https://doi.org/10.1140/epjp/s13360-025-06911-y
Regular Article
Hybrid AI-based threat prediction and mitigation framework for securing cloud storage
1
Department of Computer Science and Engineering, CMR College of Engineering and Technology, Hyderabad, Telangana, India
2
Department of Computer science and Engineering, Kakatiya Institute Technology and Science Warangal, 506015, Hyderabad, Telangana, India
3
Department of CSE, Vasavi College of Engineering, Hyderabad, Telangana, India
4
Department of Computer Science and Engineering, Koneru Lakshmaiah Education Foundation, Bowrampet, 500043, Hyderabad, Telangana, India
5
Department of CSE -DS, CVR college of engineering, Hyderabad, Telangana, India
6
Professor of CSE, Sree Dattha Group of Institutions, 501510, Hyderabad, India
a
This email address is being protected from spambots. You need JavaScript enabled to view it.
Received:
2
May
2025
Accepted:
29
September
2025
Published online:
15
October
2025
Abstract
While cloud storage systems have provided massive scalability and accessibility to data management, they have opened these platforms up to ever-evolving cyber threats. Traditional intrusion detection systems, which predominantly rely on static rules or shallow learning techniques, may not effectively capture the intricate, dynamic patterns associated with contemporary cyberattacks. However, the real-time cloud deployment of current deep learning-based solutions is limited due to their low generalizability on diverse datasets, high inference latency, and lack of explainability. To tackle these challenges, this paper presents CloudSecureAI, the first hybrid Artificial Intelligence (AI)-based threat prediction and mitigation framework, dedicated from the ground up to secure cloud storage infrastructures. CloudSecureNet, our new multi-branch deep learning model, leverages Convolutional Neural Networks (CNNs) for spatial feature extraction, Bi-directional Long Short-Term Memory (BiLSTMs) for temporal pattern learning, and Transformer encoders for capturing global dependency and contextual information. The features are then fused and passed onto an XGBoost Classifier that performs accurate and fast classification of the threats. We assessed the proposed framework comprehensively on three benchmark datasets (UNSW-NB15, cICIDS 2017, and CSE-CIC-IDS2018), achieving a maximum accuracy of 98.74% with a high level of generalizability in cross-dataset tests. CITY now features an improved architecture, with all components validated through ablation studies, and interpretable predictions utilizing Shapley Additive exPlanations (SHAP) and attention visualizations. Additionally, real-time evaluation demonstrated that CloudSecureNet exhibits low inference latency (< 4 ms on GPU) and can facilitate high-throughput deployment scenarios for the CloudSecureNet model. CloudSecureAI, thus, is an interpretable, deployment-ready solution to address cloud security challenges with solid, engineering-backed advancements in intelligent cyber threat detection systems.
Copyright comment Springer Nature or its licensor (e.g. a society or other partner) holds exclusive rights to this article under a publishing agreement with the author(s) or other rightsholder(s); author self-archiving of the accepted manuscript version of this article is solely governed by the terms of such publishing agreement and applicable law.
© The Author(s), under exclusive licence to Società Italiana di Fisica and Springer-Verlag GmbH Germany, part of Springer Nature 2025
Springer Nature or its licensor (e.g. a society or other partner) holds exclusive rights to this article under a publishing agreement with the author(s) or other rightsholder(s); author self-archiving of the accepted manuscript version of this article is solely governed by the terms of such publishing agreement and applicable law.

