arXiv Machine Learning

Concept drift mitigation through community and spectral graph analysis for the detection of cyberattacks in network traffic

arXiv AI
Sep 24

Topological Signatures of Cyber-Attack Classes in Natural Visibility Graph Representations of Network Traffic

The paper explores whether different cyber‑attack classes produce distinct topological signatures when network traffic is represented as Natural Visibility Graphs (NVGs). Using the CSE‑CIC‑IDS2018 dataset, 76 traffic features were transformed into NVGs over overlapping frames, and 10 graph‑theoretic metrics were extracted, yielding 760 descriptors per frame. A multi‑branch CNN achieved 96.20% accuracy, and statistical tests revealed that 73.1% of attack‑versus‑benign comparisons were significant, with many showing large effect sizes, especially for backward‑traffic and packet‑length features linked to connectivity, clustering, and centrality.

By Ali Melih Kanca, Ilker Turker
arXiv Machine Learning
Jul 31

ARES: Anomaly Recognition Model For Edge Streams

arXiv:2511. 22078v2 Announce Type: replace Abstract: Many real-world scenarios involving streaming information can be represented as temporal graphs, where data flows through dynamic changes in edges over time.

By Simone Mungari, Albert Bifet, Giuseppe Manco, Bernhard Pfahringer
arXiv Machine Learning
Aug 19

Community Concealment from Graph Neural Networks

The paper introduces FCom‑DICE, a feature‑aware perturbation method that rewires influential edges and adjusts node features to hide a target community from graph neural network (GNN) inference. It shows that concealment effectiveness depends on boundary connectivity and feature similarity, and that FCom‑DICE outperforms structure‑only DICE on synthetic and real networks such as Facebook, Wikipedia, and Bitcoin Transactions while preserving key structural and feature properties.

By Dalyapraz Manatova, Pablo Moriano, L. Jean Camp
arXiv Machine Learning
Sep 25

Unmasking Shortcut Learning in IoT Intrusion Detection: A Forensic, Multi-Paradigm Evaluation of Feature Dependence and Data Leakage

The paper investigates whether machine learning models for IoT intrusion detection truly learn attack patterns or rely on dataset shortcuts. Using the CyberFlowIoT-GICAP benchmark, the authors evaluate four learning paradigms across different feature sets and split strategies, finding that performance is largely driven by feature representation and that tree-based models can exploit temporal artifacts. The study also highlights asymmetric attack detectability and proposes a four-point protocol checklist for realistic evaluation.

By Uday Shankar Roy, Mahbuba Jahan Minu
arXiv Machine Learning
Aug 7

Enhancing Anomaly Resilience in Research Networks: A Large-Scale Forecasting Benchmark for Dynamic Security Baselining

arXiv:2608. 05605v1 Announce Type: cross Abstract: Research and Education Networks (RENs) serve as critical infrastructure for scientific discovery, yet they face a unique security paradox: their normal traffic patterns which are characterized by massive, bursty "elephant flows" are statistically indistinguishable from volumetric attacks such as DDoS to conventional monitoring systems.

By Mohammad Arafath Uddin Shariff, Byrav Ramamurthy
arXiv Machine Learning
Sep 22

Temporal Generalization and Explanation Stability of Control Flow Graph Neural Networks for Malware Detection

The paper evaluates how graph neural networks (GNNs) built on control flow graphs (CFGs) perform when trained on one time period and tested on a later one, using a strict temporal split. Twelve GNN variants and a flat-feature baseline were trained on 459 CFGs from 2024‑2025 and evaluated on 223 CFGs from 2026, revealing that the choice of message‑passing operator strongly affects robustness to distribution shift. Attribution stability varied by architecture, and the best-performing operator on the later corpus was also the hardest to explain, leading the authors to design a new architecture that matches its performance without search.

By Md. Asif Sajeed, Md. Nazrul Islam Mondal, Md Ashraful Hossen Akash
arXiv AI
Sep 15

A Three-Axis Stress Test of LLM vs Classical ML for Network Intrusion Detection under Distribution Shift and Adversarial Evasion

The study compares XGBoost and RoBERTa‑LoRA for network intrusion detection across three evaluation axes: same‑dataset performance, cross‑dataset transfer, and adversarial evasion. Both models perform similarly on the same dataset, but XGBoost outperforms RoBERTa‑LoRA by 15 F1 points and 25 balanced accuracy points when transferred to a different network, while RoBERTa‑LoRA wins by about 17 F1 points under adversarial evasion. Feature‑leakage ablation shows that cross‑dataset transfer improvements are non‑monotonic and directional, suggesting leakage is spread across features rather than isolated. "whyItMatters":"The findings demonstrate that a model’s superiority depends on the specific robustness axis evaluated, underscoring the need for multi‑axis, multi‑metric testing in network intrusion detection research."

By Muhammad Ebad Atif, Muhammad Haider Ali