Integrating Machine Learning–Driven Threat Detection with Advanced Cryptographic Solutions for Secure Cloud and Web Applications

PDF (958KB), PP.328-345

Views: 0 Downloads: 0

Author(s)

Tanu Sharma 1,* Farheen Siddiqui 1 Khyati Chopra 2 Jawed Ahmed 1

1. School of Engineering Sciences and Technology, Jamia Hamdard, New Delhi, Delhi, India

2. University School of Automation and Robotics, Guru Gobind Singh Indraprastha University (GGSIPU), New Delhi, Delhi, India

* Corresponding author.

DOI: https://doi.org/10.5815/ijwmt.2026.04.19

Received: 3 Apr. 2026 / Revised: 10 May 2026 / Accepted: 15 Jul. 2026 / Published: 8 Aug. 2026

Index Terms

Federated Learning, Deep Reinforcement Learning, Privacy-Preserving Security, Intrusion Detection Sys-tems, Cloud Computing Security, Adaptive Threat Detection, Web Application Security, Distributed Cybersecurity

Abstract

With the accelerated proliferation of cloud services and web-based applications, exposure to sophisticated cy-ber threats like zero-day vulnerabilities, advanced persistent threats, and application-layer attacks, has sharply increased. Conventional intrusion detection systems, along with cryptographic security mechanisms, often do not fulfill the require-ments of adaptive detection, privacy preservation, and variety of scalability within distributed systems. To alleviate these problems, this paper suggests a cross-layer adaptive security model, which includes, in the secure cloud and web applica-tions, machine learning-based anomaly detection complemented with advanced cryptographic security. The model com-bines, in this context, lightweight local anomaly detection, federated learning, selective privacy, and a deep reinforcement learning-based threat detection and security orchestration. Through federated learning, active participation in the learning process is assured, while the selective privacy mechanism preserves the model parameters. The deep reinforcement learn-ing agent adjusts the interaction, aggregation, and privacy settings according to demands of the adaptive system and the environment. The assessment of the model is realized through the CSE-CIC-IDS2018, CIC-IDS2017, and the CSIC 2010 HTTP benchmark datasets to verify the model in detection, generalization, and operational effectiveness. The results of the performed tests reflect an accuracy of 97.9%, a F1 score of 97.5%, a false positive rate of 1.8%, and a detection latency of 36 ms, surpassing performance of conventional federated and centralized state-of-the-art models. Cross-dataset testing validates the model effectiveness in the presence of highly variable traffic. The results suggest that adaptive orchestration, federated learning, and selective privacy preservation, when combined, substantially boost intrusion detection, decrease communication overhead, and ensure privacy preservation. Therefore, this framework is a scalable and robust approach to intrusion detection within contemporary cloud and web settings.

Cite This Paper

Tanu Sharma, Farheen Siddiqui, Khyati Chopra, Jawed Ahmed, "Integrating Machine Learning–Driven Threat Detection with Advanced Cryptographic Solutions for Secure Cloud and Web Applications", International Journal of Wireless and Microwave Technologies(IJWMT), Vol.16, No.4, pp. 328-345, 2026. DOI:10.5815/ijwmt.2026.04.19

