Robust Intrusion Detection with GCN-AE: A One-Class GNN Approach

Authors

  • zahra eskandari Dr. Zahra Eskandari, Assistant Professor, Department of Computer Engineering, Faculty of Electrical and Computer Engineering, Quchan University of Technology, Quchan, Iran

DOI:

https://doi.org/10.37936/ecti-eec.2026243.262491

Keywords:

Autoencoder, Graph Convolutional Networks (GCNs), Graph Neural Networks (GNNs), Graph Semi-Supervised Learning, Zero-day attacks, Evasion Attacks

Abstract

Designing Intrusion Detection Systems (IDS) that are robust against both known and emerging threats remains a critical challenge in cybersecurity. Traditional graph-based IDS approaches often rely on supervised learning, which requires large labeled datasets and struggles against evasion tactics that deviate from known attack patterns. To overcome these limitations, recent research has explored unsupervised, self-supervised, and semi-supervised learning methods that focus on modeling normal behavior to detect anomalies. Autoencoders have proven effective in learning compact and informative representations. Building on this, we propose GCN-AE, a novel one-class Graph Neural Network (GNN) model that integrates Graph Convolutional Network (GCN) layers within an Autoencoder framework. The model incorporates a specialized message-passing mechanism designed to capture normative network traffic behavior, enabling it to detect deviations without prior knowledge of attack signatures. We evaluate GCN-AE on the NF-UQ-NIDS-v1 dataset under a binary classification setting. Experimental results show that the proposed model outperforms existing approaches and exhibits strong robustness against zero-day, adversarial, and camouflage attacks. These results highlight the promise of combining GCNs with Autoencoders to enhance the adaptability and resilience of network-based IDS, providing a more effective solution for detecting both known and unknown threats in real network environments.

Downloads

Download data is not yet available.

References

@misc{ref1,

author = {Steve Morgan},

title = {Cybercrime Facts and Statistics—Report: Cyberwarfare in the C-Suite},

year = {2021},

note = {Accessed: 2021-03-01},

howpublished = {url{https://cybersecurityventures.com/wp-content/uploads/2021/01/Cyberwarfare-2021-Report.pdf} }

}

@article{ref2,

author = {Igino Corona and Giorgio Giacinto and Fabio Roli},

title = {Adversarial attacks against intrusion detection systems: Taxonomy, solutions and open issues},

journal = {Information Sciences},

volume = {239},

year = {2013}

}

@inproceedings{ref3,

author = {L. Bilge and T. Dumitras},

title = {Before we knew it: an empirical study of zero-day attacks in the real world},

booktitle = {ACM Conference on Computer and Communications Security (CCS)},

year = {2012},

pages = {833--844},

address = {Raleigh, NC, USA},

editor = {T. Yu and G. Danezis and V. D. Gligor},

publisher = {ACM}

}

@article{ref4,

author = {X. Li and J. Lv and Z. Yi},

title = {Outlier detection using structural scores in a high-dimensional space},

journal = {IEEE Trans. Cybern.},

volume = {50},

number = {5},

pages = {2302--2310},

year = {2020}

}

@inproceedings{ref5,

author = {S. Shah and P. S. Muhuri and X. Yuan and K. Roy and P. Chatterjee},

title = {Implementing a network intrusion detection system using semi-supervised support vector machine and random forest},

booktitle = {ACM Southeast Conference (ACM SE ’21)},

year = {2021},

address = {Virtual Event, USA},

pages = {180--184},

editor = {K. Rahman and E. Gamess},

publisher = {ACM}

}

@article{ref6,

author = {T. Le and H. Kim and H. Kang and H. Kim},

title = {Classification and explanation for intrusion detection system based on ensemble trees and SHAP method},

journal = {Sensors},

volume = {22},

number = {3},

pages = {1154},

year = {2022}

}

@article{ref7,

author = {B. S. Bhati and G. Chugh and F. Al-Turjman and N. S. Bhati},

title = {An improved ensemble based intrusion detection technique using xgboost},

journal = {Trans. Emerg. Telecommun. Technol.},

volume = {32},

number = {6},

year = {2021}

}

@misc{ref8,

author = {Chaitanya K. Joshi and Cristian Bodnar and Simon V. Mathis and Taco Cohen and Pietro Liò},

