LAGER: Layer-wise Graph Feature Extractor for Network Intrusion Detection
Ke He, Dong Seong Kim, Muhammad Rizwan Asghar · 2025
Network Intrusion Detection Systems (NIDS) are crucial for safeguarding networks against evolving cyber threats. However, evaluations of NIDS often assume offline training, supervised learning, or static concepts, which do not accurately capture the complexities of real-world scenarios. In this paper, we critically assess the performance of current NIDS and outlier detectors under a realistic threat model that uses online training, unsupervised learning, and is concept drift-prone. We find that conventional feature extractors struggle in diverse real-life environments. To overcome this, we propose LAGER, a novel feature extractor utilizing graph neural networks to extract representative features from a layer-wise graph representation of the network. Our results demonstrate that LAGER enhances the detection accuracy and adaptability to concept drifts for a wide range of NIDS and lays a solid foundation for robust network feature extraction.