{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,27]],"date-time":"2026-04-27T07:09:22Z","timestamp":1777273762978,"version":"3.51.4"},"reference-count":94,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62302371"],"award-info":[{"award-number":["62302371"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100013290","name":"National Key Research and Development Program of China Stem Cell and Translational Research","doi-asserted-by":"publisher","award":["2023YFB3107505"],"award-info":[{"award-number":["2023YFB3107505"]}],"id":[{"id":"10.13039\/501100013290","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Computer Science Review"],"published-print":{"date-parts":[[2026,8]]},"DOI":"10.1016\/j.cosrev.2026.100978","type":"journal-article","created":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T16:13:27Z","timestamp":1775060007000},"page":"100978","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":1,"special_numbering":"C","title":["Graph intelligence for IoT and CPS security: From connectivity patterns to cyber-physical reasoning"],"prefix":"10.1016","volume":"61","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-7434-7396","authenticated-orcid":false,"given":"Hafiz Bilal","family":"Ahmad","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4969-5718","authenticated-orcid":false,"given":"Haichang","family":"Gao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-0244-9535","authenticated-orcid":false,"given":"Naila","family":"Latif","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"issue":"14s","key":"10.1016\/j.cosrev.2026.100978_bib0005","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3593043","article-title":"A systematic review of data quality in cps and iot for industry 4.0","volume":"55","author":"Goknil","year":"2023","journal-title":"ACM Comput. Surv."},{"issue":"7","key":"10.1016\/j.cosrev.2026.100978_bib0010","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3465170","article-title":"Centralized, distributed, and everything in between: reviewing access control solutions for the iot","volume":"54","author":"Dram\u00e9-Maign\u00e9","year":"2021","journal-title":"ACM Comput. Surv."},{"key":"10.1016\/j.cosrev.2026.100978_bib0015","doi-asserted-by":"crossref","DOI":"10.1109\/ACCESS.2021.3133348","article-title":"Industrial and critical infrastructure security: technical analysis of real-life security incidents","volume":"9","author":"Makrakis","year":"2021","journal-title":"IEEE Access"},{"issue":"12","key":"10.1016\/j.cosrev.2026.100978_bib0020","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3731596","article-title":"Intrusion detection based on federated learning: a systematic review","volume":"57","author":"Hernandez-Ramos","year":"2025","journal-title":"ACM Comput. Surv."},{"key":"10.1016\/j.cosrev.2026.100978_bib0025","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.103821","article-title":"A survey on graph neural networks for intrusion detection systems: Methods, trends and challenges","volume":"141","author":"Zhong","year":"2024","journal-title":"Comput. Secur."},{"issue":"2","key":"10.1016\/j.cosrev.2026.100978_bib0030","doi-asserted-by":"crossref","first-page":"40","DOI":"10.1007\/s10462-023-10656-4","article-title":"Graph neural networks: a survey on the links between privacy and security","volume":"57","author":"Guan","year":"2024","journal-title":"Artif. Intell. Rev."},{"key":"10.1016\/j.cosrev.2026.100978_bib0035","series-title":"2020 IEEE Symposium on Security and Privacy (SP)","first-page":"1172","article-title":"Tactical provenance analysis for endpoint detection and response systems","author":"Hassan","year":"2020"},{"issue":"3","key":"10.1016\/j.cosrev.2026.100978_bib0040","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3588771","article-title":"EULER: detecting network lateral movement via scalable temporal link prediction","volume":"26","author":"King","year":"2023","journal-title":"ACM Trans. Priv. Secur."