title = {On the expressive power of geometric graph neural networks},

year = {2023},

note = {arXiv:2301.09308},

howpublished = {url{https://arxiv.org/abs/2301.09308}}

}

@article{ref9,

author = {H. Choi and M. Kim and G. Lee and W. Kim},

title = {Unsupervised learning approach for network intrusion detection system using autoencoders},

journal = {The Journal of Supercomputing},

volume = {75},

number = {9},

pages = {5597--5621},

year = {2019}

}

@article{ref11,

author = {David Pujol-Perich and José Suárez-Varela and Albert Cabellos-Aparicio and Pere Barlet-Ros},

title = {Unveiling the potential of graph neural networks for robust intrusion detection},

journal = {ACM SIGMETRICS Performance Evaluation Review},

volume = {49},

number = {4},

pages = {111--117},

year = {2022}

}

@article{ref12,

author = {X. Zhou and W. Liang and W. Li and K. Yan and S. Shimizu and K. I.-K. Wang},

title = {Hierarchical Adversarial Attacks Against Graph-Neural-Network-Based IoT Network Intrusion Detection System},

journal = {IEEE Internet of Things Journal},

volume = {9},

number = {12},

pages = {9310--9319},

year = {2022},

month = {June},

doi = {10.1109/JIOT.2021.3130434}

}

@inproceedings{ref13,

author = {Wai Weng Lo and Siamak Layeghy and Mohanad Sarhan and Marcus Gallagher and Marius Portmann},

title = {E-GraphSAGE: A Graph Neural Network based Intrusion Detection System for IoT},

booktitle = {IEEE/IFIP Network Operations and Management Symposium (NOMS)},

year = {2022},

doi = {10.1109/NOMS54207.2022.9789878}

}

@article{ref14,

author = {E. Caville and W. W. Lo and S. Layeghy and M. Portmann},

title = {Anomal-e: A self-supervised network intrusion detection system based on graph neural networks},

journal = {Knowledge-Based Systems},

volume = {258},

pages = {110030},

year = {2022}

}

@article{ref15,

author = {Hoang Nguyen and Rasha Kashef},

title = {TS-IDS: Traffic-aware self-supervised learning for IoT Network Intrusion Detection},

journal = {Knowledge-Based Systems},

volume = {279},

year = {2023},

doi = {10.1016/j.knosys.2023.110966}

}

@inproceedings{ref16,

author = {Zhenlu Sun and André M. H. Teixeira and Salman Toor},

title = {GNN-IDS: Graph Neural Network based Intrusion Detection System},

booktitle = {Proceedings of the 19th International Conference on Availability, Reliability and Security (ARES '24)},

year = {2024},

publisher = {ACM},

pages = {1--12},

doi = {10.1145/3664476.3664515}

}

@inproceedings{ref17,

author = {Julian Busch and Anton Kocheturov and Volker Tresp and Thomas Seidl},

title = {NF-GNN: Network Flow Graph Neural Networks for Malware Detection and Classification},

booktitle = {Proceedings of the ACM Workshop},

year = {2021},

pages = {121--132},

doi = {10.1145/3468791.3468814}

}

@incollection{ref19,

author = {M. Sarhan and S. Layeghy and N. Moustafa and M. Portmann},

title = {NetFlow Datasets for Machine Learning-Based Network Intrusion Detection Systems},

booktitle = {Big Data Technologies and Applications (BDTA)},

editor = {Z. Deze and H. x. Huang and R. Hou and S. Rho and N. Chilamkurti},

publisher = {Springer, Cham},

series = {Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering},

volume = {371},

year = {2021},

doi = {10.1007/978-3-030-72802-1_9}

}

@inproceedings{ref20,

author = {Premkumar and M. Schneider and C. Spivey and J. V. Pavlik and N. D. Bastian},

title = {Graph representation learning for context-aware network intrusion detection},

booktitle = {Proc. SPIE},

volume = {12538},

pages = {82--92},

year = {2023},

month = jun

}

@article{ref22,

author = {Ruijie Zhao and Yijun Wang and Zhi Xue and Tomoaki Ohtsuki and Bamidele Adebisi and Guan Gui},

title = {Semi-supervised federated learning based intrusion detection method for internet of things},

