Thursday, September 24, 2026
Science
No Result
View All Result
  • Login
  • HOME
  • SCIENCE NEWS
  • CONTACT US
  • HOME
  • SCIENCE NEWS
  • CONTACT US
No Result
View All Result
Scienmag
No Result
View All Result
Home Science News Technology and Engineering

Entropy and AI join forces to catch costly serverless wallet attacks

September 24, 2026
in Technology and Engineering
Blake Davidson
By Blake Davidson Scienmag Editorial Profile - Data Science
Reading Time: 5 mins read
0
Entropy and AI join forces to catch costly serverless wallet attacks

Entropy and AI join forces to catch costly serverless wallet attacks

Entropy and AI join forces to catch costly serverless wallet attacks

65
SHARES
587
VIEWS
Share on FacebookShare on Twitter
ADVERTISEMENT

Serverless computing has become one of the most popular ways to build modern applications. Instead of renting servers around the clock, developers upload individual functions that a cloud provider instantiates only when an event triggers them, and bills only for the milliseconds of execution consumed. This Function-as-a-Service model eliminates infrastructure management and promises near-infinite scalability, but it also creates an entirely new kind of vulnerability. Researchers at the University of Alicante in Spain have now unveiled a hybrid detection model designed to catch a threat that traditional network defenses are poorly equipped to see: the Denial of Wallet attack, in which adversaries do not try to crash a service but simply to bankrupt its owner.

The study, published open access in the journal Cybersecurity by José Manuel Ortega Candel, Francisco José Mora Gimeno and Higinio Mora Mora, makes a sharp distinction between two attack classes that are often conflated. Distributed Denial of Service attacks aim to exhaust computational resources and render a system unavailable to legitimate users. Denial of Wallet attacks, by contrast, exploit the pay-per-use billing model itself. An attacker floods a serverless application with invocation requests, forcing the platform to auto-scale and execute thousands of billable function instances. The service may remain perfectly accessible throughout the assault; the damage appears instead on the monthly invoice, in the form of invocation charges and compute time measured in gigabyte-seconds. The authors argue that treating this as an availability problem, as conventional DDoS detection does, misses the point: the harm is economic, and every undetected attack invocation carries a direct, quantifiable monetary cost.

Because the monetary loss is only the visible consequence of a technical exploitation, the team’s primary objective is not to measure financial damage after the fact but to intercept the abnormal invocation behavior that triggers it. Their threat model assumes an attacker with black-box knowledge of publicly accessible HTTP trigger endpoints, no access to internal monitoring or billing systems, and full control over invocation rates and payloads. Crucially, the detection system operates only on execution metadata that platforms such as AWS CloudWatch and Azure Monitor already expose in real time: function name, trigger type, invocation timestamp and execution duration. No request content inspection or deep packet analysis is required, which keeps the approach lightweight and privacy-preserving.

The heart of the proposed architecture is a two-stage pipeline. The first stage computes Shannon entropy, a classical information-theoretic measure of randomness, over serverless execution features within sliding time windows. Rather than measuring entropy over network-layer features like IP addresses or ports, as DDoS detectors do, the model calculates it over the distribution of function invocation types, meaning pairs of function names and trigger categories, together with execution-duration buckets. This choice is deliberate: each invocation type carries a distinct cost profile, and an attacker seeking to maximize billing will inevitably alter this distribution, either by flooding a single expensive function or by spreading calls across many functions to exploit auto-scaling. A deviation in the entropy of this distribution therefore directly signals a change in billing-relevant behavior, even when the underlying traffic looks entirely legitimate at the network layer.

The entropy stage acts as a rapid triage filter with three tiers. Traffic whose entropy falls below a lower threshold is classified as clearly benign and never reaches the computationally expensive AI models. Values above an upper threshold are flagged immediately as suspicious with near-zero false negatives. Ambiguous transactions in the intermediate range are forwarded to the second stage, where supervised machine learning and deep learning classifiers perform precise analysis. Because a missed attack costs money while a false alarm does not, the threshold calibration is explicitly optimized to minimize the false negative rate, an inversion of the availability-focused logic of conventional DDoS systems. Dynamic thresholds computed from the mean and standard deviation of a rolling baseline of the five most recent windows allow the system to track gradual workload shifts such as daily traffic cycles without mislabeling them as attacks. A sensitivity factor of 2.5 was selected empirically, covering roughly 98.76 percent of normal traffic under a Gaussian assumption, and a persistence counter requires anomalies to survive across multiple consecutive windows before a formal alert is raised.

