Advancing Network Security Through Deep Learning: A Hybrid Graph-Based and Temporal Approach to Anomaly and Threat Detection

Abhirup Arindam · International Journal for Research in Applied Science and Engineering Technology · 2025

The rapid evolution of cyber threats demands ad- vanced intrusion detection systems capable of identifying sophisticated attacks that exploit both network topology and temporal patterns. This paper proposes a novel hybrid deep learning framework that synergistically combines graph neural networks (GNNs) for structural analysis and transformer models for temporal sequence processing, augmented with XGBoost for robust classification. Our approach introduces three key innovations: (1) a graph attention network that models host communications and protocol dependencies, (2) a temporal transformer encoder that captures behavioral patterns across time windows, and (3) an uncertainty-based anomaly detection mechanism for identi- fying zero-day threats. Evaluated on the CIC-IDS2023 dataset the most recent benchmark containing contemporary attack vectors like IoT-based DDoS and cloud exploitation patterns- our framework achieves 78.28% accuracy, outperforming con- ventional CNN-LSTM baselines by 2.16%, while maintaining an F1-score of 0.7704. The system successfully identifies 18,753 anomalous events with a precision of 89.7% using an optimized detection threshold of 0.3383. Feature importance analysis reveals that protocol types (21.41%) and TCP flag patterns (30.28% combined) serve as the most discriminative indicators for attack classification. Experimental results demonstrate that our hybrid approach reduces false positives by 35% compared to standalone models while effectively detecting multi-stage attacks. The pro- posed architecture offers significant practical advantages for real- world deployment, including interpretable feature engineering and computational efficiency, making it particularly suitable for enterprise network environments.

Read the paper · More papers on PaperTik