Anomaly Detection in Microservices Architecture Using Graph Neural Networks
Matthias Osswald, Timothy Schönenberger, Gokcan Cantali, Wissem Soussi, Gürkan Gür · 2025
The rise of cloud computing has transformed application development and deployment, with Kubernetes emerging as a key platform for managing containerized applications. This paper explores the use of Graph Neural Networks (GNNs) to detect anomalies in Kubernetes clusters and proposes GNN-based Anomaly Detection in Kubernetes (GATAKU), which is instrumental in maintaining security and performance. Our work involves integrating Cilium for detailed network monitoring and data collection, setting up a Kubernetes cluster with k3s and Traefik, and simulating attack scenarios to generate realistic data. Data preprocessing and feature engineering prepare this data for the GNN training. We present the GATAKU model’s performance, highlighting metrics such as accuracy, precision, recall, and F 1 -score and compare it to baseline ML models, namely Support Vector Machine (SVM) and Random Forest (RF). Moreover, we discuss these findings and emerging challenges, including handling high-dimensional data, and explore practical implications for cybersecurity.