{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,8]],"date-time":"2026-06-08T13:01:38Z","timestamp":1780923698759,"version":"3.54.1"},"reference-count":43,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Computer Networks"],"published-print":{"date-parts":[[2026,7]]},"DOI":"10.1016\/j.comnet.2026.112418","type":"journal-article","created":{"date-parts":[[2026,5,25]],"date-time":"2026-05-25T23:17:41Z","timestamp":1779751061000},"page":"112418","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["ATHGID: Two-stage graph intrusion detection via attention-fused network-host feature and producer\u2013consumer parallelization"],"prefix":"10.1016","volume":"285","author":[{"given":"Junru","family":"Chen","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7508-2635","authenticated-orcid":false,"given":"Jue","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-9456-8936","authenticated-orcid":false,"given":"Henghua","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Haidong","family":"Peng","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"issue":"1","key":"10.1016\/j.comnet.2026.112418_b1","doi-asserted-by":"crossref","first-page":"1334","DOI":"10.1109\/TCE.2023.3328552","article-title":"Traffic intrusion detection of medical consumption electronics in the field of medical management based on integrated learning","volume":"70","author":"Sun","year":"2024","journal-title":"IEEE Trans. Consum. Electron."},{"issue":"5","key":"10.1016\/j.comnet.2026.112418_b2","doi-asserted-by":"crossref","first-page":"4059","DOI":"10.1109\/JIOT.2022.3203249","article-title":"A survey on IoT intrusion detection: Federated learning, game theory, social psychology, and explainable AI as future directions","volume":"10","author":"Arisdakessian","year":"2023","journal-title":"IEEE Internet Things J."},{"issue":"2","key":"10.1016\/j.comnet.2026.112418_b3","article-title":"An explainable and adaptive internet of things intrusion detection system supported by large language models","volume":"163","author":"Huang","year":"2026","journal-title":"Eng. Appl. Artif. Intell."},{"key":"10.1016\/j.comnet.2026.112418_b4","series-title":"ICC 2023-IEEE International Conference on Communications","first-page":"3006","article-title":"A method for network intrusion detection using flow sequence and BERT framework","author":"Nguyen","year":"2023"},{"key":"10.1016\/j.comnet.2026.112418_b5","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2025.111341","article-title":"RLFE-IDS: A framework of intrusion detection system based on retrieval augmented generation and large language model","volume":"268","author":"Li","year":"2025","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112418_b6","article-title":"LLM-powered threat intelligence: Proactive detection of zero-day attacks in electric vehicle cyber-physical systems","volume":"43","author":"Tirulo","year":"2025","journal-title":"Sustain. Energy Grids & Netw."},{"issue":"5","key":"10.1016\/j.comnet.2026.112418_b7","doi-asserted-by":"crossref","first-page":"2584","DOI":"10.1109\/TPAMI.2023.3303431","article-title":"Parallel and distributed graph neural networks: An in-depth concurrency analysis","volume":"46","author":"Besta","year":"2024","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"10.1016\/j.comnet.2026.112418_b8","article-title":"RHNN-IoT: A robust IoT intrusion detection framework based on reinforced hypergraph representation learning","volume":"176","author":"Li","year":"2026","journal-title":"Future Gener. Comput. Syst. - Int. J. eScience"},{"issue":"C","key":"10.1016\/j.comnet.2026.112418_b9","article-title":"PHO-HGNN: Hypergraph neural network based on persistent homology optimization for class-imbalanced intrusion detection","volume":"330","author":"Gao","year":"2025","journal-title":"Knowl.-Based Syst."},{"key":"10.1016\/j.comnet.2026.112418_b10","doi-asserted-by":"crossref","DOI":"10.1016\/j.engappai.2025.110851","article-title":"An adaptive graph neural network-based intrusion detection system for airborne network","volume":"152","author":"Liu","year":"2025","journal-title":"Eng. Appl. Artif. Intell."},{"key":"10.1016\/j.comnet.2026.112418_b11","series-title":"2022 IEEE Global Communications Conference","first-page":"2662","article-title":"Collaborative feature maps of networks and hosts for AI-driven intrusion detection","author":"Liu","year":"2022"},{"key":"10.1016\/j.comnet.2026.112418_b12","series-title":"ICC 2023-IEEE International Conference on Communications","first-page":"4558","article-title":"Knowledge-based zero-touch security under host and network flow features merger","author":"Shen","year":"2023"},{"key":"10.1016\/j.comnet.2026.112418_b13","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2024.110576","article-title":"Machine learning-enabled hybrid intrusion detection system with host data transformation and an advanced two-stage classifier","volume":"250","author":"Chen","year":"2024","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112418_b14","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2025.111552","article-title":"Efficient