02040nas a2200121 4500000000100000008004100001100001500042700001900057700001600076700002000092245011200112520169400224 2026 d1 aMert Nakip1 aRafał Gibała1 aAnna Grygar1 aSławomir Nowak00aTrend-based Multi-Modal Anomaly and Cyber Threat Detection with Traceable Explainability for Cloud Services3 a

Multi-modal real-time monitoring systems based on AI are
essential for ensuring system reliability and cyber-defense in cloud computing,
but are challenged by context isolation, early-fusion computational
overhead, and insufficient transparency. In order to address these
issues, this paper introduces T-MATE, an explainable Trend-based Multimodal
Anomaly and Threat detector engineered for robust, secure cloud
infrastructure monitoring. Rather than treating multi-modal streams
monolithically, T-MATE structurally decouples data modalities into independent
neural network heads, using a specialized Recurrent Trend
Predictive Neural Network (rTPNN) to isolate underlying trends and levels
across quantitative performance telemetry, while qualitatively parsing
textual event logs via Gemini 2.5 Flash. These components output
bounded anomaly scores and are integrated at the decision level
using an Empirical Reliability-Weighted Max Fusion operator, which
scales individual outputs to enforce a max-safety posture and eliminate
parameter-explosion liabilities. In order to demonstrate operational deployment
readiness, the framework is thoroughly evaluated via 10-fold
cross-validation and compared against standalone rTPNN, LSTM, and
MLP models alongside the baseline Avg-Fuse paradigm on the public
CloudAnoBench dataset. The results reveal that T-MATE achieves a superior
overall F1 Score of 0.88, a top threshold-invariant AUC-ROC of
0.96, an exceptional True Positive Rate of 0.96, and a processing footprint
that confirms its viability for close to real-time inference in enterprise
cloud infrastructures.