To train and evaluate the second-stage classifiers, the researchers had to overcome a fundamental obstacle: no publicly available labeled datasets for serverless Denial of Wallet attacks existed. They built one by combining a purpose-built DoW traffic simulator with fourteen days of real telemetry from the Microsoft Azure Functions dataset, incorporating call time series, execution durations and memory usage, and then augmenting the result with synthetic transactions generated by Generative Adversarial Networks. The final dataset contains 187,087 transactions. All experiments used Python on Google Colab with GPU and TPU acceleration, and the code and models have been released for independent verification.

The evaluation reveals a nuanced picture of when the hybrid architecture pays off. Under the optimal first-stage configuration, a 480-minute window with a low threshold, the entropy filter captured 83.08 percent of transactions as suspicious with a false negative rate of just 0.44 percent. Among the second-stage models, the bidirectional long short-term memory network, or BiLSTM, emerged as the recommended classifier, achieving a precision of 0.9810 and test accuracy of 0.9890, thanks to its ability to model invocation sequences in both forward and backward directions and capture temporal dependencies that static classifiers miss. For resource-constrained deployments, the simpler GRU architecture offers a more efficient alternative.

The most striking results concern computational efficiency under realistic attack densities. Because the original dataset contained an unrealistically high proportion of malicious traffic, roughly 70 percent, the entropy stage could filter out at most the legitimate minority. So the researchers expanded the dataset to 200,000 transactions and progressively reduced the attack density from 60 percent down to 1 percent, mirroring production conditions where attacks are rare. As the attack ratio fell, the efficiency gain of the entropy pre-filter soared. At a 1 percent attack transaction rate, the LSTM network achieved a processing gain of 91.95 percent, BiLSTM reached 91.11 percent, and the K-Neighbors classifier led traditional machine learning methods at 80.05 percent, all while maintaining F1-scores above 0.97 and ROC-AUC above 0.98 for the deep learning models. In other words, the hybrid design delivers its greatest savings precisely in the low-attack-density conditions that real serverless deployments actually experience, cutting the compute burden of security monitoring by more than nine tenths without degrading detection quality.

The authors are candid about the limits of their work. The evaluation was conducted offline on batch data, and the synthetic dataset, however carefully constructed, cannot fully replicate cold-start latency distributions, provider-specific concurrency throttling, billing rounding granularities and the workload heterogeneity of live production environments. They also note that under their specific test configuration, where attack traffic dominated, the two-stage pipeline actually imposed more total overhead than running the AI classifier alone; the entropy stage functioned primarily as an early-warning triage rather than a bulk traffic reducer in that regime. Future work will focus on large-scale deployment on OpenFaaS, an open-source platform that avoids commercial billing costs during attack experiments, and integration with cloud cost management APIs such as AWS Cost Explorer and Azure Cost Management, enabling alerts the moment projected spending exceeds user-defined thresholds.

For an industry betting its economics on serverless computing, the study arrives at an opportune moment. Major cloud providers handle ever-growing transaction volumes, and the same auto-scaling that makes functions resilient to downtime makes them exquisitely vulnerable to financial exhaustion. By re-deriving a decades-old information-theoretic concept for the peculiar anatomy of function invocations, and pairing it with deep learning classifiers that remember how workloads unfold over time, the Alicante team has produced the first hybrid methodology built specifically around the economics of Denial of Wallet attacks rather than adapted from DDoS playbooks. The message for cloud architects is clear: in the serverless era, the firewall that matters most may be the one guarding your budget.

Subject of Research: Hybrid entropy and AI-based detection of Denial of Wallet attacks in serverless computing

Article Title: Hybrid model for detecting Denial of Wallet attacks in serverless architectures

Article References: Candel, J. M. O., Gimeno, F. J. M., & Mora Mora, H. (2026). Hybrid model for detecting Denial of Wallet attacks in serverless architectures. Cybersecurity, 9(1), Article 221. https://doi.org/10.1186/s42400-026-00663-7

Image Credits: AI Generated

DOI: 10.1186/s42400-026-00663-7

Keywords: serverless computing, Denial of Wallet, cybersecurity, Shannon entropy, deep learning, BiLSTM, FaaS, cloud billing, anomaly detection, machine learning, Azure Functions, GAN data augmentation

Cite Scienmag News

Blake Davidson. (September 24, 2026). Entropy and AI join forces to catch costly serverless wallet attacks. Scienmag. https://scienmag.com/entropy-and-ai-join-forces-to-catch-costly-serverless-wallet-attacks/

Blake Davidson. "Entropy and AI join forces to catch costly serverless wallet attacks." Scienmag, 24 September 2026, https://scienmag.com/entropy-and-ai-join-forces-to-catch-costly-serverless-wallet-attacks/. Accessed 24 September 2026.