},{"key":"10.1016\/j.cosrev.2026.100978_bib0045","series-title":"Proceedings of the 16th International Workshop on Mining and Learning with Graphs","article-title":"SNAPSKETCH: a graph sketching based approach for intrusion detection in a streaming graph","author":"Paudel","year":"2020"},{"key":"10.1016\/j.cosrev.2026.100978_bib0050","series-title":"NOMS 2022-2022 IEEE\/iFIP network operations and management symposium","first-page":"1","article-title":"E-graphsage: a graph neural network based intrusion detection system for iot","author":"Lo","year":"2022"},{"issue":"10","key":"10.1016\/j.cosrev.2026.100978_bib0055","doi-asserted-by":"crossref","first-page":"210","DOI":"10.3390\/act14050210","article-title":"Multi-level graph attention network-based anomaly detection in industrial control system","volume":"14","author":"Lin","year":"2025","journal-title":"Actuators"},{"issue":"6","key":"10.1016\/j.cosrev.2026.100978_bib0060","first-page":"1","article-title":"Gnn-based advanced feature integration for ics anomaly detection","volume":"14","author":"Wang","year":"2023","journal-title":"ACM Trans. Intell. Syst. Technol."},{"key":"10.1016\/j.cosrev.2026.100978_bib0065","doi-asserted-by":"crossref","first-page":"1566","DOI":"10.1109\/TIFS.2023.3240291","article-title":"Federated graph neural network for fast anomaly detection in controller area networks","volume":"18","author":"Zhang","year":"2023","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.cosrev.2026.100978_bib0070","author":"Bahar"},{"issue":"1","key":"10.1016\/j.cosrev.2026.100978_bib0075","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3597428","article-title":"The evolution of distributed systems for graph neural networks and their origin in graph processing and deep learning: a survey","volume":"56","author":"Vatter","year":"2023","journal-title":"ACM Comput. Surv."},{"key":"10.1016\/j.cosrev.2026.100978_bib0080","series-title":"International Conference on Critical Infrastructure Protection","first-page":"65","article-title":"Industrial control system traffic data sets for intrusion detection research","author":"Morris","year":"2014"},{"key":"10.1016\/j.cosrev.2026.100978_bib0085","series-title":"2023 8th International Conference on Signal and Image Processing (ICSIP)","first-page":"860","article-title":"Securing IoT communication using physical sensor data\u2014graph layer security with federated multi-agent deep reinforcement learning","author":"Wang","year":"2023"},{"key":"10.1016\/j.cosrev.2026.100978_bib0090","series-title":"2025 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)","first-page":"169","article-title":"Ppt-gnn: a practical pretrained spatio-temporal graph neural network for network security","author":"Van Langendonck","year":"2025"},{"key":"10.1016\/j.cosrev.2026.100978_bib0095","author":"Mukherjee"},{"key":"10.1016\/j.cosrev.2026.100978_bib0100","series-title":"Proceedings of the Workshop on Autonomous Cybersecurity, ser","first-page":"34","article-title":"P3GNN: a privacy-preserving provenance graph-based model for autonomous APT detection in software defined networking","author":"Nazari","year":"2024"},{"key":"10.1016\/j.cosrev.2026.100978_bib0105","doi-asserted-by":"crossref","DOI":"10.1016\/j.epsr.2023.109118","article-title":"Detection of false data injection attacks in cyber-physical systems using graph convolutional network","volume":"217","author":"Vincent","year":"2023","journal-title":"Electr. Power Syst. Res."},{"key":"10.1016\/j.cosrev.2026.100978_bib0110","series-title":"Graph neural network-based cybersecurity of smart grids","author":"Boyaci","year":"2022"},{"key":"10.1016\/j.cosrev.2026.100978_bib0115","doi-asserted-by":"crossref","first-page":"187","DOI":"10.1007\/s10207-023-00731-w","article-title":"Enhancing attack resilience of cyber-physical systems through state dependency graph models","volume":"23","author":"Adamos","year":"2024","journal-title":"Int. J. Inf. Secur."