Are We There Yet? Unraveling the State-of-the-Art Graph Network Intrusion Detection Systems

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wang, Chenglong, Zheng, Pujia, Gui, Jiaping, Hua, Cunqing, Hassan, Wajih Ul
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908284987899904
author Wang, Chenglong
Zheng, Pujia
Gui, Jiaping
Hua, Cunqing
Hassan, Wajih Ul
author_facet Wang, Chenglong
Zheng, Pujia
Gui, Jiaping
Hua, Cunqing
Hassan, Wajih Ul
contents Network Intrusion Detection Systems (NIDS) are vital for ensuring enterprise security. Recently, Graph-based NIDS (GIDS) have attracted considerable attention because of their capability to effectively capture the complex relationships within the graph structures of data communications. Despite their promise, the reproducibility and replicability of these GIDS remain largely unexplored, posing challenges for developing reliable and robust detection systems. This study bridges this gap by designing a systematic approach to evaluate state-of-the-art GIDS, which includes critically assessing, extending, and clarifying the findings of these systems. We further assess the robustness of GIDS under adversarial attacks. Evaluations were conducted on three public datasets as well as a newly collected large-scale enterprise dataset. Our findings reveal significant performance discrepancies, highlighting challenges related to dataset scale, model inputs, and implementation settings. We demonstrate difficulties in reproducing and replicating results, particularly concerning false positive rates and robustness against adversarial attacks. This work provides valuable insights and recommendations for future research, emphasizing the importance of rigorous reproduction and replication studies in developing robust and generalizable GIDS solutions.
format Preprint
id arxiv_https___arxiv_org_abs_2503_20281
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Are We There Yet? Unraveling the State-of-the-Art Graph Network Intrusion Detection Systems
Wang, Chenglong
Zheng, Pujia
Gui, Jiaping
Hua, Cunqing
Hassan, Wajih Ul
Cryptography and Security
Artificial Intelligence
Network Intrusion Detection Systems (NIDS) are vital for ensuring enterprise security. Recently, Graph-based NIDS (GIDS) have attracted considerable attention because of their capability to effectively capture the complex relationships within the graph structures of data communications. Despite their promise, the reproducibility and replicability of these GIDS remain largely unexplored, posing challenges for developing reliable and robust detection systems. This study bridges this gap by designing a systematic approach to evaluate state-of-the-art GIDS, which includes critically assessing, extending, and clarifying the findings of these systems. We further assess the robustness of GIDS under adversarial attacks. Evaluations were conducted on three public datasets as well as a newly collected large-scale enterprise dataset. Our findings reveal significant performance discrepancies, highlighting challenges related to dataset scale, model inputs, and implementation settings. We demonstrate difficulties in reproducing and replicating results, particularly concerning false positive rates and robustness against adversarial attacks. This work provides valuable insights and recommendations for future research, emphasizing the importance of rigorous reproduction and replication studies in developing robust and generalizable GIDS solutions.
title Are We There Yet? Unraveling the State-of-the-Art Graph Network Intrusion Detection Systems
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2503.20281