A Drift-Aware, Robust, and Explainable Graph Attention Network for Intrusion Detection in Encrypted SDN Traffic
Main Article Content
Abstract
Software-Defined Networking improves network programmability but also creates security risks that are increasingly difficult to detect when traffic is encrypted and network behavior changes over time. This study proposes a drift-aware, robust, and explainable Graph Attention Network for intrusion detection in encrypted SDN traffic. The dataset combines 300,000 InSDN records with 120,000 experimentally generated encrypted flows, producing 420,000 observations divided chronologically into training, validation, and streaming-test sets. Encrypted flows were converted into directed communication graphs and processed through edge-aware attention. ADWIN monitored prediction errors to identify concept drift and trigger replay-assisted model adaptation under a prequential evaluation protocol. Robustness was assessed using feature noise, missing attributes, edge removal and insertion, topology shifts, and adversarial modifications. GNNExplainer and PGExplainer evaluated explanation fidelity, sparsity, and stability. The model achieved a macro-F1 of 0.963 under the initial distribution and recovered to 0.951 after drift adaptation, whereas static GAT declined to 0.812. It retained 96.2% of clean-data performance across perturbations, achieved 0.931 explanation fidelity, and required 184.7 ms per graph window. These results demonstrate improved recovery, robustness, and interpretability under the controlled scenarios examined.

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
By signing this statement, I hereby assign and transfer to JCSIS all exclusive copyright rights relating to the work identified above. These rights include, without limitation, the authority to publish, reproduce, revise, adapt, distribute, transmit, market, sell, and otherwise use the work and any associated materials worldwide, either in full or in part, in any language and through any existing or future form of electronic, printed, digital, or other media. JCSIS may also authorize or license third parties to exercise any of these rights. understand that these exclusive rights will be vested in JCSIS from the date on which the article is formally accepted for publication. As the copyright owner, JCSIS will have the exclusive authority to approve, license, or permit the reproduction, distribution, and other uses of the article. Nevertheless, all proprietary rights that are separate from copyright, including patent rights and rights relating to any process, method, or procedure described in the work, will remain with the author. I further acknowledge that JCSIS permits authors to reuse and share their published articles in accordance with the terms and conditions of the applicable Creative Commons license.
References
N. McKeown et al., “OpenFlow,” ACM SIGCOMM Comput. Commun. Rev., vol. 38, no. 2, pp. 69–74, Mar. 2008, doi: https://doi.org/10.1145/1355734.1355746.
M. S. Elsayed, N.-A. Le-Khac, and A. D. Jurcut, “InSDN: A Novel SDN Intrusion Dataset,” IEEE Access, vol. 8, pp. 165263–165284, 2020, doi: https://doi.org/10.1109/ACCESS.2020.3022633.
Y. Zeng, H. Gu, W. Wei, and Y. Guo, “$Deep-Full-Range$ : A Deep Learning Based Network Encrypted Traffic Classification and Intrusion Detection Framework,” IEEE Access, vol. 7, pp. 45182–45190, 2019, doi: https://doi.org/10.1109/ACCESS.2019.2908225.
W. W. Lo, S. Layeghy, M. Sarhan, M. Gallagher, and M. Portmann, “E-GraphSAGE: A Graph Neural Network based Intrusion Detection System for IoT,” in NOMS 2022-2022 IEEE/IFIP Network Operations and Management Symposium, IEEE, Apr. 2022, pp. 1–9. doi: https://doi.org/10.1109/NOMS54207.2022.9789878.
D. Pujol-Perich, J. Suarez-Varela, A. Cabellos-Aparicio, and P. Barlet-Ros, “Unveiling the potential of Graph Neural Networks for robust Intrusion Detection,” ACM SIGMETRICS Perform. Eval. Rev., vol. 49, no. 4, pp. 111–117, Jun. 2022, doi: https://doi.org/10.1145/3543146.3543171.
