AI-Driven Intelligent Threat Detection Frameworks Using Large Language Models for Hybrid Cloud Security Operations
DOI:
https://doi.org/10.21590/Keywords:
Large Language Models, hybrid cloud security, intelligent threat detection, Security Operations Center, threat intelligence, SIEM, XDR, artificial intelligence, cybersecurity, cloud security, incident response, security analyticsAbstract
Hybrid cloud environments combine private infrastructure, public cloud platforms, edge resources, and third-party services, creating complex security ecosystems with diverse attack surfaces, heterogeneous telemetry, and rapidly changing configurations. Traditional security operations increasingly struggle to correlate high-volume logs, alerts, network events, identity signals, and contextual threat intelligence across these distributed environments. Large Language Models (LLMs) offer a promising capability for augmenting security operations by interpreting heterogeneous security data, supporting natural-language investigation, correlating multi-stage attack indicators, and assisting analysts in incident triage and response. This study examines an AI-driven intelligent threat detection framework that integrates LLMs with conventional security controls, Security Information and Event Management (SIEM), Extended Detection and Response (XDR), cloud-native monitoring, threat intelligence, and automated response mechanisms. The proposed framework emphasizes contextual reasoning, multimodal security evidence, human oversight, privacy protection, prompt-security controls, and continuous evaluation. The research methodology adopts a design-oriented approach combining systematic literature analysis, framework development, experimental evaluation, and comparative assessment against conventional detection approaches. Key evaluation dimensions include detection accuracy, precision, recall, false-positive rate, response latency, contextual correlation, scalability, and computational cost. The framework is intended to improve the analytical capabilities of hybrid cloud Security Operations Centers while maintaining explainability and operational safeguards. The study contributes a structured architecture and evaluation methodology for deploying LLM-assisted threat detection in security-critical hybrid cloud environments.
References
[1] Chen, Y., Zeng, X., Luo, X., & Liu, Z. (2025). Joint client–server
selection and resource allocation based on split federated
learning in Edge-to-Cloud computing environments.
Computer Networks, 270, 111502. https://doi.org/10.1016/j.
comnet.2025.111502
[2] Pothuri, M. K. (2025). Building Self-Service BI in the Cloud with
AI Integration: Power BI and Snowflake. International Journal
of Emerging Trends in Computer Science and Information
Technology, 256-262.
[3] Tatavarthi, S., Bikkavolu, V., Gulapalli, S., Koilakonda, R. R., & Divi,
V. R. (2026, July). HybridFraudNet: A Dual-Branch CNN-GNN
Architecture for Healthcare Insurance Fraud Detection. In
2026 Seventeenth International Conference on Ubiquitous and
Future Networks (ICUFN) (pp. 917-922). IEEE.
[4] Soundappan, S. J. (2021). Integrated Artificial Intelligence
Framework for Enterprise Cloud Modernization and Intelligent
Threat Management Systems. International Journal of Research
Publications in Engineering, Technology and Management
(IJRPETM), 4(4), 5274-5284.
[5] Sharma, K., Singhal, A. B., karthik Chundi, V. R., & Arveti, S. (2026,
February). Analyzing Interdependencies Between IoT DataIntegration Capabilities and Real-Time Operational Decision-
Making: A DEMATEL Approach. In 2026 5th International
Conference on Innovative Practices in Technology and
Management (ICIPTM) (pp. 1-5). IEEE.
[6] Devineni, A., Pochincharla, S., & Muppalla, L. K. (2022). A
telemetry-fusion framework for proactive incident detection
in multi-tenant financial cloud platforms. International Journal
of Advances in Signal and Image Sciences, 13–18.
[7] Batzner, J., Nelaturu, S. H., Stachura, D., Kornilova, A., Crall, J.,
Cerruti, T., ... & Choshen, L. (2026). Every Eval Ever: A Unifying
Schema and Community Repository for AI Evaluation Results.
arXiv preprint arXiv:2606.14516.
[8] Nekkalapudi, K. (2026, June). Building Scalable Microservices
with Java, Spring Boot, Kafka, and Kubernetes on AWS. In 2026
5th International Conference on Computer Networks, Big Data
and IoT (ICCBI) (pp. 704-710). IEEE.
