针对物联网网络异构性,提出新型图神经网络融合方法提升入侵检测能力。
Enhanced Feature Extraction for IoT Network Intrusion Detection Using GNNs and KAN

- 设计多尺度选择性注意力机制,自适应提取节点与边特征。
- 在四个基准数据集上优于现有方法,对低频复杂攻击检测准确率更高。
- 适合关注物联网安全、图神经网络优化的研究者与工程师。
物联网(IoT)网络因动态拓扑、流量不均衡和复杂攻击模式,亟需先进网络安全技术。传统基于图神经网络(GNN)的入侵检测方法难以有效建模节点与边特征,且对细粒度异常响应不足。为此,本文提出SKGFusionKAN,将GraphSAGE与多尺度选择性核注意力机制结合,通过边导向的消息传递增强信息传播,利用选择性核注意力自适应加权多尺度边信息以应对异构性。引入门控融合机制动态整合多尺度特征,提升对演化攻击的鲁棒性。最后采用柯尔莫哥洛夫-阿诺德网络(KAN)进行分类,具备更强非线性建模能力,有助于检测复杂低频攻击。在四个NIDS基准数据集上的实验表明,SKGFusionKAN在二分类与多分类任务中均持续优于当前最先进方法,展现了其在物联网安全领域的应用潜力。
原文摘要 · Abstract (English)
Recent advancements in the Internet of Things (IoT) emphasize the urgent need for advanced network security, as IoT networks feature dynamic topologies, imbalanced traffic, and complex attack patterns. Unlike general IT networks, IoT environments exhibit extreme heterogeneity and sparse topologies. Traditional GNN-based intrusion detection methods often struggle to efficiently model node and edge features or capture fine-grained anomalies in such settings. To address this, we propose SKGFusionKAN, a novel IoT-tailored approach enhancing GraphSAGE with a multi-scale selective kernel attention mechanism. This enables adaptive extraction of node and edge features under diverse traffic conditions. Specifically, our edge-oriented message passing strengthens information propagation, while selective kernel attention adaptively weights edge-derived information from different scales to handle heterogeneity. We also introduce a gated fusion process to dynamically integrate multi-scale features, improving robustness against evolving attacks. Finally, we leverage Kolmogorov-Arnold Networks (KAN) for classification, offering superior nonlinear modeling capabilities essential for detecting intricate, low-frequency attacks. To our knowledge, this work presents a comprehensive integration of GNNs and KAN with dedicated architectural innovations for IoT intrusion detection. Extensive experiments on four NIDS benchmarks show that SKGFusionKAN consistently outperforms state-of-the-art approaches in binary and multiclass tasks, demonstrating its potential for IoT security.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。