Tehnički vjesnik, Vol. 33 No. 5, 2026.
Izvorni znanstveni članak
https://doi.org/10.17559/TV-20251122003150
Temporal-Contextual Graph Transformer for Adaptive Intrusion Detection Systems in Internet of Things
R. Nithya
; Department of CSE, Vivekanandha College of Engineering for Women (Autonomous), India
K. Vinoth Kumar
; SRM Bharathidasan College of Engineering and Technology (SRMBCET), SRM Pudukkottai Campus, Tamil Nadu, India
*
A. Mohan Kumar
; Department of ECE, Kongunadu College of Engineering and Technology, Thottiyam, India
* Dopisni autor.
Sažetak
The increasing complexity and stealth of cyber-attacks, particularly in Internet of Things (IoT) environments, necessitate robust intrusion detection systems (IDSs) capable of identifying latent anomalies within large-scale network traffic. Although Graph Neural Networks (GNNs) have demonstrated strong potential for modeling inter-nodal dependencies, existing approaches face significant challenges in capturing temporal dynamics, scaling to massive graphs, and mitigating the over-smoothing problem. Moreover, many current solutions lack interpretability, limiting their practical usability for security analysts who require timely and explainable threat intelligence. To address these limitations, this paper proposes a Temporal-Contextual Graph Transformer for Adaptive Intrusion Detection (TCG-AID). The framework integrates a dynamic graph construction module with a Temporal-Contextual Graph Transformer (TCGT) block, in which temporal gating mechanisms are embedded within the self-attention architecture to effectively learn evolving attack patterns and sequential dependencies. Hierarchical attention is employed to enhance scalability, while an adaptive anomaly detection head jointly leverages supervised and unsupervised learning for robust detection across diverse attack scenarios. A key novelty of TCG-AID is its interpretability layer, which provides explicit insights into the factors influencing detection decisions, thereby improving analyst trust and response effectiveness. Comprehensive experiments on real-world network traffic datasets demonstrate that TCG-AID achieves superior detection performance while maintaining strong computational efficiency. As dataset size increases from 103 to 106 samples, TCG-AID exhibits 30-55% lower training time and 40-60% faster inference time compared to deep learning and graph-based baselines, including CNN-LSTM, RNN-IDS, XGBoost, and E-GraphSAGE. Importantly, its time complexity grows sub-linearly on a logarithmic scale, confirming excellent scalability for large-scale IoT deployments. These results establish TCG-AID as an accurate, scalable, and explainable IDS framework capable of delivering actionable threat intelligence in real-world IoT environments.
Ključne riječi
graph attention network; internet of things (IoT); intrusion detection system; transformer-based model
Hrčak ID:
350424
URI
Datum izdavanja:
31.8.2026.
Posjeta: 0 *