X. Zhou, W. Liang, W. Li, K. Yan, S. Shimizu, and K. I.-K. Wang, “Hierarchical Adversarial Attacks Against Graph-Neural-Network-Based IoT Network Intrusion Detection System,” IEEE Internet Things J., vol. 9, no. 12, pp. 9310–9319, Jun. 2022, doi: https://doi.org/10.1109/JIOT.2021.3130434.
A. Bifet and R. Gavaldà, “Learning from Time-Changing Data with Adaptive Windowing,” in Proceedings of the 2007 SIAM International Conference on Data Mining, Philadelphia, PA: Society for Industrial and Applied Mathematics, Apr. 2007, pp. 443–448. doi: https://doi.org/10.1137/1.9781611972771.42.
T. A. Tang, L. Mhamdi, D. McLernon, S. A. R. Zaidi, M. Ghogho, and F. El Moussa, “DeepIDS: Deep Learning Approach for Intrusion Detection in Software Defined Networking,” Electronics, vol. 9, no. 9, p. 1533, Sep. 2020, doi: https://doi.org/10.3390/electronics9091533.
S. Rezaei and X. Liu, “Deep Learning for Encrypted Traffic Classification: An Overview,” IEEE Commun. Mag., vol. 57, no. 5, pp. 76–81, May 2019, doi: https://doi.org/10.1109/MCOM.2019.1800819.
J. Gama, I. Žliobaitė, A. Bifet, M. Pechenizkiy, and A. Bouchachia, “A survey on concept drift adaptation,” ACM Comput. Surv., vol. 46, no. 4, pp. 1–37, Apr. 2014, doi: https://doi.org/10.1145/2523813.
W. Jin, Y. Ma, X. Liu, X. Tang, S. Wang, and J. Tang, “Graph Structure Learning for Robust Graph Neural Networks,” in Proceedings of the 26th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, New York, NY, USA: ACM, Aug. 2020, pp. 66–74. doi: https://doi.org/10.1145/3394486.3403049.
Q. Huang, M. Yamada, Y. Tian, D. Singh, and Y. Chang, “GraphLIME: Local Interpretable Model Explanations for Graph Neural Networks,” IEEE Trans. Knowl. Data Eng., vol. 35, no. 7, pp. 6968–6972, Jul. 2023, doi: https://doi.org/10.1109/TKDE.2022.3187455.
A. O. Alzahrani and M. J. F. Alenazi, “Designing a Network Intrusion Detection System Based on Machine Learning for Software Defined Networks,” Futur. Internet, vol. 13, no. 5, p. 111, Apr. 2021, doi: https://doi.org/10.3390/fi13050111.
S. Xu, J. Han, J. Wang, and Y. Bai, “An encrypted traffic classification method based on autoencoders and convolutional neural networks,” PLoS One, vol. 20, no. 9, p. e0333276, Sep. 2025, doi: https://doi.org/10.1371/journal.pone.0333276.
S. Cai, H. Tang, J. Chen, Y. Hu, and W. Guo, “CDDA-MD: An efficient malicious traffic detection method based on concept drift detection and adaptation technique,” Comput. Secur., vol. 148, p. 104121, Jan. 2025, doi: https://doi.org/10.1016/j.cose.2024.104121.
T.-L. Huoh, Y. Luo, P. Li, and T. Zhang, “Flow-Based Encrypted Network Traffic Classification With Graph Neural Networks,” IEEE Trans. Netw. Serv. Manag., vol. 20, no. 2, pp. 1224–1237, Jun. 2023, doi: https://doi.org/10.1109/TNSM.2022.3227500.
B. Lantz, B. Heller, and N. McKeown, “A network in a laptop,” in Proceedings of the 9th ACM SIGCOMM Workshop on Hot Topics in Networks, New York, NY, USA: ACM, Oct. 2010, pp. 1–6. doi: https://doi.org/10.1145/1868447.1868466.
