Skip to content
Open access

DMGCRL: Dynamic Multi-Scale Graph Contrastive Representation Learning for Network Intrusion Detection

2026 · IEEE Transactions on Network and Service Management · Vol 23, pp. 7450-7467 · 0 citations · 74 references

TL;DR

Dynamic Multiscale Graph Contrastive Representation Learning (DMGCRL), a self-supervised framework that hierarchically models network intrusions at different levels, is proposed, which consistently outperforms SOTA methods in network intrusion detection.

Abstract

Graph neural networks (GNNs) have recently attracted significant attention in network intrusion detection systems (NIDS) due to their ability to model network traffic as graphs and capture complex relationships within network flows. However, existing GNN-based methods face critical limitations: they rely on limited or noisy labeled data and struggle to detect threats at various scales, ranging from local anomalies (e.g., port scanning) to coordinated subnetwork attacks (e.g., botnets) and global network-wide campaigns (e.g., DDoS attacks). To bridge this gap, we propose Dynamic Multiscale Graph Contrastive Representation Learning (DMGCRL), a self-supervised framework that hierarchically models network intrusions at different levels. At the node level, DMGCRL constructs structure-aware subnetworks around individual traffic flows to capture fine-grained behavioral deviations. For subnetwork-level threats, it employs substructure-aware pooling to identify coordinated anomalies among clustered malicious nodes. Finally, at the global level, DMGCRL derives representations that reflect the holistic state of the network, enabling detection of large-scale threats, such as distributed malware propagation. DMGCRL designs a shared GNN encoder with a multi-level contrastive loss to align multiscale representations while largely eliminating label dependence. It learns discriminative features from unlabeled traffic, refines decision boundaries without supervision, and reveals anomalies by contrasting related and unrelated nodes across scales. Performance evaluation was conducted on five publicly available network traffic datasets for binary and multiclass detection. Results show that DMGCRL consistently outperforms SOTA methods, achieving an F1 score of 99.86% on NF-CSE-CIC-IDS2018-V2 and 96.11% on NF-UNSW-NB15-V2 under binary detection and the lowest mean false positive rates, 1.28% and 2.33% under multiclass detection on the two datasets.

Read PDF

Similar papers

#graph neural networks Open access Sep 2026

Online intrusion detection in computer networks using edge-aware attentive graph neural network

Graph Neural Network (GNN)-based intrusion detection systems (IDS) have emerged as powerful tools for modeling the structural patterns of network traffic. However, most existing methods rely on large, temporally aggregated graphs and random train-test splits, which risk information leakage from future traffic and overs...

Áron Kiss, K. Nehéz, O. Hornyák · 0 citations
Open access Sep 2026

Graph-guided contrastive transformer architecture for robust and explainable network intrusion detection

Intrusion detection systems (IDS) are very instrumental in protecting contemporary network infrastructures against the ever-advancing cyberattacks. Conventional signature-based and machine learning-enabled IDS solutions frequently have difficulty when it comes to high false-positive rates, inability to flexibly adapt t...

Archana Jayapal, Kamalakkannan Somasundaram, Arun Kumar Ramamoorthy · 0 citations
#machine learning Preprint Sep 2026

FoundAna: A GNN-assisted Foundation Model for Graph Anomaly Detection

FindAna is introduced, a GNN-assisted Foundation Model for Graph Anomaly Detection - the first foundation model framework designated for generalizable, cross-graph anomaly detection by combining GNNs and transformers.

Suprim Nakarmi, Chahana Dahal, Yue Zhao et al. · 0 citations
Open access Aug 2026

An Explainable and Interpretable GNN Based on Temporal Time Series: An IDS Approach

This work develops and compares traditional classifiers against a GNN-based IDS on the UNSW-NB15 dataset, for both binary and multiclass classification and reveals attack-specific structural patterns, confirming that temporally structured GNNs improve detection while providing interpretable predictions.

Alberto Caballero Ferrero, Shadi Motaali, Xavier Larriva-Novo et al. · 0 citations
Open access 2026

Sparse Structural Knowledge Enhanced Graph Neural Networks for Anomaly Detection in Social Networks

: Social network platforms have become primary channels for information dissemination, yet they are increasingly exploited by anomalous users such as bots, fake accounts, and coordinated disinformation spreaders. These malicious actors manipulate public opinion, spread misinformation and undermine platform integrity, p...

Zehan Li, Yingyi Li, Zhi-Wei Tang et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.