Sharing attack telemetry across organisations boosts collective defence but raises compliance headaches. We apply differential‑privacy noise mechanisms and secure enclaves (SGX) to sanitise NetFlow and IDS alert feeds before aggregation. The framework guarantees probabilistic anonymity while preserving statistical fidelity for machine‑learning models. Pilot deployments include three universities and one regional ISP.





