Frontiers in Emerging Multidisciplinary Sciences

Open Access Peer Review International
Open Access

Intelligent Graph Neural Network Framework for Detecting and Classifying Cyber Threats in Cloud Infrastructure

4 Department of Computer Science, Polytechnic University of Tirana, Albania
4 Faculty of Information Technology, University of Tirana, Albania

Abstract

Cloud infrastructure has become increasingly interconnected, dynamic, and heterogeneous, creating security conditions in which cyber threats can propagate across users, virtual machines, containers, services, networks, and data resources. Conventional security mechanisms that primarily analyze isolated events may therefore overlook relational dependencies among entities and activities. This paper proposes an intelligent Graph Neural Network (GNN) framework for detecting and classifying cyber threats in cloud infrastructure by representing cloud security events as a heterogeneous graph and learning threat-related structural and behavioral patterns. The proposed framework integrates graph construction, feature representation, graph-based message propagation, threat classification, and risk-oriented decision generation. Its theoretical foundation is derived from probabilistic networks, dependency modeling, chain-graph representations, causal discovery, and structural learning. The framework is particularly informed by the graph-based deep-learning approach of Marri et al. (2025), which establishes the relevance of graph-based learning for identifying cyber threats in cloud platforms. The methodology conceptualizes cloud entities as nodes and their interactions as edges, allowing the model to capture both local characteristics and higher-order relationships. A multi-stage architecture is developed for preprocessing security telemetry, constructing dynamic graphs, extracting graph representations, identifying anomalous structures, and assigning threat classes. Analytical findings indicate that graph representation can improve contextual threat identification compared with isolated-event analysis because malicious activity is interpreted through relationships among cloud entities. However, challenges involving graph scalability, class imbalance, dynamic topology, weak labels, and explainability remain significant. The proposed framework consequently provides a theoretically grounded architecture for intelligent cloud-threat detection while identifying directions for empirical validation and operational deployment.

How to Cite

Erion Hoxha, & Elira Kola. (2026). Intelligent Graph Neural Network Framework for Detecting and Classifying Cyber Threats in Cloud Infrastructure. Frontiers in Emerging Multidisciplinary Sciences, 3(08), 36–42. Retrieved from https://irjernet.com/index.php/fems/article/view/487

References

Andersson, S. A., Madigan, D., & Perlman, M. D. (1996). An alternative markov property for chain graphs. In Proceedings of the 12th Conference on Uncertainty in Artificial Intelligence, pp. 40–48. AI.
Andrews, B., Spirtes, P., & Cooper, G. F. (2020). On the completeness of causal discovery in the presence of latent confounding with tiered background knowledge. In Proceedings of the 23th International Conference on Artificial Intelligence and Statistics, pp. 4002–4011. PMLR.
Balaji, S., Babu, M. M., Iyer, L. M., Luscombe, N. M., & Aravind, L. (2006). Comprehensive analysis of combinatorial regulation using the transcriptional regulatory network of yeast. Journal of molecular biology, 360(1), 213–227.
Bhattacharya, R., Malinsky, D., & Shpitser, I. (2020). Causal inference under interference and network uncertainty. In Proceedings of the 36th Conference on Uncertainty in Artificial Intelligence, pp. 1028–1038. PMLR.
Chen, C., Chang, K. C.-C., Li, Q., & Zheng, X. (2018). Semi-supervised learning meets factorization: Learning to recommend with chain graph model. ACM Transactions on Knowledge Discovery from Data, 12(6), 1–24.
Cowell, R. G., Dawid, P., Lauritzen, S. L., & Spiegelhalter, D. J. (2007). Probabilistic networks and expert systems: Exact computational methods for Bayesian networks. Springer Science & Business Media.
Cox, D. R., & Wermuth, N. (2014). Multivariate dependencies: Models, analysis and interpretation. Chapman and Hall/CRC.
Eigenmann, M. F., Nandy, P., & Maathuis, M. H. (2017). Structure learning of linear gaussian structural equation models with weak edges. In Proceedings of the 33th Conference on Uncertainty in Artificial Intelligence.
Gama-Castro, S., Jiḿenez-Jacinto, V., Peralta-Gil, M., Santos-Zavaleta, A., Pẽnaloza-Spinola, M. I., Contreras-Moreira, B., Segura-Salazar, J., Muniz-Rascado, L., Martinez-Flores, I., Salgado, H., et al. (2008). Regulondb (version 6.0): gene regulation model of escherichia coli k-12 beyond transcription, active (experimental) annotated promoters and textpresso navigation. Nucleic acids research, 36(suppl1), D120–D124.
M. R. Marri, S. B. Kurada, S. Gupta, S. Dey, S. Kumar and R. Chauhan, "Graph-Based Deep Learning Model for Identifying Cyber Threats in Cloud Platforms," 2025 International Conference on Computational Intelligence, Security, and Artificial Intelligence (IntelliSecAI), Al-Khobar, Saudi Arabia, 2025, pp. 1-7, doi: 10.1109/IntelliSecAI66368.2025.11472831.