Dynamic Pruned Ensemble Framework for Zero-Day Attack Detection in Cloud-Native Environments via Adaptive AI-Driven Anomaly Detection
Fuente:
Zenodo
Gespeichert in:
| Hauptverfasser: | , , |
|---|---|
| Format: | Recurso digital |
| Veröffentlicht: |
Zenodo
2026
|
| Schlagworte: | |
| Online-Zugang: | |
| Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
| _version_ | 1866902331617968128 |
|---|---|
| author | Omkar, Kulkarni Rohitash, Chandra Md Rabiul, Islam Mehdi |
| author_facet | Omkar, Kulkarni Rohitash, Chandra Md Rabiul, Islam Mehdi |
| contents | <h2><a name="abstract"></a>Abstract</h2> <p class="MsoNormal"><span>We propose a dynamic pruned ensemble framework for zero-day attack detection in cloud-native environments, addressing the limitations of static anomaly detection systems in handling evolving threats and heterogeneous telemetry data. The framework integrates specialized base models—a CNN for network flow analysis, a Transformer for log parsing, and a GBDT ensemble for API metrics—each optimized for distinct cloud observability modalities. A Thompson sampling-based bandit controller dynamically selects and prunes models during inference, balancing detection accuracy with computational efficiency while adapting to real-time cloud context through a GRU-modulated reward function. The system uniquely combines adaptive ensemble pruning with infrastructure-aware feedback, enabling it to respond to autoscaling events and policy changes without manual intervention. Moreover, the framework processes inputs from conventional cloud monitoring tools (e.g., Prometheus, Istio) and fuses anomaly scores into SIEM systems via context-weighted aggregation. Experimental validation demonstrates superior detection performance and resource efficiency compared to monolithic approaches, particularly for previously unseen attack patterns. The proposed method achieves this by continuously optimizing model composition based on operational feedback, hence eliminating redundant computations while maintaining high sensitivity to emerging threats. This work bridges the gap between AI-driven anomaly detection and cloud-native operational constraints, offering a scalable solution for real-time security in dynamic environments.</span></p> |
| format | Recurso digital |
| id | zenodo_https___doi_org_10_5281_zenodo_19545852 |
| institution | Zenodo |
| language | |
| publishDate | 2026 |
| publisher | Zenodo |
| record_format | zenodo |
| spellingShingle | Dynamic Pruned Ensemble Framework for Zero-Day Attack Detection in Cloud-Native Environments via Adaptive AI-Driven Anomaly Detection Omkar, Kulkarni Rohitash, Chandra Md Rabiul, Islam Mehdi Cyber Security, Dynamic Framework, Cloud Environment, Zero day cyber attack <h2><a name="abstract"></a>Abstract</h2> <p class="MsoNormal"><span>We propose a dynamic pruned ensemble framework for zero-day attack detection in cloud-native environments, addressing the limitations of static anomaly detection systems in handling evolving threats and heterogeneous telemetry data. The framework integrates specialized base models—a CNN for network flow analysis, a Transformer for log parsing, and a GBDT ensemble for API metrics—each optimized for distinct cloud observability modalities. A Thompson sampling-based bandit controller dynamically selects and prunes models during inference, balancing detection accuracy with computational efficiency while adapting to real-time cloud context through a GRU-modulated reward function. The system uniquely combines adaptive ensemble pruning with infrastructure-aware feedback, enabling it to respond to autoscaling events and policy changes without manual intervention. Moreover, the framework processes inputs from conventional cloud monitoring tools (e.g., Prometheus, Istio) and fuses anomaly scores into SIEM systems via context-weighted aggregation. Experimental validation demonstrates superior detection performance and resource efficiency compared to monolithic approaches, particularly for previously unseen attack patterns. The proposed method achieves this by continuously optimizing model composition based on operational feedback, hence eliminating redundant computations while maintaining high sensitivity to emerging threats. This work bridges the gap between AI-driven anomaly detection and cloud-native operational constraints, offering a scalable solution for real-time security in dynamic environments.</span></p> |
| title | Dynamic Pruned Ensemble Framework for Zero-Day Attack Detection in Cloud-Native Environments via Adaptive AI-Driven Anomaly Detection |
| topic | Cyber Security, Dynamic Framework, Cloud Environment, Zero day cyber attack |
| url | https://doi.org/10.5281/zenodo.19545852 |