Reference

[1]A. Agarwal, S. B. Verma, and B. K. Gupta, “A review of cloud security issues and challenges,” ADCAIJ: Advances in Distributed Computing and Artificial Intelligence Journal, vol. 12, no. 1, pp. 1–14, 2023. DOI: 10.14201/ad-caij.31459.
[2]M. A. Hasan and G. Shrivastava, “Cloud computing: Enhancing security, driving innovation, and shaping the future,” International Journal on Computational Modelling Applications, vol. 2, no. 1, pp. 53–64, 2025. DOI: 10.63503/j.ijcma.2025.53.
[3]M. Rahmati and A. Pagano, “Federated learning-driven cybersecurity framework for IoT networks with privacy preserving and real-time threat detection capabilities,” Informatics, vol. 12, no. 3, p. 62, 2025. DOI: 10.3390/infor-matics12030062.
[4]A. E. Hafez and M. M. Almustafa, “Detecting security vulnerabilities in web applications: A proposed system,” International Journal of Safety and Security Engineering, vol. 14, no. 6, pp. 1933–1940, 2024. DOI:10.18280/ijsse.140627.
[5]R. Bakır, “UniEmbed: A novel approach to detect XSS and SQL injection attacks leveraging multiple feature fusion with machine learning techniques,” Arabian Journal for Science and Engineering, vol. 50, pp. 15591–15604, 2025. DOI: 10.1007/s13369-024-09916-4.
[6]E. M. Timofte, M. Dimian, A. Graur, A. D. Potorac, D. Balan, I. Croitoru, D.-F. Hrit, can, and M. Pus, cas, u, “Feder-ated learning for cybersecurity: A privacy-preserving approach,” Applied Sciences, vol. 15, no. 12, p. 6878, 2025. DOI:10.3390/app15126878.
[7]S. Chitimoju, “Federated learning in cybersecurity: Privacy-preserving AI for threat detection,” International Jour-nal of Digital Innovation, vol. 6, no. 1, 2025. DOI: 10.13140/RG.2.2.24196.44169.
[8]R. Almanasir, D. Al-Solomon, S. Indrawes, M. A. Almaiah, M. Islam, and M. Alshar’e, “Classification of threats and countermeasures of cloud computing,” Journal of Cyber Security and Risk Auditing, vol. 2025, no. 2, pp. 27–42, 2025. DOI: 10.63180/jcsra.thestap.2025.2.3.
[9]Y. Lilhore et al., “SmartTrust: a hybrid deep learning framework for real-time threat detection in cloud environments using Zero-Trust Architecture,” Journal of Cloud Computing, vol. 14, no. 35, 2025. DOI: 10.1186/s13677-025-00764-7.
[10]G. Sreelatha, T. K. Tak, R. Kalimuthu, et al., “Detecting hidden communication threats in cloud systems us-ing advanced pattern and threat propagation analysis,” Journal of Cloud Computing, vol. 14, no. 55, 2025. DOI:10.1186/s13677-025-00778-1.
[11]M. Sarhan, S. Layeghy, M. Gallagher, et al., “From zero-shot machine learning to zero-day attack detection,” Inter-national Journal of Information Security, vol. 22, no. 4, pp. 947–959, 2023. DOI: 10.1007/s10207-023-00676-0.
[12]Y. Guo, “A review of machine learning-based zero-day attack detection: Challenges and future directions,” Computer Communications, vol. 198, pp. 175–185, 2023. DOI: 10.1016/j.comcom.2022.11.001.
[13]Z. Dai, L. Y. Por, Y.-L. Chen, J. Yang, C. S. Ku, R. Alizadehsani, and P. Plawiak, “An intrusion detection model to detect zero-day attacks in unseen data using machine learning,” PLOS ONE, vol. 19, no. 9, p. e0308469, 2024. DOI: 10.1371/journal.pone.0308469.
[14]K. Yakub Reddy and G. ShankarLingam, “Artificial intelligence in intrusion detection systems: Trends, frameworks, and future directions for cybersecurity,” International Journal of Intelligent Systems and Applications in Engineer-ing, vol. 12, no. 17s, pp. 949–959, 2024. DOI: 10.17148/IJISAE.2024.12177689.
[15]M. A. Hossain and M. S. Islam, “Towards decentralized cybersecurity: A novel privacy-preserving federated learning approach for botnet attack detection,” Blockchain: Research and Applications, vol. 6, no. 3, p. 100355, 2025. DOI: 10.1016/j.bcra.2025.100355.
[16]M. Ragab, E. B. Ashary, B. M. Alghamdi, R. Aboalela, N. Alsaadi, L. A. Maghrabi, and K. H. Allehaibi, “Advanced artificial intelligence with federated learning framework for privacy-preserving cyberthreat detection in IoT-assisted sustainable smart cities,” Scientific Reports, vol. 15, no. 1, p. 4470, 2025. DOI:10.1038/s41598-025-88843-2.
[17]G. Chandu, T. Karthik, and B. Parag, “Federated learning for distributed IoT security: A privacy-preserving approach to intrusion detection,” IEEE Access, vol. 13, 2025. DOI: 10.1109/ACCESS.2025.11095679.
[18]Z. J. Alibadi, “Security challenges and solutions in cloud-based software systems,” International Journal of Com-puter Trends and Technology, vol. 72, no. 10, pp. 160–172, 2024. DOI: 10.14445/22312803/IJCTT-V72I10P123.
