Skip to content
Open access

An Explainable and Interpretable GNN Based on Temporal Time Series: An IDS Approach

Aug 2026 · Electronics · Vol 15, pp. 3764 · 0 citations · 20 references

TL;DR

This work develops and compares traditional classifiers against a GNN-based IDS on the UNSW-NB15 dataset, for both binary and multiclass classification and reveals attack-specific structural patterns, confirming that temporally structured GNNs improve detection while providing interpretable predictions.

Abstract

Intrusion Detection Systems (IDSs) based on traditional machine learning treat network flows as independent tabular samples, ignoring the relational and topological structure that characterizes modern distributed attacks. Graph Neural Networks (GNNs) overcome this limitation by modeling network topology, which in turn raise the need to make their predictions transparent. This work develops and compares traditional classifiers against a GNN-based IDS on the UNSW-NB15 dataset, for both binary and multiclass classification. A novel graph construction is proposed in which each node is an individual flow and edges are defined by temporal proximity through three complementary strategies (conversation chains and temporal k-NN by source and destination IP). Three GNN backbones—GraphSAGE, Graph Convolutional Network (GCN) and Graph Attention Network (GAT)—are trained under an identical, matched pipeline and a chronological, inductive evaluation protocol, so that any difference is attributable to the backbone alone. A two-stage classifier then separates detection from attack-type categorisation, with GNNExplainer providing interpretability, and SHAP applied to the traditional models. In binary classification, GraphSAGE achieves an Accuracy of 0.9906, Precision of 0.9856, Recall of 0.9998, F1-Score of 0.9927 and ROC-AUC of 0.9965, exceeding the traditional baselines in their conventional evaluation setting, while GCN and GAT reach comparable detection (F1 ≈ 0.99), showing that the temporal graph rather than the specific backbone drives detection. The explainability analysis identifies TTL-related and connection-state variables as dominant predictors and reveals attack-specific structural patterns, confirming that temporally structured GNNs improve detection while providing interpretable predictions.

Read PDF

Similar papers

Conference Open access 2026

A Lightweight NLP-CNN Framework Based on Semantic Flow Representation for Network Intrusion Detection

One lesson emerges from the experiments: putting the effort into how traffic is written down, instead of making the classifier heavier, offers an economical and workable path to intrusion detection across heterogeneous network environments.

Asmaa Benchama, Khalid Zebbara · 0 citations
Preprint Aug 2026

Cognitive Graph Intelligence for Adaptive and Robust DDoS Attack Detection in Next Generation Networks

By integrating temporal graph construction, adversarial augmentation, and GCN classification, GraphGAN effectively models coordinated attack behaviors and mitigates class imbalance, providing a robust and topology-aware solution for intrusion detection in data-constrained environments.

Mohammad Arif Hossain, Yeahia Sarker, Md Jafrin Hossain et al. · 0 citations
Open access Sep 2026

A cross-attention CNN–LSTM fusion model for network traffic anomaly detection

Detecting cyber intrusions in modern IoT networks is challenging because of their large scale, heterogeneous device ecosystems, and high-volume traffic patterns. This paper presents a cross-attention CNN–LSTM fusion architecture that jointly learns the spatial and temporal characteristics of network traffic for bin...

Mohamed Fakri, A. Najid, Rachid Ben Said et al. · 0 citations
Open access Aug 2026

Deep Learning-Based Network Intrusion Detection Using Hybrid CNN and LSTM Architecture

The findings indicate that hybrid deep learning techniques can improve network security by enhancing intrusion detection capability while reducing false alarms.

A. O. Jimoh-Mahmud, Abubakar Dayyabu, Abubakar Sadiq Idris et al. · 0 citations
Open access Sep 2026

Isolating Graph Topology from Model Architecture in GNN-Based Fraud Detection: An Empirical Framework

Graph topology and model architecture are routinely co-designed in GNN-based fraud detection, making it impossible to attribute performance gains to either component. We address this by fixing the training loop, features, and evaluation protocol while independently varying the graph construction strategy and GNN archit...

Roya Amiri, Sardar F. Jaf · 0 citations
Open access 2026

DMGCRL: Dynamic Multi-Scale Graph Contrastive Representation Learning for Network Intrusion Detection

Graph neural networks (GNNs) have recently attracted significant attention in network intrusion detection systems (NIDS) due to their ability to model network traffic as graphs and capture complex relationships within network flows. However, existing GNN-based methods face critical limitations: they rely on limited or...

Raeed Al-Sabri, Abdullatif Albaseer, Mohamed M. Abdallah et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.