Machine Learning-Based Cyber Defense for Cloud Infrastructure: An Adaptive Deep Q-Network Architecture for Intelligent Intrusion Detection and Automated Threat Mitigation

📅 2026-08-12
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the challenge of complex and evolving cyberattacks in cloud environments by proposing an adaptive dynamic defense framework based on reinforcement learning. The work introduces, for the first time, a Deep Q-Network (DQN) into cloud security to establish an end-to-end intelligent intrusion detection and automated response loop. Leveraging feature engineering and data preprocessing, the model is trained on the CICIDS2017 dataset and validated on UNSW-NB15. Experimental results demonstrate that the system achieves 99.72% accuracy, a 99.66% F1-score, and a 0.999 ROC-AUC under previously unseen and evolving attacks, with a false positive rate of only 0.31%, an average detection latency of 15 ms, and an attack mitigation rate of 99.54%, thereby significantly enhancing real-time performance and generalization capability.
📝 Abstract
With the increasing complexity of cyber assaults in cloud environments, adaptable security solutions are needed that can support real-time detection and autonomous response. In this paper, we propose a reinforcement learning-based dynamic cyber defense framework. We deploy a Deep Q-Network (DQN) to train effective defensive strategies to counteract the evolving cyberattacks. We leverage the CICIDS2017 dataset for model creation and the UNSW-NB15 dataset for external validation, involving preprocessing of data, feature engineering, and adaptive policy learning. We compare the proposed DQN with decision tree, support vector machine, random forest, XGBoost, and multilayer perceptron models. The proposed DQN achieves an accuracy of 99.72%, a precision of 99.68%, a recall of 99.65%, an F1-score of 99.66%, and an ROC-AUC of 0.999, while the false positive rate is 0.31%, the false negative rate is 0.35%, and the detection latency is 15 ms. The framework achieved 99.54% attack mitigation rate, demonstrating strong adaptive and real-time defensive capabilities. These results demonstrate the potential of reinforcement learning as a powerful and scalable approach for autonomous cybersecurity in modern cloud environments.
Problem

Research questions and friction points this paper is trying to address.

cloud security
intrusion detection
autonomous response
adaptive defense
cyberattacks
Innovation

Methods, ideas, or system contributions that make the work stand out.

Deep Q-Network
Reinforcement Learning
Intrusion Detection
Adaptive Cyber Defense
Cloud Security
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
M
Md Yassir Mottalib
Master of Science in Information System Technology, Wilmington University, USA
M
Md Yousuf
Master's of Science in Data Analytics, College of Sciences and Technology, University of Houston-Downtown, USA
E
Eklachur Rahman Bhuiyan
Master of Science in Information Technology, Washington University of Science and Technology, USA
S
S M Ahsan Habib
Department of Electrical Engineering and Computer Science, South Dakota School of Mines & Technology, USA
S
Sonjoy Kumar Dey
McComish, Department of Electrical Engineering and Computer Science, South Dakota State University, USA
M
Md. Salahuddin Gazi
Master of Science in Information Technology, Washington University of Science and Technology, USA
M
Molay Kumar Roy
Ms in Digital Marketing & Information Technology Management, St. Francis College, USA
A
Asaduzzaman Anik
Master of Business Administration (MBA) in Management, Stanton University, Los Angeles, California