Performance Analysis of LSTM and GNN based Models for Cyber Attack Detection in Clouds

Kazi Abdullah Al Arafat, Md. Iqbal Hossain, Jeff Richards, Imtiaz Parvez · 2025

Anomaly detection in cloud environments plays a crucial role in cyber forensics, enabling the identification of malicious activities and potential cyber attacks. This study investigates the effectiveness of three deep learning architectures— Long Short-Term Memory (LSTM), Graph Neural Network (GNN), and hybrid LSTM-GNN (combination of LSTM and GNN) for detecting cyber anomalies in infrastructure as a service (IaaS) cloud environments. The deep learning models are trained on a dataset that includes various resource utilization metrics such as CPU, memory, and storage, as well as network activity logs. The simulation results demonstrate that the LSTM-GNN model achieves the highest accuracy of 0.996 and the best F1-score of 0.997, making it the most reliable architecture for cyber forensic applications. The LSTM model, while efficient, shows a trade-off in accuracy, whereas the GNN model highlights the role of graph-based insights in anomaly detection. These findings provide valuable insights into the trade-offs between accuracy, computational efficiency, and model robustness in cyber forensic applications.

Read the paper · More papers on PaperTik