Hierarchical Graph Neural Networks for Resilient Intrusion Detection in Consumer IoT With Limited Labeled Data

Guolong Zheng, Changgui Xu, Jianshan Zhang, Chen Hou, Xu Yang, Tao Huang, Xuan Liu, Muhammad Khurram Khan · IEEE Transactions on Consumer Electronics · 2025

The growing number of interconnected systems in consumer IoT environments and the increasing intelligence of AI-enabled cyber threats have introduced significant security challenges. Intrusion detection systems must be not only accurate but also resilient to evolving threats and robust against adversarial manipulation. A major limitation is the lack of labeled data for evolving adversarial attacks, which limits the generalization of detection models, making them less practical for the dynamic and heterogeneous nature of IoT networks. To overcome these limitations, we propose, a hierarchical graph neural network designed for accurate and resilient network intrusion detection using few labeled examples. utilizes a packet-level graph attention network for adaptive feature filtering, which enhances resilience to subtle data perturbations, coupled with a flow-level temporal model to capture complex spatial and temporal dependencies in traffic patterns. By hierarchically abstracting these features, it learns robust representations of normal and malicious network behavior from limited data. Experimental results on multiple widely used network intrusion datasets demonstrate the ’s remarkable data efficiency and resilience. With as little as 5% of labeled training data, achieves an F1-score of 0.97 and an accuracy of 0.98 across all the benchmarks. Even in extreme data scarcity, using just 0.1% of labeled data, it maintains a high F1-score of 0.94+ and an accuracy of 0.96+. Furthermore, we demonstrate the model’s resilience by evaluating it against common adversarial evasion attacks, such as the Fast Gradient Sign Method (FGSM) and Projected Gradient Descent (PGD). Under these attacks, ś accuracy only degrades minimally to 0.95, outperforming standard deep learning baselines whose performance drops below 90% under similar conditions. These results validate as a scalable, resilient, and practical method for efficient network intrusion detection with high accuracy and low false positives, even in data-scarce and adversarial IoT environments.

Read the paper · More papers on PaperTik