Attention Guided Graph Neural Network and Bayesian Reasoning Framework for Cross-Zone Cyber-Physical Threat Intelligence and Context-Aware Predictive Smart Defense

PDF (1546KB), PP.89-107

Views: 0 Downloads: 0

Author(s)

Macherla Malleswara Rao 1,* Pavan Kumar Tummala 1

1. Department of Computer Science and Engineering, Koneru Lakshmaiah Education Foundation, Vaddeswaram, Guntur, 522302, India

* Corresponding author.

DOI: https://doi.org/10.5815/ijcnis.2026.05.06

Received: 6 Feb. 2026 / Revised: 25 Mar. 2026 / Accepted: 3 Jun. 2026 / Published: 8 Oct. 2026

Index Terms

Smart Defense, Deep Ladder Imputation Network, Multi-Agent Reinforcement Learning, TabNet Encoder, FedQMIX, Attack Detection.

Abstract

Context-sensitive smart defense represents a crucial element in protecting distributed cyber-physical systems against advanced and well-coordinated adversarial actions. The current defense architectures face serious issues, such as incompleteness of situational observability and a lack of cross-zone coordination during uncertainty conditions. In order to overcome these constraints, a context-aware smart defense system was proposed that integrates multi-source data and different learning approaches for Intrusion Detection System (IDS) and mitigation. The framework is a collection of data from a variety of sensors, surveillance cameras, radars, and threat databases scattered across numerous Defense Zones. During data transmission from multi-modality devices, there is a possibility of intrusion. For IDS, the network data is pre-processed using Deep Ladder Imputation Networks (DLIN) to fill in gaps and then dispersion-based normalization. Structured sensor and network data are used by the TabNet encoder, and cross-modal attention modules are used to preserve essential network features from different modalities. Graph Neural Networks are used to enable the spatial-temporal analysis to extract the contextual threat information. In the case of emerging or data-sparse zones, Auto Encoder-based Transfer-Learning (AE-TL) methods can be used to produce domain adaptation based on data-rich zones. When attacks are detected, a federated learning-based multi-agent reinforcement learning based on FedQMIX coordinates defense measures without violating data privacy. Bayesian threat inference is used to assess the possibility of future adversarial attacks in non-attack conditions. Empirical assessments indicate that the suggested transfer-learning approach achieves an accuracy of 98.50% and an F-beta of 97.85%. Federated learning combined with reinforcement learning attains an accuracy of 98.1% and 95.6% on attack data and generated data, respectively. Overall, the framework enhances threat detection and coordinated response capabilities, providing a solution to the protection of distributed cyber-physical infrastructures.

Cite This Paper

Macherla Malleswara Rao, Pavan Kumar Tummala, "Attention Guided Graph Neural Network and Bayesian Reasoning Framework for Cross-Zone Cyber-Physical Threat Intelligence and Context-Aware Predictive Smart Defense", International Journal of Computer Network and Information Security(IJCNIS), Vol.18, No.5, pp. 89-107, 2026. DOI:10.5815/ijcnis.2026.05.06