journal = {IEEE Internet of Things Journal},

volume = {10},

number = {10},

pages = {8645--8657},

year = {2023},

doi = {10.1109/JIOT.2022.3175918}

}

@inproceedings{ref23,

author = {Y. Zhang and J. Yan},

title = {Semi-supervised domain-adversarial training for intrusion detection against false data injection in the smart grid},

booktitle = {Proceedings of the 2020 International Joint Conference on Neural Networks (IJCNN)},

pages = {1--7},

year = {2020},

doi = {10.1109/IJCNN48605.2020.9207525}

}

@article{ref25,

author = {J. Zhao and X. Liu and Q. Yan and B. Li and M. Shao and H. Peng},

title = {Multi-attributed heterogeneous graph convolutional network for bot detection},

journal = {Information Sciences},

volume = {537},

pages = {380--393},

month = oct,

year = {2020}

}

@article{ref26,

title = {Applying self-supervised learning to network intrusion detection for network flows with graph neural network},

journal = {Computer Networks},

volume = {248},

pages = {110495},

year = {2024},

issn = {1389-1286},

doi = {https://doi.org/10.1016/j.comnet.2024.110495},

url = {https://www.sciencedirect.com/science/article/pii/S138912862400327X},

author = {Renjie Xu and Guangwei Wu and Weiping Wang and Xing Gao and An He and Zhengpeng Zhang},

}

@article{ref27,

title = {A survey on graph neural networks for intrusion detection systems: Methods, trends and challenges},

journal = {Computers & Security},

volume = {141},

pages = {103821},

year = {2024},

issn = {0167-4048},

doi = {https://doi.org/10.1016/j.cose.2024.103821},

url = {https://www.sciencedirect.com/science/article/pii/S0167404824001226},

author = {Meihui Zhong and Mingwei Lin and Chao Zhang and Zeshui Xu},

keywords = {Intrusion detection systems, Graph neural networks, Graph representation learning, Information retrieval, Anomaly detection},

abstract = {Intrusion detection systems (IDS) play a crucial role in maintaining network security. With the increasing sophistication of cyber attack methods, traditional detection approaches are encountering more challenges. In recent years, graph neural networks (GNNs) have garnered significant attention in the field of intrusion detection due to their unique ability to capture the relationships within the graph structure of data communications. In this review, we propose a novel taxonomy that categorizes advanced research into three distinct areas: tasks related to graph construction, network design, and GNN models deployment. We detail a generalized design process for GNN-based intrusion detection models, discussing the challenges encountered at each stage. Building upon these discussions, we conduct a systematic survey of existing works. Ultimately, we delve into a thorough exploration of the future research directions and the pending issues in this domain. By adopting a problem-oriented taxonomy and conducting a targeted survey, this review aims to provide scholars with a clear, systematic framework for deepening their understanding and further exploration of the field.}

}

@ARTICLE{ref32,

author={Ghadermazi, Jalal and Hore, Soumyadeep and Shah, Ankit and Bastian, Nathaniel D.},

journal={IEEE Transactions on Information Forensics and Security},

title={GTAE-IDS: Graph Transformer-Based Autoencoder Framework for Real-Time Network Intrusion Detection},

year={2025},

volume={20},

number={},

pages={4026-4041},

keywords={Telecommunication traffic;Transformers;Real-time systems;Feature extraction;Training;IP networks;Graph neural networks;Autoencoders;Accuracy;Data models;Network intrusion detection;graph representation learning;graph transformer;autoencoders;real-time anomaly detection;network security},

doi={10.1109/TIFS.2025.3557741}}

@ARTICLE{ref33,

author={Song, Zixing and Yang, Xiangli and Xu, Zenglin and King, Irwin},

journal={IEEE Transactions on Neural Networks and Learning Systems},

title={Graph-Based Semi-Supervised Learning: A Comprehensive Review},

year={2023},

volume={34},

number={11},

pages={8174-8194},

keywords={Taxonomy;Semisupervised learning;Manifolds;Codes;Training;Prediction algorithms;Image color analysis;Graph embedding;graph representation learning;graph-based semi-supervised learning (GSSL);semi-supervised learning (SSL)},

