The paper explores whether different cyber‑attack classes produce distinct topological signatures when network traffic is represented as Natural Visibility Graphs (NVGs). Using the CSE‑CIC‑IDS2018 dataset, 76 traffic features were transformed into NVGs over overlapping frames, and 10 graph‑theoretic metrics were extracted, yielding 760 descriptors per frame. A multi‑branch CNN achieved 96.20% accuracy, and statistical tests revealed that 73.1% of attack‑versus‑benign comparisons were significant, with many showing large effect sizes, especially for backward‑traffic and packet‑length features linked to connectivity, clustering, and centrality.
By Ali Melih Kanca, Ilker Turker
arXiv:2606. 17109v1 Announce Type: cross Abstract: Given their effectiveness in modeling the relational structure among network traffic flows, graph neural networks (GNNs) have been widely adopted in network intrusion detection systems (NIDSs).
By Jianli Dai, Guangwei Wu, Jiacheng Li, Weiping Wang, An He, Xinjun Xiao
arXiv:2609.09442v2 Announce Type: replace-cross
Abstract: In network traffic, legitimate behaviours and attack techniques evolve jointly - the phenomenon known as 'concept drift' [1]. Every detector...
By Julien Michel, Abdul Qadir Khan, Majed Jaber, Pierre Parrend
arXiv:2608. 13575v1 Announce Type: cross Abstract: Recent machine learning (ML) advances have demonstrated that deep learning (DL) achieves impressive results in different application domains, including the classification of computer network traffic to corresponding applications.
By Igor Cherepanov, David Sessler, Alex Ulmer, Felix Wagner, Throsten May, J\"orn Kohlhammer
arXiv:2512. 22179v3 Announce Type: replace Abstract: Detecting previously unseen attacks remains a major challenge for machine learning-based intrusion detection systems.
By Rajeeb Thapa Chhetri, Saurab Thapa, Avinash Kumar, Zhixiong Chen
The paper introduces FCom‑DICE, a feature‑aware perturbation method that rewires influential edges and adjusts node features to hide a target community from graph neural network (GNN) inference. It shows that concealment effectiveness depends on boundary connectivity and feature similarity, and that FCom‑DICE outperforms structure‑only DICE on synthetic and real networks such as Facebook, Wikipedia, and Bitcoin Transactions while preserving key structural and feature properties.
By Dalyapraz Manatova, Pablo Moriano, L. Jean Camp
arXiv:2606. 06342v1 Announce Type: cross Abstract: Topological Data Analysis (TDA) offers a principled, intrinsic lens for comparing neural representations.
By Yan Wang, Tianyang Hu
arXiv:2609.17061v1 Announce Type: cross
Abstract: Message-passing Graph Neural Networks (GNNs) iteratively propagate and aggregate local neighborhood information followed by global readout to learn g...
By Sanyam Sanjay Jain, Anshika Krishnatray, Aditya Sharma, Vinti Agarwal
Message-passing Graph Neural Networks (GNNs) iteratively propagate and aggregate local neighborhood information followed by global readout to learn graph representations. However, their discriminative...
arXiv:2511. 22078v2 Announce Type: replace Abstract: Many real-world scenarios involving streaming information can be represented as temporal graphs, where data flows through dynamic changes in edges over time.
By Simone Mungari, Albert Bifet, Giuseppe Manco, Bernhard Pfahringer
arXiv:2606. 08067v1 Announce Type: new Abstract: Graph neural networks (GNNs) are widely deployed on relational data, yet they can leak sensitive or proprietary information about the training graph adjacency, e.
By Zhanke Zhou, Bo Han, Xuan Li, Jiangchao Yao, Sanmi Koyejo, Michael K. Ng
arXiv:2608.30745v1 Announce Type: new
Abstract: The widespread adoption of encrypted traffic poses severe challenges to current security situational awareness systems based on network traffic monitor...
By Ze Chen, Qiming Yu, Zijia Song, Guozheng Yang, Wei Yan