{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,20]],"date-time":"2026-05-20T22:06:02Z","timestamp":1779314762483,"version":"3.51.4"},"reference-count":46,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004608","name":"Jiangsu Province Natural Science Foundation","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100004608","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Computer Networks"],"published-print":{"date-parts":[[2026,7]]},"DOI":"10.1016\/j.comnet.2026.112389","type":"journal-article","created":{"date-parts":[[2026,5,20]],"date-time":"2026-05-20T18:03:27Z","timestamp":1779300207000},"page":"112389","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["FSG-NID: Early network intrusion detection via flow segment graph analysis"],"prefix":"10.1016","volume":"285","author":[{"given":"Bayi","family":"Xu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4172-1977","authenticated-orcid":false,"given":"Xiaoyan","family":"Hu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Guang","family":"Cheng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9905-8952","authenticated-orcid":false,"given":"Ruidong","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8829-0182","authenticated-orcid":false,"given":"Hua","family":"Wu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/j.comnet.2026.112389_b1","doi-asserted-by":"crossref","DOI":"10.1016\/j.jnca.2020.102767","article-title":"Deep learning methods in network intrusion detection: A survey and an objective comparison","volume":"169","author":"Gamage","year":"2020","journal-title":"J. Netw. Comput. Appl."},{"key":"10.1016\/j.comnet.2026.112389_b2","doi-asserted-by":"crossref","first-page":"7783","DOI":"10.1109\/TIFS.2024.3441862","article-title":"Early network intrusion detection enabled by attention mechanisms and RNNs","volume":"19","author":"Djaidja","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112389_b3","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.103821","article-title":"A survey on graph neural networks for intrusion detection systems: Methods, trends and challenges","volume":"141","author":"Zhong","year":"2024","journal-title":"Comput. Secur."},{"issue":"12","key":"10.1016\/j.comnet.2026.112389_b4","doi-asserted-by":"crossref","first-page":"10859","DOI":"10.1007\/s13369-020-04907-7","article-title":"An improved intrusion detection system based on KNN hyperparameter tuning and cross-validation","volume":"45","author":"Wazirali","year":"2020","journal-title":"Arab. J. Sci. Eng."},{"key":"10.1016\/j.comnet.2026.112389_b5","doi-asserted-by":"crossref","first-page":"130","DOI":"10.1016\/j.knosys.2017.09.014","article-title":"An effective intrusion detection framework based on SVM with feature augmentation","volume":"136","author":"Wang","year":"2017","journal-title":"Knowl.-Based Syst."},{"key":"10.1016\/j.comnet.2026.112389_b6","doi-asserted-by":"crossref","unstructured":"B. Ingre, A. Yadav, A.K. Soni, Decision tree based intrusion detection system for NSL-KDD dataset, in: Proc. Int. Conf. Inf. Commun. Technol. Intell. Syst., 2017, pp. 207\u2013218.","DOI":"10.1007\/978-3-319-63645-0_23"},{"key":"10.1016\/j.comnet.2026.112389_b7","doi-asserted-by":"crossref","first-page":"386","DOI":"10.1016\/j.ins.2019.10.069","article-title":"A hybrid deep learning model for efficient intrusion detection in big data environment","volume":"513","author":"Hassan","year":"2020","journal-title":"Inf. Sci."},{"key":"10.1016\/j.comnet.2026.112389_b8","doi-asserted-by":"crossref","first-page":"170","DOI":"10.1016\/j.comcom.2023.04.018","article-title":"CANET: A hierarchical CNN-attention model for network intrusion detection","volume":"205","author":"Ren","year":"2023","journal-title":"Comput. Commun."},{"issue":"4","key":"10.1016\/j.comnet.2026.112389_b9","first-page":"2705","article-title":"Enhancing IoT intrusion detection system with modified E-GraphSAGE: a graph neural network approach","volume":"16","author":"Mirlashari","year":"2024","journal-title":"Int. J. Inf. Technol."