},{"key":"10.1016\/j.cosrev.2026.100978_bib0120","series-title":"2023 IEEE Symposium on Security and Privacy (SP)","first-page":"20","article-title":"SCAPHY: detecting modern ICS attacks by correlating behaviors in SCADA and PHYsical","author":"Ike","year":"2023"},{"key":"10.1016\/j.cosrev.2026.100978_bib0125","series-title":"2020 IEEE 18th International Conference on Industrial Informatics (INDIN)","first-page":"461","article-title":"Knowledge-based cyber threat intelligence and reasoning for industrial control systems","volume":"vol. 1","author":"Ning","year":"2020"},{"key":"10.1016\/j.cosrev.2026.100978_bib0130","article-title":"Attack scenario reconstruction approach using attack graph and alert data mining","volume":"54","author":"Hu","year":"2020","journal-title":"J. Inf. Secur. Appl."},{"key":"10.1016\/j.cosrev.2026.100978_bib0135","series-title":"2025 IEEE 10th European Symposium on Security and Privacy (EuroS&P)","first-page":"923","article-title":"Ctinexus: automatic cyber threat intelligence knowledge graph construction using large language models","author":"Cheng","year":"2025"},{"key":"10.1016\/j.cosrev.2026.100978_bib0140","series-title":"2024 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)","first-page":"100","article-title":"Actionable cyber threat intelligence using knowledge graphs and large language models","author":"Fieblinger","year":"2024"},{"issue":"1","key":"10.1016\/j.cosrev.2026.100978_bib0145","doi-asserted-by":"crossref","first-page":"184","DOI":"10.1007\/s44196-023-00369-5","article-title":"APT attack detection based on graph convolutional neural networks","volume":"16","author":"Ren","year":"2023","journal-title":"Int. J. Comput. Intell. Syst."},{"key":"10.1016\/j.cosrev.2026.100978_bib0150","doi-asserted-by":"crossref","DOI":"10.1016\/j.compeleceng.2023.108660","article-title":"Cybersecurity knowledge graph enabled attack chain detection for cyber-physical systems","volume":"108","author":"Qi","year":"2023","journal-title":"Comput. Electr. Eng."},{"issue":"1","key":"10.1016\/j.cosrev.2026.100978_bib0155","doi-asserted-by":"crossref","first-page":"106","DOI":"10.1186\/s42400-025-00505-y","article-title":"Cti-thinker: an llm-driven system for cti knowledge graph construction and attack reasoning","volume":"9","author":"Yang","year":"2026","journal-title":"Cybersecurity"},{"key":"10.1016\/j.cosrev.2026.100978_bib0160","series-title":"2023 IEEE Symposium Series on Computational Intelligence (SSCI)","first-page":"807","article-title":"Intrusion detection for wireless sensor network using graph neural networks","author":"Gharavian","year":"2023"},{"issue":"65","key":"10.1016\/j.cosrev.2026.100978_bib0165","first-page":"356","article-title":"Intrusion detection in IoT networks using dynamic graph modeling and graph-based neural networks","volume":"13","author":"Villegas-Ch","year":"2025","journal-title":"IEEE Access"},{"key":"10.1016\/j.cosrev.2026.100978_bib0170","doi-asserted-by":"crossref","first-page":"3972","DOI":"10.1109\/TIFS.2022.3208815","article-title":"THREATRACE: detecting and tracing host-based threats in node level through provenance graph learning","volume":"17","author":"Wang","year":"2022","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.cosrev.2026.100978_bib0175","series-title":"2018 IEEE International Conference on Communications Workshops (ICC Workshops)","first-page":"1","article-title":"A graph-based security framework for securing industrial IoT networks from vulnerability exploitations","author":"George","year":"2018"},{"issue":"11","key":"10.1016\/j.cosrev.2026.100978_bib0180","doi-asserted-by":"crossref","first-page":"2937","DOI":"10.3390\/en18112937","article-title":"Critical node identification for cyber-physical power distribution systems based on complex network theory: a real case study","volume":"18","author":"Doostinia","year":"2025","journal-title":"Energies"},{"issue":"11","key":"10.1016\/j.cosrev.2026.100978_bib0185","doi-asserted-by":"crossref","first-page":"2439","DOI":"10.3390\/electronics12112439","article-title":"Critical node identification method of power grid based on the improved entropy weight method","volume":"12","author":"Li","year":"2023","journal-title":"Electronics"},{"issue":"3","key":"10.1016\/j.cosrev.2026.100978_bib0190","doi-asserted-by":"crossref","first-page":"1510","DOI":"10.1109\/TPWRD.2022.3230926","article-title":"Graph-based interdependent cyber-physical risk analysis of power distribution networks","volume":"38","author":"Palomino","year":"2023","journal-title":"IEEE Trans. Power Deliv."