Reference

[1]M. Sarhan, W. W. Lo, S. Layeghy, and M. Portmann, “HBFL: A hierarchical blockchain-based federated learning framework for collaborative IoT intrusion detection,” Computers and Electrical Engineering, vol. 103, Art. no. 108379, 2022.
[2]A. P. Kalapaaking, I. Khalil, and X. Yi, “Blockchain-based federated learning with SMPC model verification against poisoning attack for healthcare systems,” IEEE Transactions on Emerging Topics in Computing, vol. 12, no. 1, pp. 269–280, 2024.
[3]E. Hallaji, R. Razavi-Far, M. Saif, and E. Herrera-Viedma, “Label noise analysis meets adversarial training: A defense against label poisoning in federated learning,” Knowledge-Based Systems, vol. 266, Art. no. 110384, 2023.
[4]Z. Song, H. Sun, H. H. Yang, X. Wang, Y. Zhang, and T. Q. S. Quek, “Reputation-based federated learning for secure wireless networks,” IEEE Internet of Things Journal, vol. 9, no. 2, pp. 1212–1226, 2022.
[5]Y. Li, X. Wei, Y. Li, Z. Dong, and M. Shahidehpour, “Detection of false data injection attacks in smart grid: A secure federated deep learning approach,” IEEE Transactions on Smart Grid, vol. 13, no. 6, pp. 4862–4872, 2022.
[6]M. K. Ishak, “Mathematical modeling of cyberattack defense mechanism using hybrid transfer learning with snow ablation optimization algorithm in critical infrastructures,” IEEE Access, vol. 13, pp. 13329–13340, 2025.
[7]N. Khatri, S. Lee, and S. Y. Nam, “Transfer learning-based intrusion detection system for a controller area network,” IEEE Access, vol. 11, pp. 120963–120982, 2023.
[8]R. Rentero-Trejo, D. Flores-Martín, J. Galán-Jiménez, J. García-Alonso, J. M. Murillo, and J. Berrocal, “Using federated learning to achieve proactive context-aware IoT environments,” Journal of Web Engineering, vol. 21, no. 1, pp. 53–74, 2022.
[9]T. T. Thein, Y. Shiraishi, and M. Morii, “Personalized federated learning-based intrusion detection system: Poisoning attack and defense,” Future Generation Computer Systems, vol. 153, pp. 182–192, 2024.
[10]K. Sethi, E. Sai Rupesh, R. Kumar, et al., “A context-aware robust intrusion detection system: A reinforcement learning-based approach,” International Journal of Information Security, vol. 19, pp. 657–678, 2020.
[11]E. Hallaji, R. Razavi-Far, and M. Saif, “DLIN: Deep ladder imputation network,” IEEE Transactions on Cybernetics, vol. 52, no. 9, pp. 8629–8641, 2022.
[12]C. Hafemeister and R. Satija, “Normalization and variance stabilization of single-cell RNA-seq data using regularized negative binomial regression,” Genome Biology, vol. 20, Art. no. 296, 2019.
[13]M. S. C. V., A. M. K., R. Satheesh, and H. H. Alhelou, “Enhanced electric vehicle energy consumption prediction with TabTransformer, TabNet, and bidirectional encoder representations from transformers embeddings,” IEEE Transactions on Industrial Informatics, vol. 21, no. 10, pp. 7445–7454, 2025.
[14]W. Cai, Y. Wang, J. Ma, and Q. Jin, “CAN: Effective cross features by global attention mechanism and neural network for ad click prediction,” Tsinghua Science and Technology, vol. 27, no. 1, pp. 186–195, 2022.
[15]Z. Li, M. Bilal, X. Xu, J. Jiang, and Y. Cui, “Federated learning-based cross-enterprise recommendation with graph neural networks,” IEEE Transactions on Industrial Informatics, vol. 19, no. 1, pp. 673–682, 2023.
[16]K. Dev, Z. Ashraf, P. K. Muhuri, et al., “Deep autoencoder based domain adaptation for transfer learning,” Multimedia Tools and Applications, vol. 81, pp. 22379–22405, 2022.
[17]S. Cao, H. Zhang, T. Wen, H. Zhao, Q. Zheng, W. Zhang, and D. Zheng, “FedQMIX: Communication-efficient federated learning via multi-agent reinforcement learning,” High-Confidence Computing, vol. 4, no. 2, Art. no. 100179, 2024.
[18]W. Siripattanadilok and T. Siriborvornratanakul, “Recognition of partially occluded soft-shell mud crabs using Faster R-CNN and Grad-CAM,” Aquaculture International, vol. 32, pp. 2977–2997, 2024.
[19]S. T. Mehedi, A. Anwar, Z. Rahman, K. Ahmed, and R. Islam, “Dependable intrusion detection system for IoT: A deep transfer learning based approach,” IEEE Transactions on Industrial Informatics, vol. 19, no. 1, pp. 1006–1017, 2023.
[20]D. C. Nguyen et al., “Federated learning for industrial Internet of Things in future industries,” IEEE Wireless Communications, vol. 28, no. 6, pp. 192–199, 2021.
[21]S. Bhosale, “Network intrusion detection dataset,” Kaggle, Oct. 2018. [Online]. Available: https://www.kaggle.com/sampadab17/network-intrusion-detection
[22]J. Al-Sawwa, “Multi-Step Cyber-Attack Dataset (MSCAD),” Kaggle, 2022. [Online]. Available: https://www.kaggle.com/datasets/drjamailalsawwa/mscad
[23]A. Alhowaide, “IoT dataset for intrusion detection systems,” Kaggle, 2021. [Online]. Available: https://www.kaggle.com/datasets/azalhowaide/iot-dataset-for-intrusion-detection-systems-ids