Blake Davidson. "Entropy and AI join forces to catch costly serverless wallet attacks." Scienmag. September 24, 2026. https://scienmag.com/entropy-and-ai-join-forces-to-catch-costly-serverless-wallet-attacks/

Tags: AI-based cybersecurityanomaly detectionAzure FunctionsBiLSTMcloud billingcloud billing exploitationcloud function abusecybersecuritydeep learningDenial of WalletDenial of Wallet attacksentropy analysis in cybersecurityFaaSGAN data augmentationhybrid detection modelsinnovative cybersecurity researchMachine learningpreventing costly serverless attacksscalable attack detectionserverless application securityserverless computingServerless computing vulnerabilitiesserverless scalability risksShannon entropy
Share26Tweet16
Previous Post

Prostate Cancer Study on SULF2 Retracted Over Overlapping Blot Images

Next Post

Science Has a Blind Spot: Nondualism Emerges as a New Research Paradigm for Mindfulness Studies

Related Posts

Noisy Gates Put Gate Teleportation to the Test
Technology and Engineering

Noisy Gates Put Gate Teleportation to the Test

September 24, 2026
Slanted Groove Welding Tames Distortion in Thick Steel Plates
Technology and Engineering

Slanted Groove Welding Tames Distortion in Thick Steel Plates

September 24, 2026
When Democracy Says No: The Strange Paradox of AI Built on the Public’s Values
Technology and Engineering

When Democracy Says No: The Strange Paradox of AI Built on the Public’s Values

September 24, 2026
Mamba-Based AI Sharpens Medical Image Segmentation With Position Awareness and Dynamic Upsampling
Technology and Engineering

Mamba-Based AI Sharpens Medical Image Segmentation With Position Awareness and Dynamic Upsampling

September 24, 2026
Drones on 5G Now Spot Cracked Building Tiles in Real Time
Technology and Engineering

Drones on 5G Now Spot Cracked Building Tiles in Real Time

September 24, 2026
Rhenium-Palladium Nanoalloy Clusters Reveal Magic Stability and Solar Promise in New Quantum Study
Technology and Engineering

Rhenium-Palladium Nanoalloy Clusters Reveal Magic Stability and Solar Promise in New Quantum Study

September 24, 2026
Next Post
Science Has a Blind Spot: Nondualism Emerges as a New Research Paradigm for Mindfulness Studies

Science Has a Blind Spot: Nondualism Emerges as a New Research Paradigm for Mindfulness Studies

  • Mothers who receive childcare support from maternal grandparents show more optimized

    Mothers who receive childcare support from maternal grandparents show more parental warmth, finds NTU Singapore study

    27656 shares
    Share 11059 Tweet 6912
  • University of Seville Breaks 120-Year-Old Mystery, Revises a Key Einstein Concept

    1061 shares
    Share 424 Tweet 265
  • Bee body mass, pathogens and local climate influence heat tolerance

    682 shares
    Share 273 Tweet 171
  • Researchers record first-ever images and data of a shark experiencing a boat strike

    546 shares
    Share 218 Tweet 137
  • Groundbreaking Clinical Trial Reveals Lubiprostone Enhances Kidney Function

    531 shares
    Share 212 Tweet 133
Science

Embark on a thrilling journey of discovery with Scienmag.com—your ultimate source for cutting-edge breakthroughs. Immerse yourself in a world where curiosity knows no limits and tomorrow’s possibilities become today’s reality!

RECENT NEWS

  • Science Has a Blind Spot: Nondualism Emerges as a New Research Paradigm for Mindfulness Studies
  • Entropy and AI join forces to catch costly serverless wallet attacks
  • Prostate Cancer Study on SULF2 Retracted Over Overlapping Blot Images
  • Budget Mass Spectrometers Can Match the Big Machines in Plasma Proteomics, Study Finds

Categories

  • Agriculture
  • Anthropology
  • Archaeology
  • Athmospheric
  • Biology
  • Biotechnology
  • Blog
  • Bussines
  • Cancer
  • Chemistry
  • Climate
  • Earth Science
  • Editorial Policy
  • Marine
  • Mathematics
  • Medicine
  • Pediatry
  • Policy
  • Psychology & Psychiatry
  • Science Education
  • Social Science
  • Space
  • Technology and Engineering

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 5,151 other subscribers

© 2025 Scienmag - Science Magazine

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • HOME
  • SCIENCE NEWS
  • CONTACT US

© 2025 Scienmag - Science Magazine

Discover more from Science

Subscribe now to keep reading and get access to the full archive.

Continue reading