{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,19]],"date-time":"2026-05-19T15:02:22Z","timestamp":1779202942307,"version":"3.51.4"},"reference-count":27,"publisher":"Oxford University Press (OUP)","issue":"1","license":[{"start":{"date-parts":[[2025,11,22]],"date-time":"2025-11-22T00:00:00Z","timestamp":1763769600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/academic.oup.com\/pages\/standard-publication-reuse-rights"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62372175"],"award-info":[{"award-number":["62372175"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62372285"],"award-info":[{"award-number":["62372285"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100013105","name":"Shanghai Rising-Star Program","doi-asserted-by":"publisher","award":["22QA1403800"],"award-info":[{"award-number":["22QA1403800"]}],"id":[{"id":"10.13039\/501100013105","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Innovation Program of Shanghai Municipal Education Commission","award":["2021-01-07-00-08-E00101"],"award-info":[{"award-number":["2021-01-07-00-08-E00101"]}]},{"name":"Shanghai International Joint Lab of Trustworthy Intelligent Software","award":["22510750100"],"award-info":[{"award-number":["22510750100"]}]},{"name":"Shanghai Pilot Program for Basic Research","award":["TQ20240212"],"award-info":[{"award-number":["TQ20240212"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,1,13]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>To date, machine learning models have been widely applied to intrusion detection system (IDS) for improving detection accuracy, where most IDS suffer from adversarial evasion attacks that may lead to data loss and user privacy leakage. Although there have been numerous solutions proposed against adversarial evasion attacks, they often neglect the relationships between different traffic and heavily relied on data labels. Therefore, this paper proposes AEDGNN, a new approach for detecting adversarial evasion attacks using graph neural network (GNN) model. On one hand, AEDGNN employs E-GraphSAGE to capture network topology in IDS for building the relationship between different inputs. On the other hand, AEDGNN utilizes deep graph infomax (DGI) to train the GNN in a self-supervised manner for maximizing mutual information between local and global representations. In addition, to clarify the practical performance of defending against traditional adversarial attacks, we implement AEDGNN and classic machine learning models based on CIC-IDS2018 benchmark dataset. The experimental results show that AEDGNN achieves significant improvements on both normal and adversarial samples compared to classic solutions. The accuracy of AEDGNN is 0.02%\u20131.53% higher than that of classic solutions for normal samples, and 26.04%\u201359.04% higher for adversarial samples.<\/jats:p>","DOI":"10.1093\/comjnl\/bxaf096","type":"journal-article","created":{"date-parts":[[2025,11,22]],"date-time":"2025-11-22T20:01:17Z","timestamp":1763841677000},"page":"18-27","source":"Crossref","is-referenced-by-count":1,"title":["On adversarial attack detection in intrusion detection system with graph neural network"],"prefix":"10.1093","volume":"69","author":[{"given":"Kai","family":"Zhang","sequence":"first","affiliation":[{"name":"College of Computer Science and Technology , Shanghai University of Electric Power, No. 1851, Huchenghuan Road, Pudong New Area, 201306, Shanghai,","place":["China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qingqing","family":"Li","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology , Shanghai University of Electric Power, No. 1851, Huchenghuan Road, Pudong New Area, 201306, Shanghai,","place":["China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jianting","family":"Ning","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering , Wuhan University, No. 299, Bayi Road, Wuchang District, 430072, Wuhan,","place":["China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Junqing","family":"Gong","sequence":"additional","affiliation":[{"name":"Software Engineering Institute , East China Normal University, No. 