Explainable AI-Driven Zero-Day Malware Detection Using Hybrid Transformer-Graph Networks in Cloud-Native Environments
DOI:
https://doi.org/10.63544/8wxdhb56Keywords:
Explainable Artificial Intelligence, Zero-Day Malware Detection, Transformer Networks, Graph Neural Networks, Cloud-Native Security, Kubernetes Security, Container Security, Cybersecurity AnalyticsAbstract
Cloud-native environments increasingly rely on containers, microservices, Kubernetes orchestration, and automated deployment pipelines, creating complex attack surfaces vulnerable to zero-day malware. Traditional signature-based and isolated machine-learning approaches often fail to detect unknown threats and provide limited explanations for security analysts. This study proposes an Explainable Artificial Intelligence-driven zero-day malware-detection framework using hybrid Transformer-Graph Networks. The Transformer component analyzes temporal patterns in system calls, process execution, Kubernetes audit logs, network flows, identity events, and resource utilization. The Graph Neural Network component models relationships among containers, pods, services, service accounts, processes, nodes, and network endpoints. Their combined representation improves detection of multi-stage attacks, including privilege escalation, credential access, lateral movement, command-and-control communication, and cryptomining. Explainability methods identify influential events, features, and graph relationships behind each alert. The framework is evaluated using accuracy, precision, recall, F1-score, false-positive rate, detection latency, scalability, and explanation quality. It supports transparent, adaptive, and operationally useful threat detection for cloud-native security operations.
REFERENCES
[1] S. N. Qaisarani et al., "X-THREAT framework for adaptive and explainable deep learning-based minority-class and zero-day cyber threat detection," Scientific Reports, vol. 16, Art. no. 28721, 2026, doi: 10.1038/s41598-026-63529-5.
[2] E. Amer, S. El-Sappagh, T. Abuhamad, B. A. S. Al-Rimy, and A. Mohasseb, "GraphShield: Advanced dynamic graph-based malware detection using graph neural networks," Expert Systems with Applications, vol. 298, Art. no. 129812, 2026, doi: 10.1016/j.eswa.2025.129812.
[3] M. Gaber, M. Ahmed, and H. Janicke, "Zero day malware detection with Alpha: Fast DBI with Transformer models for real world application," Computers & Electrical Engineering, vol. 128, Art. no. 110751, 2025, doi: 10.1016/j.compeleceng.2025.110751.
[4] H. Wu et al., "A graph neural network framework for dynamic malware detection using API calls and lightweight containers," in Proc. 5th Int. Conf. Intelligent Communications and Computing (ICICC), 2025, pp. 294-301, doi: 10.1109/ICICC66840.2025.11199642.
[5] D. Natsos and A. L. Symeonidis, "Transformer-based malware detection using process resource utilization metrics," Results in Engineering, vol. 25, Art. no. 104250, 2025, doi: 10.1016/j.rineng.2025.104250.
[6] S. I. Berrios Vasquez, P. A. Hermosilla Monckton, D. I. Leiva Muñoz, and H. Allende, "Zero-day threat mitigation via deep learning in cloud environments," Applied Sciences, vol. 15, no. 14, Art. no. 7885, 2025, doi: 10.3390/app15147885.
[7] Zhen, Y., Tian, D., Fu, X., & Hu, C., "A novel malware detection method based on audit logs and graph neural network," Engineering Applications of Artificial Intelligence, vol. 152, Art. no. 110524, 2025, doi: 10.1016/j.engappai.2025.110524.
[8] H. Mohammadian, G. Higgins, S. Ansong, R. Razavi-Far, and A. A. Ghorbani, "Explainable malware detection through integrated graph reduction and learning techniques," Big Data Research, vol. 41, Art. no. 100555, 2025, doi: 10.1016/j.bdr.2025.100555.
[9] H. Shokouhinejad, G. Higgins, R. Razavi-Far, H. Mohammadian, and A. A. Ghorbani, "On the consistency of GNN explanations for malware detection," Information Sciences, vol. 721, Art. no. 122603, 2025, doi: 10.1016/j.ins.2025.122603.
[10] H. Shokouhinejad, R. Razavi-Far, G. Higgins, and A. A. Ghorbani, "Enhancing GNN explanations for malware detection with dual subgraph matching," Machine Learning and Knowledge Extraction, vol. 8, no. 1, Art. no. 2, 2026, doi: 10.3390/make8010002.
[11] A. Aly, A. M. Hamad, M. Al-Qutt, et al., "Real-time multi-class threat detection and adaptive deception in Kubernetes environments," Scientific Reports, vol. 15, Art. no. 8924, 2025, doi: 10.1038/s41598-025-91606-8.
[12] M. Osswald, T. Schönenberger, G. Cantali, W. Soussi, and G. Gür, "Anomaly detection in microservices architecture using graph neural networks," in Proc. 33rd Euromicro Int. Conf., 2025, doi: 10.1109/PDP66500.2025.00085.
[13] S. Kwon, W. Son, and J. H. Lee, "Anomaly detection in containerized tactical systems using temporal graph neural networks," in Proc. IEEE Military Communications Conf. (MILCOM), 2025, pp. 1566-1571, doi: 10.1109/MILCOM64451.2025.11310523.
[14] A. Nousias et al., "Malware detection in Docker containers: An image is worth a thousand logs," in Proc. IEEE Int. Conf. Communications (ICC), 2025, doi: 10.1109/ICC52391.2025.11161263.
[15] J. Ryu, R. Kim, S. Lee, S. Kim, H. Choi, and S. Kim, "Hybrid runtime detection of malicious containers using eBPF," Computers, Materials & Continua, vol. 86, no. 3, Art. no. 13, 2026, doi: 10.32604/cmc.2025.074871.
