Skip to content
Conference

Are Temporal Graph Based Intrusion Detection Results Trustworthy? A Dataset Audit and Evaluation Framework

Aug 2026 · 2026 International Conference on Intelligent Multimedia, Networking, and Security (IMNS) · pp. 1-6 · 0 citations · 21 references

Abstract

Temporal Graph Neural Networks (TGNNs) have been increasingly applied to network intrusion detection (NID), with some studies reporting accuracy exceeding 99%. This paper argues that such performance can be an artifact of dataset construction flaws rather than genuine model capability. We conduct an empirical audit of two NID datasets and identify three categories of dataset flaws when tabular NID datasets are converted to temporal graphs: node identity leakage, temporal concentration of attack traffic, and class imbalance interacting with graph structure. We further propose an evaluation framework comprising a node identity leakage detection protocol and an attack-aware chronological split strategy. We demonstrate the node identity leakage detection protocol empirically through a controlled experiment across two TGNN architectures - T-GCN (RNN-based) and A3T-GCN2 (attention-based). We also compare the attack flow rate change between a standard dataset split method and our split strategy. Together, this proposed evaluation framework provides a more reliable and rigorous basis for future TGNN-NID research.

View source

Similar papers

Review Sep 2026

A First-Principles Evaluation of Graph-Based Network Intrusion Detection Systems

Graph-based network intrusion detection systems (GIDS) report strong benchmark detection metrics, but those metrics establish little about deployability. We approach the problem from first principles: rather than inheriting the preprocessing, windowing, and thresholding conventions of each published system, we ask what...

Rui Zhao, Wajih Ul Hassan · 0 citations
#graph neural networks Open access Sep 2026

Online intrusion detection in computer networks using edge-aware attentive graph neural network

Graph Neural Network (GNN)-based intrusion detection systems (IDS) have emerged as powerful tools for modeling the structural patterns of network traffic. However, most existing methods rely on large, temporally aggregated graphs and random train-test splits, which risk information leakage from future traffic and overs...

Áron Kiss, K. Nehéz, O. Hornyák · 0 citations
Open access Sep 2026

IOTTRUST: graph-based anomaly detection for IoT intrusion using network flow topology and community structure analysis on UNSW-NB15

Introduction Conventional machine learning approaches to IoT intrusion detection treat each network flow record as an independent observation, discarding the relational structure that connects flows across source IPs, destination IPs, and subnet communities. This article presents IOTTRUST, a graph-augmented intrusion d...

Nachaat Mohamed, Hamed Taherdoost · 0 citations
Open access Sep 2026

Real-Traffic Enrichment for Improved Minority Web Attack Detection in Network Intrusion Detection

Class imbalance severely limits Network Intrusion Detection Systems (NIDSs) for minority Web attack classes: CICIDS2017 contains only 21 SQL Injection instances among 2.27 million benign flows. This study enriches CICIDS2017 with authentic SQL Injection, Cross-Site Scripting (XSS), and Web Brute Force (WBF) traffic cap...

Zeyneb Berkat, Amina Fatima Zahra Yahiaoui, Mahfoud Aliouat et al. · 0 citations
Open access 2026

Explainable Machine Learning for Suspicious Network Traffic Detection Using the UNSW-NB15 Dataset

Machine-learning-based intrusion detection can identify suspicious network traffic with high predictive performance, but security analysts also need to understand why a traffic record is classified as an attack. This paper presents an explainable machine-learning framework for binary suspicious-traffic detection using...

D. P., H. S. · 0 citations
Open access 2026

SHAP-GSD: Temporal Multi-Granular Explanation Method for Graph Neural Networks in Network Intrusion Detection

SHapley Additive exPlanations on Graph-Structured Data (SHAP-GSD), a temporally constrained Shapley framework that decomposes each alert into three attribution layers, is presented, the first Shapley formulation to simultaneously deliver temporally faithful, multi-granularity attribution across all three evidence dimen...

Riko Luša, Damir Pintar, Mihaela Vranić · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.