Kandadi, Akhila, Gupta, Shaguna, Bhaskaran, Ranjith and Muntean, Cristina Hava (2026) Scalable Threat Assessment Machine Learning Framework for CI/CD DevSecOps Pipelines. In: 2026 2nd International Conference on Federated Learning and Intelligent Computing Systems (FLICS). IEEE, Valencia, Spain, pp. 281-289. ISBN 979-8-3315-6336-3
Full text not available from this repository.Abstract
Current Continuous Integration and Continuous Deployment (CI/CD) pipelines increasingly use machine learning (ML) to predict, detect, and respond to security risks, yet they remain vulnerable to sophisticated attacks that can bypass traditional security tooling. These approaches create a hurdle to code deployment due to frequent false-positive alerts, which add operational overhead for developers. In DevSecOps, security is expected to operate as an automated and integral part of the delivery workflow, but achieving this at scale remains challenging. This paper proposes a cloud-native threat assessment framework for CI/CD DevSecOps pipelines centered on a hybrid Transformer-GNN ensemble model, where the Transformer captures temporal attack dynamics from ordered event sequences andthe GNN approximates structural relationships based on feature similarity to identify coordinated anomalies. The framework is trained and evaluated using the CICIDS-2017 intrusion detection dataset, a widely used benchmark for network-based threat detection. While not CI/CD-specific, it enables validation of the model’s ability to capture temporal and structural attack patterns. Class imbalance is handled using focal loss with logdampened class weights and stratified sampling that preserves the temporal coherence required by sequential deep learning models. The proposed framework achieves 99.98% accuracy with a 0.0005% false positive rate, bridging the integration gap between advanced ML-based detection and practical DevSecOps requirements.
Actions (login required)
![]() |
View Item |
Tools
Tools