arXiv:2603. 10676v2 Announce Type: replace Abstract: Industrial Control Systems (ICS) underpin critical infrastructure and face growing cyber-physical threats due to the convergence of operational technology and networked environments.
By Kosti Koistinen, Kirsi Hellsten, Joni Herttuainen, Kimmo K. Kaski
The paper explores whether different cyber‑attack classes produce distinct topological signatures when network traffic is represented as Natural Visibility Graphs (NVGs). Using the CSE‑CIC‑IDS2018 dataset, 76 traffic features were transformed into NVGs over overlapping frames, and 10 graph‑theoretic metrics were extracted, yielding 760 descriptors per frame. A multi‑branch CNN achieved 96.20% accuracy, and statistical tests revealed that 73.1% of attack‑versus‑benign comparisons were significant, with many showing large effect sizes, especially for backward‑traffic and packet‑length features linked to connectivity, clustering, and centrality.
By Ali Melih Kanca, Ilker Turker
arXiv:2511. 22078v2 Announce Type: replace Abstract: Many real-world scenarios involving streaming information can be represented as temporal graphs, where data flows through dynamic changes in edges over time.
By Simone Mungari, Albert Bifet, Giuseppe Manco, Bernhard Pfahringer
The paper introduces FCom‑DICE, a feature‑aware perturbation method that rewires influential edges and adjusts node features to hide a target community from graph neural network (GNN) inference. It shows that concealment effectiveness depends on boundary connectivity and feature similarity, and that FCom‑DICE outperforms structure‑only DICE on synthetic and real networks such as Facebook, Wikipedia, and Bitcoin Transactions while preserving key structural and feature properties.
By Dalyapraz Manatova, Pablo Moriano, L. Jean Camp
Natural Visibility Graph (NVG)-based representations provide a promising approach for capturing structural patterns in sequential network traffic. However, whether different cyber-attack classes exhib...
arXiv:2606. 07857v1 Announce Type: cross Abstract: The rise of edge-based machine learning has enabled distributed adaptation of language models across mobile and IoT devices, offering privacy preservation and real-time responsiveness.
By Stefan Behfar, Richard Mortier
arXiv:2607. 00553v1 Announce Type: cross Abstract: Lightweight machine learning models are increasingly proposed for intrusion detection in Industrial Internet of Things (IIoT) networks due to their suitability for resource-constrained edge deployment.
By MD Azizul Hakim, Md Shihab Uddin, Talha Ibne Anis
The paper investigates whether machine learning models for IoT intrusion detection truly learn attack patterns or rely on dataset shortcuts. Using the CyberFlowIoT-GICAP benchmark, the authors evaluate four learning paradigms across different feature sets and split strategies, finding that performance is largely driven by feature representation and that tree-based models can exploit temporal artifacts. The study also highlights asymmetric attack detectability and proposes a four-point protocol checklist for realistic evaluation.
By Uday Shankar Roy, Mahbuba Jahan Minu
arXiv:2608. 05605v1 Announce Type: cross Abstract: Research and Education Networks (RENs) serve as critical infrastructure for scientific discovery, yet they face a unique security paradox: their normal traffic patterns which are characterized by massive, bursty "elephant flows" are statistically indistinguishable from volumetric attacks such as DDoS to conventional monitoring systems.
By Mohammad Arafath Uddin Shariff, Byrav Ramamurthy
arXiv:2608.22075v2 Announce Type: replace-cross
Abstract: Adversaries now move faster than manual response processes can absorb. The average eCrime breakout time, that is, the interval between initia...
By Alexandre Amaral, Fernando Moro, Ana Malheiro
The paper evaluates how graph neural networks (GNNs) built on control flow graphs (CFGs) perform when trained on one time period and tested on a later one, using a strict temporal split. Twelve GNN variants and a flat-feature baseline were trained on 459 CFGs from 2024‑2025 and evaluated on 223 CFGs from 2026, revealing that the choice of message‑passing operator strongly affects robustness to distribution shift. Attribution stability varied by architecture, and the best-performing operator on the later corpus was also the hardest to explain, leading the authors to design a new architecture that matches its performance without search.
By Md. Asif Sajeed, Md. Nazrul Islam Mondal, Md Ashraful Hossen Akash
The study compares XGBoost and RoBERTa‑LoRA for network intrusion detection across three evaluation axes: same‑dataset performance, cross‑dataset transfer, and adversarial evasion. Both models perform similarly on the same dataset, but XGBoost outperforms RoBERTa‑LoRA by 15 F1 points and 25 balanced accuracy points when transferred to a different network, while RoBERTa‑LoRA wins by about 17 F1 points under adversarial evasion. Feature‑leakage ablation shows that cross‑dataset transfer improvements are non‑monotonic and directional, suggesting leakage is spread across features rather than isolated.
"whyItMatters":"The findings demonstrate that a model’s superiority depends on the specific robustness axis evaluated, underscoring the need for multi‑axis, multi‑metric testing in network intrusion detection research."
By Muhammad Ebad Atif, Muhammad Haider Ali