Skip to content

A Dynamic Graph Neural Network Framework for Advanced Persistent Threat Detection in Cloud Computing

Aug 2026 · International Journal for Global Academic & Scientific Research · 0 citations · 31 references

TL;DR

Although the framework performed slightly better than the best baseline under the tested conditions, the improvement was not statistically significant enough to establish consistent superiority and emphasize the need for further evaluation of deployment time, base-rate estimation, and real-world cybersecurity scenarios.

Abstract

Advanced Persistent Threats (APTs) are highly sophisticated and constantly evolving attacks that are difficult to detect using traditional static intrusion detection systems. This study introduces a novel framework called Dynamic Graph Neural Network (Dynamic-GNN) for detecting anomalous behaviors associated with APTs using temporal network and provenance data. The framework constructs cybersecurity temporal graphs and integrates dynamic graph representation learning, attention-based aggregation, and adaptive benign-reference updating to capture behavioral changes over time. The proposed framework was evaluated on the CICIDS2017 and DARPA Transparent Computing benchmark datasets using consistent training, validation, and testing procedures. The evaluation metrics included accuracy, precision, recall, F1-score, and AUC. The proposed approach achieved 94.70% accuracy, 94.41% precision, 94.63% recall, and 94.52% F1-score. Although the framework performed slightly better than the best baseline under the tested conditions, the improvement was not statistically significant enough to establish consistent superiority. The results support the potential of adaptive dynamic graph learning for detecting evolving anomalies and emphasize the need for further evaluation of deployment time, base-rate estimation, and real-world cybersecurity scenarios.

Read PDF

Similar papers

Open access Sep 2026

Graph-guided contrastive transformer architecture for robust and explainable network intrusion detection

Intrusion detection systems (IDS) are very instrumental in protecting contemporary network infrastructures against the ever-advancing cyberattacks. Conventional signature-based and machine learning-enabled IDS solutions frequently have difficulty when it comes to high false-positive rates, inability to flexibly adapt t...

Archana Jayapal, Kamalakkannan Somasundaram, Arun Kumar Ramamoorthy · 0 citations
Conference Aug 2026

SecureEnsembleNet: Intelligent Cyber Threat Detection with Ensemble Learning

The rapid growth of network-connected systems has made cyber threat detection a critical priority for modern infrastructures. Traditional signature-based intrusion detection systems (IDSs) struggle to detect novel and evolving attacks, creating the need for intelligent learning-based approaches. This paper presents Sec...

Buddha Dev Sarker, Md Fahim Ahammed, Md Rasheduzzaman Labu et al. · 0 citations
Review Open access Sep 2026

DEEP LEARNING-BASED INTRUSION DETECTION SYSTEMS: ARCHITECTURES, IMPLEMENTATIONS, AND CHALLENGES IN MODERN NETWORK ANOMALY DETECTION

The increasing complexity of cyber threats has strengthened the need for adaptive network intrusion detection systems (IDS). This systematic literature review (SLR) synthesizes nine peer-reviewed studies published from 2024 to 2026 on deep learning (DL)-based network anomaly detection. The review follows a PRISMA 2020-...

A. Havy, Muhammad Faishol Amrulloh · 0 citations
Conference Open access 2025

Adaptive Behavioral Anomaly Detection: Integrating UEBA and EDR for Real-Time Mitigation of Threats and Insider Risks

: This research presents a comprehensive hybrid security system integrating User and Entity Behavior Analytics (UEBA) with Endpoint Detection and Response (EDR) capabilities to address sophisticated cyber threats including Advanced Persistent Threats (APTs) and insider attacks. The proposed architecture leverages the E...

A. Landge, Smita M. Chaudhari, Soham G. Jadhav et al. · 0 citations
Open access Aug 2026

Deep Graph Learning Architecture for Real-Time Cyber Threat Identification and Detection in Cloud Platforms

The rapid adoption of cloud computing has transformed enterprise information infrastructures into highly dynamic environments characterized by distributed resources, elastic workloads, interconnected services, and continuously changing user and application behavior. These characteristics increase the complexity of iden...

Muhammad Rizki Pratama, Siti Nurhaliza Putri · 0 citations
Open access Aug 2026

Adaptive Hybrid Random Forest–Lstm Framework for Network Anomaly Detection in Dynamic Cloud Environments

The increasing adoption of cloud computing introduces security challenges due to dynamic network traffic. Traditional intrusion detection systems and single-model machine learning (ML) approaches struggle to detect sophisticated cyberattacks and adapt to changing patterns. This study proposes an Adaptive Hybrid Random...

V. A. Tamakloe, Donald Terdoo Jam · 0 citations

Related blog posts

Microsoft Research Blog Jul 13, 2026

Verifying Rust cryptography in SymCrypt, from standards to code

Cryptographic code supports vital protections in modern computing systems. Learn how a new method helps verify code as developers write it while preserving speed and adaptability as it gets implemented and evolves. The post Verifying Rust cryptography in SymCrypt, from standards to code appeared first on Microsoft Research.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.