Dynamic Pruned Ensemble Framework for Zero-Day Attack Detection in Cloud-Native Environments via Adaptive AI-Driven Anomaly Detection

Fuente: Zenodo
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Omkar, Kulkarni, Rohitash, Chandra, Md Rabiul, Islam Mehdi
Format: Recurso digital
Veröffentlicht: Zenodo 2026
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866902331617968128
author Omkar, Kulkarni
Rohitash, Chandra
Md Rabiul, Islam Mehdi
author_facet Omkar, Kulkarni
Rohitash, Chandra
Md Rabiul, Islam Mehdi
contents <h2><a name="abstract"></a>Abstract</h2> <p class="MsoNormal"><span>We propose a dynamic pruned ensemble framework for zero-day attack detection in cloud-native environments, addressing the limitations of static anomaly detection systems in handling evolving threats and heterogeneous telemetry data. The framework integrates specialized base models—a CNN for network flow analysis, a Transformer for log parsing, and a GBDT ensemble for API metrics—each optimized for distinct cloud observability modalities. A Thompson sampling-based bandit controller dynamically selects and prunes models during inference, balancing detection accuracy with computational efficiency while adapting to real-time cloud context through a GRU-modulated reward function. The system uniquely combines adaptive ensemble pruning with infrastructure-aware feedback, enabling it to respond to autoscaling events and policy changes without manual intervention. Moreover, the framework processes inputs from conventional cloud monitoring tools (e.g., Prometheus, Istio) and fuses anomaly scores into SIEM systems via context-weighted aggregation. Experimental validation demonstrates superior detection performance and resource efficiency compared to monolithic approaches, particularly for previously unseen attack patterns. The proposed method achieves this by continuously optimizing model composition based on operational feedback, hence eliminating redundant computations while maintaining high sensitivity to emerging threats. This work bridges the gap between AI-driven anomaly detection and cloud-native operational constraints, offering a scalable solution for real-time security in dynamic environments.</span></p>
format Recurso digital
id zenodo_https___doi_org_10_5281_zenodo_19545852
institution Zenodo
language
publishDate 2026
publisher Zenodo
record_format zenodo
spellingShingle Dynamic Pruned Ensemble Framework for Zero-Day Attack Detection in Cloud-Native Environments via Adaptive AI-Driven Anomaly Detection
Omkar, Kulkarni
Rohitash, Chandra
Md Rabiul, Islam Mehdi
Cyber Security, Dynamic Framework, Cloud Environment, Zero day cyber attack
<h2><a name="abstract"></a>Abstract</h2> <p class="MsoNormal"><span>We propose a dynamic pruned ensemble framework for zero-day attack detection in cloud-native environments, addressing the limitations of static anomaly detection systems in handling evolving threats and heterogeneous telemetry data. The framework integrates specialized base models—a CNN for network flow analysis, a Transformer for log parsing, and a GBDT ensemble for API metrics—each optimized for distinct cloud observability modalities. A Thompson sampling-based bandit controller dynamically selects and prunes models during inference, balancing detection accuracy with computational efficiency while adapting to real-time cloud context through a GRU-modulated reward function. The system uniquely combines adaptive ensemble pruning with infrastructure-aware feedback, enabling it to respond to autoscaling events and policy changes without manual intervention. Moreover, the framework processes inputs from conventional cloud monitoring tools (e.g., Prometheus, Istio) and fuses anomaly scores into SIEM systems via context-weighted aggregation. Experimental validation demonstrates superior detection performance and resource efficiency compared to monolithic approaches, particularly for previously unseen attack patterns. The proposed method achieves this by continuously optimizing model composition based on operational feedback, hence eliminating redundant computations while maintaining high sensitivity to emerging threats. This work bridges the gap between AI-driven anomaly detection and cloud-native operational constraints, offering a scalable solution for real-time security in dynamic environments.</span></p>
title Dynamic Pruned Ensemble Framework for Zero-Day Attack Detection in Cloud-Native Environments via Adaptive AI-Driven Anomaly Detection
topic Cyber Security, Dynamic Framework, Cloud Environment, Zero day cyber attack
url https://doi.org/10.5281/zenodo.19545852