},{"key":"10.1016\/j.cosrev.2026.100978_bib0195","series-title":"Proceedings of the 2024 Winter Simulation Conference","first-page":"774","article-title":"Optimizing cyber-resilience in critical infrastructure networks","author":"Pal","year":"2024"},{"key":"10.1016\/j.cosrev.2026.100978_bib0200","series-title":"Proceedings of the 22nd ACM SIGKDD international conference on Knowledge discovery and data mining","first-page":"855","article-title":"node2vec: scalable feature learning for networks","author":"Grover","year":"2016"},{"issue":"91","key":"10.1016\/j.cosrev.2026.100978_bib0205","article-title":"Advancements in securing federated learning with IDS: a comprehensive review of neural networks and feature engineering techniques for malicious client detection","volume":"58","author":"Latif","year":"2025","journal-title":"Artif. Intell. Rev."},{"issue":"1","key":"10.1016\/j.cosrev.2026.100978_bib0210","doi-asserted-by":"crossref","first-page":"14","DOI":"10.1007\/s13278-025-01419-w","article-title":"Refined graph encoder embedding via self-training and latent community recovery","volume":"15","author":"Shen","year":"2025","journal-title":"Soc. Netw. Anal. Min."},{"key":"10.1016\/j.cosrev.2026.100978_bib0215","doi-asserted-by":"crossref","first-page":"424","DOI":"10.1109\/TNSE.2025.3584219","article-title":"Principal graph encoder embedding and principal community detection","volume":"13","author":"Shen","year":"2026","journal-title":"IEEE Trans. Netw. Sci. Eng."},{"key":"10.1016\/j.cosrev.2026.100978_bib0220","author":"Kipf"},{"key":"10.1016\/j.cosrev.2026.100978_bib0225","series-title":"International conference on learning representations","first-page":"2","article-title":"Graph attention networks","volume":"vol. 6","author":"Veli\u010dkovi\u0107","year":"2018"},{"key":"10.1016\/j.cosrev.2026.100978_bib0230","series-title":"Advances in neural information processing systems 30","article-title":"Inductive representation learning on large graphs","author":"Hamilton","year":"2017"},{"key":"10.1016\/j.cosrev.2026.100978_bib0235","author":"Hao"},{"key":"10.1016\/j.cosrev.2026.100978_bib0240","author":"Rossi"},{"key":"10.1016\/j.cosrev.2026.100978_bib0245","series-title":"The world wide web conference","first-page":"2022","article-title":"Heterogeneous graph attention network","author":"Wang","year":"2019"},{"key":"10.1016\/j.cosrev.2026.100978_bib0250","doi-asserted-by":"crossref","first-page":"686","DOI":"10.1016\/j.jcp.2018.10.045","article-title":"Physics-informed neural networks: a deep learning framework for solving forward and inverse problems involving nonlinear partial differential equations","volume":"378","author":"Raissi","year":"2019","journal-title":"J. Comput. Phys."},{"key":"10.1016\/j.cosrev.2026.100978_bib0255","author":"Qi"},{"issue":"1","key":"10.1016\/j.cosrev.2026.100978_bib0260","doi-asserted-by":"crossref","first-page":"2692","DOI":"10.1038\/s41598-025-85822-5","article-title":"Design of an integrated model with temporal graph attention and transformer-augmented rnns for enhanced anomaly detection","volume":"15","author":"Veesam","year":"2025","journal-title":"Sci. Rep."},{"issue":"1","key":"10.1016\/j.cosrev.2026.100978_bib0265","doi-asserted-by":"crossref","first-page":"44","DOI":"10.3390\/fi17010044","article-title":"Fraud detection in cryptocurrency networks\u2014an exploration using anomaly detection and heterogeneous graph transformers","volume":"17","author":"P\u00e9rez-Cano","year":"2025","journal-title":"Future Internet"},{"key":"10.1016\/j.cosrev.2026.100978_bib0270","author":"Guan"},{"issue":"11","key":"10.1016\/j.cosrev.2026.100978_bib0275","article-title":"Anomaly detection via semantically conjugate view learning on industrial temporal data","volume":"12","author":"Wang","year":"2025","journal-title":"IEEE Internet Things J."