},{"issue":"5","key":"10.1016\/j.comnet.2026.112389_b10","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s10586-025-05100-x","article-title":"An edge-enhanced GraphSAGE-based intrusion detection model for the internet of things","volume":"28","author":"Li","year":"2025","journal-title":"Clust. Comput."},{"key":"10.1016\/j.comnet.2026.112389_b11","doi-asserted-by":"crossref","unstructured":"M. Wang, N. Yang, N. Weng, Exploring the impact of early detection on DL-based NIDSs models, in: Proc. IEEE Ubiquitous Computing, Electronics & Mobile Communication Conf., UEMCON, 2023, pp. 0684\u20130691.","DOI":"10.1109\/UEMCON59035.2023.10316123"},{"key":"10.1016\/j.comnet.2026.112389_b12","doi-asserted-by":"crossref","first-page":"7147","DOI":"10.1109\/TIFS.2024.3431932","article-title":"K-GetNID: Knowledge-guided graphs for early and transferable network intrusion detection","volume":"19","author":"Wang","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112389_b13","doi-asserted-by":"crossref","unstructured":"T. Ahmad, D. Truscan, J. Vain, I. Porres, Early Detection of Network Attacks Using Deep Learning, in: Proc. IEEE Int. Conf. Softw. Test., Verif. Valid. Workshops, ICST Workshops, 2022, pp. 30\u201339.","DOI":"10.1109\/ICSTW55395.2022.00020"},{"key":"10.1016\/j.comnet.2026.112389_b14","doi-asserted-by":"crossref","first-page":"68588","DOI":"10.1109\/ACCESS.2023.3291686","article-title":"On early detection of anomalous network flows","volume":"11","author":"Fox","year":"2023","journal-title":"IEEE Access"},{"key":"10.1016\/j.comnet.2026.112389_b15","doi-asserted-by":"crossref","unstructured":"I. Guarino, G. Bovenzi, D. Di Monda, G. Aceto, D. Ciuonzo, A. Pescap\u2019e, On the use of machine learning approaches for the early classification in network intrusion detection, in: Proc. IEEE Int. Symp. Measurements & Networking, M&N, 2022, pp. 1\u20136.","DOI":"10.1109\/MN55117.2022.9887775"},{"key":"10.1016\/j.comnet.2026.112389_b16","doi-asserted-by":"crossref","unstructured":"M.M. Islam, T. Ahmad, D. Truscan, An Evaluation of Transformer Models for Early Intrusion Detection in Cloud Continuum, in: Proc. IEEE Int. Conf. Cloud Comput. Technol. Sci., CloudCom, 2023, pp. 279\u2013284.","DOI":"10.1109\/CloudCom59040.2023.00052"},{"key":"10.1016\/j.comnet.2026.112389_b17","doi-asserted-by":"crossref","unstructured":"T. Ahmad, D. Truscan, Early Detection with Explainability of Network Attacks Using Deep Learning, in: Proc. IEEE Int. Conf. Softw. Testing, Verification and Validation Workshops, ICSTW, 2024, pp. 161\u2013167.","DOI":"10.1109\/ICSTW60967.2024.00040"},{"key":"10.1016\/j.comnet.2026.112389_b18","doi-asserted-by":"crossref","first-page":"2367","DOI":"10.1109\/TIFS.2021.3050608","article-title":"Accurate decentralized application identification via encrypted traffic analysis using graph neural networks","volume":"16","author":"Shen","year":"2021","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112389_b19","doi-asserted-by":"crossref","unstructured":"Z. Hu, B. Qu, X. Li, C. Li, An Encrypted Traffic Classification Framework Based on Higher-Interaction-Graph Neural Network, in: Proc. Australas. Conf. Inf. Secur. Privacy, 2024, pp. 383\u2013403.","DOI":"10.1007\/978-981-97-5101-3_21"},{"key":"10.1016\/j.comnet.2026.112389_b20","doi-asserted-by":"crossref","first-page":"4892","DOI":"10.1109\/TCE.2025.3548798","article-title":"FIR-GNN: A graph neural network using flow interaction relationships for intrusion detection of consumer electronics in smart home network","volume":"71","author":"Fu","year":"2025","journal-title":"IEEE Trans. Consum. Electron."},{"key":"10.1016\/j.comnet.2026.112389_b21","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2022.102861","article-title":"Comparative research on network intrusion detection methods based on machine learning","volume":"121","author":"Zhang","year":"2022","journal-title":"Comput. Secur."},{"issue":"1","key":"10.1016\/j.comnet.2026.112389_b22","article-title":"PCM-RF: a hybrid feature selection mechanism for intrusion detection system in IoT","volume":"8","author":"Ahmed","year":"2025","journal-title":"Secur. Priv."