Skip to content
Open access

Interpretable Deep Learning Defences via User Anomaly Detection in Cloud Platforms

Jul 2026 · Journal of Intelligent Decision Making and Information Science · 0 citations · 11 references

Abstract

Cloud platforms are the targets of highly advanced attacks that are designed to circumvent traditional rule based IDSs, such as: credential misuse, insider threats, privilege escalation, lateral movements, etc. To protect against user attacks, this paper introduces an interpretable deep learning defence framework in the context of user anomaly detection for both IaaS and PaaS cloud service layers and SaaS application layer. Multi-source authentication logs/records, APIs, networks logs are combined into integrated behavioural tensors and classified as anomalies by processing with the recurrent neural network with attention-based temporal weights. The mathematical model for access probability distribution, the model for anomaly scoring and temporal sequence modeling, as well as the model for Mahalanobis-distance-based deviation analysis further enhance the analysis's rigor and interpretability. Experimental results show that the detection accuracy achieved is 97.4%, followed by 96.8% precision, 97.9% recall and 97.3% F1-score, which are much higher than those of the conventional rule-based and black-box deep learning IDSs.

Read PDF