2026· IEEE Open Journal of the Communications Society· Vol 7, pp. 11714-11739· 0 citations· 50 references
TL;DR
SHapley Additive exPlanations on Graph-Structured Data (SHAP-GSD), a temporally constrained Shapley framework that decomposes each alert into three attribution layers, is presented, the first Shapley formulation to simultaneously deliver temporally faithful, multi-granularity attribution across all three evidence dimensions for a GNN-based NIDS.
Abstract
In graph neural network (GNN)-based network intrusion detection systems (NIDS), an alert may reflect flow attributes, recent endpoint communications, or anomalous endpoint behaviour. Feature-only Shapley methods identify which flow attributes triggered the flag, but cannot attribute temporal neighbourhood context or endpoint novelty. This paper presents SHapley Additive exPlanations on Graph-Structured Data (SHAP-GSD), a temporally constrained Shapley framework that decomposes each alert into three attribution layers: 48 semantic feature groups, temporal-neighbourhood flows within a strict per-edge cut-off admitting only evidence available at the moment of detection, and a node-level coalition combining rolling endpoint state with a binary first-appearance flag. On the NF-UNSW-NB15-v3 dataset, SHAP-GSD improves macro-F1 by 6.33% over TE-G-SAGE under the identical chronological split. Temporal-neighbourhood evidence is present on roughly half of explained flows, and semantic grouping concentrates attribution within a small subset of the 48 named groups, scoring higher on both necessity and sufficiency than the ungrouped dimensions at matched masking scope, so readability costs no fidelity. A Shellcode case study shows the temporal neighbourhood weighs against the alert and the endpoint first-appearance flag makes zero contribution, distinctions a single-granularity explainer would collapse into one undifferentiated score. SHAP-GSD is the first Shapley formulation to simultaneously deliver temporally faithful, multi-granularity attribution across all three evidence dimensions for a GNN-based NIDS.
Graph Neural Network (GNN)-based intrusion detection systems (IDS) have emerged as powerful tools for modeling the structural patterns of network traffic. However, most existing methods rely on large, temporally aggregated graphs and random train-test splits, which risk information leakage from future traffic and overs...
Áron Kiss, K. Nehéz, O. Hornyák· Intelligent Data Analysis· 0 citations
Introduction Conventional machine learning approaches to IoT intrusion detection treat each network flow record as an independent observation, discarding the relational structure that connects flows across source IPs, destination IPs, and subnet communities. This article presents IOTTRUST, a graph-augmented intrusion d...
Nachaat Mohamed, Hamed Taherdoost· Frontiers in Big Data· 0 citations
Temporal Graph Neural Networks (TGNNs) have been increasingly applied to network intrusion detection (NID), with some studies reporting accuracy exceeding 99%. This paper argues that such performance can be an artifact of dataset construction flaws rather than genuine model capability. We conduct an empirical audit of...
Yin-Ning Zhang, Sait Suer, S. M. T. F. A. Chowdhoury et al.· 2026 International Conferenc...· 0 citations
A reliability-aware edge–cloud framework that treats early detection as a sequential routing problem, and identifies the minimum-evidence gate and cloud-refinement stage as the main reliability controls.
Siraj Azam, Farheen Naaz, Mikail Mohammed Salim· Electronics· 0 citations
Graph Neural Networks achieve strong closed-set accuracy in network intrusion detection but cannot flag zero-day attacks, because the closed-world assumption forces every input into a known class. OpenMax adds an Extreme Value Theory reject option, yet its Euclidean distance ignores the class-conditional covariance tha...
Thanh T. Nguyen, Minho Park· Electronics· 0 citations
Graph neural networks (GNNs) have recently attracted significant attention in network intrusion detection systems (NIDS) due to their ability to model network traffic as graphs and capture complex relationships within network flows. However, existing GNN-based methods face critical limitations: they rely on limited or...
Raeed Al-Sabri, Abdullatif Albaseer, Mohamed M. Abdallah et al.· IEEE Transactions on Network...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.