3663, North Zhongshan Road, Putuo District, 200062, Shanghai,","place":["China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Haifeng","family":"Qian","sequence":"additional","affiliation":[{"name":"Software Engineering Institute , East China Normal University, No. 3663, North Zhongshan Road, Putuo District, 200062, Shanghai,","place":["China"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"286","published-online":{"date-parts":[[2025,11,22]]},"reference":[{"key":"2026011907114171900_ref1","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1016\/j.jnca.2012.09.004","article-title":"Intrusion detection system: a comprehensive review","volume":"36","author":"Liao","year":"2013","journal-title":"J Netw Comput Appl"},{"key":"2026011907114171900_ref2","doi-asserted-by":"publisher","first-page":"308","DOI":"10.1016\/j.comnet.2015.02.026","article-title":"Ddos attack protection in the era of cloud computing and software-defined networking","volume":"81","author":"Wang","year":"2015","journal-title":"Comput Netw"},{"key":"2026011907114171900_ref3","doi-asserted-by":"crossref","first-page":"1409","DOI":"10.1109\/INFOCOM48880.2022.9796926","article-title":"Feco: boosting intrusion detection capability in IOT networks via contrastive learning","volume-title":"IEEE INFOCOM 2022-IEEE Conference on Computer Communications","author":"Wang","year":"2022"},{"key":"2026011907114171900_ref4","volume-title":"Eleventh Hour CISSP: Study Guide","author":"Conrad","year":"2016, , ,"},{"key":"2026011907114171900_ref5","article-title":"Explaining and harnessing adversarial examples.","author":"Goodfellow","year":"2014"},{"key":"2026011907114171900_ref6","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3395352.3402618","article-title":"Generative adversarial attacks against intrusion detection systems using active learning","volume-title":"Proceedings of the 2nd ACM Workshop on Wireless Security and Machine Learning","author":"Shu","year":"2020"},{"key":"2026011907114171900_ref7","volume-title":"Intriguing properties of neural networks.","author":"Szegedy"},{"key":"2026011907114171900_ref8","doi-asserted-by":"crossref","first-page":"70","DOI":"10.1109\/SPW.2018.00019","article-title":"Bringing a Gan to a knife-fight: adapting malware communication to avoid detection","volume-title":"2018 IEEE Security and Privacy Workshops (SPW)","author":"Rigaki","year":"2018"},{"key":"2026011907114171900_ref9","first-page":"1","article-title":"Evading machine learning botnet detection models via deep reinforcement learning","volume-title":"ICC 2019\u20132019 IEEE International Conference on Communications (ICC)","author":"Di","year":"2019"},{"key":"2026011907114171900_ref10","doi-asserted-by":"publisher","first-page":"162","DOI":"10.1016\/j.neucom.2022.09.004","article-title":"Adversarial attacks and defenses in deep learning for image recognition: a survey","volume":"514","author":"Wang","year":"2022","journal-title":"Neurocomputing"},{"key":"2026011907114171900_ref11","doi-asserted-by":"publisher","first-page":"362","DOI":"10.1002\/rob.21918","article-title":"A survey of deep learning techniques for autonomous driving","volume":"37","author":"Grigorescu","year":"2020","journal-title":"J Field Robot"},{"key":"2026011907114171900_ref12","doi-asserted-by":"crossref","article-title":"Adversarial and clean data are not twins.","author":"Gong","DOI":"10.1145\/3593078.3593935"},{"key":"2026011907114171900_ref13","doi-asserted-by":"crossref","first-page":"582","DOI":"10.1109\/SP.2016.41","article-title":"Distillation as a defense to adversarial perturbations against deep neural networks","volume-title":"2016 IEEE Symposium on Security and Privacy (SP)","author":"Papernot","year":"2016"},{"key":"2026011907114171900_ref14","volume-title":"On the (statistical) detection of adversarial examples","author":"Grosse","year":"2017"},{"key":"2026011907114171900_ref15","article-title":"On detecting adversarial perturbations","author":"Metzen"},{"key":"2026011907114171900_ref16","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/NOMS54207.2022.9789878","article-title":"E-graphsage: a graph neural network