Aug 2026· Engineering Reports· Vol 8· 0 citations· 28 references
TL;DR
A hybrid intrusion detection framework that combines generative adversarial learning with graph attention‐based modeling that leverages adversarial data generation to improve the representation of minority attack classes and employs graph attention mechanisms to capture structural dependencies among communicating entities is proposed.
Abstract
The rapid expansion of the internet of things (IoT) has enabled large‐scale connectivity across healthcare, smart homes, industrial automation, and intelligent infrastructure. However, this growth has also increased the exposure of IoT environments to complex and evolving cyber threats. Traditional intrusion detection systems, particularly signature‐based approaches, are often ineffective against previously unseen attacks and struggle to adapt to the heterogeneous and dynamic nature of IoT traffic. To address these challenges, this study proposes a hybrid intrusion detection framework that combines generative adversarial learning with graph attention‐based modeling. The proposed model leverages adversarial data generation to improve the representation of minority attack classes and employs graph attention mechanisms to capture structural dependencies among communicating entities. The framework was evaluated using the UNSW‐NB15 dataset and compared with baseline deep learning models, including generative adversarial networks, graph convolutional networks, and graph attention networks. The proposed method achieved an accuracy of 81.23%, precision of 83.89%, recall of 78.01%, and F1‐score of 80.84% on the held‐out test set, while also reducing false‐positive and false‐negative rates relative to the comparison models. The results demonstrate the effectiveness of combining adversarial data augmentation with graph attention‐based representation learning under the controlled, offline evaluation conditions used in this study. Although the framework may be relevant to IoT and industrial cybersecurity applications, its scalability, real‐time performance, edge‐device feasibility, and effectiveness in operational environments require further experimental validation.
In a comparative review of forty peer-reviewed studies, it is demonstrated that hybrid DL models provide excellent detection performance (99-100% classification accuracy on benchmark datasets) as well as practical viability for deployment with privacy-preserving Federated Learning for large-scale data.
Mohammed Gharkan, Mustafa I. Hussien Al-Janabi, Obaid Salim· Al-Noor Journal of Engineeri...· 0 citations
The proposed accurate and interpretable framework shows strong potential as an edge-deployable security solution for safeguarding IoT devices and improving cyber resilience.
Prabhav Jain, Aashima Sharma, A. Noonia et al.· Scientific Reports· 0 citations
The Hybrid Autoencoder–TabTransformer framework provides an effective intrusion detection solution that demonstrates strong performance under the evaluated experimental conditions and comparative analysis with existing deep learning‐based intrusion detection approaches confirms the superior and balanced performance of...
Rui Guo, Guangjun Wen· Transactions on Emerging Tel...· 0 citations
A Traffic-Aware Imbalance Learning Network (TAIL-Net) for lightweight and imbalance-aware IoT intrusion detection that introduces a traffic-aware semantic feature mapping mechanism that reorganizes network traffic attributes according to their semantic relationships to improve feature representation learning.
The rapid growth of the Internet of Things (IoT) has created a highly interconnected digital
environment, but this expansion has also introduced complex security risks, especially at the
application layer where most user-level operations occur. Many existing intrusion detection
systems (IDS) are unable to cope with...
F. C. Uzoezie· International Journal of Com...· 0 citations
A Hybrid Convolutional Neural Network–Long Short-Term Memory (CNN–LSTM) model for effective IoT malware detection is proposed, which enhances detection capability for both known and zero-day attacks.