Defending Network Intrusion Detection Systems Based on Graph Neural Networks Against Structural Adversarial Attacks

📅 2026-08-25
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文提出一种基于对抗训练的防御框架,通过生成对抗样本来增强图神经网络在网络安全入侵检测系统中对结构对抗攻击的鲁棒性。
📝 Abstract
Graph Neural Networks (GNNs) represent a promising solution for Machine Learning (ML) based Network Intrusion Detection Systems (NIDS), thanks to their ability to leverage both network flow features and topological patterns. While GNN classifiers demonstrate superior robustness against feature-based adversarial attacks compared to other ML detectors, they remain vulnerable to structural adversarial attacks, where an attacker perturbs the underlying network graph topology by injecting edges or inserting nodes. Such attacks pose a realistic and severe threat, undermining the reliability of GNN-based NIDS in practical deployments. While countermeasures have been proposed in the literature, they often rely on assumptions that are unrealistic in real-world cybersecurity scenarios. In this paper, we propose a defense framework based on adversarial training to strengthen GNN-based NIDS against structural attacks. We generate adversarial samples by strategically replacing the source and destination nodes in benign network flows, thereby efficiently mimicking edge injection attacks. We evaluate our approach on two widely used datasets (CTU-13 and TON-IoT) using E-GraphSAGE as the base GNN classifier. Experimental results show that our approach produces hardened detectors with superior detection performance on clean graphs and enhanced robustness against structural adversarial attacks.
Problem

Research questions and friction points this paper is trying to address.

Graph Neural Networks
Network Intrusion Detection Systems
Structural Adversarial Attacks
Adversarial Training
Innovation

Methods, ideas, or system contributions that make the work stand out.

adversarial training
structural adversarial attacks
GNN-based NIDS
edge injection attacks
robustness
🔎 Similar Papers
No similar papers found.
D
Dimitri Galli
Department of Engineering "Enzo Ferrari", University of Modena and Reggio Emilia, Modena, Italy
A
Andrea Venturi
Department of Digital Security, Vicomtech, San Sebastián, Spain
D
Dario Stabili
Department of Engineering "Enzo Ferrari", University of Modena and Reggio Emilia, Modena, Italy
Mauro Andreolini
Mauro Andreolini
Department of Engineering "Enzo Ferrari", University of Modena and Reggio Emilia, Modena, Italy
Mirco Marchetti
Mirco Marchetti
University of Modena and Reggio Emilia
Automotive securityIntrusion detectionNetwork securityCloud securitySystem security