arXiv:2512.10280cs.CRcs.AI2025-12被引 6

用图神经网络实时检测云身份日志中的隐蔽威胁

Graph Neural Network Based Adaptive Threat Detection for Cloud Identity and Access Management Logs

  • 将日志建模为动态异构图,捕捉用户与资源的复杂关系
  • 在真实数据上精度和召回率优于LSTM与GCN基线模型
  • 适合关注零信任安全与内部威胁防护的技术团队

云基础设施和分布式身份系统的快速扩张显著增加了现代企业的复杂性和攻击面。传统基于规则或签名的检测系统难以识别身份与访问管理(IAM)日志中的新型或演化威胁,因为异常行为可能在统计上看似正常但具有上下文恶意性。本文提出一种基于图神经网络的自适应威胁检测框架,可实时从IAM审计日志中学习用户的潜在资源交互模式。通过将IAM日志建模为异构动态图,该系统捕获了用户、角色、会话和访问操作等实体间的时序、关联与上下文依赖关系。模型采用基于注意力的聚合和图嵌入更新机制,实现对不断变化的云环境的持续适应。在合成与真实世界IAM数据集上的实验表明,所提方法在检测精度和召回率上均优于基线LSTM与GCN分类器,同时在多租户云环境中保持可扩展性。该框架的适应性有助于主动缓解内部威胁、权限提升和横向移动攻击,为AI驱动的零信任访问分析奠定基础。本工作弥合了图机器学习与实际云安全智能之间的差距。

原文摘要 · Abstract (English)

The rapid expansion of cloud infrastructures and distributed identity systems has significantly increased the complexity and attack surface of modern enterprises. Traditional rule based or signature driven detection systems are often inadequate in identifying novel or evolving threats within Identity and Access Management logs, where anomalous behavior may appear statistically benign but contextually malicious. This paper presents a Graph Neural Network Based Adaptive Threat Detection framework designed to learn latent user resource interaction patterns from IAM audit trails in real time. By modeling IAM logs as heterogeneous dynamic graphs, the proposed system captures temporal, relational, and contextual dependencies across entities such as users, roles, sessions, and access actions. The model incorporates attention based aggregation and graph embedding updates to enable continual adaptation to changing cloud environments. Experimental evaluation on synthesized and real world IAM datasets demonstrates that the proposed method achieves higher detection precision and recall than baseline LSTM and GCN classifiers, while maintaining scalability across multi tenant cloud environments. The frameworks adaptability enables proactive mitigation of insider threats, privilege escalation, and lateral movement attacks, contributing to the foundation of AI driven zero trust access analytics. This work bridges the gap between graph based machine learning and operational cloud security intelligence.

图神经网络云安全零信任威胁检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。