intrusion detection via heterogeneous graph attention networks and parallel provenance analysis","volume":"270","author":"Wu","year":"2025","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112418_b15","doi-asserted-by":"crossref","first-page":"7783","DOI":"10.1109\/TIFS.2024.3441862","article-title":"Early network intrusion detection enabled by attention mechanisms and RNNs","volume":"19","author":"Djaidja","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"B","key":"10.1016\/j.comnet.2026.112418_b16","article-title":"Real-time fusion multi-tier DNN-based collaborative IDPS with complementary features for secure UAV-enabled 6G networks","volume":"252","author":"Hadi","year":"2024","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.comnet.2026.112418_b17","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2025.128089","article-title":"XG-NID: Dual-modality network intrusion detection using a heterogeneous graph neural network and large language model","volume":"287","author":"Farrukh","year":"2025","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.comnet.2026.112418_b18","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2025.126854","article-title":"Improved network anomaly detection system using optimized autoencoder - LSTM","volume":"273","author":"Narmadha","year":"2025","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.comnet.2026.112418_b19","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2023.123027","article-title":"Dugat-LSTM: Deep learning based network intrusion detection system using chaotic optimization strategy","volume":"245","author":"Devendiran","year":"2024","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.comnet.2026.112418_b20","doi-asserted-by":"crossref","DOI":"10.1016\/j.jnca.2025.104253","article-title":"MOOO-RDQN: A deep reinforcement learning based method for multi-objective optimization of controller placement and traffic monitoring in SDN","volume":"242","author":"Chen","year":"2025","journal-title":"J. Netw. Comput. Appl."},{"key":"10.1016\/j.comnet.2026.112418_b21","first-page":"1","article-title":"GCB-PPO2: A hybrid deep reinforcement learning intrusion detection system for under-represented attack categories in SDN","author":"Chen","year":"2025","journal-title":"IEEE Trans. Netw. Sci. Eng."},{"key":"10.1016\/j.comnet.2026.112418_b22","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.103821","article-title":"A survey on graph neural networks for intrusion detection systems: Methods, trends and challenges","volume":"141","author":"Zhong","year":"2024","journal-title":"Comput. Secur."},{"key":"10.1016\/j.comnet.2026.112418_b23","doi-asserted-by":"crossref","first-page":"5817","DOI":"10.1109\/TIFS.2023.3318960","article-title":"Toward early and accurate network intrusion detection using graph embedding","volume":"18","author":"Hu","year":"2023","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112418_b24","doi-asserted-by":"crossref","first-page":"1965","DOI":"10.1109\/TIFS.2025.3539100","article-title":"Intrusion detection for internet of things: An anchor graph clustering approach","volume":"20","author":"Wu","year":"2025","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112418_b25","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2022.116545","article-title":"Hybrid intrusion detection using MapReduce based black widow optimized convolutional long short-term memory neural networks","volume":"194","author":"Kanna","year":"2022","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.comnet.2026.112418_b26","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.103859","article-title":"Two-stage multi-datasource machine learning for attack technique and lifecycle detection","volume":"142","author":"Lin","year":"2024","journal-title":"Comput. Secur."},{"key":"10.1016\/j.comnet.2026.112418_b27","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.104263","article-title":"AJSAGE: A intrusion detection scheme based on jump-knowledge connection to GraphSAGE","volume":"150","author":"Xu","year":"2025","journal-title":"Comput. Secur."},{"key":"10.1016\/j.comnet.2026.112418_b28","doi-asserted-by":"crossref","first-page":"57","DOI":"10.1016\/j.ins.2022.03.065","article-title":"PDAE: Efficient network intrusion detection in IoT using parallel deep auto-encoders","volume":"598","author":"Basati","year":"2022","journal-title":"Inf. Sci."},{"key":"10.1016\/j.comnet.2026.112418_b29","doi-asserted-by":"crossref","DOI":"10.1016\/j.compeleceng.2023.108869","article-title":"Optimizing intrusion detection systems using parallel metric learning","volume":"110","author":"Sudha","year":"2023","journal-title":"Comput. Electr. Eng."},{"key":"10.1016\/j.comnet.2026.112418_b30","doi-asserted-by":"crossref","first-page":"55","DOI":"10.1016\/j.jpdc.2022.01.030","article-title":"A distributed intrusion detection system to detect DDoS attacks in blockchain-enabled IoT network","volume":"164","author":"Kumar","year":"2022","journal-title":"J. Parallel Distrib. Comput."