MGAN: A Multi-view Graph Adaptive Network for Robust Malicious Traffic Detection
Ernest Akpaku, Jinfu Chen, Mukhtar Ahmed, Francis Kwadzo Agbenyegah, Joshua Ofoeda · ACM Transactions on Privacy and Security · 2025
Detecting malicious network traffic in large-scale, dynamic environments presents a significant challenge due to the complexity of network relationships and the evolving nature of cyber threats. Existing graph-based and sequence-based models often fail to capture both spatial dependencies and temporal patterns effectively, resulting in suboptimal detection. This study introduces the Multi-view Graph Adaptive Network (MGAN), a novel framework that integrates multi-hop graph neural network (GNN) aggregation with transformer-based sequence modeling to address these challenges. MGAN captures long-range spatial dependencies and temporal dynamics in network traffic, enabling the detection of complex attack patterns. It incorporates Dirichlet sampling for robust neighbor selection in sparse and noisy data environments and mutual information maximization to align multi-view representations for consistency. Additionally, a multi-view attention mechanism aggregates information across different hops, balancing local and global network context. Extensive experiments on four real-world datasets demonstrate MGAN’s superiority over 7 baseline models, achieving an average F1-Score above 97%, surpassing the best baseline by 2.35%. MGAN maintains detection accuracy above 97% and remains robust under data sparsity, achieving F1-Scores over 95% even when 40% of connectivity information is removed. Under noisy conditions, MGAN retains accuracy above 93%, outperforming baselines by over 4.5%. In zero-day attack scenarios, it achieves detection rates exceeding 96% for previously unseen attack categories. MGAN also exhibits exceptional computational efficiency, processing 2,034 samples per second with a detection time of 3.00 milliseconds per sample, outperforming all competing models in both accuracy and speed.