{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T08:15:12Z","timestamp":1778660112324,"version":"3.51.4"},"reference-count":58,"publisher":"MDPI AG","issue":"5","license":[{"start":{"date-parts":[[2026,4,24]],"date-time":"2026-04-24T00:00:00Z","timestamp":1776988800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Computers"],"abstract":"<jats:p>Despite its continued growth, cloud computing remains susceptible to significant security challenges, as shared virtualised environments pose threats at multiple levels. These vulnerabilities are caused by a lack of security coverage in the responsibility model between the provider and the tenant. In this work, we propose the multi-layered architecture VIRTUOSO (VIRTual Unified Operation Security Optimiser) to cover these security gaps through advanced automation and ML. VIRTUOSO has four layers. The Input Layer extracts key risk components from collected telemetry data. The Deep Automation Security Layer provides automated actions and continuous monitoring of security defences. Its counterpart, the Intelligent Security Layer, predicts threats using anomaly detection. The last layer, the Output Layer, returns an aggregated risk summary. The datasets we used were chosen for their relevance: the UNSW-NB15 dataset, a subset of the web-attack classification from CSE-CIC-IDS2018, and a sample of anonymised log events from AWS CloudTrail. Our ensemble classifiers achieve a best accuracy of 95.08% \u00b1 0.13% on UNSW-NB15 (RF), with statistically significant differences among models confirmed by the Friedman test (p &lt; 0.004) and Nemenyi post hoc analysis, and 99.25% \u00b1 0.52% on web-attack (CatBoost), where ensemble differences are not statistically significant (p = 0.093), consistent with the high separability of this dataset. The training-test gap and DNN curves show no overfitting, whereas our adversarial tests show a maximum accuracy loss of 8.1% at \u03b5 = 0.02. With these promising results, we can assert that, pending verification in an actual cloud environment and potential integration with FL, our ensemble classifier model appears to be a good real-world prototype.<\/jats:p>","DOI":"10.3390\/computers15050272","type":"journal-article","created":{"date-parts":[[2026,4,24]],"date-time":"2026-04-24T12:29:11Z","timestamp":1777033751000},"page":"272","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["VIRTUOSO: A Multilayer Cloud Security and Risk Management Framework"],"prefix":"10.3390","volume":"15","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5118-7739","authenticated-orcid":false,"given":"Raja Waseem","family":"Anwar","sequence":"first","affiliation":[{"name":"Department of Computer Science, German University of Technology in Oman, P.O. Box 1816, Muscat P.C 130, Oman"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5343-7837","authenticated-orcid":false,"given":"Flavio","family":"Pastore","sequence":"additional","affiliation":[{"name":"Department of Computer Science, German University of Technology in Oman, P.O. Box 1816, Muscat P.C 130, Oman"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tariq","family":"Abdullah","sequence":"additional","affiliation":[{"name":"College of Science & Engineering, University of Derby, Derby DE22 1GB, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2026,4,24]]},"reference":[{"key":"ref_1","unstructured":"Gartner (2026, February 15). Gartner Forecasts Worldwide Public Cloud End User Spending to Total $723 Billion in 2025. Available online: https:\/\/www.gartner.com\/en\/newsroom\/press-releases\/2024-11-19-gartner-forecasts-worldwide-public-cloud-end-user-spending-to-total-723-billion-dollars-in-2025."},{"key":"ref_2","unstructured":"Cybersecurity Ventures (2026, February 15). Cybercrime to Cost the World $10.5 Trillion Annually by 2025. Available online: https:\/\/cybersecurityventures.com\/cybercrime-damage-costs-10-trillion-by-2025\/."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"103","DOI":"10.1007\/s10586-018-2823-6","article-title":"Internet of Things: Information security challenges and solutions","volume":"22","author":"Miloslavskaya","year":"2019","journal-title":"Clust. Comput."},{"key":"ref_4","unstructured":"GitLab (2026, February 15). 2023 Global DevSecOps Report. Available online: https:\/\/about.gitlab.com\/blog\/gitlab-global-devsecops-ai-report\/."},{"key":"ref_5","unstructured":"Amazon Web Services (2024, December 15). Introducing Amazon GuardDuty Extended Threat Detection: AI\/ML Attack Sequence Identification for Enhanced Cloud Security. Available online: https:\/\/aws.amazon.com\/blogs\/aws\/introducing-amazon-guardduty-extended-threat-detection-aiml-attack-sequence-identification-for-enhanced-cloud-security\/."