Risk-Aware Federated Graph-Temporal Learning for Cross-Domain Application Programming Interface Security Monitoring
Main Article Content
Abstract
Application programming interfaces have become the principal communication surface of cloud-native and distributed business systems, but their security telemetry is fragmented across gateways, service meshes, application logs, and organizational domains. Centralized monitoring is difficult when request payloads, identity tokens, object identifiers, and business parameters cannot leave their original security boundaries. This paper presents FedAPI-Mon, a risk-aware federated graph-temporal framework for cross-domain application programming interface security monitoring. Each participant converts locally observed requests into windowed call graphs that jointly represent endpoint semantics, identity transitions, object access, response status, latency, and invocation order. A relational graph-attention encoder learns lateral dependencies among services, while a temporal self-attention encoder models multi-step behaviors that are weak when viewed as isolated requests. A risk-aware aggregation rule then weights local updates by threat coverage, update consistency, and validation reliability, reducing model drift under non-independent and non-identically distributed traffic. Finally, an adaptive boundary combines classification confidence, representation distance, and short-term baseline deviation to identify both known and previously withheld attack patterns. Controlled replay experiments containing 1.24 million requests, 40 monitoring items, 12 services, and six attack families show a macro-F1 of 96.4%, a receiver-operating-characteristic area of 98.3%, and a 1.7% false-positive rate. In leave-one-attack-family-out tests, the method retains a macro-F1 of 91.8%. It also compresses 96.2% of repetitive alerts while preserving 95.4% of malicious events. The results indicate that federated graph-temporal learning can improve API risk visibility without centralizing sensitive request data.
Downloads
Article Details

This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution License that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work (See The Effect of Open Access).
References
OWASP Foundation, “OWASP Top 10 API Security Risks – 2023,” OWASP API Security Project, 2023. [Online]. Available: https://owas p.org/API-Security/editions/2023/en/0x11-t10/.
H. B. McMahan, E. Moore, D. Ramage, S. Hampson and B. Agüera y Arcas, “Communication-efficient learning of deep networks from decentralized data,” in Proc. 20th Int. Conf. Artif. Intell. Stat., 2017, pp. 1273– 1282.
M. Du, F. Li, G. Zheng and V. Srikumar, “DeepLog: Anomaly detection and diagnosis from system logs through deep learning,” in Proc. ACM SIGSAC Conf. Comput. Commun. Secur., 2017, pp. 1285–1298, DOI: 10.1145/3133956.3134015.
P. Veliˇckovi´c et al., “Graph attention networks,” in Proc. 6th Int. Conf. Learn. Represent., 2018.
A. Vaswani et al., “Attention is all you need,” in Proc. Adv. Neural Inf. Process. Syst. 30, 2017, pp. 5998–6008.
T. Li, A. K. Sahu, M. Zaheer, M. Sanjabi, A. Talwalkar and V. Smith, “Federated optimization in heterogeneous networks,” in Proc. Mach. Learn. Syst., vol. 2, 2020, pp. 429–450.
S. P. Karimireddy et al., “SCAFFOLD: Stochastic controlled averaging for federated learning,” in Proc. 37th Int. Conf. Mach. Learn., 2020, pp. 5132–5143.
T.-Y. Lin, P. Goyal, R. Girshick, K. He and P. Dollár, “Focal loss for dense object detection,” in Proc. IEEE Int. Conf. Comput. Vis., 2017, pp. 2999– 3007.
W. L. Hamilton, R. Ying and J. Leskovec, “Inductive representation learning on large graphs,” in Proc. Adv. Neural Inf. Process. Syst. 30, 2017, pp. 1024–1034.
D. P. Kingma and J. Ba, “Adam: A method for stochastic optimization,” in Proc. 3rd Int. Conf. Learn. Represent., 2015.