Intelligent Graph Neural Network Framework for Detecting and Classifying Cyber Threats in Cloud Infrastructure
Abstract
Cloud infrastructure has become increasingly interconnected, dynamic, and heterogeneous, creating security conditions in which cyber threats can propagate across users, virtual machines, containers, services, networks, and data resources. Conventional security mechanisms that primarily analyze isolated events may therefore overlook relational dependencies among entities and activities. This paper proposes an intelligent Graph Neural Network (GNN) framework for detecting and classifying cyber threats in cloud infrastructure by representing cloud security events as a heterogeneous graph and learning threat-related structural and behavioral patterns. The proposed framework integrates graph construction, feature representation, graph-based message propagation, threat classification, and risk-oriented decision generation. Its theoretical foundation is derived from probabilistic networks, dependency modeling, chain-graph representations, causal discovery, and structural learning. The framework is particularly informed by the graph-based deep-learning approach of Marri et al. (2025), which establishes the relevance of graph-based learning for identifying cyber threats in cloud platforms. The methodology conceptualizes cloud entities as nodes and their interactions as edges, allowing the model to capture both local characteristics and higher-order relationships. A multi-stage architecture is developed for preprocessing security telemetry, constructing dynamic graphs, extracting graph representations, identifying anomalous structures, and assigning threat classes. Analytical findings indicate that graph representation can improve contextual threat identification compared with isolated-event analysis because malicious activity is interpreted through relationships among cloud entities. However, challenges involving graph scalability, class imbalance, dynamic topology, weak labels, and explainability remain significant. The proposed framework consequently provides a theoretically grounded architecture for intelligent cloud-threat detection while identifying directions for empirical validation and operational deployment.
How to Cite
References
Most read articles by the same author(s)
- Arben Hoxha, Elira Kola, An Efficient Deep Belief Network Approach for Real-Time Financial Fraud Identification and Automated Alerting in Cloud Platforms , Frontiers in Emerging Multidisciplinary Sciences: Vol. 3 No. 08 (2026): Volume 03 Issue 08