[9] Raja, G. V. (2022). AI Enabled Cloud and Data Engineering
Frameworks for Secure, Scalable, and Intelligent Cyber Physical
Analytics Systems. International Journal of Research and
Applied Innovations, 5(4), 7395-7409.
[10] Attaluri, V. C., Hullurappa, M., Batchu, R., Mudunuri, L. N. R.,
Vemulapalli, G., & Palakurti, N. R. (2025, April). Identity Access
Management for Network Devices: Enhancing Security of
Modern IT Infrastructure in Healthcare. In 2025 International
Conference on Data Science and Business Systems (ICDSBS)
(pp. 1-7). IEEE.
[11] Mathew, A. (2021). Artificial intelligence and cognitive
computing for 6G communications & networks. International
Journal of Computer Science and Mobile Computing, 10(3),
26-31.
[12] Tarigoppula, S. (2023). Adaptive cloud cost optimization
through predictive auto-scaling and infrastructure intelligence.
International Journal of Future Innovative Science and
Technology, 6(2), 10278–10290.
[13] Ganesan, N., & Kandhasamy, V. (2026). Early Detection of Cotton
Plant Diseases Using Zebra Optimizer with Deep Learning
Approach. Traitement du Signal, 43(1), 519.
[14] Maroju, P. K., & Mudunuri, L. N. R. (2025, October). Generative
AI as a Cyber Weapon: Synthetic Identity Fraud and Phishing at
Scale. In International Conference on Artificial Intelligence and
Networking (pp. 573-585). Cham: Springer Nature Switzerland.
[15] Ramasamy, M. (2024). Secure and extensible platform
architectures for enterprise network orchestration. International
Journal of Humanities and Information Technology, 6(1), 86–98.
[16] Mohile, A., Kumara, S., Sivashanmugam, S. P., & Mathur, S.
(2026, April). A Machine Learning-Driven Framework for
Rapid Cybersecurity Incident Response and Mitigation. In
2026 International Conference on Connected Intelligence for
Industrial Applications (CI2A) (pp. 1-6). IEEE.
[17] Chinnam, N. B. (2024). Cross-network scheduling optimization
for unified retail distribution networks. International Journal
of Engineering & Extended Technologies Research (IJEETR),
6(4), 8183–8188.
[18] Goyal, K. K., Hebbar, K. S., & Mali, R. K. (2026, March). AI
Modernization Enabled by Cloud-Native and Edge-Intelligent
Architectures. In International Conference on Information
Technology and Artificial Intelligence (pp. 102-114). Cham:
Springer Nature Switzerland.
[19] Jayaraman, S., Rajendran, S., & P, S. P. (2019). Fuzzy c-means
clustering and elliptic curve cryptography using privacy
preserving in cloud. International Journal of Business
Intelligence and Data Mining, 15(3), 273-287.
[20] Rekulapalli, K., Kagga, S. R., Ayyagari, V., Akula, A., & Raj Akula,
R. (2026). AI in HRM: Enhancing workforce competency and
organizational effectiveness. Proceedings of the International
Conference on Innovative Computing and Communication
(ICICC 2026).
[21] Yadavalli, V. R. (2025). Incident memory graphs for predictive
AMS triage and self-improving SAP operations. International
Journal of Science, Research and Technology, 8(2), 13913–13927.
[22] Ahuja, D. (2024). An overview of OpenShift architecture
and enterprise container platform management. Journal of
Science Engineering Technology and Management Science,
1(1), 224–232.
[23] Bandhela, R. R., & Kundavaram, R. R. (2023). A comparative
study on neural network architectures for image recognition
applications. Journal of Computational Analysis and
Applications (JoCAAA), 31(1), 1334-1342.
[24] Hashmi, H., & Srikanth, V. (2023, November). Combining Neural
Networks to Recognize Offline Digits & Words by Training the
Model Using Keras. In 2023 3rd International Conference on
Advancement in Electronics & Communication Engineering
(AECE) (pp. 694-697). IEEE.
