, applications, and future directions. Future Internet, 15.","DOI":"10.3390\/fi15120403"},{"key":"ref_14","first-page":"19","article-title":"Federated learning: Applications, challenges and future directions","volume":"18","author":"Bharati","year":"2022","journal-title":"Int. J. Hybrid Intell. Syst."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"36097","DOI":"10.1109\/ACCESS.2023.3264584","article-title":"K-fl: Kalman filter-based clustering federated learning method","volume":"11","author":"Kim","year":"2023","journal-title":"IEEE Access"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Xiao, P., Cheng, S., Stankovic, V., and Vukobratovic, D. (2020). Averaging is probably not the optimum way of aggregating parameters in federated learning. Entropy, 22.","DOI":"10.20944\/preprints202001.0207.v1"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Liu, H., and Lang, B. (2019). Machine learning and deep learning methods for intrusion detection systems: A survey. Appl. Sci., 9.","DOI":"10.3390\/app9204396"},{"key":"ref_18","unstructured":"Onietan, C.I.O., Martins, I., Owoseni, T., Omonedo, E.C., and Eze, C.P. (2023, January 5\u20137). A preliminary study on the application of hybrid machine learning techniques in network intrusion detection systems. Proceedings of the 2023 International Conference on Science, Engineering and Business for Sustainable Development Goals (SEB-SDG), Omu-Aran, Nigeria."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Haripriya, L., and Jabbar, M.A. (2018, January 29\u201331). Role of machine learning in intrusion detection system. Proceedings of the 2018 Second International Conference on Electronics, Communication and Aerospace Technology (ICECA), Coimbatore, India.","DOI":"10.1109\/ICECA.2018.8474576"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"103111","DOI":"10.1016\/j.jnca.2021.103111","article-title":"Towards secure intrusion detection systems using deep learning techniques: Comprehensive analysis and review","volume":"187","author":"Lee","year":"2021","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"346","DOI":"10.1016\/j.comcom.2022.09.012","article-title":"Federated learning for intrusion detection system: Concepts, challenges and future directions","volume":"195","author":"Agrawal","year":"2022","journal-title":"Comput. Commun."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3687124","article-title":"Survey on federated learning for intrusion detection system: Concept, architectures, aggregation strategies, challenges, and future directions","volume":"57","author":"Khraisat","year":"2024","journal-title":"ACM Comput. Surv."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Shahzad, H., Sattar, A.R., and Skandaraniyam, J. (2021, January 8\u201310). DGA domain detection using deep learning. Proceedings of the 2021 IEEE 5th International Conference on Cryptography, Security and Privacy (CSP), Zhuhai, China.","DOI":"10.1109\/CSP51677.2021.9357591"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Kumar, S., and Bhatia, A. (2019, January 16\u201319). Detecting domain generation algorithms to prevent ddos attacks using deep learning. Proceedings of the 2019 IEEE International Conference on Advanced Networks and Telecommunications Systems (ANTS), Goa, India.","DOI":"10.1109\/ANTS47819.2019.9118156"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Zhang, W.W., Gong, J., and Liu, Q. (2013, January 9\u201311). Detecting machine generated domain names based on morpheme features. Proceedings of the 1st International Workshop on Cloud Computing and Information Security, Shanghai, China.","DOI":"10.2991\/ccis-13.2013.94"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Yadav, S., Reddy, A.K.K., Reddy, A.N., and Ranjan, S. (2010, January 1\u20133). Detecting algorithmically generated malicious domain names. Proceedings of the 10th ACM SIGCOMM Conference on Internet Measurement, Melbourne, Australia.","DOI":"10.1145\/1879141.1879148"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Drichel, A., Meyer, U., Sch\u00fcppen, S., and Teubert, D. (2020, January 25\u201328). Analyzing the real-world applicability of DGA classifiers. Proceedings of the 15th International Conference on Availability, Reliability and Security, Online.","DOI":"10.1145\/3407023.3407030"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Yu, B., Pan, J., Hu, J., Nascimento, A., and De Cock, M. (2018, January 8\u201313). Character level based detection of DGA domain names. Proceedings of the 2018 International Joint Conference on Neural Networks (IJCNN), Rio de Janeiro, Brazil.","DOI":"10.1109\/IJCNN.2018.8489147"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Catania, C., Garc\u00eda, S., and Torres, P. (2018, January 1\u20135). Deep convolutional neural networks for DGA detection. Proceedings of the Argentine Congress of Computer Science, Buenos Aires, Argentina.","DOI":"10.1007\/978-3-030-20787-8_23"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"2401","DOI":"10.1016\/j.neucom.2017.11.018","article-title":"A LSTM based framework for handling multiclass imbalance in DGA botnet detection","volume":"275","author":"Tran","year":"2018","journal-title":"Neurocomputing"},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"504","DOI":"10.1126\/science.1127647","article-title":"Reducing the dimensionality of data with neural networks","volume":"313","author":"Hinton","year":"2006","journal-title":"Science"},{"key":"ref_32","unstructured":"Kingma, D.P., and Welling, M. (2013). Auto-encoding variational bayes. arXiv."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"6303","DOI":"10.1109\/TNNLS.2021.3135460","article-title":"Deep clustering analysis via dual variational autoencoder with spherical latent embeddings","volume":"34","author":"Yang","year":"2021","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"10344","DOI":"10.3934\/mbe.2022484","article-title":"Achieving deep clustering through the use of variational autoencoders and similarity-based loss","volume":"19","author":"Ma","year":"2022","journal-title":"Math. Biosci. Eng."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"972","DOI":"10.1126\/science.1136800","article-title":"Clustering by passing messages between data points","volume":"315","author":"Frey","year":"2007","journal-title":"Science"},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Triastcyn, A., and Faltings, B. (2019, January 9\u201312). Federated learning with bayesian differential privacy. Proceedings of the 2019 IEEE International Conference on Big Data (Big Data), Los Angeles, CA, USA.","DOI":"10.1109\/BigData47090.2019.9005465"},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Ding, L., Li, L., Han, J., Fan, Y., and Hu, D. (2019). Detecting Domain Generation Algorithms with Bi-LSTM. Comput. Mater. Contin., 61.","DOI":"10.32604\/cmc.2019.06160"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Gogoi, B., and Ahmed, T. (2023, January 23\u201325). DGA domain detection using pretrained character based transformer models. Proceedings of the 2023 IEEE Guwahati Subsection Conference (GCON), Guwahati, India.","DOI":"10.1109\/GCON58516.2023.10183602"},{"key":"ref_39","unstructured":"Devlin, J., Chang, M.W., Lee, K., and Toutanova, K. (2019, January 2\u20137). Bert: Pre-training of deep bidirectional transformers for language understanding. Proceedings of the 2019 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, Minneapolis, MN, USA. (Long and Short Papers)."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/17\/7\/299\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T18:03:42Z","timestamp":1760033022000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/17\/7\/299"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,7,3]]},"references-count":39,"journal-issue":{"issue":"7","published-online":{"date-parts":[[2025,7]]}},"alternative-id":["fi17070299"],"URL":"https:\/\/doi.org\/10.3390\/fi17070299","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,7,3]]}}}