[16] V. Govindarajan and J. H. Muzamal, "Advanced cloud intrusion detection framework using graph based features transformers and contrastive learning," Scientific Reports, vol. 15, Art. no. 20511, 2025, doi: 10.1038/s41598-025-07956-w.
[17] R. Xie and D. Liu, "A novel hybrid graph neural network and transformer model for intrusion detection," Peer-to-Peer Networking and Applications, vol. 19, Art. no. 59, 2026, doi: 10.1007/s12083-025-02171-w.
[18] M. C. Ipek and S. Sen, "Explainable Android malware detection and malicious code localization using graph attention," Journal of Information Security and Applications, vol. 98, Art. no. 104385, 2026, doi: 10.1016/j.jisa.2026.104385.
[19] G. Andresini, A. Appice, V. Belvedere, G. Fiameni, and D. Malerba, "Anakin: Explainable Android malware detection with graph neural networks," Cybersecurity, vol. 9, Art. no. 116, 2026, doi: 10.1186/s42400-026-00552-z.
[20] F. Ares-Robledo, H. Rifà-Pous, and R. Clariso, "Graph neural networks for anomaly detection: A systematic review of dynamic temporal approaches," Artificial Intelligence Review, vol. 59, Art. no. 129, 2026, doi: 10.1007/s10462-026-11532-7.
[21] Imtiaz, U. (2026). Dynamic Security Certification Framework for Evolving Distributed Architectures. In: Shukla, S., Sayama, H., Tiwari, K., George, J.P., Kureethara, J.V. (eds) Data Science and Security. IDSCS 2025. Lecture Notes in Networks and Systems, vol 1947. Springer, Cham. https://doi.org/10.1007/978-3-032-24360-7_32
[22] Imtiaz, U. (2026). Ghost Signals: Ethical RF Adversarial Testing of Consumer Alarm Ecosystems. In: Shukla, S., Sayama, H., Tiwari, K., George, J.P., Kureethara, J.V. (eds) Data Science and Security. IDSCS 2025. Lecture Notes in Networks and Systems, vol 1945. Springer, Cham. https://doi.org/10.1007/978-3-032-24075-0_21
[23] M. I. K. Jabed, M. Imran, A. A. Khan, M. Mehedi, A. Islam, and R. Pervez, "Explainable machine learning framework for early heart disease detection using SMOTE and SHAP," Vascular and Endovascular Review, vol. 9, no. 1, pp. 316-324, 2026.
[24] M. I. K. Jabed, M. R. M. Sirazy, S. Mandal, S. A. Akter, A. Hassan, and H. Esa, "Developing AI-based financial forecasting and cybersecurity systems for the US digital economy," Frontiers in Computer Science and Artificial Intelligence, vol. 5, no. 5, pp. 30-38, 2026.
[25] M. I. K. Jabed, M. P. Ahmed, F. M. Tofa, M. F. Islam, C. A. Gomes, and R. M. Sirazy, "Federated intrusion detection for Internet of Medical Things networks: Differential privacy, non-IID robustness, and cross-device generalization," Journal of Computer Science and Technology Studies, vol. 8, no. 8, pp. 303-315, 2026.
[26] P. S. Ponduru, "Decision intelligence for AI and emerging technologies: The AEGIS-DM framework for trustworthy, cost-aware, and low-latency decision making," 2024.
[27] P. S. Ponduru, P. P. V. Nandanavanam, and S. K. K. Ponduru, "SAFE-HealCloud: Safety-aware, agentic self-healing for cloud infrastructure," International Journal of Scientific Research in Computer Science, Engineering and Information Technology, vol. 12, no. 4, pp. 163-188, 2026.
[28] C. A. Gomes, M. I. K. Jabed, T. Ahammad, S. Mandal, S. Hassan, M. K. Sejan, P. S. Ponduru, M. M. Bhuiyan, and M. L. Jamali, "Operational and financial evidence for generative AI in United States healthcare administrative workflows," Frontiers in Computer Science and Artificial Intelligence, vol. 4, no. 4, pp. 138-145, 2025.
[29] M. R. Hasan, M. A. Rahman, C. A. H. Gomes, F. N. Nitu, C. A. Gomes, M. R. Islam, and R. E. R. Shawon, "Building robust AI and machine learning models for supplier risk management: A data-driven strategy for enhancing supply chain resilience in the USA," Advances in Consumer Research, vol. 2, no. 4, pp. 1152-1171, 2025.
[30] M. D. Rasheed, W. Khan, M. Imran, N. Ahmad, Y. Khan, M. Akram, and M. Sultana, "Leveraging artificial intelligence for advance data networking and cybersecurity," Spectrum of Engineering Sciences, vol. 4, no. 3, pp. 286-298, 2026.
[31] Fahad Amin (2025). A Scalable Framework for Interpretable Binary Vulnerability Analysis Using Data Dependency Modeling. In Proceedings of the International Conference on Artificial Intelligence and Cybersecurity (ICAIC 2025), 249-255.
[32] F. Amin, "Binary Flaw Detection: A Security Analysis Paper," in 2025 International Conference on Advances in Machine Intelligence, and Cybersecurity Technologies (AMICT), Kota Kinabalu, Sabah, Malaysia, 2025, pp. 325-330, doi: 10.1109/AMICT65811.2025.11402666.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Zerminey Saleem, Muhammad Hanif Hussain Khan , Farhad Ullah, Muhammad Taha Bashir (Author)

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.