Exploring Graph Neural Networks for Robust Network Intrusion Detection

Sarika Saxena, Jyoti Grover, Sunita Singhal · Procedia Computer Science · 2025

The importance of network security has increased due to the rise in cyberattacks. NDSs, or network intrusion detection systems, are essential for keeping an eye on network activity and spotting possible threats. AI-based solutions are still not commonly used in corporate network environments, despite a lot of research being done on the use of Deep Learning (DL) and Machine Learning (ML) for intrusion detection. In this work, the application of graph neural networks (GNNs) to network intrusion detection is investigated. Network traffic may be represented as a graph with devices as nodes and connections as edges. This makes GNNs an excellent tool for improving network security because they are well-suited for evaluating graph-structured data. The analysis of individual samples by conventional machine learning-based intrusion detection systems (IDSs) might result in the omission of network dependencies, erroneous predictions, and an increase in false alarms. We suggest an Intrusion Detection System (GNN-IDS) based on GNNs to address these issues. This system combines real-time data monitoring with an attack graph to capture both static and dynamic network features. The GNN acts as the core component, analyzing the importance of nearby nodes and their features to make accurate predictions. By incorporating an attack graph, GNN-IDS not only detects anomalies but also identifies the specific malicious activities causing them. Our experimental results using the CIC-IOT-2023 dataset show that GNN-IDS is highly effective, capable of handling uncertainty, providing clear explanations, and demonstrating robustness, highlighting its potential to improve network security significantly.

Read the paper · More papers on PaperTik