TY - CPAPER AU - Mert Nakip AU - Rafał Gibała AU - Anna Grygar AU - Sławomir Nowak AB -
Multi-modal real-time monitoring systems based on AI are
essential for ensuring system reliability and cyber-defense in cloud computing,
but are challenged by context isolation, early-fusion computational
overhead, and insufficient transparency. In order to address these
issues, this paper introduces T-MATE, an explainable Trend-based Multimodal
Anomaly and Threat detector engineered for robust, secure cloud
infrastructure monitoring. Rather than treating multi-modal streams
monolithically, T-MATE structurally decouples data modalities into independent
neural network heads, using a specialized Recurrent Trend
Predictive Neural Network (rTPNN) to isolate underlying trends and levels
across quantitative performance telemetry, while qualitatively parsing
textual event logs via Gemini 2.5 Flash. These components output
bounded anomaly scores and are integrated at the decision level
using an Empirical Reliability-Weighted Max Fusion operator, which
scales individual outputs to enforce a max-safety posture and eliminate
parameter-explosion liabilities. In order to demonstrate operational deployment
readiness, the framework is thoroughly evaluated via 10-fold
cross-validation and compared against standalone rTPNN, LSTM, and
MLP models alongside the baseline Avg-Fuse paradigm on the public
CloudAnoBench dataset. The results reveal that T-MATE achieves a superior
overall F1 Score of 0.88, a top threshold-invariant AUC-ROC of
0.96, an exceptional True Positive Rate of 0.96, and a processing footprint
that confirms its viability for close to real-time inference in enterprise
cloud infrastructures.
Multi-modal real-time monitoring systems based on AI are
essential for ensuring system reliability and cyber-defense in cloud computing,
but are challenged by context isolation, early-fusion computational
overhead, and insufficient transparency. In order to address these
issues, this paper introduces T-MATE, an explainable Trend-based Multimodal
Anomaly and Threat detector engineered for robust, secure cloud
infrastructure monitoring. Rather than treating multi-modal streams
monolithically, T-MATE structurally decouples data modalities into independent
neural network heads, using a specialized Recurrent Trend
Predictive Neural Network (rTPNN) to isolate underlying trends and levels
across quantitative performance telemetry, while qualitatively parsing
textual event logs via Gemini 2.5 Flash. These components output
bounded anomaly scores and are integrated at the decision level
using an Empirical Reliability-Weighted Max Fusion operator, which
scales individual outputs to enforce a max-safety posture and eliminate
parameter-explosion liabilities. In order to demonstrate operational deployment
readiness, the framework is thoroughly evaluated via 10-fold
cross-validation and compared against standalone rTPNN, LSTM, and
MLP models alongside the baseline Avg-Fuse paradigm on the public
CloudAnoBench dataset. The results reveal that T-MATE achieves a superior
overall F1 Score of 0.88, a top threshold-invariant AUC-ROC of
0.96, an exceptional True Positive Rate of 0.96, and a processing footprint
that confirms its viability for close to real-time inference in enterprise
cloud infrastructures.