Graph Neural Networks and Graph Autoencoders for intrusion detection systems: A systematic review, taxonomy and comparative analysis


Yagmur E., KOÇAK C., Keles A.

Computer Networks, cilt.288, 2026 (SCI-Expanded, Scopus)

  • Yayın Türü: Makale / Derleme
  • Cilt numarası: 288
  • Basım Tarihi: 2026
  • Doi Numarası: 10.1016/j.comnet.2026.112598
  • Dergi Adı: Computer Networks
  • Derginin Tarandığı İndeksler: Science Citation Index Expanded (SCI-EXPANDED), Scopus, ABI/INFORM, Aerospace Database, Applied Science & Technology Source, Compendex, INSPEC, Library, Information Science & Technology Abstracts (LISTA), zbMATH, Information Science & Technology Abstracts (LISTA), EBSCO Communication Source, Business Source Ultimate (EBSCO), Communication Source (EBSCO), Engineering Source (EBSCO), Technology Collection (ProQuest)
  • Anahtar Kelimeler: Anomaly detection, Cybersecurity, Deep learning, Graph Autoencoders, Graph Neural Networks, Network intrusion detection systems
  • Gazi Üniversitesi Adresli: Evet

Özet

As the volume and complexity of network-based attacks escalate, traditional Intrusion Detection Systems (IDS) encounter significant challenges, including data imbalance, limited availability of labeled datasets, and the detection of zero-day threats. In this context, Graph Neural Networks (GNNs), capable of modeling the topological structure and relational dependencies of network traffic, have emerged as a pivotal research domain. However, the role of Graph Autoencoders (GAEs), characterized by their unsupervised learning capabilities, remains relatively underexplored in the IDS literature. This study provides a systematic and PRISMA-based evaluation of GNN and GAE-based approaches in IDS. In contrast to existing surveys, this study provides a structured categorization of the literature across three primary dimensions: (i) Architectural Approaches, (ii) Application Domains, with a particular emphasis on IoT/IIoT environments, and (iii) System Objectives. Each dimension is systematically analyzed with respect to graph construction methods, learning paradigms, model components, datasets, evaluation metrics, and comparative performance results. Our findings indicate that while supervised GNN models excel in learning known attack patterns, GAE-based frameworks significantly enhance anomaly detection through label-independent structures. Furthermore, hybrid GNN-GAE architectures demonstrate superior generalizability by integrating representation learning with robust decision-making. Consequently, this review establishes a multidimensional perspective on hybrid methodologies, highlights performance trade-offs across different model categories, and defines a strategic research roadmap to address open challenges, including scalability, explainability (XAI), and real-time processing.