Abstract
<title>Abstract</title> <p>The proliferation of networked infrastructure, spanning enterprise information systems, Internet of Things (IoT) deployments, and industrial control environments, has widened the attack surface available to adversaries and made purely centralised intrusion detection increasingly difficult to sustain. Centralised architectures typically require raw traffic or log data to be transmitted to a single analytic Centre, an arrangement that raises bandwidth, latency, regulatory, and confidentiality concerns. Federated learning (FL) has emerged as an alternative paradigm in which distributed clients collaboratively train a shared detection model while retaining their data locally. This paper presents a systematic review of FL-based architectures, applications, and open challenges in distributed cyber threat detection. Following a structured search of Scopus, IEEE Xplore, ACM Digital Library, and ScienceDirect, a corpus of peer-reviewed studies published between 2017 and 2025 was analyzed to characterise architectural variants, aggregation strategies, application domains, and adversarial threats specific to federated intrusion detection. The review finds that hierarchical and blockchain-assisted architectures are gaining traction in resource-constrained and trust-sensitive environments, that non-independent and identically distributed (non-IID) data remain the principal obstacle to model convergence, and that poisoning and inference attacks constitute the most consequential unresolved security risks. Three original figures and three tables synthesised the reviewed architectures, comparative study characteristics, and the federated training lifecycle together with its attack surface. The review concludes by outlining research directions concerning robust aggregation, communication efficiency, and standardised benchmarking for federated cyber threat detection.</p>