A Drift-Aware, Robust, and Explainable Graph Attention Network for Intrusion Detection in Encrypted SDN Traffic

Main Article Content

Junaedi
Ardiane Rossi Kurniawan Maranto
Huynh Trong Thua

Abstract

Software-Defined Networking improves network programmability but also creates security risks that are increasingly difficult to detect when traffic is encrypted and network behavior changes over time. This study proposes a drift-aware, robust, and explainable Graph Attention Network for intrusion detection in encrypted SDN traffic. The dataset combines 300,000 InSDN records with 120,000 experimentally generated encrypted flows, producing 420,000 observations divided chronologically into training, validation, and streaming-test sets. Encrypted flows were converted into directed communication graphs and processed through edge-aware attention. ADWIN monitored prediction errors to identify concept drift and trigger replay-assisted model adaptation under a prequential evaluation protocol. Robustness was assessed using feature noise, missing attributes, edge removal and insertion, topology shifts, and adversarial modifications. GNNExplainer and PGExplainer evaluated explanation fidelity, sparsity, and stability. The model achieved a macro-F1 of 0.963 under the initial distribution and recovered to 0.951 after drift adaptation, whereas static GAT declined to 0.812. It retained 96.2% of clean-data performance across perturbations, achieved 0.931 explanation fidelity, and required 184.7 ms per graph window. These results demonstrate improved recovery, robustness, and interpretability under the controlled scenarios examined.

Section
Articles

References

N. McKeown et al., “OpenFlow,” ACM SIGCOMM Comput. Commun. Rev., vol. 38, no. 2, pp. 69–74, Mar. 2008, doi: https://doi.org/10.1145/1355734.1355746.

M. S. Elsayed, N.-A. Le-Khac, and A. D. Jurcut, “InSDN: A Novel SDN Intrusion Dataset,” IEEE Access, vol. 8, pp. 165263–165284, 2020, doi: https://doi.org/10.1109/ACCESS.2020.3022633.

Y. Zeng, H. Gu, W. Wei, and Y. Guo, “$Deep-Full-Range$ : A Deep Learning Based Network Encrypted Traffic Classification and Intrusion Detection Framework,” IEEE Access, vol. 7, pp. 45182–45190, 2019, doi: https://doi.org/10.1109/ACCESS.2019.2908225.

W. W. Lo, S. Layeghy, M. Sarhan, M. Gallagher, and M. Portmann, “E-GraphSAGE: A Graph Neural Network based Intrusion Detection System for IoT,” in NOMS 2022-2022 IEEE/IFIP Network Operations and Management Symposium, IEEE, Apr. 2022, pp. 1–9. doi: https://doi.org/10.1109/NOMS54207.2022.9789878.

D. Pujol-Perich, J. Suarez-Varela, A. Cabellos-Aparicio, and P. Barlet-Ros, “Unveiling the potential of Graph Neural Networks for robust Intrusion Detection,” ACM SIGMETRICS Perform. Eval. Rev., vol. 49, no. 4, pp. 111–117, Jun. 2022, doi: https://doi.org/10.1145/3543146.3543171.

X. Zhou, W. Liang, W. Li, K. Yan, S. Shimizu, and K. I.-K. Wang, “Hierarchical Adversarial Attacks Against Graph-Neural-Network-Based IoT Network Intrusion Detection System,” IEEE Internet Things J., vol. 9, no. 12, pp. 9310–9319, Jun. 2022, doi: https://doi.org/10.1109/JIOT.2021.3130434.

A. Bifet and R. Gavaldà, “Learning from Time-Changing Data with Adaptive Windowing,” in Proceedings of the 2007 SIAM International Conference on Data Mining, Philadelphia, PA: Society for Industrial and Applied Mathematics, Apr. 2007, pp. 443–448. doi: https://doi.org/10.1137/1.9781611972771.42.

T. A. Tang, L. Mhamdi, D. McLernon, S. A. R. Zaidi, M. Ghogho, and F. El Moussa, “DeepIDS: Deep Learning Approach for Intrusion Detection in Software Defined Networking,” Electronics, vol. 9, no. 9, p. 1533, Sep. 2020, doi: https://doi.org/10.3390/electronics9091533.

S. Rezaei and X. Liu, “Deep Learning for Encrypted Traffic Classification: An Overview,” IEEE Commun. Mag., vol. 57, no. 5, pp. 76–81, May 2019, doi: https://doi.org/10.1109/MCOM.2019.1800819.

J. Gama, I. Žliobaitė, A. Bifet, M. Pechenizkiy, and A. Bouchachia, “A survey on concept drift adaptation,” ACM Comput. Surv., vol. 46, no. 4, pp. 1–37, Apr. 2014, doi: https://doi.org/10.1145/2523813.

W. Jin, Y. Ma, X. Liu, X. Tang, S. Wang, and J. Tang, “Graph Structure Learning for Robust Graph Neural Networks,” in Proceedings of the 26th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, New York, NY, USA: ACM, Aug. 2020, pp. 66–74. doi: https://doi.org/10.1145/3394486.3403049.

Q. Huang, M. Yamada, Y. Tian, D. Singh, and Y. Chang, “GraphLIME: Local Interpretable Model Explanations for Graph Neural Networks,” IEEE Trans. Knowl. Data Eng., vol. 35, no. 7, pp. 6968–6972, Jul. 2023, doi: https://doi.org/10.1109/TKDE.2022.3187455.

