GraphINR-IDS: Graph-Topology-Aware implicit neural reconstruction for zero-day intrusion detection in encrypted network traffic
Abstract
Payload encryption has shifted network intrusion detection towards flow-metadata analysis, yet most metadata-based detectors represent traffic through fixed feature windows, token sequences or periodic graph snapshots, discretising traffic before learning and binding the detector to a granularity selected in advance. GraphINR-IDS instead models benign flow behaviour as a continuous reconstruction function over source–destination topology, capture time and observable metadata. Spectral coordinates of the graph Laplacian encode communication position, multi-frequency sinusoids encode capture time, and a SIREN network reconstructs each flow from its own coordinate, with anomaly decisions following from standardised feature-wise residuals. Fitting, standardisation and calibration use benign flows exclusively, so the attack families met at test time are absent from fitting by construction. Twelve one-class detectors were compared on UNSW-NB15 and CIC-IDS2017 under one random and two chronological protocols. GraphINR-IDS reached 99.06 ± 0.12 % F1 at a 5.13 % false-positive rate, with the strongest threshold-free ranking of the twelve (AUROC 99.66 %, AUPRC 99.88 %). A fixed-capacity LSTM comparator lost roughly 55 to 67 percentage points of F1 as its window grew from 8 to 64 flows, whereas the continuous formulation requires no equivalent selection. Separate ablations attributed 1.15 percentage points of F1 to the spectral coordinate and 0.31 to hierarchical frequency decomposition, with no measurable contribution from graph-conditioned modulation on the static graphs evaluated. Chronological transfer raised realised false-positive rates for every detector, and re-estimating feature-wise residual statistics alongside the threshold recovered substantially more performance than threshold-only recalibration. The evidence supports continuous graph-temporal reconstruction as a competitive benign-only formulation and identifies calibration drift as a principal limitation under the evaluated protocols. Direct validation on operational encrypted traffic and evolving topologies remains necessary.