Articles | Open Access |

Adaptive Graph Neural Network Model for Real-Time Intrusion and Cyber Threat Detection in Cloud Networks

Muhammad Ahmed Khan , School of Electrical Engineering and Computer Science, NUST, Pakistan
Ayesha Noor , Research Department of Computer Science, COMSATS University Islamabad, Pakistan

Abstract

The increasing interconnectivity, elasticity, and distributed architecture of cloud networks have created a security environment in which conventional intrusion detection approaches face difficulties in representing dynamic relationships among users, virtual machines, workloads, services, and network flows. This paper proposes an Adaptive Graph Neural Network (AGNN) Model for real-time intrusion and cyber threat detection in cloud networks. The proposed approach represents cloud infrastructure as a dynamic attributed graph and combines graph-based relational learning, adaptive representation updating, attention mechanisms, transfer-learning principles, and risk-oriented classification. The methodological foundation is informed by the data-centric perspective of machine learning (Emmert-Streib & Dehmer, 2022), deep transfer learning (Bashath et al., 2022), attention-based neural architectures (Cui et al., 2016), and transformer-based representation learning (Devlin et al., 2018; Clark et al., 2020). Experimental-design principles are incorporated to support systematic configuration and evaluation (Barker & Milivojevich, 2016; Cox & Reid, 2000). The framework further builds upon graph-based cyber-threat learning demonstrated for cloud platforms by Marri et al. (2025). The proposed model dynamically updates node and edge representations as network conditions change, enabling detection of anomalous communication patterns, compromised entities, lateral movement, and coordinated attacks. The findings indicate that a graph-oriented adaptive architecture provides a stronger theoretical basis for cloud intrusion detection than isolated feature-based classification because security decisions can incorporate both entity-level behavior and relational context. The principal contribution is an integrated framework that connects dynamic graph construction, adaptive graph representation, threat classification, and risk analysis within a real-time cloud-security pipeline.

Keywords

Graph Neural Networks, Cloud Security, Intrusion Detection, Cyber Threat Detection

References

Back, S., Chinthakindi, S. C., Kedia, A., Lee, H., & Choo, J. (2020). Neurquri: Neural question requirement inspector for answerability prediction in machine reading comprehension. In International Conference on Learning Representations.

Barker, T. B., & Milivojevich, A. (2016). Quality by experimental design. CRC Press.

Bashath, S., Perera, N., Tripathi, S., Manjang, K., Dehmer, M., & Emmert-Streib, F. (2022). A data-centric review of deep transfer learning with applications to text data. Information Sciences, 585, 498–528.

Briggs, J. (2021). Fine-tuning with squad 2.0.

Chen, D., Fisch, A., Weston, J., & Bordes, A. (2017). Reading wikipedia to answer open-domain questions. arXiv preprint arXiv:1704.00051.

Clark, K., Luong, M.-T., Le, Q. V., & Manning, C. D. (2020). Electra: Pre-training text encoders as discriminators rather than generators. arXiv preprint arXiv:2003.10555.

Conneau, A., & Lample, G. (2019). Cross-lingual language model pretraining. Advances in Neural Information Processing Systems, 32.

Cox, D. R., & Reid, N. (2000). The theory of the design of experiments. Chapman and Hall/CRC.

Cui, Y., Chen, Z., Wei, S., Wang, S., Liu, T., & Hu, G. (2016). Attention-over-attention neural networks for reading comprehension. arXiv preprint arXiv:1607.04423.

Devlin, J., Chang, M.-W., Lee, K., & Toutanova, K. (2018). Bert: Pre-training of deep bidirectional transformers for language understanding. arXiv preprint arXiv:1810.04805.

Emmert-Streib, F., & Dehmer, M. (2022). Taxonomy of machine learning paradigms: A data-centric perspective. Wiley Interdisciplinary Reviews: Data Mining and Knowledge Discovery, 12(5), e1470.

M. R. Marri, S. B. Kurada, S. Gupta, S. Dey, S. Kumar and R. Chauhan, "Graph-Based Deep Learning Model for Identifying Cyber Threats in Cloud Platforms," 2025 International Conference on Computational Intelligence, Security, and Artificial Intelligence (IntelliSecAI), Al-Khobar, Saudi Arabia, 2025, pp. 1-7, doi: 10.1109/IntelliSecAI66368.2025.11472831.

Article Statistics

Downloads

Download data is not yet available.

Copyright License

Download Citations

How to Cite

Muhammad Ahmed Khan, & Ayesha Noor. (2026). Adaptive Graph Neural Network Model for Real-Time Intrusion and Cyber Threat Detection in Cloud Networks. International Journal of Computer Science & Information System, 11(08), 59–67. Retrieved from https://scientiamreearch.org/index.php/ijcsis/article/view/497