O. Barut, R. Zhu, Y. Luo, and T. Zhang, “TLS Encrypted Application Classification Using Machine Learning with Flow Feature Engineering,” in 2020 the 10th International Conference on Communication and Network Security, New York, NY, USA: ACM, Nov. 2020, pp. 32–41. doi: https://doi.org/10.1145/3442520.3442529.
Z. Diao et al., “EC-GCN: A encrypted traffic classification framework based on multi-scale graph convolution networks,” Comput. Networks, vol. 224, p. 109614, Apr. 2023, doi: https://doi.org/10.1016/j.comnet.2023.109614.
J. J. Davis and A. J. Clark, “Data preprocessing for anomaly based network intrusion detection: A review,” Comput. Secur., vol. 30, no. 6–7, pp. 353–375, Sep. 2011, doi: https://doi.org/10.1016/j.cose.2011.05.008.
M. Di Mauro, G. Galatro, G. Fortino, and A. Liotta, “Supervised feature selection techniques in network intrusion detection: A critical review,” Eng. Appl. Artif. Intell., vol. 101, p. 104216, May 2021, doi: https://doi.org/10.1016/j.engappai.2021.104216.
Y. Zhang, H. Zhang, and B. Zhang, “An Effective Ensemble Automatic Feature Selection Method for Network Intrusion Detection,” Information, vol. 13, no. 7, p. 314, Jun. 2022, doi: https://doi.org/10.3390/info13070314.
A. Moscovich and S. Rosset, “On the Cross-Validation Bias due to Unsupervised Preprocessing,” J. R. Stat. Soc. Ser. B Stat. Methodol., vol. 84, no. 4, pp. 1474–1502, Sep. 2022, doi: https://doi.org/10.1111/rssb.12537.
S. Kapoor and A. Narayanan, “Leakage and the reproducibility crisis in machine-learning-based science,” Patterns, vol. 4, no. 9, p. 100804, Sep. 2023, doi: https://doi.org/10.1016/j.patter.2023.100804.
G. Ren, G. Cheng, and N. Fu, “Accurate Encrypted Malicious Traffic Identification via Traffic Interaction Pattern Using Graph Convolutional Network,” Appl. Sci., vol. 13, no. 3, p. 1483, Jan. 2023, doi: https://doi.org/10.3390/app13031483.
S. A. A. Kalafy, S. Pashazadeh, and P. Salehpour, “Dynamic graph neural network-based framework to increase detection accuracy in SDN under DDOS,” Sci. Rep., vol. 16, no. 1, p. 2305, Dec. 2025, doi: https://doi.org/10.1038/s41598-025-32102-x.
J. Lu, A. Liu, F. Dong, F. Gu, J. Gama, and G. Zhang, “Learning under Concept Drift: A Review,” IEEE Trans. Knowl. Data Eng., pp. 1–1, 2018, doi: https://doi.org/10.1109/TKDE.2018.2876857.
G. Andresini, F. Pendlebury, F. Pierazzi, C. Loglisci, A. Appice, and L. Cavallaro, “INSOMNIA,” in Proceedings of the 14th ACM Workshop on Artificial Intelligence and Security, New York, NY, USA: ACM, Nov. 2021, pp. 111–122. doi: https://doi.org/10.1145/3474369.3486864.
Z. Liu, Y. Luo, L. Wu, S. Li, Z. Liu, and S. Z. Li, “Are Gradients on Graph Structure Reliable in Gray-box Attacks?,” in Proceedings of the 31st ACM International Conference on Information & Knowledge Management, New York, NY, USA: ACM, Oct. 2022, pp. 1360–1368. doi: https://doi.org/10.1145/3511808.3557238.
X. Li, J. Wang, and Z. Yan, “Can Graph Neural Networks be Adequately Explained? A Survey,” ACM Comput. Surv., vol. 57, no. 5, pp. 1–36, May 2025, doi: https://doi.org/10.1145/3711122.