Can Graph-Based Microservice Performance Detection Be Used for Microservice Intrusion Detection?

Fuente: arXiv
Saved in:
Bibliographic Details
Main Author: Ma, Yunjian
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916041331834880
author Ma, Yunjian
author_facet Ma, Yunjian
contents Microservice systems expose rich telemetry streams, including metrics, logs, and distributed traces. Existing performance anomaly detection methods increasingly model these systems as graphs, where nodes represent services and edges represent runtime dependencies. This paper asks whether graph-based microservice performance detection can also serve as a foundation for microservice intrusion detection. We deploy a Docker Compose based synthetic e-commerce microservice benchmark, run 50 controlled trials across five attack types under normal workloads, and collect metrics, logs, and distributed traces. Each request trace is converted into a request-level invocation graph with multi-modal node features derived from timestamped logs and per-service performance metrics. As a first baseline, we train a two-layer graph convolutional network for 6-way classification over 21,438 request graphs. The model achieves 96.2% test accuracy with a macro F1 of 0.955 under a graph-level random split. We then conduct modality ablation, trial-level split evaluation, non-graph baseline comparison, runtime analysis, t-SNE visualization, confusion-matrix analysis, and error-case inspection. The stricter trial-level results show that trace structure alone is insufficient, logs and metrics improve detection, and strong flattened baselines currently outperform the shallow graph model on the engineered feature set.
format Preprint
id arxiv_https___arxiv_org_abs_2605_24283
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Can Graph-Based Microservice Performance Detection Be Used for Microservice Intrusion Detection?
Ma, Yunjian
Software Engineering
C.2.0; C.2.4; I.2.6; I.5.2; K.6.5
Microservice systems expose rich telemetry streams, including metrics, logs, and distributed traces. Existing performance anomaly detection methods increasingly model these systems as graphs, where nodes represent services and edges represent runtime dependencies. This paper asks whether graph-based microservice performance detection can also serve as a foundation for microservice intrusion detection. We deploy a Docker Compose based synthetic e-commerce microservice benchmark, run 50 controlled trials across five attack types under normal workloads, and collect metrics, logs, and distributed traces. Each request trace is converted into a request-level invocation graph with multi-modal node features derived from timestamped logs and per-service performance metrics. As a first baseline, we train a two-layer graph convolutional network for 6-way classification over 21,438 request graphs. The model achieves 96.2% test accuracy with a macro F1 of 0.955 under a graph-level random split. We then conduct modality ablation, trial-level split evaluation, non-graph baseline comparison, runtime analysis, t-SNE visualization, confusion-matrix analysis, and error-case inspection. The stricter trial-level results show that trace structure alone is insufficient, logs and metrics improve detection, and strong flattened baselines currently outperform the shallow graph model on the engineered feature set.
title Can Graph-Based Microservice Performance Detection Be Used for Microservice Intrusion Detection?
topic Software Engineering
C.2.0; C.2.4; I.2.6; I.5.2; K.6.5
url https://arxiv.org/abs/2605.24283