},{"key":"10.1016\/j.cosrev.2026.100978_bib0280","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2024.125877","article-title":"A dynamic provenance graph-based detector for advanced persistent threats","volume":"265","author":"Wang","year":"2025","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.cosrev.2026.100978_bib0285","series-title":"2024 IEEE 7th Information Technology, Networking, Electronic and Automation Control Conference (ITNEC)","first-page":"775","article-title":"An graph neural network approach with self-supervised learning for malware detection","author":"Su","year":"2024"},{"key":"10.1016\/j.cosrev.2026.100978_bib0290","series-title":"Security and Privacy in Communication Networks","first-page":"3","article-title":"DeepHunter: a graph neural network based approach for robust cyber threat hunting","author":"Wei","year":"2021"},{"key":"10.1016\/j.cosrev.2026.100978_bib0295","series-title":"2022 IEEE Global Communications Conference (GLOBECOM)","first-page":"897","article-title":"A graph learning approach with audit records for advanced attack investigation","author":"Liu","year":"2022"},{"key":"10.1016\/j.cosrev.2026.100978_bib0300","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2022.103081","article-title":"Attack graph analysis: an explanatory guide","volume":"126","author":"Zenitani","year":"2023","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100978_bib0305","series-title":"2023 7th Cyber Security in Networking Conference (CSNet)","first-page":"178","article-title":"Graph-based attack path discovery for network security","author":"Meng","year":"2023"},{"issue":"3","key":"10.1016\/j.cosrev.2026.100978_bib0310","doi-asserted-by":"crossref","first-page":"1090","DOI":"10.1016\/j.dcan.2022.05.015","article-title":"A malware propagation prediction model based on representation learning and graph convolutional networks","volume":"9","author":"Li","year":"2023","journal-title":"Digit. Commun. Netw."},{"key":"10.1016\/j.cosrev.2026.100978_bib0315","series-title":"International Conference on Learning Representations","article-title":"Adversarial attacks on graph neural networks via meta learning","author":"Z\u00fcgner","year":"2019"},{"key":"10.1016\/j.cosrev.2026.100978_bib0320","series-title":"2024 12th International Symposium on Digital Forensics and Security (ISDFS)","first-page":"01","article-title":"Adversarial machine learning for detecting advanced threats inspired by stuxnet in critical infrastructure networks","author":"Ahmad","year":"2024"},{"key":"10.1016\/j.cosrev.2026.100978_bib0325","series-title":"Thirty-seventh Conference on Neural Information Processing Systems","article-title":"Adversarial training for graph neural networks: Pitfalls, solutions, and new directions","author":"Gosch","year":"2023"},{"key":"10.1016\/j.cosrev.2026.100978_bib0330","doi-asserted-by":"crossref","first-page":"2284","DOI":"10.1109\/TIFS.2026.3666308","article-title":"Adversarial training for graph neural networks via graph subspace energy optimization","volume":"21","author":"Liu","year":"2026","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.cosrev.2026.100978_bib0335","doi-asserted-by":"crossref","first-page":"7812","DOI":"10.1007\/s10489-021-02272-y","article-title":"Robust graph convolutional networks with directional graph adversarial training","volume":"51","author":"Hu","year":"2021","journal-title":"Applied Intell."