Return
An explainable generative AI framework for detecting low-rate API-based DDoS attacks in cloud environments
DOI:10.1016/j.rineng.2026.111220.png)
Abstract
En 中文
• Proposes EGDF, a unified flow-based framework combining WGAN-GP augmentation, attention-LSTM classification, PSO-based adaptive thresholding, and SHAP explainability for low-rate DDoS detection. • Achieves 98.23% accuracy and 99.79% AUC on merged CIC benchmark datasets, with 95% confidence intervals reported for all metrics across five stratified folds. • Demonstrates generalization to an independent 2024 cloud dataset (97.2% accuracy, AUC 0.9977) without dataset-specific retuning. • Ablation study confirms PSO-based thresholding as the most impactful single component, reducing FPR by over 95% relative to the LSTM-only baseline. • SHAP analysis identifies Flow Bytes/s, Subflow Forward Packets, and inter-arrival timing features as dominant detection signals, providing operational interpretability for security analysts.
Keywords:
API-level DDoS detection
Explainable AI (XAI)
Wasserstein GAN (WGAN-GP)
Attention-LSTM
Intrusion detection systems
AI Summary
Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.
Journal
IF:
7.9
Papers:
1.1W
Citations:
1.7W

