Anomaly Detection in Cloud API Access Patterns Using Temporal Convolutional Networks

PDF (1030KB), PP.53-68

Views: 0 Downloads: 0

Author(s)

Narendra Kumar 1,* D. Lakshmi Padmaja 2 M. Rajanidevi 3 Dasaradha Ramayya Lanka 4 A. Mahendar 5 V. Gokula Krishnan 6

1. Department of CSE, Amity University Jharkhand, Ranchi - 835303, Jharkhand, India

2. School of Engineering, Anurag University, Hyderabad - 500088, India

3. Department of ECE, Koneru Lakshmaiah Education Foundation, Vaddeswaram - 522302, Andhra Pradesh, India

4. Department of AIML, Aditya University, Surampalem-533437, Andhra Pradesh, India

5. Department of CSE, CMR Technical Campus, Hyderabad - 501401, Telangana, India

6. Department of CSE, Easwari Engineering College, Chennai - 600089, Tamil Nadu, India

* Corresponding author.

DOI: https://doi.org/10.5815/ijcnis.2026.05.04

Received: 7 Mar. 2026 / Revised: 14 Apr. 2026 / Accepted: 25 May 2026 / Published: 8 Oct. 2026

Index Terms

Cloud API Security, Anomaly Detection, Temporal Convolutional Networks (TCN), Self-Supervised Learning, Access Pattern Analysis, Intrusion Detection Systems.

Abstract

Cloud platforms generate massive API access logs, where abnormal patterns may indicate security breaches, insider threats, or compromised credentials, demanding intelligent and automated anomaly detection mechanisms. Conventional approaches employ segmentation, statistical profiling, clustering, recurrent networks, and supervised classifiers to model sequential API behavior and distinguish normal activities from malicious deviations. These techniques generally achieve high detection accuracy and improved threat visibility, enhancing cybersecurity monitoring systems while reducing manual auditing efforts in large-scale distributed cloud environments. However, they struggle with evolving attack patterns, high false-positive rates, limited temporal dependency modelling, data imbalance, and poor generalization across heterogeneous cloud infrastructures. This study proposes a self-supervised Temporal Convolutional Network with adaptive anomaly scoring, achieving robust sequential modelling, reduced false alarms, and improved detection stability in cloud APIs. A self-supervised Temporal Convolutional Network models sequential API behavior using causal dilated convolutions and adaptive scoring, enabling accurate, scalable, and real-time cloud anomaly detection.

Cite This Paper

Narendra Kumar, D. Lakshmi Padmaja, M. Rajanidevi, Dasaradha Ramayya Lanka, A. Mahendar, V. Gokula Krishnan, "Anomaly Detection in Cloud API Access Patterns Using Temporal Convolutional Networks", International Journal of Computer Network and Information Security(IJCNIS), Vol.18, No.5, pp. 53-68, 2026. DOI:10.5815/ijcnis.2026.05.04

