Work place: Department of Computer Science and Engineering, Jain College of Engineering, Belagavi, Affiliated to Visvesvaraya Technological University, Belagavi, Karnataka, India
E-mail: vsdandagi@gmail.com
Website: https://orcid.org/0000-0002-8586-0995
Research Interests:
Biography
Vidya S. Dandagi, is an Associate Professor in the Department of Computer Science and Engineering at Jain College of Engineering, Belagavi, India. She has over 16 years of teaching experience at both undergraduate and postgraduate levels in Computer Science and Engineering. She has authored and co-authored several research papers published in peer-reviewed national and international journals and conference proceedings. Her research interests include the Semantic Web, Graph Machine Learning, data analytics, and artificial intelligence.
By Rohit B. Sadigale Vidya S. Dandagi Vijay H. Kalmani
DOI: https://doi.org/10.5815/ijwmt.2026.05.11, Pub. Date: 8 Oct. 2026
Signature-based IDS is becoming more difficult due to the ever-increasing amount of encrypted network traffic. Hence, the demand for interpretable and lightweight intrusion detection techniques becomes essential. In this paper, we propose Graph-Temporal Adaptive Intrusion Detection-Non-Parametric (GTAID-NP), which is a novel graph-temporal framework that exploits degree-based graph structure, temporal periodicity extracted using Fast Fourier Transform, and non-parametric log-odds estimation. We evaluate our proposed model on the BCCC-DarkNet-2025 benchmark dataset that contains 22,795 flow records, among which 6,317 are encrypted and 16,478 are not encrypted, which are expressed by 427 features. An extensive ablation study on 192 experiment setups was done to analyze the influence of bin granularity, total-variation smoothing, feature selection strategy, top-K feature selection threshold, graph augmentation, temporal periodicity extraction, and leakage-guard correction based on an 80:20 stratified train-test split. Among all experimental setups, the best setup achieves an AUC of 0.878. The results suggest that fine granular binning, weak smoothing, and joint consideration of graph-structure and temporal properties contribute to better detection performance. We also conduct robustness evaluation of GTAID-NP through five different random seed runs, which achieve a mean AUC of 0.9074 ± 0.0036, showing the stable performance of GTAID-NP on various train/test splits. While the ensemble methods outperform our model on the benchmark score, GTAID-NP can be regarded as a transparent and lightweight approach for intrusion detection on encrypted traffic. Future research works include adversarial robustness, federated inference, and adaptive online learning.
[...] Read more.Subscribe to receive issue release notifications and newsletters from MECS Press journals