Explainable Graph Neural Detection of Coordinated Cyber Threats in Dynamic Networks
DOI:
https://doi.org/10.36520/joofin.v1.i1.1Keywords:
graph neural networkAbstract
Coordinated cyber attacks are relational events: multiple hosts, accounts, flows, or processes may participate in attack chains whose structure changes over time. Flat feature classifiers can overlook these dependencies, while graph neural networks often provide limited operational explanations. This paper proposes CipherGraph-X, a temporal graph intrusion-detection framework that combines normalized message passing, short-horizon temporal state reuse, and subgraph-oriented explanation scoring. A controlled dynamic-network benchmark was generated with benign communication, coordinated malicious communities, evolving node features, and time-varying attack connectivity. Three detection strategies were compared: feature-only logistic classification, static graph convolution, and the proposed temporal graph model. CipherGraph-X improved mean F1 over the feature-only baseline and static GCN in the held-out snapshots. A perturbation-based explanation test further showed higher fidelity for subgraph rationales than gradient-only explanations in the controlled setting. The framework is intended to connect detection accuracy with analyst-facing evidence by returning both a threat probability and the influential local graph context. Results are a reproducible proof-of-concept and require validation on operational network datasets before deployment claims can be made.
Downloads
References
[1] M.-H. Zhong, M.-W. Lin, C. Zhang, and Z. Xu, “A survey on graph neural networks for intrusion detection systems: Methods, trends and challenges,” Computers & Security, vol. 141, art. 103821, 2024, doi: 10.1016/j.cose.2024.103821.
[2] B. Sharma, L. Sharma, C. Lal, and S. Roy, “Explainable artificial intelligence for intrusion detection in IoT networks: A deep learning based approach,” Expert Systems with Applications, vol. 238, art. 121751, 2024, doi: 10.1016/j.eswa.2023.121751.
[3] P. Deng and Y. Huang, “Edge-featured multi-hop attention graph neural network for intrusion detection system,” Computers & Security, vol. 148, art. 104132, 2025, doi: 10.1016/j.cose.2024.104132.
[4] S. Wali, Y. A. Farrukh, and I. Khan, “Explainable AI and random forest based reliable intrusion detection system,” Computers & Security, vol. 157, art. 104542, 2025, doi: 10.1016/j.cose.2025.104542.
[5] “Transformer-based knowledge distillation for explainable intrusion detection system,” Computers & Security, vol. 154, art. 104417, 2025, doi: 10.1016/j.cose.2025.104417.
[6] Y. Gao et al., “IR-IDS: A network intrusion detection method based on causal feature selection and explainable model optimization,” Computers & Security, vol. 155, art. 104496, 2025, doi: 10.1016/j.cose.2025.104496.
[7] Y. A. Farrukh, S. Wali, I. Khan, and N. D. Bastian, “XG-NID: Dual-modality network intrusion detection using a heterogeneous graph neural network and large language model,” Expert Systems with Applications, vol. 287, art. 128089, 2025, doi: 10.1016/j.eswa.2025.128089.
[8] M. Soylu and R. Das, “A hybrid graph neural network model for predicting cyber attacks from heterogeneous and dynamic network data,” IEEE Access, vol. 13, pp. 151512–151526, 2025, doi: 10.1109/ACCESS.2025.3603403.
[9] “Multi head self-attention gated graph convolutional network based multi-attack intrusion detection in MANET,” Computers & Security, vol. 136, art. 103526, 2024, doi: 10.1016/j.cose.2023.103526.
[10] A. Abusitta, M. Q. Li, and B. C. M. Fung, “Survey on explainable AI: Techniques, challenges and open issues,” Expert Systems with Applications, vol. 255, art. 124710, 2024, doi: 10.1016/j.eswa.2024.124710.
[11] S. Shoukat, T. Gao, D. Javeed, M. S. Saeed, and M. Adil, “Trust my IDS: An explainable AI integrated deep learning-based transparent threat detection system for industrial networks,” Computers & Security, vol. 149, art. 104191, 2025, doi: 10.1016/j.cose.2024.104191.
[12] E. Amer, S. El-Sappagh, T. Abuhamad, B. A. S. Al-Rimy, and A. Mohasseb, “GraphShield: Advanced dynamic graph-based malware detection using graph neural networks,” Expert Systems with Applications, vol. 298, art. 129812, 2026, doi: 10.1016/j.eswa.2025.129812.
[13] V. Ponzi and C. Napoli, “Graph neural networks: Architectures, applications, and future directions,” IEEE Access, vol. 13, pp. 62870–62891, 2025, doi: 10.1109/ACCESS.2025.3558752.
[14] M. Basak et al., “X-GANet: An explainable graph-based framework for robust network intrusion detection,” Applied Sciences, vol. 15, no. 9, art. 5002, 2025, doi: 10.3390/app15095002.
[15] “Explainable AI-based intrusion detection in IoT systems,” Internet of Things, vol. 31, art. 101589, 2025, doi: 10.1016/j.iot.2025.101589.
[16] M. Soylu and R. Das, “Prediction and graph visualization of cyber attacks using graph attention networks,” Computers & Security, vol. 157, art. 104534, 2025, doi: 10.1016/j.cose.2025.104534.
[17] I. Khan, S. Wali, and Y. A. Farrukh, “RADIANT: Reactive autoencoder defense for industrial adversarial network threats,” Computers & Security, vol. 154, art. 104403, 2025, doi: 10.1016/j.cose.2025.104403.
[18] S. Wali, Y. A. Farrukh, I. Khan, and J. A. Hamilton, “Covert penetrations: Analyzing and defending SCADA systems from stealth and hijacking attacks,” Computers & Security, vol. 156, art. 104449, 2025, doi: 10.1016/j.cose.2025.104449.
[19] J. Hu, M. Ammar, B. Z. Hussain, J. Kim, and I. Khan, “Reinforcement-learning-driven integrated detection and mitigation of UAV GPS spoofing attacks,” IEEE Internet Things J., vol. 12, no. 18, pp. 36926–36941, 2025, doi: 10.1109/JIOT.2025.3579307.
[20] X. Yang and X. Zhao, “A generalizable anomaly detection method in dynamic graphs,” Proc. AAAI Conf. Artif. Intell., vol. 39, no. 20, 2025, doi: 10.1609/aaai.v39i20.35508.
[21] J. Feng and X. Zhao, “Dynamic graph anomaly detection model combining dual behavior contrast,” The European Journal on Artificial Intelligence, vol. 38, no. 4, pp. 617–629, 2025, doi: 10.1177/30504554251347752.
[22] “DIGNN-A: Real-time network intrusion detection with integrated neural networks based on dynamic graph,” Computers, Materials & Continua, vol. 82, no. 1, pp. 817–842, 2025, doi: 10.32604/cmc.2024.057660.
[23] V. Z. Mohale and I. C. Obagbuwa, “Evaluating machine learning-based intrusion detection systems with explainable AI: Enhancing transparency and interpretability,” Frontiers in Computer Science, vol. 7, art. 1520741, 2025, doi: 10.3389/fcomp.2025.1520741.
[24] V. Z. Mohale and I. C. Obagbuwa, “A systematic review on the integration of explainable artificial intelligence in intrusion detection systems,” Frontiers in Artificial Intelligence, vol. 8, art. 1526221, 2025, doi: 10.3389/frai.2025.1526221.
[25] “A survey on the applications of deep learning in network intrusion detection systems to enhance network security,” IEEE Access, 2025, doi: 10.1109/ACCESS.2025.3624952.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Eva Mufida Padilla (Author)

This work is licensed under a Creative Commons Attribution 4.0 International License.