AutoGraphAD: Unsupervised network anomaly detection using Variational Graph Autoencoders

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Anyfantis, Georgios, Barlet-Ros, Pere
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917428707983360
author Anyfantis, Georgios
Barlet-Ros, Pere
author_facet Anyfantis, Georgios
Barlet-Ros, Pere
contents Network Intrusion Detection Systems (NIDS) are essential tools for detecting network attacks and intrusions. While extensive research has explored the use of supervised Machine Learning for attack detection and characterisation, these methods require accurately labelled datasets, which are very costly to obtain. Moreover, existing public datasets have limited and/or outdated attacks, and many of them suffer from mislabelled data. To reduce the reliance on labelled data, we propose AutoGraphAD, a novel unsupervised anomaly detection based on a Heterogeneous Variational Graph Autoencoder. AutoGraphAD operates on heterogeneous graphs, made from connection and IP nodes that represent network activity. The model is trained using unsupervised and contrastive learning, without relying on any labelled data. The model's losses are then weighted and combined in an anomaly score used for anomaly detection. Overall, AutoGraphAD yields the same, and in some cases better, results than Anomal-E, but without requiring costly downstream anomaly detectors. As a result, AutoGraphAD achieves around 1.18 orders of magnitude faster training and 1.03 orders of magnitude faster inference, which represents a significant advantage for operational deployment.
format Preprint
id arxiv_https___arxiv_org_abs_2511_17113
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle AutoGraphAD: Unsupervised network anomaly detection using Variational Graph Autoencoders
Anyfantis, Georgios
Barlet-Ros, Pere
Cryptography and Security
Artificial Intelligence
Machine Learning
Network Intrusion Detection Systems (NIDS) are essential tools for detecting network attacks and intrusions. While extensive research has explored the use of supervised Machine Learning for attack detection and characterisation, these methods require accurately labelled datasets, which are very costly to obtain. Moreover, existing public datasets have limited and/or outdated attacks, and many of them suffer from mislabelled data. To reduce the reliance on labelled data, we propose AutoGraphAD, a novel unsupervised anomaly detection based on a Heterogeneous Variational Graph Autoencoder. AutoGraphAD operates on heterogeneous graphs, made from connection and IP nodes that represent network activity. The model is trained using unsupervised and contrastive learning, without relying on any labelled data. The model's losses are then weighted and combined in an anomaly score used for anomaly detection. Overall, AutoGraphAD yields the same, and in some cases better, results than Anomal-E, but without requiring costly downstream anomaly detectors. As a result, AutoGraphAD achieves around 1.18 orders of magnitude faster training and 1.03 orders of magnitude faster inference, which represents a significant advantage for operational deployment.
title AutoGraphAD: Unsupervised network anomaly detection using Variational Graph Autoencoders
topic Cryptography and Security
Artificial Intelligence
Machine Learning
url https://arxiv.org/abs/2511.17113