Skip to content
Open access

DMGCRL: Dynamic Multi-Scale Graph Contrastive Representation Learning for Network Intrusion Detection

2026 · IEEE Transactions on Network and Service Management · Vol 23, pp. 7450-7467 · 0 citations · 74 references

Abstract

Graph neural networks (GNNs) have recently attracted significant attention in network intrusion detection systems (NIDS) due to their ability to model network traffic as graphs and capture complex relationships within network flows. However, existing GNN-based methods face critical limitations: they rely on limited or noisy labeled data and struggle to detect threats at various scales, ranging from local anomalies (e.g., port scanning) to coordinated subnetwork attacks (e.g., botnets) and global network-wide campaigns (e.g., DDoS attacks). To bridge this gap, we propose Dynamic Multiscale Graph Contrastive Representation Learning (DMGCRL), a self-supervised framework that hierarchically models network intrusions at different levels. At the node level, DMGCRL constructs structure-aware subnetworks around individual traffic flows to capture fine-grained behavioral deviations. For subnetwork-level threats, it employs substructure-aware pooling to identify coordinated anomalies among clustered malicious nodes. Finally, at the global level, DMGCRL derives representations that reflect the holistic state of the network, enabling detection of large-scale threats, such as distributed malware propagation. DMGCRL designs a shared GNN encoder with a multi-level contrastive loss to align multiscale representations while largely eliminating label dependence. It learns discriminative features from unlabeled traffic, refines decision boundaries without supervision, and reveals anomalies by contrasting related and unrelated nodes across scales. Performance evaluation was conducted on five publicly available network traffic datasets for binary and multiclass detection. Results show that DMGCRL consistently outperforms SOTA methods, achieving an F1 score of 99.86% on NF-CSE-CIC-IDS2018-V2 and 96.11% on NF-UNSW-NB15-V2 under binary detection and the lowest mean false positive rates, 1.28% and 2.33% under multiclass detection on the two datasets.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.