Skip to content
Open access

SHAP-GSD: Temporal Multi-Granular Explanation Method for Graph Neural Networks in Network Intrusion Detection

2026 · IEEE Open Journal of the Communications Society · Vol 7, pp. 11714-11739 · 0 citations · 50 references

TL;DR

SHapley Additive exPlanations on Graph-Structured Data (SHAP-GSD), a temporally constrained Shapley framework that decomposes each alert into three attribution layers, is presented, the first Shapley formulation to simultaneously deliver temporally faithful, multi-granularity attribution across all three evidence dimensions for a GNN-based NIDS.

Abstract

In graph neural network (GNN)-based network intrusion detection systems (NIDS), an alert may reflect flow attributes, recent endpoint communications, or anomalous endpoint behaviour. Feature-only Shapley methods identify which flow attributes triggered the flag, but cannot attribute temporal neighbourhood context or endpoint novelty. This paper presents SHapley Additive exPlanations on Graph-Structured Data (SHAP-GSD), a temporally constrained Shapley framework that decomposes each alert into three attribution layers: 48 semantic feature groups, temporal-neighbourhood flows within a strict per-edge cut-off admitting only evidence available at the moment of detection, and a node-level coalition combining rolling endpoint state with a binary first-appearance flag. On the NF-UNSW-NB15-v3 dataset, SHAP-GSD improves macro-F1 by 6.33% over TE-G-SAGE under the identical chronological split. Temporal-neighbourhood evidence is present on roughly half of explained flows, and semantic grouping concentrates attribution within a small subset of the 48 named groups, scoring higher on both necessity and sufficiency than the ungrouped dimensions at matched masking scope, so readability costs no fidelity. A Shellcode case study shows the temporal neighbourhood weighs against the alert and the endpoint first-appearance flag makes zero contribution, distinctions a single-granularity explainer would collapse into one undifferentiated score. SHAP-GSD is the first Shapley formulation to simultaneously deliver temporally faithful, multi-granularity attribution across all three evidence dimensions for a GNN-based NIDS.

Read PDF

Similar papers

#graph neural networks Open access Sep 2026

Online intrusion detection in computer networks using edge-aware attentive graph neural network

Graph Neural Network (GNN)-based intrusion detection systems (IDS) have emerged as powerful tools for modeling the structural patterns of network traffic. However, most existing methods rely on large, temporally aggregated graphs and random train-test splits, which risk information leakage from future traffic and overs...

Áron Kiss, K. Nehéz, O. Hornyák · 0 citations
Open access Sep 2026

IOTTRUST: graph-based anomaly detection for IoT intrusion using network flow topology and community structure analysis on UNSW-NB15

Introduction Conventional machine learning approaches to IoT intrusion detection treat each network flow record as an independent observation, discarding the relational structure that connects flows across source IPs, destination IPs, and subnet communities. This article presents IOTTRUST, a graph-augmented intrusion d...

Nachaat Mohamed, Hamed Taherdoost · 0 citations
Conference Aug 2026

Are Temporal Graph Based Intrusion Detection Results Trustworthy? A Dataset Audit and Evaluation Framework

Temporal Graph Neural Networks (TGNNs) have been increasingly applied to network intrusion detection (NID), with some studies reporting accuracy exceeding 99%. This paper argues that such performance can be an artifact of dataset construction flaws rather than genuine model capability. We conduct an empirical audit of...

Yin-Ning Zhang, Sait Suer, S. M. T. F. A. Chowdhoury et al. · 0 citations
Open access Aug 2026

A Reliability-Aware Edge–Cloud Framework for Early Intrusion Detection in IoT Networks

A reliability-aware edge–cloud framework that treats early detection as a sequential routing problem, and identifies the minimum-evidence gate and cloud-refinement stage as the main reliability controls.

Siraj Azam, Farheen Naaz, Mikail Mohammed Salim · 0 citations
Open access Aug 2026

MaGOS-IDS: A Mahalanobis-Enhanced OpenMax Method for Graph Neural Network-Based Intrusion Detection

Graph Neural Networks achieve strong closed-set accuracy in network intrusion detection but cannot flag zero-day attacks, because the closed-world assumption forces every input into a known class. OpenMax adds an Extreme Value Theory reject option, yet its Euclidean distance ignores the class-conditional covariance tha...

Thanh T. Nguyen, Minho Park · 0 citations
Open access 2026

DMGCRL: Dynamic Multi-Scale Graph Contrastive Representation Learning for Network Intrusion Detection

Graph neural networks (GNNs) have recently attracted significant attention in network intrusion detection systems (NIDS) due to their ability to model network traffic as graphs and capture complex relationships within network flows. However, existing GNN-based methods face critical limitations: they rely on limited or...

Raeed Al-Sabri, Abdullatif Albaseer, Mohamed M. Abdallah et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.