Risk-Aware Federated Graph-Temporal Learning for Cross-Domain Application Programming Interface Security Monitoring

Main Article Content

X. H. Ai
Y. T. Huang
Q. Meng
Z. L. Chen
Y. Dong
Y. Yin

Abstract

Application programming interfaces have become the principal communication surface of cloud-native and distributed business systems, but their security telemetry is fragmented across gateways, service meshes, application logs, and organizational domains. Centralized monitoring is difficult when request payloads, identity tokens, object identifiers, and business parameters cannot leave their original security boundaries. This paper presents FedAPI-Mon, a risk-aware federated graph-temporal framework for cross-domain application programming interface security monitoring. Each participant converts locally observed requests into windowed call graphs that jointly represent endpoint semantics, identity transitions, object access, response status, latency, and invocation order. A relational graph-attention encoder learns lateral dependencies among services, while a temporal self-attention encoder models multi-step behaviors that are weak when viewed as isolated requests. A risk-aware aggregation rule then weights local updates by threat coverage, update consistency, and validation reliability, reducing model drift under non-independent and non-identically distributed traffic. Finally, an adaptive boundary combines classification confidence, representation distance, and short-term baseline deviation to identify both known and previously withheld attack patterns. Controlled replay experiments containing 1.24 million requests, 40 monitoring items, 12 services, and six attack families show a macro-F1 of 96.4%, a receiver-operating-characteristic area of 98.3%, and a 1.7% false-positive rate. In leave-one-attack-family-out tests, the method retains a macro-F1 of 91.8%. It also compresses 96.2% of repetitive alerts while preserving 95.4% of malicious events. The results indicate that federated graph-temporal learning can improve API risk visibility without centralizing sensitive request data.

Downloads

Download data is not yet available.

Article Details

How to Cite
Ai, X. H., Huang, Y. T., Meng, Q., Chen, Z. L., Dong, Y., & Yin, Y. (2026). Risk-Aware Federated Graph-Temporal Learning for Cross-Domain Application Programming Interface Security Monitoring. Advanced Electromagnetics, 15(3), 10229–10235. https://doi.org/10.7716/aem.v15i3.4225
Section
Research Articles

References

OWASP Foundation, “OWASP Top 10 API Security Risks – 2023,” OWASP API Security Project, 2023. [Online]. Available: https://owas p.org/API-Security/editions/2023/en/0x11-t10/.

H. B. McMahan, E. Moore, D. Ramage, S. Hampson and B. Agüera y Arcas, “Communication-efficient learning of deep networks from decentralized data,” in Proc. 20th Int. Conf. Artif. Intell. Stat., 2017, pp. 1273– 1282.

M. Du, F. Li, G. Zheng and V. Srikumar, “DeepLog: Anomaly detection and diagnosis from system logs through deep learning,” in Proc. ACM SIGSAC Conf. Comput. Commun. Secur., 2017, pp. 1285–1298, DOI: 10.1145/3133956.3134015.

View Article

P. Veliˇckovi´c et al., “Graph attention networks,” in Proc. 6th Int. Conf. Learn. Represent., 2018.

A. Vaswani et al., “Attention is all you need,” in Proc. Adv. Neural Inf. Process. Syst. 30, 2017, pp. 5998–6008.

T. Li, A. K. Sahu, M. Zaheer, M. Sanjabi, A. Talwalkar and V. Smith, “Federated optimization in heterogeneous networks,” in Proc. Mach. Learn. Syst., vol. 2, 2020, pp. 429–450.

S. P. Karimireddy et al., “SCAFFOLD: Stochastic controlled averaging for federated learning,” in Proc. 37th Int. Conf. Mach. Learn., 2020, pp. 5132–5143.

T.-Y. Lin, P. Goyal, R. Girshick, K. He and P. Dollár, “Focal loss for dense object detection,” in Proc. IEEE Int. Conf. Comput. Vis., 2017, pp. 2999– 3007.

W. L. Hamilton, R. Ying and J. Leskovec, “Inductive representation learning on large graphs,” in Proc. Adv. Neural Inf. Process. Syst. 30, 2017, pp. 1024–1034.

D. P. Kingma and J. Ba, “Adam: A method for stochastic optimization,” in Proc. 3rd Int. Conf. Learn. Represent., 2015.