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"544","DOI":"10.1016\/j.future.2017.07.060","article-title":"Internet of Things security and forensics: Challenges and opportunities","volume":"78","author":"Conti","year":"2018","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"12","DOI":"10.1145\/3298981","article-title":"Federated Machine Learning: Concept and Applications","volume":"10","author":"Yang","year":"2019","journal-title":"ACM Trans. Intell. Syst. Technol."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"49","DOI":"10.1109\/MSEC.2018.2888775","article-title":"Privacy-Preserving Machine Learning: Threats and Solutions","volume":"17","author":"Chang","year":"2019","journal-title":"IEEE Secur. Priv."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Moustafa, N., and Slay, J. (2015). UNSW-NB15: A comprehensive data set for network intrusion detection systems. Proceedings of the Military Communications and Information Systems Conference (MilCIS 2015), Canberra, Australia, 10\u201312 November 2015, IEEE.","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Sharafaldin, I., Habibi Lashkari, A., and Ghorbani, A.A. (2018). Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization. Proceedings of the 4th International Conference on Information Systems Security and Privacy (ICISSP 2018), Funchal, Portugal, 22\u201324 January 2018, SciTePress.","DOI":"10.5220\/0006639801080116"},{"key":"ref_11","unstructured":"Piper, S. (2026, January 11). Public Dataset of CloudTrail Logs from flaws.cloud. Available online: https:\/\/summitroute.com\/downloads\/flaws_cloudtrail_logs.tar."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"684","DOI":"10.1016\/j.future.2015.09.021","article-title":"Integration of Cloud computing and Internet of Things: A survey","volume":"56","author":"Botta","year":"2016","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_13","unstructured":"National Institute of Standards and Technology (NIST) (2026, February 15). Security Reference Architecture for Cloud Computing. NIST Special Publication 500-299, Available online: https:\/\/csrc.nist.gov\/pubs\/sp\/500\/299\/ipd."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Wang, Z., and Jiang, X. (2010). HyperSafe: A lightweight approach to provide lifetime hypervisor control-flow integrity. Proceedings of the IEEE Symposium on Security and Privacy, Oakland, CA, USA, 16\u201319 May 2010, IEEE.","DOI":"10.1109\/SP.2010.30"},{"key":"ref_15","unstructured":"Cloud Security Alliance (2026, February 15). Cloud Controls Matrix v4.0. Available online: https:\/\/cloudsecurityalliance.org\/research\/cloud-controls-matrix."},{"key":"ref_16","unstructured":"Amazon Web Services (2025, November 12). Shared Responsibility Model. Available online: https:\/\/aws.amazon.com\/compliance\/shared-responsibility-model\/."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Gentry, C., Sahai, A., and Waters, B. (2013). Homomorphic Encryption from Learning with Errors: Conceptually Simpler, Asymptotically-Faster, Attribute-Based. Proceedings of the Annual Cryptology Conference (CRYPTO), Springer.","DOI":"10.1007\/978-3-642-40041-4_5"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"120","DOI":"10.1016\/j.comcom.2017.07.006","article-title":"Data security and privacy preservation in cloud storage environments based on cryptographic mechanisms","volume":"111","author":"Kaaniche","year":"2017","journal-title":"Comput. Commun."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Xu, X., Weber, I., Staples, M., Zhu, L., Bosch, J., Bass, L., Pautasso, C., and Rimba, P. (2017). A Taxonomy of Blockchain-Based Systems for Architecture Design. Proceedings of the IEEE International Conference on Software Architecture (ICSA), Gothenburg, Sweden, 3\u20137 April 2017, IEEE.","DOI":"10.1109\/ICSA.2017.33"},{"key":"ref_20","unstructured":"Decentralized Identity Foundation (2025, October 14). Decentralized Identity Foundation: DIF. Available online: https:\/\/identity.foundation\/."},{"key":"ref_21","unstructured":"McMahan, B., Moore, E., Ramage, D., Hampson, S., and Arcas, B.A.y. (2017, January 20\u201322). Communication-Efficient Learning of Deep Networks from Decentralized Data. Proceedings of the 20th International Conference on Artificial Intelligence and Statistics (AISTATS), Fort Lauderdale, FL, USA."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1561\/2200000083","article-title":"Advances and Open Problems in Federated Learning","volume":"14","author":"Kairouz","year":"2021","journal-title":"Found. Trends Mach. Learn."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Panchal, Y., Sheikh, R., Sethi, K.K., Bhanodia, P.K., Rajput, S.S., and Rathore, N.P.S. (2024). Privacy Preserving Techniques in Data Science: A Review. Proceedings of the 2024 International Conference on Advances in Computing, Robotics, Smart Systems and Engineering Technologies (ACROSET), Gwalior, India, 27\u201328 September 2024, IEEE.","DOI":"10.1109\/ACROSET62108.2024.10743362"},{"key":"ref_24","unstructured":"Mehmood, A., Bin-Gulaym, M.A., and Zhao, J. (2023). Multi-Factor and Multi-Layer (MF-ML) Authentication Framework for Cloud Platforms. Appl. Sci., 13."