cs.CRSep 22, 2026

Topological Signatures of Cyber-Attack Classes in Natural Visibility Graph Representations of Network Traffic

Authors: Ali Melih Kanca, Ilker Turker

Organizations: Department of Computer Engineering, Faculty of Computing and Informatics Sciences, Karabuk University, Karabuk, Türkiye

Abstract

Natural Visibility Graph (NVG)-based representations provide a promising approach for capturing structural patterns in sequential network traffic. However, whether different cyber-attack classes exhibit distinctive topological signatures in such representations remains insufficiently understood. This study investigates the discriminative and structural characteristics of NVG-based network traffic representations using the CSE-CIC-IDS2018 dataset. Seventy-six numerical traffic features were independently transformed into NVGs within overlapping frames of 40 observations, and ten graph-theoretic metrics were extracted from each graph, resulting in 760 topological descriptors per frame. The discriminative capability of these representations was evaluated using a multi-branch convolutional neural network (CNN) with stratified five-fold cross-validation. The model achieved an average accuracy of 96.20% and a Matthews correlation coefficient (MCC) of 0.9566. To characterize class-specific topological differences, Kruskal-Wallis and Mann-Whitney U tests were combined with Benjamini-Hochberg false discovery rate correction and effect-size measures. Of the 10,640 attack-versus-benign comparisons, 7,777 (73.1%) remained statistically significant after FDR correction, with 4,844 exhibiting large Cliff's delta effects. The strongest global differences were predominantly associated with backward-traffic and packet-length-related features combined with connectivity, clustering, and centrality measures. These findings indicate that NVG-derived representations can provide strong discriminative capability while revealing class-dependent topological patterns associated with different cyber-attack classes.

Explore similar work

CardsList
  1. Graph Classification via Network Usable Information: From Representation Evaluation to Structure Selection

    Jul 3, 2026Abdullah Shaik, Anwar SaidGraph Representation LearningMultiple Centrality Measures

  2. Timestamp-Aware Spatio-Temporal Graph Contrastive Learning for Network Intrusion Detection

    Jun 15, 2026Jianli Dai, Guangwei Wu, Jiacheng Li +3Intrusion DetectionTemporal Graph Neural Networks

  3. Concept drift mitigation through community and spectral graph analysis for the detectionof cyberattacks in network traffic

    Sep 8, 2026Julien Michel, Abdul Qadir Khan, Majed Jaber +1Threat DetectionGeneralist Graph Anomaly Detection