NORMA eResearch @NCI Library

Scalable Threat Assessment Machine Learning Framework for CI/CD DevSecOps Pipelines

Kandadi, Akhila, Gupta, Shaguna, Bhaskaran, Ranjith and Muntean, Cristina Hava (2026) Scalable Threat Assessment Machine Learning Framework for CI/CD DevSecOps Pipelines. In: 2026 2nd International Conference on Federated Learning and Intelligent Computing Systems (FLICS). IEEE, Valencia, Spain, pp. 281-289. ISBN 979-8-3315-6336-3

Full text not available from this repository.
Official URL: https://doi.org/10.1109/FLICS70075.2026.11621927

Abstract

Current Continuous Integration and Continuous Deployment (CI/CD) pipelines increasingly use machine learning (ML) to predict, detect, and respond to security risks, yet they remain vulnerable to sophisticated attacks that can bypass traditional security tooling. These approaches create a hurdle to code deployment due to frequent false-positive alerts, which add operational overhead for developers. In DevSecOps, security is expected to operate as an automated and integral part of the delivery workflow, but achieving this at scale remains challenging. This paper proposes a cloud-native threat assessment framework for CI/CD DevSecOps pipelines centered on a hybrid Transformer-GNN ensemble model, where the Transformer captures temporal attack dynamics from ordered event sequences andthe GNN approximates structural relationships based on feature similarity to identify coordinated anomalies. The framework is trained and evaluated using the CICIDS-2017 intrusion detection dataset, a widely used benchmark for network-based threat detection. While not CI/CD-specific, it enables validation of the model’s ability to capture temporal and structural attack patterns. Class imbalance is handled using focal loss with logdampened class weights and stratified sampling that preserves the temporal coherence required by sequential deep learning models. The proposed framework achieves 99.98% accuracy with a 0.0005% false positive rate, bridging the integration gap between advanced ML-based detection and practical DevSecOps requirements.

Item Type: Book Section
Uncontrolled Keywords: intelligent computing systems; distributed AI systems; CI/CD pipelines; DevSecOps; threat assessment; transformer networks; graph neural networks; cloud-native platforms
Subjects: Q Science > QH Natural history > QH301 Biology > Methods of research. Technique. Experimental biology > Data processing. Bioinformatics > Artificial intelligence
Q Science > Q Science (General) > Self-organizing systems. Conscious automata > Artificial intelligence
T Technology > T Technology (General) > Information Technology > Cloud computing
Q Science > QA Mathematics > Computer software > Computer Security
T Technology > T Technology (General) > Information Technology > Computer software > Computer Security
Q Science > Q Science (General) > Self-organizing systems. Conscious automata > Machine learning
Divisions: School of Computing > Staff Research and Publications
Depositing User: Tamara Malone
Date Deposited: 26 Aug 2026 15:46
Last Modified: 26 Aug 2026 15:46
URI: https://norma.ncirl.ie/id/eprint/9674

Actions (login required)

View Item View Item