},{"key":"ref_25","unstructured":"ENISA (2023). Multilayer Framework for Good Cybersecurity Practices for AI, European Union Agency for Cybersecurity. Available online: https:\/\/www.enisa.europa.eu\/publications\/multilayer-framework-for-good-cybersecurity-practices-for-ai."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"132","DOI":"10.1007\/s10462-024-10776-5","article-title":"Research trends in deep learning and machine learning for cloud computing security","volume":"57","author":"Alzoubi","year":"2024","journal-title":"Artif. Intell. Rev."},{"key":"ref_27","first-page":"102419","article-title":"Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study","volume":"50","author":"Ferrag","year":"2020","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_28","unstructured":"(2026, March 28). Innovation Insight for Cloud-Native Application Protection Platforms. Gartner Research. Available online: https:\/\/www.gartner.com."},{"key":"ref_29","first-page":"2669","article-title":"Deep Reinforcement Learning for Cyber Security","volume":"31","author":"Nguyen","year":"2021","journal-title":"IEEE Trans. Netw. Learn. Syst."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"35365","DOI":"10.1109\/ACCESS.2018.2836950","article-title":"Machine Learning and Deep Learning Methods for Cybersecurity","volume":"6","author":"Xin","year":"2018","journal-title":"IEEE Access"},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"2477","DOI":"10.1109\/TNSM.2024.3352586","article-title":"Reinforcement Learning Meets Network Intrusion Detection: A Transferable and Adaptable Framework for Anomaly Behavior Identification","volume":"21","author":"He","year":"2024","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_32","first-page":"38","article-title":"Deep Learning for Anomaly Detection: A Survey","volume":"54","author":"Chalapathy","year":"2021","journal-title":"ACM Comput. Surv."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"949","DOI":"10.1007\/s10586-017-1117-8","article-title":"A Survey of Deep Learning-Based Network Anomaly Detection","volume":"22","author":"Kwon","year":"2019","journal-title":"Clust. Comput."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"314","DOI":"10.1007\/s44163-025-00578-1","article-title":"A comprehensive survey on intrusion detection systems with advances in machine learning, deep learning and emerging cybersecurity challenges","volume":"5","author":"Hozouri","year":"2025","journal-title":"Discov. Artif. Intell."},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Almorsy, M., Grundy, J., and Ibrahim, A.S. (2012). TOSSMA: A Tenant-Oriented SaaS Security Management Architecture. Proceedings of the IEEE Fifth International Conference on Cloud Computing (CLOUD), Honolulu, HI, USA, 24\u201329 June 2012, IEEE.","DOI":"10.1109\/CLOUD.2012.146"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"344","DOI":"10.1016\/j.ins.2018.04.081","article-title":"Security-by-design in multi-cloud applications: An optimization approach","volume":"454\u2013455","author":"Casola","year":"2018","journal-title":"Inf. Sci."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Rashid, T., Agrafiotis, I., and Nurse, J.R. (2016). A New Take on Detecting Insider Threats: Exploring the Usefulness of Content in Context. Proceedings of the 8th ACM CCS International Workshop on Managing Insider Security Threats, Vienna, Austria, 28 October 2016, Association for Computing Machinery.","DOI":"10.1145\/2995959.2995964"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Neupane, S., Ables, J., Anderson, W., Mittal, S., Rahimi, S., Banicescu, I., and Seale, M. (2022). Explainable Intrusion Detection Systems (X-IDS): A Survey of Current Methods, Challenges and Opportunities. arXiv.","DOI":"10.1109\/ACCESS.2022.3216617"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Bauer, E., Schluga, O., Maksuti, S., Bicaku, A., Hofbauer, D., Ivkic, I., Tauber, M.G., and Wohrer, A. (2017). Towards a security baseline for IaaS-cloud back-ends in Industry 4.0. Proceedings of the International Conference for Internet Technology and Secured Transactions (ICITST), Cambridge, UK, 11\u201314 December 2017, IEEE.","DOI":"10.23919\/ICITST.2017.8356438"},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"102124","DOI":"10.1016\/j.cose.2020.102124","article-title":"Continuous auditing and threat detection in multi-cloud infrastructure","volume":"102","author":"Torkura","year":"2021","journal-title":"Comput. Secur."},{"key":"ref_41","unstructured":"Microsoft (2026, February 15). Shared Responsibility in the Cloud. Microsoft Azure Security Documentation. Available online: https:\/\/learn.microsoft.com\/en-us\/azure\/security\/fundamentals\/shared-responsibility."},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Chen, T., and Guestrin, C. (2016). XGBoost: A Scalable Tree Boosting System. Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, Association for Computing Machinery.","DOI":"10.1145\/2939672.2939785"},{"key":"ref_43","unstructured":"Ke, G., Meng, Q., Finley, T., Wang, T., Chen, W., Ma, W., Ye, Q., and Liu, T.