},{"key":"10.1016\/j.comnet.2026.112389_b23","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103598","article-title":"Designing accurate lightweight intrusion detection systems for IoT networks using fine-tuned linear SVM and feature selectors","volume":"137","author":"Azimjonov","year":"2024","journal-title":"Comput. Secur."},{"issue":"2","key":"10.1016\/j.comnet.2026.112389_b24","article-title":"SA-ResNet: An intrusion detection method based on spatial attention mechanism and residual neural network fusion","volume":"83","author":"Cai","year":"2025","journal-title":"Comput. Mater. Contin."},{"key":"10.1016\/j.comnet.2026.112389_b25","doi-asserted-by":"crossref","DOI":"10.1016\/j.iot.2025.101624","article-title":"A lightweight hybrid approach for intrusion detection systems using a chi-square feature selection approach in IoT","volume":"32","author":"Benaddi","year":"2025","journal-title":"Internet Things"},{"issue":"6","key":"10.1016\/j.comnet.2026.112389_b26","doi-asserted-by":"crossref","first-page":"493","DOI":"10.1007\/s11760-025-04083-x","article-title":"Multi-classification algorithm based on graph convolutional neural network for intrusion detection","volume":"19","author":"Du","year":"2025","journal-title":"Signal, Image Video Process."},{"key":"10.1016\/j.comnet.2026.112389_b27","doi-asserted-by":"crossref","unstructured":"Y. Shen, J. Tao, L. Yu, Y. Luo, EAMTI: A Novel Method Toward Early and Accurate Malicious Traffic Identification, in: Proc. IFIP Int. Conf. Netw. Parallel Comput., 2024, pp. 417\u2013429.","DOI":"10.1007\/978-981-96-2864-3_33"},{"key":"10.1016\/j.comnet.2026.112389_b28","unstructured":"K. Xu, W. Hu, J. Leskovec, S. Jegelka, How Powerful are Graph Neural Networks?, in: Proc. Int. Conf. Learn. Represent., ICLR, 2019."},{"issue":"13","key":"10.1016\/j.comnet.2026.112389_b29","doi-asserted-by":"crossref","first-page":"5941","DOI":"10.3390\/s23135941","article-title":"CICIoT2023: A real-time dataset and benchmark for large-scale attacks in IoT environment","volume":"23","author":"Neto","year":"2023","journal-title":"Sensors"},{"key":"10.1016\/j.comnet.2026.112389_b30","doi-asserted-by":"crossref","unstructured":"I. Sharafaldin, A.H. Lashkari, S. Hakak, A.A. Ghorbani, Developing realistic distributed denial of service (DDoS) attack dataset and taxonomy, in: Proc. Int. Carnahan Conf. Secur. Technol., ICCST, 2019, pp. 1\u20138.","DOI":"10.1109\/CCST.2019.8888419"},{"key":"10.1016\/j.comnet.2026.112389_b31","doi-asserted-by":"crossref","unstructured":"I. Sharafaldin, A.H. Lashkari, A.A. Ghorbani, Toward generating a new intrusion detection dataset and intrusion traffic characterization, in: Proc. Int. Conf. Inf. Syst. Secur. Privacy, ICISSP, 2018, pp. 108\u2013116.","DOI":"10.5220\/0006639801080116"},{"key":"10.1016\/j.comnet.2026.112389_b32","doi-asserted-by":"crossref","unstructured":"J. Sinha, M. Manollas, Efficient deep CNN-BiLSTM model for network intrusion detection, in: Proc. Int. Conf. Artif. Intell. Pattern Recognit., 2020, pp. 223\u2013231.","DOI":"10.1145\/3430199.3430224"},{"key":"10.1016\/j.comnet.2026.112389_b33","doi-asserted-by":"crossref","DOI":"10.1016\/j.iot.2023.100699","article-title":"A deep learning approach for intrusion detection in internet of things using focal loss function","volume":"22","author":"Dina","year":"2023","journal-title":"Internet Things"},{"issue":"11","key":"10.1016\/j.comnet.2026.112389_b34","article-title":"Visualizing data using t-SNE","volume":"9","author":"Van der Maaten","year":"2008","journal-title":"J. Mach. Learn. Res."},{"key":"10.1016\/j.comnet.2026.112389_b35","unstructured":"T.N. Kipf, M. Welling, Semi-Supervised Classification with Graph Convolutional Networks, in: Proc. Int. Conf. Learn. Represent., ICLR, 2017, pp. 1\u201314."},{"key":"10.1016\/j.comnet.2026.112389_b36","unstructured":"P. Velickovic, G. Cucurull, A. Casanova, A. Romero, P. Li\u00f2, Y. Bengio, Graph Attention Networks, in: Proc. Int. Conf. Learn. Represent., ICLR, 2018, pp. 1\u201312."