Topological Signatures of Cyber-Attack Classes in Natural Visibility Graph Representations of Network Traffic
Read the original on Hugging Face Trending Papers →The Flow has not summarised this story yet — read it at Hugging Face Trending Papers.
The Flow has not summarised this story yet — read it at Hugging Face Trending Papers.
The paper explores whether different cyber‑attack classes produce distinct topological signatures when network traffic is represented as Natural Visibility Graphs (NVGs). Using the CSE‑CIC‑IDS2018 dataset, 76 traffic features were transformed into NVGs over overlapping frames, and 10 graph‑theoretic metrics were extracted, yielding 760 descriptors per frame. A multi‑branch CNN achieved 96.20% accuracy, and statistical tests revealed that 73.1% of attack‑versus‑benign comparisons were significant, with many showing large effect sizes, especially for backward‑traffic and packet‑length features linked to connectivity, clustering, and centrality.
arXiv:2606. 17109v1 Announce Type: cross Abstract: Given their effectiveness in modeling the relational structure among network traffic flows, graph neural networks (GNNs) have been widely adopted in network intrusion detection systems (NIDSs).
arXiv:2609.09442v2 Announce Type: replace-cross Abstract: In network traffic, legitimate behaviours and attack techniques evolve jointly - the phenomenon known as 'concept drift' [1]. Every detector...
arXiv:2608. 13575v1 Announce Type: cross Abstract: Recent machine learning (ML) advances have demonstrated that deep learning (DL) achieves impressive results in different application domains, including the classification of computer network traffic to corresponding applications.
arXiv:2512. 22179v3 Announce Type: replace Abstract: Detecting previously unseen attacks remains a major challenge for machine learning-based intrusion detection systems.
The paper introduces FCom‑DICE, a feature‑aware perturbation method that rewires influential edges and adjusts node features to hide a target community from graph neural network (GNN) inference. It shows that concealment effectiveness depends on boundary connectivity and feature similarity, and that FCom‑DICE outperforms structure‑only DICE on synthetic and real networks such as Facebook, Wikipedia, and Bitcoin Transactions while preserving key structural and feature properties.