kth.sePublications KTH
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Deep Learning-based Cryptojacking Detection in Cloud Containerized Environments
KTH, School of Electrical Engineering and Computer Science (EECS), Computing and Learning Systems.ORCID iD: 0000-0003-4732-9543
KTH, School of Electrical Engineering and Computer Science (EECS).
KTH, School of Electrical Engineering and Computer Science (EECS), Computing and Learning Systems. KTH Royal Inst Technol, Networked Syst Secur NSS Grp, Stockholm, Sweden.ORCID iD: 0000-0002-3267-5374
2025 (English)In: 2025 IEEE Middle East Conference On Communications And Networking, Mecom, IEEE , 2025Conference paper, Published paper (Refereed)
Abstract [en]

Cryptojacking attacks in cloud Docker environments exploit computational resources for unauthorized cryptocurrency mining, degrading performance and increasing operational costs. Existing detection methods suffer from performance overhead, the inability to detect obfuscated activities, or the detection of runtime attacks. We present a lightweight Deep Learning (DL) framework analyzing resource utilization patterns for cryptojacking detection in controlled experimental environments. Our methodology employs temporal feature extraction from cloud Virtual Machine (VM) metrics (i.e., CPU, memory, disk I/O, and network utilization) and evaluates four popular DL architectures against direct mining and obfuscated scenarios. Systematic evaluation across Bitcoin, Ethereum, Shiba Inu, and Monero demonstrates that four architectures achieve 1.0 accuracy in our experimental setup. The optimal CNN architecture utilizes 4,548 parameters, maintains > 0.97 precision in obfuscated scenarios, and achieves < 0.001% false positive rates. The framework enables efficient cryptojacking detection in containerized environments with minimal computational overhead while maintaining robust security capabilities under controlled evaluation conditions.

Place, publisher, year, edition, pages
IEEE , 2025.
Keywords [en]
Cryptojacking, Deep Learning, Cloud Security, Docker Containers, Cryptocurrency Mining, Cloud Computing
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:kth:diva-386882DOI: 10.1109/MECOM67453.2015.11439580ISI: 001776444700036ISBN: 979-8-3315-8588-4 (print)ISBN: 979-8-3315-8587-7 (print)OAI: oai:DiVA.org:kth-386882DiVA, id: diva2:2090971
Conference
2025 Middle East Conference on Communications and Networking-MECOM, NOV 04-06, 2025, Cairo, EGYPT
Note

QC 20260810

Available from: 2026-08-10 Created: 2026-08-10 Last updated: 2026-08-10Bibliographically approved

Open Access in DiVA

No full text in DiVA

Other links

Publisher's full text

Authority records

Hussain, AhmedFlores, JavierPapadimitratos, Panos

Search in DiVA

By author/editor
Hussain, AhmedFlores, JavierPapadimitratos, Panos
By organisation
Computing and Learning SystemsSchool of Electrical Engineering and Computer Science (EECS)
Computer Sciences

Search outside of DiVA

GoogleGoogle Scholar

doi
isbn
urn-nbn

Altmetric score

doi
isbn
urn-nbn
Total: 9 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf