Structural Controls for Temporal Edge Explanations in Snapshot-Based GNN Intrusion Detection
编号:24
访问权限:仅限参会人
更新:2026-10-04 23:18:23 浏览:11次
Online
摘要
Snapshot-based GNN intrusion detectors represent hosts as nodes and flows as edges, so edge explanations of adjacent traffic windows can agree for structural reasons unrelated to attribution. In a controlled case study of E-GraphSAGE on the Infilteration [sic] class of NF-CSE-CIC-IDS2018-v3, with two held-out transitions, ten seeds per range, and descriptive sweeps over mostly in-sample transitions, we test such reasons for GNNExplainer, Saliency, and Occlusion. The reverse copy of the explained flow, added by the bidirectional graph construction, carries most of the raw overlap in one range, and topologylevel cosines are reproduced by binary masks. In the primary comparison, Range A overlap without the target exceeds a null matched on endpoint incidence and flow count (0.179 against 0.097, 10/10 seeds). At the primary 30-epoch budget, the mean same-window top-10 Jaccard between GNNExplainer seeds is only 0.62. Retraining without reverse copies leaves too few active pairs for the protocol’s primary comparison in Range A and reverses the Range B result, so these findings are constructionspecific. Temporal stability alone is therefore not sufficient evidence of explanation quality.
关键词
graph neural networks, network intrusion detection, explainable AI, GNNExplainer, temporal stability, network flow
稿件作者
Thanh Van Tong
Posts and Telecommunications Institute of Technology (PTIT)
Ngoc Hieu Le
Posts and Telecommunications Institute of Technology (PTIT)
Nguyễn Minh Tuấn
Faculty of Information Technology Posts and Telecommunications Institute of Technology Ho Chi Minh City
Xuan Cho Do
Posts and Telecommunications Institute of Technology (PTIT)
Cong Hung Tran
The Saigon International University (SIU)
发表评论