🤖 AI Summary
AI-era web security faces novel challenges, including automated attacks and large language model (LLM) misuse. This paper proposes a programmable defense framework leveraging CDN-based edge computing, integrating machine learning–driven anomaly detection, adaptive DDoS mitigation, anti-spoofing bot identification, and API forward modeling. It introduces the first threat taxonomy grounded in edge-observable signals, accompanied by lightweight evaluation metrics, dynamic deployment policies, and governance guidelines. The work further explores explainable AI (XAI) and multi-agent autonomous defense paradigms. Experimental results demonstrate that the framework reduces mean threat detection and response time by 62%, cuts centralized data backhaul overhead by up to 78%, and enhances compliance with GDPR and China’s Cybersecurity等级 Protection (MLPS) standards. Concurrently, it uncovers emerging risks—including edge AI model poisoning and cross-domain adversarial example transfer—highlighting critical vulnerabilities in edge-deployed AI systems.
📝 Abstract
The modern web stack, which is dominated by browser-based applications and API-first backends, now operates under an adversarial equilibrium where automated, AI-assisted attacks evolve continuously. Content Delivery Networks (CDNs) and edge computing place programmable defenses closest to users and bots, making them natural enforcement points for machine-learning (ML) driven inspection, throttling, and isolation. This survey synthesizes the landscape of AI-enhanced defenses deployed at the edge: (i) anomaly- and behavior-based Web Application Firewalls (WAFs) within broader Web Application and API Protection (WAAP), (ii) adaptive DDoS detection and mitigation, (iii) bot management that resists human-mimicry, and (iv) API discovery, positive security modeling, and encrypted-traffic anomaly analysis. We add a systematic survey method, a threat taxonomy mapped to edge-observable signals, evaluation metrics, deployment playbooks, and governance guidance. We conclude with a research agenda spanning XAI, adversarial robustness, and autonomous multi-agent defense. Our findings indicate that edge-centric AI measurably improves time-to-detect and time-to-mitigate while reducing data movement and enhancing compliance, yet introduces new risks around model abuse, poisoning, and governance.