Skip to content
Open access

The Method of Malicious Traffic Detection for Internet of Things Based on Lightweight Graph Neural Networks

2026 · Computers, Materials & Continua · 0 citations · 29 references

TL;DR

A Lightweight Graph-Attentive Network for Traffic Detection (LGNT), which improves the balance between traffic-interaction modeling, detection performance, and deployment efficiency while keeping the parameter scale at 0.236 million.

Abstract

: With the sustained expansion of complex Internet of Things (IoT) ecosystems, malicious traffic detection has become critical for maintaining both cyber security and operational continuity. Modern IoT deployments contain heterogeneous devices, ubiquitous sensing layers, edge services, and autonomous assets, so abnormal communication may affect not only data confidentiality but also physical operations. To address the limitations of independent flow-level detection and heavy graph propagation, this paper proposes a Lightweight Graph-Attentive Network for Traffic Detection (LGNT). LGNT constructs a directed traffic-interaction graph from NetFlow records, where communication entities are represented as nodes and traffic sessions are represented as edges. Communication-strength-based auxiliary node supervision provides an activity-aware structural signal, while a compact backbone combining topology adaptive graph convolution (TAGConv) and graph attention v2 convolution (GATv2Conv) captures local topological dependencies and key communication relations. A structure-significance pruning strategy is further introduced to reduce the message-passing edge set and graph computation overhead. Experiments on NetFlow BoT-IoT (NF-BoT-IoT) and NetFlow ToN-IoT (NF-ToN-IoT) show that LGNT obtains effective results in both binary and multi-class detection tasks. Specifically, it achieves 94.28% accuracy, 97.36% area under the curve (AUC), and 86.88% F1 on NF-BoT-IoT, and 99.93% accuracy, 99.95% AUC, and 69.05% weighted F1 on NF-ToN-IoT. The per-class analysis further shows that long-tailed minority categories remain challenging in fine-grained NF-ToN-IoT recognition. Overall, LGNT improves the balance between traffic-interaction modeling, detection performance, and deployment efficiency while keeping the parameter scale at 0.236 million.

Read PDF

Similar papers

#machine learning Preprint Aug 2026

Clustering-Based Collective Anomaly Detection in IoT Systems: A Graph Neural Network Approach

The rapid advancement of Internet of Things (IoT) technology has led to the widespread deployment of smart, interconnected devices across a range of domains. However, this expansion has also resulted in a substantial increase in network traffic, creating more opportunities for malicious actors to launch cyberattacks an...

Dalila Khettaf, D. Djenouri, Zeinab Rezaeifar et al. · 0 citations
Conference Aug 2026

Flow Meets Graph: A Dynamic Fusion Relational Graph Convolutional Network for IoMT Intrusion Detection

The rapid popularity of the Internet of Medical Things (IoMT) has introduced a "topology blind spot" in traditional Network Intrusion Detection Systems (NIDS), meaning they cannot distinguish attacks with similar statistical traffic configurations and completely different network topologies. To address this issue, this...

Gao-Yang Guo, Faizan Qamar, Han-Li Chen et al. · 0 citations
Open access Sep 2026

IOTTRUST: graph-based anomaly detection for IoT intrusion using network flow topology and community structure analysis on UNSW-NB15

IOTTRUST is presented, a graph-augmented intrusion detection framework for IoT networks that constructs a directed network flow graph from the UNSW-NB15 dataset and enriches per-flow machine learning with 24 graph-derived topology features computed per source and destination IP.

Nachaat Mohamed, Hamed Taherdoost · 0 citations
#graph neural networks Open access Sep 2026

Lightweight Relation-Aware Graph Neural Networks for Network Threat Detection in the Social Internet of Things

Network threat detection in the Internet of Things must exploit typed relations between devices: a device with unremarkable flow statistics may still be compromised relative to its ownership, co-location, and social ties. Existing graph-based intrusion detectors discard relation type, while lightweight detectors compre...

Yi-Fan Qin, Zheng Zhao · 0 citations
Open access 2026

Data-Driven Detection of Multi-vector IoT DDoS Attacks across Network Layers

—As cyberattacks targeting Internet of Things (IoT) networks grow more sophisticated, the demand for models capable of accurately detecting and mitigating these threats becomes increasingly urgent existing detection systems often concentrate on a single attack surface which leads to critical blind spots in IoT network...

Rania A. Al-Ali, Mohammad M. Alnabhan, Q. A. Al-Haija · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.