-Y. (2017). LightGBM: A Highly Efficient Gradient Boosting Decision Tree. Advances in Neural Information Processing Systems 30, Curran Associates Inc."},{"key":"ref_44","unstructured":"Prokhorenkova, L., Gusev, G., Vorobev, A., Dorogush, A.V., and Gulin, A. (2018). CatBoost: Unbiased boosting with categorical features. Advances in Neural Information Processing Systems 31, Curran Associates Inc."},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Chicco, D., and Jurman, G. (2020). The advantages of the Matthews correlation coefficient (MCC) over F1 score and accuracy in binary classification evaluation. BMC Genom., 21.","DOI":"10.1186\/s12864-019-6413-7"},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Elhanashi, A., Gasmi, K., Begni, A., Dini, P., Zheng, Q., and Saponara, S. (2023). Machine learning techniques for anomaly-based detection system on CSE-CIC-IDS2018 dataset. Applications in Electronics Pervading Industry, Environment and Society, Springer.","DOI":"10.1007\/978-3-031-30333-3_17"},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"41525","DOI":"10.1109\/ACCESS.2019.2895334","article-title":"Deep Learning Approach for Intelligent Intrusion Detection System","volume":"7","author":"Vinayakumar","year":"2019","journal-title":"IEEE Access"},{"key":"ref_48","doi-asserted-by":"crossref","first-page":"205","DOI":"10.1016\/j.dcan.2022.08.012","article-title":"Feature extraction for machine learning-based intrusion detection in IoT networks","volume":"10","author":"Sarhan","year":"2024","journal-title":"Digit. Commun. Netw."},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"349","DOI":"10.1016\/j.future.2018.06.055","article-title":"Detection of advanced persistent threat using machine-learning correlation analysis","volume":"89","author":"Ghafir","year":"2018","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"1851","DOI":"10.1109\/COMST.2019.2891891","article-title":"A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities","volume":"21","author":"Alshamrani","year":"2019","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_51","unstructured":"Cloud Security Alliance (2026, February 15). The State of Multi-Cloud Identity Survey. CSA Research, October 2024. Available online: https:\/\/cloudsecurityalliance.org."},{"key":"ref_52","unstructured":"Du, M., Jia, R., and Song, D. (2021, January 4). Robust Anomaly Detection and Backdoor Attack Detection Via Differential Privacy. Proceedings of the International Conference on Learning Representations (ICLR), Vienna, Austria."},{"key":"ref_53","unstructured":"Hu, V.C., Ferraiolo, D., Kuhn, R., Schnitzer, A., Sandlin, K., Miller, R., and Scarfone, K. (2019). Guide to Attribute Based Access Control (ABAC) Definition and Considerations, U.S. Department of Commerce. NIST Special Publication 800-162."},{"key":"ref_54","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1093\/ijlit\/eay015","article-title":"Demonstrable accountability for data protection in the Internet of Things","volume":"27","author":"Urquhart","year":"2019","journal-title":"Int. J. Law Inf. Technol."},{"key":"ref_55","doi-asserted-by":"crossref","first-page":"52138","DOI":"10.1109\/ACCESS.2018.2870052","article-title":"Peeking inside the black-box: A survey on Explainable Artificial Intelligence (XAI)","volume":"6","author":"Adadi","year":"2018","journal-title":"IEEE Access"},{"key":"ref_56","doi-asserted-by":"crossref","first-page":"e2751","DOI":"10.7717\/peerj-cs.2751","article-title":"Federated learning with LSTM for intrusion detection in IoT-based wireless sensor networks: A multi-dataset analysis","volume":"11","author":"Anwar","year":"2025","journal-title":"PeerJ Comput. Sci."},{"key":"ref_57","unstructured":"Carlini, N., Athalye, A., Papernot, N., Brendel, W., Rauber, J., Tsipras, D., Goodfellow, I., Madry, A., and Kurakin, A. (2019). On Evaluating Adversarial Robustness. Advances in Neural Information Processing Systems (NeurIPS), Neural Information Processing Systems Foundation, Inc."},{"key":"ref_58","doi-asserted-by":"crossref","first-page":"25","DOI":"10.1049\/cit2.12028","article-title":"A survey on adversarial attacks and defences","volume":"6","author":"Chakraborty","year":"2021","journal-title":"CAAI Trans. Intell. Technol."}],"container-title":["Computers"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-431X\/15\/5\/272\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T08:01:43Z","timestamp":1778659303000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-431X\/15\/5\/272"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,24]]},"references-count":58,"journal-issue":{"issue":"5","published-online":{"date-parts":[[2026,5]]}},"alternative-id":["computers15050272"],"URL":"https:\/\/doi.org\/10.3390\/computers15050272","relation":{},"ISSN":["2073-431X"],"issn-type":[{"value":"2073-431X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,4,24]]}}}