A. O. Alzahrani and M. J. F. Alenazi, “Designing a Network Intrusion Detection System Based on Machine Learning for Software Defined Networks,” Futur. Internet, vol. 13, no. 5, p. 111, Apr. 2021, doi: https://doi.org/10.3390/fi13050111.

S. Xu, J. Han, J. Wang, and Y. Bai, “An encrypted traffic classification method based on autoencoders and convolutional neural networks,” PLoS One, vol. 20, no. 9, p. e0333276, Sep. 2025, doi: https://doi.org/10.1371/journal.pone.0333276.

S. Cai, H. Tang, J. Chen, Y. Hu, and W. Guo, “CDDA-MD: An efficient malicious traffic detection method based on concept drift detection and adaptation technique,” Comput. Secur., vol. 148, p. 104121, Jan. 2025, doi: https://doi.org/10.1016/j.cose.2024.104121.

T.-L. Huoh, Y. Luo, P. Li, and T. Zhang, “Flow-Based Encrypted Network Traffic Classification With Graph Neural Networks,” IEEE Trans. Netw. Serv. Manag., vol. 20, no. 2, pp. 1224–1237, Jun. 2023, doi: https://doi.org/10.1109/TNSM.2022.3227500.

B. Lantz, B. Heller, and N. McKeown, “A network in a laptop,” in Proceedings of the 9th ACM SIGCOMM Workshop on Hot Topics in Networks, New York, NY, USA: ACM, Oct. 2010, pp. 1–6. doi: https://doi.org/10.1145/1868447.1868466.

O. Barut, R. Zhu, Y. Luo, and T. Zhang, “TLS Encrypted Application Classification Using Machine Learning with Flow Feature Engineering,” in 2020 the 10th International Conference on Communication and Network Security, New York, NY, USA: ACM, Nov. 2020, pp. 32–41. doi: https://doi.org/10.1145/3442520.3442529.

Z. Diao et al., “EC-GCN: A encrypted traffic classification framework based on multi-scale graph convolution networks,” Comput. Networks, vol. 224, p. 109614, Apr. 2023, doi: https://doi.org/10.1016/j.comnet.2023.109614.

J. J. Davis and A. J. Clark, “Data preprocessing for anomaly based network intrusion detection: A review,” Comput. Secur., vol. 30, no. 6–7, pp. 353–375, Sep. 2011, doi: https://doi.org/10.1016/j.cose.2011.05.008.

M. Di Mauro, G. Galatro, G. Fortino, and A. Liotta, “Supervised feature selection techniques in network intrusion detection: A critical review,” Eng. Appl. Artif. Intell., vol. 101, p. 104216, May 2021, doi: https://doi.org/10.1016/j.engappai.2021.104216.

Y. Zhang, H. Zhang, and B. Zhang, “An Effective Ensemble Automatic Feature Selection Method for Network Intrusion Detection,” Information, vol. 13, no. 7, p. 314, Jun. 2022, doi: https://doi.org/10.3390/info13070314.

A. Moscovich and S. Rosset, “On the Cross-Validation Bias due to Unsupervised Preprocessing,” J. R. Stat. Soc. Ser. B Stat. Methodol., vol. 84, no. 4, pp. 1474–1502, Sep. 2022, doi: https://doi.org/10.1111/rssb.12537.

S. Kapoor and A. Narayanan, “Leakage and the reproducibility crisis in machine-learning-based science,” Patterns, vol. 4, no. 9, p. 100804, Sep. 2023, doi: https://doi.org/10.1016/j.patter.2023.100804.

G. Ren, G. Cheng, and N. Fu, “Accurate Encrypted Malicious Traffic Identification via Traffic Interaction Pattern Using Graph Convolutional Network,” Appl. Sci., vol. 13, no. 3, p. 1483, Jan. 2023, doi: https://doi.org/10.3390/app13031483.

S. A. A. Kalafy, S. Pashazadeh, and P. Salehpour, “Dynamic graph neural network-based framework to increase detection accuracy in SDN under DDOS,” Sci. Rep., vol. 16, no. 1, p. 2305, Dec. 2025, doi: https://doi.org/10.1038/s41598-025-32102-x.

J. Lu, A. Liu, F. Dong, F. Gu, J. Gama, and G. Zhang, “Learning under Concept Drift: A Review,” IEEE Trans. Knowl. Data Eng., pp. 1–1, 2018, doi: https://doi.org/10.1109/TKDE.2018.2876857.

G. Andresini, F. Pendlebury, F. Pierazzi, C. Loglisci, A. Appice, and L. Cavallaro, “INSOMNIA,” in Proceedings of the 14th ACM Workshop on Artificial Intelligence and Security, New York, NY, USA: ACM, Nov. 2021, pp. 111–122. doi: https://doi.org/10.1145/3474369.3486864.

Z. Liu, Y. Luo, L. Wu, S. Li, Z. Liu, and S. Z. Li, “Are Gradients on Graph Structure Reliable in Gray-box Attacks?,” in Proceedings of the 31st ACM International Conference on Information & Knowledge Management, New York, NY, USA: ACM, Oct. 2022, pp. 1360–1368. doi: https://doi.org/10.1145/3511808.3557238.

X. Li, J. Wang, and Z. Yan, “Can Graph Neural Networks be Adequately Explained? A Survey,” ACM Comput. Surv., vol. 57, no. 5, pp. 1–36, May 2025, doi: https://doi.org/10.1145/3711122.