based intrusion detection system for IOT","volume-title":"NOMS 2022\u20132022 IEEE\/IFIP Network Operations and Management Symposium","author":"Lo","year":"2022"},{"key":"2026011907114171900_ref17","first-page":"4","article-title":"William L Hamilton, Pietro Li\u00f2, Yoshua Bengio, and R Devon Hjelm","volume":"2","author":"Velickovic","year":"2019","journal-title":"Deep graph infomax ICLR (Poster)"},{"key":"2026011907114171900_ref18","doi-asserted-by":"crossref","first-page":"14","DOI":"10.1145\/3359992.3366642","article-title":"Towards evaluation of nidss in adversarial setting","volume-title":"Proceedings of the 3rd ACM CoNEXT Workshop on Big DAta, Machine Learning and Artificial Intelligence for Data Communication Networks","author":"Hashemi","year":"2019"},{"key":"2026011907114171900_ref19","doi-asserted-by":"crossref","first-page":"39","DOI":"10.1109\/SP.2017.49","article-title":"Towards evaluating the robustness of neural networks","volume-title":"2017 IEEE Symposium on Security and Privacy (Sp)","author":"Carlini","year":"2017"},{"key":"2026011907114171900_ref20","doi-asserted-by":"publisher","first-page":"201","DOI":"10.1016\/j.ins.2013.03.022","article-title":"Adversarial attacks against intrusion detection systems: taxonomy, solutions and open issues","volume":"239","author":"Corona","year":"2013","journal-title":"Inform Sci"},{"key":"2026011907114171900_ref21","article-title":"Towards deep learning models resistant to adversarial attacks.","author":"Madry"},{"key":"2026011907114171900_ref22","doi-asserted-by":"publisher","first-page":"4","DOI":"10.1109\/TNNLS.2020.2978386","article-title":"A comprehensive survey on graph neural networks","volume":"32","author":"Zonghan","year":"2020","journal-title":"IEEE Trans Neural Netw Learn Syst"},{"key":"2026011907114171900_ref23","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/NCA.2019.8935039","article-title":"Evaluating the effectiveness of adversarial attacks against botnet detectors","volume-title":"2019 IEEE 18th International Symposium on Network Computing and Applications (NCA)","author":"Apruzzese","year":"2019"},{"key":"2026011907114171900_ref24","doi-asserted-by":"crossref","first-page":"79","DOI":"10.1007\/978-3-031-05981-0_7","article-title":"Idsgan: generative adversarial networks for attack generation against intrusion detection","volume-title":"Advances in Knowledge Discovery and Data Mining: 26th Pacific-Asia Conference, PAKDD 2022, Chengdu, China, May 16\u201319","author":"Lin","year":"2022"},{"key":"2026011907114171900_ref25","article-title":"Inductive representation learning on large graphs","author":"Hamilton","journal-title":"Annual Conference on Neural Information Processing Systems 2017:1024\u20131034"},{"key":"2026011907114171900_ref26","article-title":"Towards a standard feature set for network intrusion detection system datasets","volume":"27","author":"Sarhan","journal-title":"Mobile Netw Appl"},{"key":"2026011907114171900_ref27","article-title":"Toward generating a new intrusion detection dataset and intrusion traffic characterization","author":"Sharafaldin","journal-title":"Proceedings of the 4th International Conference on Information Systems Security and Privacy (ICISSP 2018)"}],"container-title":["The Computer Journal"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/69\/1\/18\/65482491\/bxaf096.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/69\/1\/18\/65482491\/bxaf096.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,19]],"date-time":"2026-01-19T12:11:54Z","timestamp":1768824714000},"score":1,"resource":{"primary":{"URL":"https:\/\/academic.oup.com\/comjnl\/article\/69\/1\/18\/8340431"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,22]]},"references-count":27,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,11,22]]},"published-print":{"date-parts":[[2026,1,13]]}},"URL":"https:\/\/doi.org\/10.1093\/comjnl\/bxaf096","relation":{},"ISSN":["0010-4620","1460-2067"],"issn-type":[{"value":"0010-4620","type":"print"},{"value":"1460-2067","type":"electronic"}],"subject":[],"published-other":{"date-parts":[[2026,1]]},"published":{"date-parts":[[2025,11,22]]}}}