Reference

[1]A. Aziz and K. Munir, “Anomaly Detection in Logs using Deep Learning,” IEEE Access,  vol. 12, pp. 176124-176135, 2024, 2024. DOI:10.1109/ACCESS.2024.3506332 — hybrid deep learning anomaly detection combining unsupervised encoders and autoencoders for log data.
[2]V.Yuqing Wang, Mika Mäntylä, Jesse Nyyssölä, Ke Ping, and Liqiang Wang, “Cross-System Software Log-based Anomaly Detection Using Meta-Learning,” arXiv preprint, Dec. 2024.
[3]Jiawei Lu and Chengrong Wu, “TPLogAD: Unsupervised Log Anomaly Detection Based on Event Templates and Key Parameters,” arXiv preprint, Nov. 2024.
[4]Mohamed Allam, Noureddine Boujnah, Noel E. O’Connor, and Mingming Liu, “Synthetic Time Series for Anomaly Detection in Cloud Microservices,” arXiv preprint, Jul. 2024.
[5]Guoming Jiang, “Artificial intelligence-based adaptive anomaly detection technology for IaaS cloud virtual machines,” Journal of Engineering and Applied Science, Apr. vol. 71, art. no. 102, 2024.
[6]Thalakola Syamsundararao et al., “Anomaly Detection in Time Series Data Using Deep Learning,” International Journal of Intelligent Systems and Applications in Engineering, Mar. vol. 12, no. 21s, pp. 866–874, 2024.
[7]A. Aluwala, “AI-Driven Anomaly Detection in Network Monitoring Techniques and Tools,” Journal of Artificial Intelligence & Cloud Computing,  vol. 3, no. 3, 2024.
[8]Y. Alaca, Y. Çelik, and S. Goel, “Anomaly Detection in Cyber Security with Graph-Based LSTM in Log Analysis,” Chaos Theory and Applications,  vol. 5, no. 3, pp. 188–197, 2023, doi: 10.51537/chaos.1348302.
[9]R. Marbel, Y. Cohen, R. Dubin, A. Dvir, and C. Hajaj, “Cloudy with a Chance of Anomalies: Dynamic Graph Neural Network for Early Detection of Cloud Services' User Anomalies,” arXiv:2409.12726, 2024.
[10]S. S. Saravanan, T. Luo, and M. V. Ngo, “TSI-GAN: Unsupervised Time Series Anomaly Detection using Convolutional Cycle-Consistent Generative Adversarial Networks,” arXiv:2303.12952, 2023.
[11]C. Lee, T. Yang, Z. Chen, Y. Su, and M. R. Lyu, “Maat: Performance Metric Anomaly Anticipation for Cloud Services with Conditional Diffusion,” arXiv:2308.07676, 2023.
[12]H. Lim, S. Park, M. Kim, J. Lee, S. Lim, and N. Park, “MadSGM: Multivariate Anomaly Detection with Score-based Generative Models,” arXiv:2308.15069, 2023.
[13]Y. Yamanaka, T. Takahashi, T. Minami, and Y. Nakajima, “LogELECTRA: Self-supervised Anomaly Detection for Unstructured Logs,” arXiv:2402.10397, 2024.
[14]P. Pospieszny, W. Mormul, K. Szyndler, and S. Kumar, “ADALog: Adaptive Unsupervised Anomaly Detection in Logs with Self-attention Masked Language Model,” in Proc. 10th Int. Conf. Machine Learning Technologies (ICMLT),  pp. 248–256, 2025, doi: 10.1109/ICMLT65785.2025.11193311.
[15]J. Lu and C. Wu, “TPLogAD: Unsupervised Log Anomaly Detection Based on Event Templates and Key Parameters,” arXiv:2411.15250, 2024.
[16]J. Liu et al., “Log-based Anomaly Detection based on EVT Theory with Feedback,” arXiv:2306.05032, 2023.
[17]A.-R. Al-Ghuwairi, Y. Sharrab, D. Al-Fraihat, M. AlElaimat, A. Alsarhan, and A. Algarni, “Intrusion detection in cloud computing based on time series anomalies utilizing machine learning,” Journal of Cloud Computing,  vol. 12, no. 127, 2023, doi: 10.1186/s13677-023-00491-x.
[18]H. Lim, S. Park, M. Kim, J. Lee, S. Lim, and N. Park, “MadSGM: Multivariate Anomaly Detection with Score-based Generative Models,” arXiv preprint arXiv:2308. ,pp.15069, 2023.
[19]S. S. Saravanan, T. Luo, and M. V. Ngo, “TSI-GAN: Unsupervised Time Series Anomaly Detection Using Convolutional Cycle-Consistent Generative Adversarial Networks,” arXiv preprint arXiv:2303.12952, 2023.
[20]C. Lee, T. Yang, Z. Chen, Y. Su, and M. R. Lyu, “Maat: Performance Metric Anomaly Anticipation for Cloud Services with Conditional Diffusion,” arXiv preprint arXiv:2308.07676, 2023.
[21]Y. Yamanaka, T. Takahashi, T. Minami, and Y. Nakajima, “LogELECTRA: Self-supervised Anomaly Detection for Unstructured Logs,” arXiv preprint arXiv:2402.10397, 2024.
[22]P. Pospieszny, W. Mormul, K. Szyndler, and S. Kumar, “ADALog: Adaptive Unsupervised Anomaly Detection in Logs with Self-attention Masked Language Model,” in Proc. 10th Int. Conf. Machine Learning Technologies (ICMLT), pp. 248–256, 2025 ,doi: 10.1109/ICMLT65785.2025.11193311.
[23]Data- https://github.com/logpai/loghub?