1
- https://doi.org/10.1109/commantel68363.2025.11368519
Compliance-Aware Cross-Border Federated Learning for Security Telemetry under HIPAA/GDPR
- Dec 14, 2025
- Nishanth Sirikonda +3 more
We propose a hierarchical, policy-aware federated learning (FL) framework that enforces strict data residency while training intrusion and anomaly detectors across jurisdictions such as the United States and the European Union. A policy engine encoded in a domain-specific YAML dialect constrains cross-border traffic to either nothing or to differentially private (DP) summaries whose privacy loss is tracked with a Renyi DP accountant; regional aggregators train local models that are fused into a global backbone through secure aggregation. Using public cybersecurity datasets partitioned into simulated US/EU sites, we benchmark ROC-AUC, macro-F1, cross-border communication cost, and cumulative privacy loss $\varepsilon$ under varying non-IID severity and temporal drift. Results indicate the proposed method preserves compliance (zero residency violations) while matching or exceeding flat FL baselines at $10 \%-30 \%$ lower cross-border bandwidth for comparable $\varepsilon$. We release an open-source reference implementation including policy schemas, enforcement hooks, and an auditable DP accountant, along with a reproducibility checklist and SDK to operationalize compliance in FL deployments.