},{"key":"10.1016\/j.comnet.2026.112389_b37","first-page":"1024","article-title":"Inductive representation learning on large graphs","author":"Hamilton","year":"2017","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.comnet.2026.112389_b38","doi-asserted-by":"crossref","first-page":"9289","DOI":"10.1109\/TIFS.2025.3601396","article-title":"Traffic2Chain: Revealing covert multi-step attacks through unsupervised traffic behaviour correlation","volume":"20","author":"Xie","year":"2025","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112389_b39","doi-asserted-by":"crossref","DOI":"10.1109\/TIFS.2025.3574971","article-title":"Respond to change with constancy: Instruction-tuning with LLM for non-IID network traffic classification","author":"Lin","year":"2025","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112389_b40","doi-asserted-by":"crossref","first-page":"1475","DOI":"10.1109\/TIFS.2025.3530702","article-title":"TCG-IDS: Robust network intrusion detection via temporal contrastive graph learning","volume":"20","author":"Wu","year":"2025","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112389_b41","doi-asserted-by":"crossref","first-page":"3204","DOI":"10.1109\/TIFS.2025.3551643","article-title":"A-NIDS: Adaptive network intrusion detection system based on clustering and stacked CTGAN","volume":"20","author":"Zha","year":"2025","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112389_b42","doi-asserted-by":"crossref","unstructured":"X. Zhang, R. Zhao, Z. Jiang, H. Chen, Y. Ding, E.C.H. Ngai, S.-H. Yang, Continual Learning with Strategic Selection and Forgetting for Network Intrusion Detection, in: IEEE INFOCOM 2025-IEEE Conf. Comput. Commun., 2025, pp. 1\u201310.","DOI":"10.1109\/INFOCOM55648.2025.11044615"},{"issue":"2","key":"10.1016\/j.comnet.2026.112389_b43","doi-asserted-by":"crossref","first-page":"1118","DOI":"10.1109\/TDSC.2024.3429271","article-title":"Wafbooster: Automatic boosting of WAF security against mutated malicious payloads","volume":"22","author":"Wu","year":"2024","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"10.1016\/j.comnet.2026.112389_b44","doi-asserted-by":"crossref","first-page":"2157","DOI":"10.1109\/TIFS.2025.3537827","article-title":"Vulseye: Detect smart contract vulnerabilities via stateful directed graybox fuzzing","volume":"20","author":"Liang","year":"2025","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112389_b45","doi-asserted-by":"crossref","first-page":"6441","DOI":"10.1109\/TIFS.2024.3413592","article-title":"Rethinking membership inference attacks against transfer learning","volume":"19","author":"Wu","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"11","key":"10.1016\/j.comnet.2026.112389_b46","doi-asserted-by":"crossref","first-page":"20705","DOI":"10.1109\/TITS.2025.3587750","article-title":"DATI-IDS: domain adaptation and time-series imaging-based intrusion detection system for connected autonomous vehicles","volume":"26","author":"Tan","year":"2025","journal-title":"IEEE Trans. Intell. Transp. Syst."}],"container-title":["Computer Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1389128626004019?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1389128626004019?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,5,20]],"date-time":"2026-05-20T21:15:11Z","timestamp":1779311711000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S1389128626004019"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7]]},"references-count":46,"alternative-id":["S1389128626004019"],"URL":"https:\/\/doi.org\/10.1016\/j.comnet.2026.112389","relation":{},"ISSN":["1389-1286"],"issn-type":[{"value":"1389-1286","type":"print"}],"subject":[],"published":{"date-parts":[[2026,7]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"FSG-NID: Early network intrusion detection via flow segment graph analysis","name":"articletitle","label":"Article Title"},{"value":"Computer Networks","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.comnet.2026.112389","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"112389"}}