Dual-autoencoder multi-task self-supervised one-class graph anomaly detection for network traffic
To address the limitations of intrusion detection under unknown attacks and label scarcity, this paper proposes GDAE, a multi-task self-supervised one-class anomaly detection framework for network traffic graphs. It constructs an edge-level directed graph from NetFlow, employs E-GraphSAGE for structure-aware edge embeddings, and captures multi-scale normal patterns via local structure and global semantic autoencoders with a structure consistency prediction task. To compensate for the lack of negative samples, a dual-path pseudo-anomaly generation mechanism using feature perturbation and structural discarding is designed, with an anomaly discriminator to learn the normal-abnormal boundary. Training employs Kendall uncertainty for adaptive multi-task loss weighting and extreme value theory for threshold estimation, demonstrating strong performance on two large-scale benchmark datasets. Experiments on NF-UNSW-NB15-v2 and NF-CSE-CIC-IDS2018-v2 demonstrate GDAE’s superior performance over unsupervised and graph-based baselines in PR-AUC and Macro-F1, with strong stability and efficiency, offering a new pathway for lightweight, robust self-supervised one-class intrusion detection.