PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
January 21, 2026Future Internet0 citationsOpen Access

An Unsupervised Cloud-Centric Intrusion Diagnosis Framework Using Autoencoder and Density-Based Learning

View Full Paper
SSSuresh K. STEThenmozhi ElumalaiRRRadhakrishnan Rajamani

Key Points

  • This research aims to develop a framework for unsupervised intrusion diagnosis in cloud environments.
  • Integrated autoencoder for representation learning and density-based categorization
  • Trained dual-stage autoencoder with benign traffic for anomaly detection
  • Used reconstruction-error analysis to identify anomalies
  • Grouped detected anomalies with density-based learning
  • Conducted experiments on the CSE-CIC-IDS2018 dataset
  • Achieved 99.46% anomaly detection accuracy with high recall and low false-negative rates
  • Obtained 98.79% multiclass attack classification accuracy
  • Clustering evaluation showed a Silhouette Score of 0.9857 and Davies–Bouldin Index of 0.0091
  • Demonstrated robust performance under imbalanced traffic conditions

Abstract

Cloud computing environments generate high-dimensional, large-scale, and highly dynamic network traffic, making intrusion diagnosis challenging due to evolving attack patterns, severe traffic imbalance, and limited availability of labeled data. To address these challenges, this study presents an unsupervised, cloud-centric intrusion diagnosis framework that integrates autoencoder-based representation learning with density-based attack categorization. A dual-stage autoencoder is trained exclusively on benign traffic to learn compact latent representations and to identify anomalous flows using reconstruction-error analysis, enabling effective anomaly detection without prior attack labels. The detected anomalies are subsequently grouped using density-based learning to uncover latent attack structures and support fine-grained multiclass intrusion diagnosis under varying attack densities. Experiments conducted on the large-scale CSE-CIC-IDS2018 dataset demonstrate that the proposed framework achieves an anomaly detection accuracy of 99.46%, with high recall and low false-negative rates in the optimal latent-space configuration. The density-based classification stage achieves an overall multiclass attack classification accuracy of 98.79%, effectively handling both majority and minority attack categories. Clustering quality evaluation reports a Silhouette Score of 0.9857 and a Davies–Bouldin Index of 0.0091, indicating strong cluster compactness and separability. Comparative analysis against representative supervised and unsupervised baselines confirms the framework’s scalability and robustness under highly imbalanced cloud traffic, highlighting its suitability for future Internet cloud security ecosystems.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

S et al. (2026) studied this question.

synapsesocial.com/papers/69706c87b6488063ad5c18bbhttps://doi.org/10.3390/fi18010054
Ask AI
Helpful
Bookmark
Share
View Full Paper