Skip to content

GIC-IDS: A Unified Graph Intrusion Detection Framework with Information Bottleneck and Contrastive Learning

Jul 2026 · Journal of Signal Processing Systems · Vol 98 · 0 citations · 33 references
Computer Science

TL;DR

GIC-IDS is proposed, a unified intrusion detection framework that integrates graph structure learning, information bottleneck, and contrastive learning that consistently outperforms representative baseline methods in terms of detection accuracy, robustness, and generalization capability.

View source

Similar papers

Open access 2026

TAE-MAGSAGE: Topology Aware Metric Learning for Graph Based Network Intrusion Detection

TAE-MAGSAGE, an edge-centric graph learning model which uses the observed communication structure to construct graphs and applies a line graph transformation to perform flow-level classification without collapsing the interaction relationships, is introduced.

Poonam Nehru, Yunpeng Zhang, Renjie Hu et al. · 0 citations
Conference 2026

HETCLNN: A Lightweight Intrusion Detection Network with Class-Aware Self-Knowledge Distillation

With the proliferation of edge computing, building efficient NIDS faces challenges related to limited computational resources and class imbalance. To address the issues of high overhead and poor detection of rare attacks in existing models, this paper proposes a lightweight intrusion detection model based on Class-Aware Self-Knowledge Distillation (CASKD). Architecturally, we design a lightweight network utilizing Heterogeneous Convolution (HetConv)-based residual and inverted residual structures. For training, a temperature-based CASKD method is introduced to tackle extreme class imbalance. Experimental results on CIC-IDS2017 and Bot-IoT datasets demonstrate classification accuracies exceeding 99\%. The proposed method significantly reduces computational overhead while improving detection precision for rare attacks, achieving an optimal balance between model compactness and performance.

Chenghao Liu · 0 citations
Open access Aug 2026

MaGOS-IDS: A Mahalanobis-Enhanced OpenMax Method for Graph Neural Network-Based Intrusion Detection

Graph Neural Networks achieve strong closed-set accuracy in network intrusion detection but cannot flag zero-day attacks, because the closed-world assumption forces every input into a known class. OpenMax adds an Extreme Value Theory reject option, yet its Euclidean distance ignores the class-conditional covariance that encodes attack-specific structure, which produces unreliable tail models and rejection thresholds. We propose MaGOS-IDS, which extracts topology-aware embeddings with an edge-aware GCN that fuses flow-level edge features directly into message passing, whitens each class with a regularized Mahalanobis distance so the reject decision respects per-class variance and correlation, and calibrates a per-class EVT tail on these distances to set an attack-pattern-aware rejection boundary without a hand-tuned cutoff. We provide a theoretical justification via a peaks-over-threshold argument: whitening removes the per-class covariance dependence of the distance tail, so a single extreme-value tail model calibrates consistently across classes. On three benchmarks (NF-BoT-IoT, CIC-IDS-2017, UNSW-NB15) under withheld zero-day families, MaGOS-IDS raises open-set AU-PR over the Euclidean OpenMax baseline (0.932 vs. 0.848 on UNSW-NB15) while adding negligible inference cost.

Thanh T. Nguyen, Minho Park · 0 citations
Conference Aug 2026

Are Temporal Graph Based Intrusion Detection Results Trustworthy? A Dataset Audit and Evaluation Framework

Temporal Graph Neural Networks (TGNNs) have been increasingly applied to network intrusion detection (NID), with some studies reporting accuracy exceeding 99%. This paper argues that such performance can be an artifact of dataset construction flaws rather than genuine model capability. We conduct an empirical audit of two NID datasets and identify three categories of dataset flaws when tabular NID datasets are converted to temporal graphs: node identity leakage, temporal concentration of attack traffic, and class imbalance interacting with graph structure. We further propose an evaluation framework comprising a node identity leakage detection protocol and an attack-aware chronological split strategy. We demonstrate the node identity leakage detection protocol empirically through a controlled experiment across two TGNN architectures - T-GCN (RNN-based) and A3T-GCN2 (attention-based). We also compare the attack flow rate change between a standard dataset split method and our split strategy. Together, this proposed evaluation framework provides a more reliable and rigorous basis for future TGNN-NID research.

Yin-Ning Zhang, Sait Suer, S. M. T. F. A. Chowdhoury et al. · 0 citations
Open access Jul 2026

A domain-agnostic explainable framework for network attack detection across diverse traffic datasets

An explainable deep learning framework evaluated across multiple heterogeneous cyber attack datasets, including Kitsune, Server-Based network data,enterprise logs, and Malware Traffic datasets, demonstrating the effectiveness of the proposed framework in handling heterogeneous network traffic while providing interpretable insights into model predictions.

Abed Alanazi · 0 citations
Open access Jul 2026

A Stacking Ensemble Framework with Mutual Information Feature Selection and SHAP for Explainable Network Intrusion Detection

An explainable network intrusion detection framework that integrates Mutual Information-based feature selection, a stacking ensemble classifier, and SHapley Additive exPlanations (SHAP) that provides both global and local interpretations of model decisions is proposed.

Anjali Singh · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.