},{"key":"10.1016\/j.cosrev.2026.100978_bib0340","series-title":"Database Systems for Advanced Applications: 27th International Conference, DASFAA 2022, Virtual Event, April 11\u201314, 2022, Proceedings, Part I","first-page":"682","article-title":"Learning robust representation through graph adversarial contrastive learning","author":"Guo","year":"2022"},{"issue":"1","key":"10.1016\/j.cosrev.2026.100978_bib0345","doi-asserted-by":"crossref","first-page":"538","DOI":"10.1109\/COMST.2022.3233793","article-title":"Adversarial machine learning for network intrusion detection systems: a comprehensive survey","volume":"25","author":"He","year":"2023","journal-title":"IEEE Commun. Surv. & Tutorials"},{"key":"10.1016\/j.cosrev.2026.100978_bib0350","series-title":"Guide to operational technology (ot) security","author":"Stouffer","year":"2023"},{"key":"10.1016\/j.cosrev.2026.100978_bib0360","series-title":"Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security (ASIACCS)","article-title":"Attacks against process control systems: risk assessment, detection, and response","author":"C\u00e1rdenas","year":"2011"},{"key":"10.1016\/j.cosrev.2026.100978_bib0365","series-title":"International Conference on Broadband and Wireless Computing, Communication and Applications","first-page":"117","article-title":"Netflow datasets for machine learning-based network intrusion detection systems","author":"Sarhan","year":"2021"},{"key":"10.1016\/j.cosrev.2026.100978_bib0370","doi-asserted-by":"crossref","DOI":"10.1016\/j.compeleceng.2022.108061","article-title":"An electric power digital twin for cyber security testing, research and education","volume":"101","author":"Kandasamy","year":"2022","journal-title":"Comput. Electr. Eng."},{"issue":"4","key":"10.1016\/j.cosrev.2026.100978_bib0375","doi-asserted-by":"crossref","first-page":"134","DOI":"10.3390\/fi16040134","article-title":"Leveraging digital twin technology for enhanced cybersecurity in cyber\u2013physical production systems","volume":"16","author":"Jiang","year":"2024","journal-title":"Future Internet"},{"key":"10.1016\/j.cosrev.2026.100978_bib0380","series-title":"Computers & Security","first-page":"147","article-title":"A survey of network-based intrusion detection data sets","volume":"vol. 86","author":"Ring","year":"2019"},{"key":"10.1016\/j.cosrev.2026.100978_bib0385","doi-asserted-by":"crossref","first-page":"636","DOI":"10.1016\/j.procs.2020.03.330","article-title":"A review of the advancement in intrusion detection datasets","volume":"167","author":"Thakkar","year":"2020","journal-title":"Proc. Comput. Sci."},{"key":"10.1016\/j.cosrev.2026.100978_bib0390","series-title":"2015 military communications and information systems conference (MilCIS)","first-page":"1","article-title":"Unsw-nb15: a comprehensive data set for network intrusion detection systems (unsw-nb15 network data set)","author":"Moustafa","year":"2015"},{"key":"10.1016\/j.cosrev.2026.100978_bib0395","series-title":"International conference on critical information infrastructures security","first-page":"88","article-title":"A dataset to support research in the design of secure water treatment systems","author":"Goh","year":"2016"},{"key":"10.1016\/j.cosrev.2026.100978_bib0400","doi-asserted-by":"crossref","first-page":"100","DOI":"10.1016\/j.cose.2014.05.011","article-title":"An empirical comparison of botnet detection methods","volume":"45","author":"Garcia","year":"2014","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100978_bib0405","doi-asserted-by":"crossref","DOI":"10.1016\/j.hcc.2025.100360","article-title":"Adaptive anomaly detection and classification in critical infrastructure systems: a real-time privacy-preserving multi-model framework","author":"Ahmad","year":"2025","journal-title":"High-Confid. Comput."},{"issue":"5","key":"10.1016\/j.cosrev.2026.100978_bib0410","first-page":"5782","article-title":"Explainability in graph neural networks: a taxonomic survey","volume":"45","author":"Yuan","year":"2022","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"10.1016\/j.cosrev.2026.100978_bib0415","series-title":"2020 IEEE\/ACM 10th Workshop on Irregular Applications: Architectures and Algorithms (IA3)","first-page":"36","article-title":"Distdgl: distributed graph neural network training for-billion-scale graphs","author":"Zheng","year":"2020"},{"key":"10.1016\/j.cosrev.2026.100978_bib0420","doi-asserted-by":"crossref","DOI":"10.1016\/j.iot.2026.101877","article-title":"Fedmamba: robust multimodal federated intrusion detection for heterogeneous iot systems","author":"Ahmad","year":"2026","journal-title":"Internet of Things"},{"key":"10.1016\/j.cosrev.2026.100978_bib0425","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/TCSS.2025.3606798","article-title":"An explainable and privacy-preserving federated learning model for threat detection in cyber-physical-social systems","author":"Yazdinejad","year":"2025","journal-title":"IEEE Trans. Comput. Soc. Syst."