},{"issue":"3","key":"10.1016\/j.comnet.2026.112418_b31","doi-asserted-by":"crossref","first-page":"3497","DOI":"10.1109\/TII.2023.3308784","article-title":"Spatial-temporal graph model based on attention mechanism for anomalous IoT intrusion detection","volume":"20","author":"Wang","year":"2024","journal-title":"IEEE Trans. Ind. Inform."},{"key":"10.1016\/j.comnet.2026.112418_b32","article-title":"FTG-Net-E: A hierarchical ensemble graph neural network for DDoS attack detection","volume":"250","author":"Bakar","year":"2024","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112418_b33","article-title":"AI-driven robust dual attention-enhanced intrusion detection framework for IoT devices in edge-cloud computing networks","volume":"176","author":"Zhoua","year":"2026","journal-title":"Future Gener. Comput. Syst. - Int. J. eScience"},{"issue":"1","key":"10.1016\/j.comnet.2026.112418_b34","article-title":"An improved intrusion detection method for IIoT using attention mechanisms, BiGRU, and Inception-CNN","volume":"14","author":"Yang","year":"2024","journal-title":"Sci. Rep."},{"key":"10.1016\/j.comnet.2026.112418_b35","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2023.122966","article-title":"Improved network intrusion classification with attention-assisted bidirectional LSTM and optimized sparse contractive autoencoders","volume":"244","author":"Bi","year":"2024","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.comnet.2026.112418_b36","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2025.111207","article-title":"Industrial IoT intrusion attack detection based on composite attention-driven multi-layer pyramid features","volume":"263","author":"Zhai","year":"2025","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112418_b37","doi-asserted-by":"crossref","DOI":"10.1016\/j.ins.2023.119512","article-title":"A feature enhancement-based model for the malicious traffic detection with small-scale imbalanced dataset","volume":"647","author":"Wei","year":"2023","journal-title":"Inf. Sci."},{"key":"10.1016\/j.comnet.2026.112418_b38","article-title":"Securing virtualized cloud infrastructures with temporal inductive path neural networks for attack detection","volume":"323","author":"Selvam","year":"2025","journal-title":"Knowl.-Based Syst."},{"issue":"2","key":"10.1016\/j.comnet.2026.112418_b39","doi-asserted-by":"crossref","DOI":"10.1007\/s10489-024-05872-6","article-title":"Improved convolution neural network integrating attention based deep sparse auto encoder for network intrusion detection","volume":"55","author":"Geng","year":"2025","journal-title":"Appl. Intell."},{"key":"10.1016\/j.comnet.2026.112418_b40","doi-asserted-by":"crossref","first-page":"5476","DOI":"10.1109\/TIFS.2024.3402155","article-title":"ProGen: Projection-based adversarial attack generation against network intrusion detection","volume":"19","author":"Wang","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"2","key":"10.1016\/j.comnet.2026.112418_b41","doi-asserted-by":"crossref","first-page":"2389","DOI":"10.1109\/TNSM.2023.3332284","article-title":"A few-shot class-incremental learning method for network intrusion detection","volume":"21","author":"Du","year":"2024","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"10.1016\/j.comnet.2026.112418_b42","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2023.120894","article-title":"Quantum walks-based classification model with resistance for cloud computing attacks","volume":"232","author":"Wu","year":"2023","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.comnet.2026.112418_b43","series-title":"Proceedings of the 2017 IEEE 14th International Conference on Networking, Sensing and Control","first-page":"617","article-title":"Feature selection for flow-based intrusion detection using rough set theory","author":"Beer","year":"2017"}],"container-title":["Computer Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1389128626004305?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1389128626004305?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,8]],"date-time":"2026-06-08T12:11:46Z","timestamp":1780920706000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S1389128626004305"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7]]},"references-count":43,"alternative-id":["S1389128626004305"],"URL":"https:\/\/doi.org\/10.1016\/j.comnet.2026.112418","relation":{},"ISSN":["1389-1286"],"issn-type":[{"value":"1389-1286","type":"print"}],"subject":[],"published":{"date-parts":[[2026,7]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"ATHGID: Two-stage graph intrusion detection via attention-fused network-host feature and producer\u2013consumer parallelization","name":"articletitle","label":"Article Title"},{"value":"Computer Networks","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.comnet.2026.112418","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"112418"}}