{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,18]],"date-time":"2026-03-18T17:55:03Z","timestamp":1773856503786,"version":"3.50.1"},"reference-count":0,"publisher":"Slovenian Association Informatika","issue":"10","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IJCAI"],"abstract":"<jats:p>In the large-scale data environment, network security situational awareness (NSSA) often faces the problems of poor real-time performance and low early warning accuracy. Therefore, this article proposes an intelligent early warning model that integrates multi-source heterogeneous data. This model constructs a distributed processing architecture based on Spark+Flink, which integrates a hybrid analysis mechanism of long-term memory network (LSTM), self-encoder and graph neural network (GNN) to efficiently detect abnormal behaviors and infer attack paths. At the same time, a situation scoring mechanism with dynamic weight adjustment is designed, and a time decay suppression strategy is introduced to optimize the alarm output and reduce the false alarm rate. The experiment was conducted on CICIDS2017 public data set and a real log of a provincial government cloud, and evaluated by F1-score, AUC, response delay and effective alarm compression ratio. The results show that the F1-score of this model is 0.93 on CICIDS2017, which is significantly better than the traditional method. In the real government cloud environment, the system throughput is up to 183,000 pieces\/second, the average response delay is controlled within 300ms, and the number of effective alarms is reduced by over 65%. This study verifies the feasibility and superiority of the proposed model in high concurrency scenarios, and provides a practical basis for building an intelligent and extensible network security defense system.<\/jats:p>","DOI":"10.31449\/inf.v50i10.12390","type":"journal-article","created":{"date-parts":[[2026,3,18]],"date-time":"2026-03-18T11:12:43Z","timestamp":1773832363000},"source":"Crossref","is-referenced-by-count":0,"title":["A Hybrid Deep Learning Architecture for Network Security Situation Awareness and Pre-Alarm in Large-Scale Data Environments Using LSTM, Autoencoder, and GNN"],"prefix":"10.31449","volume":"50","author":[{"given":"Xiaoxia","family":"Wang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"16141","published-online":{"date-parts":[[2026,3,18]]},"container-title":["Informatica"],"original-title":[],"link":[{"URL":"https:\/\/www.informatica.si\/index.php\/informatica\/article\/download\/12390\/6598","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.informatica.si\/index.php\/informatica\/article\/download\/12390\/6598","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,18]],"date-time":"2026-03-18T11:12:44Z","timestamp":1773832364000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.informatica.si\/index.php\/informatica\/article\/view\/12390"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3,18]]},"references-count":0,"journal-issue":{"issue":"10","published-online":{"date-parts":[[2026,3,18]]}},"URL":"https:\/\/doi.org\/10.31449\/inf.v50i10.12390","relation":{},"ISSN":["1854-3871","0350-5596"],"issn-type":[{"value":"1854-3871","type":"electronic"},{"value":"0350-5596","type":"print"}],"subject":[],"published":{"date-parts":[[2026,3,18]]}}}