综述异构图神经网络在网络安全异常检测中的应用与挑战
A Survey of Heterogeneous Graph Neural Networks for Cybersecurity Anomaly Detection
- 按异常类型和图动态分类,系统梳理HGNN方法
- 分析主流模型在真实数据集上的检测性能差异
- 适合关注网络安全与图学习交叉研究的学者
异常检测是网络安全中的关键任务,识别内部威胁、访问违规和协同攻击对保障系统韧性至关重要。基于图的方法在建模实体交互方面日益重要,但多数依赖同质且静态结构,难以捕捉真实环境中的异构性和时序演化。异构图神经网络(HGNN)通过引入类型感知变换和关系敏感聚合,提升了复杂网络数据的建模能力。然而当前基于HGNN的异常检测研究分散,建模策略多样,缺乏对比评估与标准化基准。本文系统综述了网络安全领域中HGNN的应用,提出按异常类型与图动态性的分类体系,分析代表性模型并映射至关键应用场景。同时回顾常用基准数据集与评估指标,指出其优劣。最后,识别出建模、数据与部署方面的开放挑战,并展望未来方向。本综述旨在为构建可扩展、可解释、可部署的HGNN异常检测方案奠定基础。
原文摘要 · Abstract (English)
Anomaly detection is a critical task in cybersecurity, where identifying insider threats, access violations, and coordinated attacks is essential for ensuring system resilience. Graph-based approaches have become increasingly important for modeling entity interactions, yet most rely on homogeneous and static structures, which limits their ability to capture the heterogeneity and temporal evolution of real-world environments. Heterogeneous Graph Neural Networks (HGNNs) have emerged as a promising paradigm for anomaly detection by incorporating type-aware transformations and relation-sensitive aggregation, enabling more expressive modeling of complex cyber data. However, current research on HGNN-based anomaly detection remains fragmented, with diverse modeling strategies, limited comparative evaluation, and an absence of standardized benchmarks. To address this gap, we provide a comprehensive survey of HGNN-based anomaly detection methods in cybersecurity. We introduce a taxonomy that classifies approaches by anomaly type and graph dynamics, analyze representative models, and map them to key cybersecurity applications. We also review commonly used benchmark datasets and evaluation metrics, highlighting their strengths and limitations. Finally, we identify key open challenges related to modeling, data, and deployment, and outline promising directions for future research. This survey aims to establish a structured foundation for advancing HGNN-based anomaly detection toward scalable, interpretable, and practically deployable solutions.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。