},{"key":"10.1016\/j.cosrev.2026.100978_bib0430","doi-asserted-by":"crossref","first-page":"6693","DOI":"10.1109\/TIFS.2024.3420126","article-title":"A robust privacy-preserving federated learning model against model poisoning attacks","volume":"19","author":"Yazdinejad","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.cosrev.2026.100978_bib0435","series-title":"The book of why: the new science of cause and effect","author":"Pearl","year":"2018"},{"key":"10.1016\/j.cosrev.2026.100978_bib0440","article-title":"Gnnexplainer: generating explanations for graph neural networks","volume":"32","author":"Ying","year":"2019","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.cosrev.2026.100978_bib0445","series-title":"International conference on artificial intelligence and statistics","first-page":"4499","article-title":"Cf-gnnexplainer: counterfactual explanations for graph neural networks","author":"Lucic","year":"2022"},{"key":"10.1016\/j.cosrev.2026.100978_bib0450","article-title":"Parameterized explainer for graph neural network","volume":"33","author":"Luo","year":"2020","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.cosrev.2026.100978_bib0455","series-title":"Proceedings of the First Learning on Graphs Conference, ser","first-page":":44:1","article-title":"Graphframex: Towards systematic evaluation of explainability methods for graph neural networks","volume":"vol. 198","author":"Amara","year":"2022"},{"key":"10.1016\/j.cosrev.2026.100978_bib0460","series-title":"Artificial intelligence and statistics","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","author":"McMahan","year":"2017"},{"issue":"1","key":"10.1016\/j.cosrev.2026.100978_bib0465","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1186\/s42400-018-0017-4","article-title":"Graph-based visual analytics for cyber threat intelligence","volume":"1","author":"B\u00f6hm","year":"2018","journal-title":"Cybersecurity"},{"key":"10.1016\/j.cosrev.2026.100978_bib0470","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2022.103069","article-title":"Understanding situation awareness in socs, a systematic literature review","volume":"126","author":"Ofte","year":"2023","journal-title":"Comput. Secur."},{"issue":"3","key":"10.1016\/j.cosrev.2026.100978_bib0475","doi-asserted-by":"crossref","first-page":"5327","DOI":"10.32604\/cmc.2025.068509","article-title":"A security operation and event management (soem) platform for critical infrastructures protection","volume":"85","author":"Caviglia","year":"2025","journal-title":"Computers, Materials, & Continua"}],"container-title":["Computer Science Review"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1574013726000869?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1574013726000869?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,4,14]],"date-time":"2026-04-14T19:17:34Z","timestamp":1776194254000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S1574013726000869"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,8]]},"references-count":94,"alternative-id":["S1574013726000869"],"URL":"https:\/\/doi.org\/10.1016\/j.cosrev.2026.100978","relation":{},"ISSN":["1574-0137"],"issn-type":[{"value":"1574-0137","type":"print"}],"subject":[],"published":{"date-parts":[[2026,8]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Graph intelligence for IoT and CPS security: From connectivity patterns to cyber-physical reasoning","name":"articletitle","label":"Article Title"},{"value":"Computer Science Review","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.cosrev.2026.100978","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Inc. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"100978"}}