An Adaptive Hybrid Intelligence System for API Abuse and Data Exposure Detection
DOI:
https://doi.org/10.47392/IRJAEH.2026.0422Keywords:
Anomaly detection, Cloud security, Data exposure, Hybrid intelligence, Isolation ForestAbstract
As application programming interfaces (APIs) have become the primary communication layer for digital services, they are increasingly targeted by sophisticated cyber attackers seeking direct access to sensitive data. Traditional security mechanisms, which rely on static rules and predefined signatures, often fail to detect evolving attack patterns and zero-day threats. This paper proposes an intelligent, lightweight middleware security layer designed to mitigate API abuse and prevent unauthorized data exposure in real-time. The proposed system addresses the critical limitations of conventional API security approaches — such as the inability to detect low-and-slow request patterns and Broken Object Level Authorization (BOLA) flaws — by implementing a hybrid architecture. This multi-staged pipeline transitions from deterministic filtering to behavioral analysis. It first employs a rule engine to block high-frequency attacks and validate authentication with minimal latency. For more advanced threats, an artificial intelligence (AI) engine utilizes the Isolation Forest algorithm to identify subtle anomalies in request patterns and endpoint access, even when valid credentials are used. Finally, the system inspects outgoing response payloads to detect and prevent mass data exposure caused by authorization flaws or backend misconfigurations. By integrating an adaptive feedback loop for continuous model refinement, demonstrates enhanced resistance to zero-day attacks compared to static systems. The final solution provides a scalable and industrially applicable framework for safeguarding cloud-based ecosystems. Experimental deployment using a Python-based stack comprising Fast API, Scikit-learn, MongoDB, and Redis confirms that combining fast rule-based filtering with AI-driven anomaly detection effectively protects modern applications from sophisticated API abuse and sensitive data leakage.
Downloads
Downloads
Published
Issue
Section
License
Copyright (c) 2026 International Research Journal on Advanced Engineering Hub (IRJAEH)

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
.