Concept drift mitigation through community and spectral graph analysis for the detection of cyberattacks in network traffic
Read the original on arXiv Machine Learning →The Flow has not summarised this story yet — read it at arXiv Machine Learning.
The Flow has not summarised this story yet — read it at arXiv Machine Learning.
arXiv:2603. 10676v2 Announce Type: replace Abstract: Industrial Control Systems (ICS) underpin critical infrastructure and face growing cyber-physical threats due to the convergence of operational technology and networked environments.
The paper explores whether different cyber‑attack classes produce distinct topological signatures when network traffic is represented as Natural Visibility Graphs (NVGs). Using the CSE‑CIC‑IDS2018 dataset, 76 traffic features were transformed into NVGs over overlapping frames, and 10 graph‑theoretic metrics were extracted, yielding 760 descriptors per frame. A multi‑branch CNN achieved 96.20% accuracy, and statistical tests revealed that 73.1% of attack‑versus‑benign comparisons were significant, with many showing large effect sizes, especially for backward‑traffic and packet‑length features linked to connectivity, clustering, and centrality.
arXiv:2511. 22078v2 Announce Type: replace Abstract: Many real-world scenarios involving streaming information can be represented as temporal graphs, where data flows through dynamic changes in edges over time.
The paper introduces FCom‑DICE, a feature‑aware perturbation method that rewires influential edges and adjusts node features to hide a target community from graph neural network (GNN) inference. It shows that concealment effectiveness depends on boundary connectivity and feature similarity, and that FCom‑DICE outperforms structure‑only DICE on synthetic and real networks such as Facebook, Wikipedia, and Bitcoin Transactions while preserving key structural and feature properties.
Natural Visibility Graph (NVG)-based representations provide a promising approach for capturing structural patterns in sequential network traffic. However, whether different cyber-attack classes exhib...
arXiv:2606. 07857v1 Announce Type: cross Abstract: The rise of edge-based machine learning has enabled distributed adaptation of language models across mobile and IoT devices, offering privacy preservation and real-time responsiveness.