Advanced GraphQL Security with AI-Driven Threat Detection
Speaker: Hiranya Kavishani, Technical Lead at WSO2
This talk by Hiranya Kavishani, Technical Lead at WSO, explores how AI and machine learning can be applied to secure GraphQL APIs from advanced threats that traditional security mechanisms often miss. While GraphQL enables precise data access and developer efficiency, it also opens the door to complex attack vectors like deeply nested queries, alias overloading, query injections, and denial-of-service attacks. Many of these threats slip past REST-era protections or static validations.
The presentation covers how intelligent models—trained on query behaviour patterns and schema structures—can detect anomalies, identify zero-day attacks, and adapt to evolving threat landscapes in real time. We’ll discuss approaches such as graph-based anomaly detection, few-shot payload classifiers, and explainable AI (XAI) to make detection more accurate, lightweight, and transparent.
Key Takeaways:
• A clear understanding of the unique security challenges in GraphQL
• Practical methods to integrate AI-driven threat detection at the query layer
• Strategies to improve detection accuracy while maintaining developer agility and system performance
• As APIs grow more dynamic and data-rich, security must evolve too. This talk shows how AI can play a crucial role in defending GraphQL APIs without slowing innovation.
Conference Details:
Conference: apidays Australia 2025
Theme: Platforms, Products, and People: The Power of APIs in the Age of AI
Date: 29 - 30 October 2025 • MCEC, Melbourne Australia
--------------------------
Resources from apidays:
Join our upcoming conferences: https://www.apidays.global/
Read the latest API news: https://www.apiscene.io
Explore the API Landscape: https://apilandscape.apiscene.io/