[25] Kasarapu, B. C. (2026). Generative AI-Enabled Micro-Frontend
Framework for Scalable and Intelligent Enterprise Retail
Applications. International Journal of Computer Information
Systems and Industrial Management Applications, 18(5s),
297-309.
[26] Konatham, M. R., Uddandarao, D. P., Vadlamani, R. K., &
Konatham, S. K. R. (2025, July). Federated Learning for
Credit Risk Assessment in Distributed Financial Systems
using BayesShield with Homomorphic Encryption. In 2025
International Conference on Computing Technologies & Data
Communication (ICCTDC) (pp. 1-6). IEEE.
[27] Shaik, N. P. (2025). Automated TLS certificate lifecycle
management: A policy-driven framework for Kubernetes
security hardening. International Journal of Computer
Technology and Electronics Communication, 8(2), 10497–10502.
[28] Sudhan, S. K. H. H., & Kumar, S. S. (2016). Gallant Use of Cloud
by a Novel Framework of Encrypted Biometric Authentication
and Multi Level Data Protection. Indian Journal of Science and
Technology, 9, 44.
[29] Bitragunta, S. L. V. (2024). Intelligent electric vehicle charging
hubs AI-based demand forecasting and smart energy
management. International Journal of Emerging Trends in
Engineering and Management Research, 9(2), 15383–15393.
[30] Neela, S. (2025). Middleware-Driven Hybrid Integration: Bridging
the Gap in Modern Enterprise Architecture. International
Journal of Scientific Research in Computer Science, Engineering
and Information Technology, 11(1), 3527-3536.
[31] Bandari, U., & Perumal, R. S. (2025). Copilots for self-service BI:
A practitioner comparison of generative analytics assistants
across enterprisedata platforms. International Journal of
Engineering & Extended Technologies Research, 7(6), 11312–
11322.
[32] Madabathula, L. (2026, May). A Resilient Multi-Petabyte
Lakehouse Architecture for Regulated Enterprises: Design
Patterns and Failure Recovery. In 2026 2nd International
Conference on Sustainable Computing and Integrated
Communication in Changing Landscape of AI (ICSCAI) (pp.
731-735). IEEE.
[33] Selvarajan, K. (2024). Observability-driven reliability engineeringfor distributed data platforms. International Journal of
Computer Technology and Electronics Communication, 7(4),
9258–9268. https://doi.org/10.15680/IJCTECE.2024.0704019
[34] Polamarasetty, V. K. (2026). Enterprise HR technology
modernization through global Workday implementation and
legacy system consolidation. International Journal of Research
and Applied Innovations, 9(1), 13691–13696.
[35] Karrothu, A. (2025). Engineering scalable cloud-native
distributed systems for real-time security telemetry ingestion
and threat detection. Journal of Computational Analysis and
Applications (JoCAAA), 34(12), 1175–1188. https://eudoxuspress.
com/index.php/pub/article/view/5221
[36] Gajjela, H., & Kari, M. (2024). Secure Multi-Tenant AI Architecture
Enhances Enterprise AI Adoption Through Tenant Trust Using
PLS-SEM in India’s Salesforce Cloud Industry. International
Journal of Engineering Science & Humanities, 14(2), 253-271.
[37] Khare, A., & Goyal, A. K. (2026, May). Integrating Artificial
Intelligence and Big Data in Supply Chain Management for
Increased Efficiency and Sustainability. In Proceedings of Fifth
International Conference on Computing and Communication
Networks: ICCCN 2025, Volume 4 (Vol. 4, p. 447). Springer Nature.
[38] Srikanth, V., Walia, R., Augustine, P. J., Simla, J., & Jegajothi,
B. (2022, March). Chaotic Whale Optimization based Node
Localization Protocol for Wireless Sensor Networks Enabled
Indoor Communication. In 2022 International Conference on
Electronics and Renewable Systems (ICEARS) (pp. 702-707). IEEE.
[39] Sharifuzzaman Sagar, A. S. M., Haider, A., & Kim, H. S. (2025).
A hierarchical adaptive federated reinforcement learning for
efficient resource allocation and task scheduling in hierarchical
IoT network. Computer Communications, 229, 107969. https://
doi.org/10.1016/j.comcom.2024.107969


