A Hybrid Graph Neural Network Framework for Cyberattack Detection Based on Network Traffic Graphs
Keywords:
Graph Neural Networks, Cyberattack Detection, Graph Convolutional Network, Intrusion Detection System, Network Traffic Analysis.Abstract
The increasing complexity of modern communication networks and the growing diversity of cyberattacks have exposed the limitations of traditional intrusion detection systems that treat network traffic records as independent instances. Although graph neural networks (GNNs) have shown promising performance in cybersecurity applications, most existing approaches rely on a single graph learning architecture and fixed graph construction strategies. To address these limitations, this paper proposes HGCF-Net, a Hybrid Graph Neural Network framework that integrates Graph Convolutional Networks (GCNs) and Graph Attention Networks (GATs) through an adaptive feature fusion mechanism for cyberattack detection. The proposed framework transforms network traffic flows into graph-structured representations to capture both global communication patterns and local neighborhood dependencies. Experiments conducted on the CSE-CIC-IDS2018 dataset demonstrate that the proposed model achieved an Accuracy of 99.28%, an F1-score of 99.09%, and an AUC of 99.63%, outperforming several recent graph-based intrusion detection methods. The results confirm the effectiveness and robustness of HGCF-Net for intelligent cyberattack detection in modern network environments.
References
W. Stallings, Network Security Essentials: Applications and Standards, 7th ed. Pearson, 2021.
Check Point Research, The State of Cyber Security 2024, Check Point Software Technologies, 2024.
S. Russell and P. Norvig, Artificial Intelligence: A Modern Approach, 4th ed. Pearson, 2021.
I. Goodfellow, Y. Bengio, and A. Courville, Deep Learning. MIT Press, 2016.
Y. LeCun, Y. Bengio, and G. Hinton, "Deep Learning," Nature, vol. 521, no. 7553, pp. 436–444, 2015.
T. N. Kipf and M. Welling, "Semi-Supervised Classification with Graph Convolutional Networks," International Conference on Learning Representations (ICLR), 2017.
P. Veličković, G. Cucurull, A. Casanova, A. Romero, P. Liò, and Y. Bengio, "Graph Attention Networks," International Conference on Learning Representations (ICLR), 2018.
Z. Wu, S. Pan, F. Chen, G. Long, C. Zhang, and P. S. Yu, "A Comprehensive Survey on Graph Neural Networks," IEEE Transactions on Neural Networks and Learning Systems, vol. 32, no. 1, pp. 4–24, 2021.
I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, "Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization," Proceedings of ICISSP, 2018.
A. H. Lashkari, G. D. Gil, M. S. I. Mamun, and A. A. Ghorbani, "Characterization of Tor Traffic Using Time-Based Features," Proceedings of ICISSP, 2017.
A. Khraisat, I. Gondal, P. Vamplew, and J. Kamruzzaman, "Survey of Intrusion Detection Systems: Techniques, Datasets and Challenges," Cybersecurity, vol. 2, no. 20, 2019.
N. Moustafa and J. Slay, "UNSW-NB15: A Comprehensive Data Set for Network Intrusion Detection Systems," Military Communications and Information Systems Conference (MilCIS), 2015.
H. Wang, Y. Li, and X. Zhang, "Graph Neural Network-Based Intrusion Detection for Cybersecurity," IEEE Access, 2023.
X. Liu, Z. Chen, and J. Wang, "Graph Attention Network for Intelligent Network Intrusion Detection," Expert Systems with Applications, 2024.
Y. Xu, H. Zhao, and L. Sun, "Self-Supervised Graph Representation Learning for Network Intrusion Detection," Knowledge-Based Systems, 2023.
F. Scarselli, M. Gori, A. C. Tsoi, M. Hagenbuchner, and G. Monfardini, "The Graph Neural Network Model," IEEE Transactions on Neural Networks, vol. 20, no. 1, pp. 61–80, 2009.
W. L. Hamilton, R. Ying, and J. Leskovec, "Inductive Representation Learning on Large Graphs," Advances in Neural Information Processing Systems (NeurIPS), 2017.
J. Zhou et al., "Graph Neural Networks: A Review of Methods and Applications," AI Open, vol. 1, pp. 57–81, 2020.
M. Abavisani and V. M. Patel, "Improving Graph Neural Networks for Network Traffic Classification," IEEE Access, 2022.
D. P. Kingma and J. Ba, "Adam: A Method for Stochastic Optimization," International Conference on Learning Representations (ICLR), 2015.
F. Pedregosa et al., "Scikit-learn: Machine Learning in Python," Journal of Machine Learning Research, vol. 12, pp. 2825–2830, 2011.
Canadian Institute for Cybersecurity (CIC), CSE-CIC-IDS2018 Dataset, University of New Brunswick, 2018.
A. H. Lashkari, Y. Zang, G. Owhuo, and M. S. I. Mamun, CICFlowMeter: Network Traffic Flow Feature Extractor, Canadian Institute for Cybersecurity, 2018.
T. Fawcett, "An Introduction to ROC Analysis," Pattern Recognition Letters, vol. 27, no. 8, pp. 861–874, 2006.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 CENTRAL ASIAN JOURNAL OF MATHEMATICAL THEORY AND COMPUTER SCIENCES

This work is licensed under a Creative Commons Attribution 4.0 International License.