[19]M. S. Rahaman, A. Islam, T. Cerny, and S. Hutton, “Static-analysis-based solutions to security challenges in cloud-native systems: Systematic mapping study,” Sensors, vol. 23, no. 4, p. 1755, 2023. DOI: 10.3390/s23041755.
[20]A. Arya and A. Mehta, “A survey of security challenges and solution in cloud computing environments,” Journal of Applied Optics, pp. 364–375, 2024. Available: https://appliedopticsjournal.net/index.php/JAO/article/view/129.
[21]Y. Liu, Y. Zhou, H. Zhang, Z. Chang, S. Xu, Y. Jia, W. Wang, and Z. Liu, “Rethinking software misconfigurations in the real world: An empirical study and literature analysis,” Journal of Systems and Software, vol. 219, p. 112314, 2024. DOI: 10.1016/j.jss.2024.112314.
[22]L. D. Manocchio et al., “A transformer framework for flow-based network intrusion detection,” Expert Systems with Applications, vol. 241, p. 122564, 2024. DOI: 10.1016/j.eswa.2023.122564.
[23]S. M. Kasongo, “Performance analysis of intrusion detection systems using a filtered/feature-reduced approach on UNSW-NB15,” Journal of Big Data, vol. 7, no. 1, pp. 1–15, 2020. DOI: 10.1186/s40537-020-00293-3.
[24]M. Al Lail, “Machine learning for network intrusion detection: A survey,” Future Internet, vol. 15, no. 7, p. 243, 2023. DOI: 10.3390/fi15070243.
[25]R. Yao, N. Wang, P. Chen, and X. Sheng, “A CNN-Transformer hybrid approach for an intrusion detection system in advanced metering infrastructure,” Multimedia Tools and Applications, vol. 82, no. 13, pp. 19463–19486, 2023. DOI: 10.1007/s11042-022-14121-2.
[26]J. L. Leevy, T. M. Khoshgoftaar, et al., “A survey and analysis of intrusion detection models based on CSE-CIC-IDS2018 big data,” Journal of Big Data, vol. 7, no. 1, pp. 1–24, 2020. DOI: 10.1186/s40537-020-00282-6.
[27]M. A. Talukder, M. M. Islam, et al., “Machine learning-based network intrusion detection for big and imbalanced data using oversampling, stacking feature embedding and feature extraction,” Journal of Big Data, vol. 11, no. 1, p. 33, 2024. DOI: 10.1186/s40537-024-00887-1.
[28]N. Moustafa and J. Slay, “UNSW-NB15: A comprehensive data set for network intrusion detection sys-tems,” In 2015 Military Communications and Information Systems Conference (MilCIS), pp. 1–6, 2015. DOI:10.1109/MilCIS.2015.7348942.
[29]I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, “Toward generating a new intrusion detection dataset and intru-sion traffic characterization,” In Proceedings of the 4th International Conference on Information Systems Security and Privacy (ICISSP), pp. 108–116, 2018. DOI: 10.5220/0006639801080116.
[30]G. Thamilarasu and S. Chawla, “Towards deep-learning-driven intrusion detection for the Internet of Things,” Sen-sors, vol. 19, no. 9, p. 1977, 2019. DOI: 10.3390/s19091977.
[31]F. Ullah, S. Ullah, G. Srivastava, and J. C.-W. Lin, “IDS-INT: Intrusion detection system using transformer-based transfer learning for imbalanced network traffic,” Digital Communications and Networks, vol. 10, no. 4, pp. 835–847, 2024. DOI: 10.1016/j.dcan.2023.03.003.
[32]X. Yuan, Z. Wang, and H. Li, “Approximate homomorphic encryption for privacy-preserving cloud analytics,” IEEE Transactions on Cloud Computing, vol. 13, no. 1, pp. 112–125, 2025. DOI: 10.1109/TCC.2025.3526110.
[33]A. Khanna and S. Kaur, “Blockchain-based security framework for cloud computing,” Journal of Cloud Computing, vol. 11, no. 1, p. 40, 2022. DOI: 10.1186/s13677-022-00301-4.
[34]Y. Liao, R. Zhang, and X. Chen, “Quantum-safe cryptography for cloud computing: A comprehensive review,” Future Generation Computer Systems, vol. 139, pp. 34–52, 2023. DOI: 10.1016/j.fgcs.2022.10.010.
[35]M. Ebrahimi and M. Bayat, “Post-quantum cryptography: Challenges and opportunities for cloud systems,” Com-puters & Security, vol. 115, p. 102610, 2022. DOI: 10.1016/j.cose.2022.102610.
[36]Y. Gong and J. Sun, “Practical homomorphic encryption for confidential cloud computing,” IEEE Transactions on Dependable and Secure Computing, vol. 21, no. 5, pp. 3840–3854, 2024. DOI: 10.1109/TDSC.2024.3364891.
[37]E. Roumpies and G. Papadopoulos, “A review of homomorphic encryption for privacy-preserving cloud applica-tions,” ACM Computing Surveys, vol. 55, no. 8, pp. 1–36, 2023. DOI: 10.1145/3557991.
[38]D. Khader and M. Alshammari, “Confidential cloud computing using homomorphic encryption,” Journal of Infor-mation Security and Applications, vol. 76, p. 103514, 2024. DOI: 10.1016/j.jisa.2023.103514.
[39]K. Xue, P. Hong, and M. Ma, “Efficient attribute-based access control for cloud storage,” IEEE Transactions on Information Forensics and Security, vol. 14, no. 12, pp. 3129–3142, 2019. DOI: 10.1109/TIFS.2019.2911181