doi={10.1109/TNNLS.2022.3155478}}

@article{ref34,

title = {Enabling semi-supervised learning in intrusion detection systems},

journal = {Journal of Parallel and Distributed Computing},

volume = {196},

pages = {105010},

year = {2025},

issn = {0743-7315},

doi = {https://doi.org/10.1016/j.jpdc.2024.105010},

url = {https://www.sciencedirect.com/science/article/pii/S0743731524001746},

author = {Panagis Sarantos and John Violos and Aris Leivadeas},

abstract = {Intrusion Detection systems (IDS) are alerting cybersecurity tools that analyze network traffic in order to identify suspicious activity and known threats. State of the art IDS rely on supervised machine learning models which are trained to categorize the network flow with a historical labeled dataset. Nonetheless, next-generation networks are characterized as heterogeneous and dynamic. The heterogeneity can make every network environment to be significantly different and the dynamicity means that new threats are constantly emerging. These two factors raise the research question if a supervised machine learning based IDS can work efficiently in a network environment different from the one that generated its labeled training data. In this paper, we first give an answer to this research question and next try to propose a semi-supervised learning approach that can be generalized sufficiently in a different network environment using unlabeled data, taking into consideration that unlabeled data are much easier and cheap to be collected compared to labeled ones. In order to have a proof of concept we made experiments with two labeled datasets CIC-IDS2017, CIC-IDS2018 which are publicly available and one unlabeled dataset PS-Azure2023 which we constructed for this work and make it also publicly available. The results confirm our assumption and the applicability of the semi-supervised learning paradigm for the design of IDS.}

}

@article{ref36,

author = {Mvula, Paul Kiyambu and Branco, Paula and Jourdan, Guy-Vincent and Viktor, Herna Lydia},

title = {A Survey on the Applications of Semi-supervised Learning to Cyber-security},

year = {2024},

issue_date = {October 2024},

publisher = {Association for Computing Machinery},

address = {New York, NY, USA},

volume = {56},

number = {10},

issn = {0360-0300},

url = {https://doi.org/10.1145/3657647},

doi = {10.1145/3657647},

abstract = {Machine Learning’s widespread application owes to its ability to develop accurate and scalable models. In cyber-security, where labeled data is scarce, Semi-Supervised Learning (SSL) emerges as a potential solution. SSL excels at tasks challenging traditional supervised and unsupervised algorithms by leveraging limited labeled data alongside abundant unlabeled data. This article presents a comprehensive survey of SSL in cyber-security, focusing on countering diverse cybercrimes, particularly intrusion detection. Despite its potential, a notable research gap persists, with few recent studies comprehensively reviewing SSL’s application in cyber-security. This study examines state-of-the-art SSL techniques tailored for cyber-security to address this gap. Relevant methods are identified, and their effectiveness is evaluated to empower researchers and practitioners with insights to enhance cyber-security measures. This work sheds light on SSL’s potential in addressing data scarcity in cyber-security domains in addition to outlining new research directions to advance this crucial field. By bridging this research gap, this manuscript paves the way for enhanced cyber-threat detection and mitigation in an increasingly interconnected world.},

journal = {ACM Comput. Surv.},

month = jun,

articleno = {253},

numpages = {41},

keywords = {Cyber-security, semi-supervised learning, web spam detection, phishing detection, intrusion detection, malware detection}

}

@article{ref38,

title={The Kolmogorov-Smirnov Test for Goodness of Fit},

author={Massey, Frank J.},

journal={Journal of the American Statistical Association},

volume={46},

number={253},

pages={68--78},

year={1951},

publisher={Taylor & Francis},

doi={10.1080/01621459.1951.10500769}

}

@misc{ref39,

title={Camouflage Adversarial Attacks on Multiple Agent Systems},

author={Ziqing Lu and Guanlin Liu and Lifeng Lai and Weiyu Xu},

year={2024},

eprint={2401.17405},

archivePrefix={arXiv},

primaryClass={cs.MA},

url={https://arxiv.org/abs/2401.17405},

}

Downloads

Published

2026-09-29

How to Cite

eskandari, zahra. (2026). Robust Intrusion Detection with GCN-AE: A One-Class GNN Approach. ECTI Transactions on Electrical Engineering, Electronics, and Communications, 24(3). https://doi.org/10.37936/ecti-eec.2026243.262491