GTAID-NP: A Bin-wise Log-Odds Framework with Graph and FFT Features for Encrypted Traffic Anomaly Detection

PDF (894KB), PP.174-190

Views: 0 Downloads: 0

Author(s)

Rohit B. Sadigale 1,2,* Vidya S. Dandagi 1 Vijay H. Kalmani 2

1. Department of Computer Science and Engineering, Jain College of Engineering, Belagavi, Affiliated to Visvesvaraya Technological University, Belagavi, Karnataka, India

2. Department of Computer Science and Engineering, Kasegaon Education Society’s, Rajaramabapu Institute of Technology, Rajaramnagar, Ishwarpur, Sangli, 415 414, Affiliated to Shivaji University, Sakharale, Maharashtra, India

* Corresponding author.

DOI: https://doi.org/10.5815/ijwmt.2026.05.11

Received: 30 May 2026 / Revised: 17 Jun. 2026 / Accepted: 23 Jul. 2026 / Published: 8 Oct. 2026

Index Terms

Encrypted Traffic Analysis, Intrusion Detection Systems, Graph-Temporal Modelling, Non-Parametric Learning, Network Traffic Analysis, Cybersecurity Analytics

Abstract

Signature-based IDS is becoming more difficult due to the ever-increasing amount of encrypted network traffic. Hence, the demand for interpretable and lightweight intrusion detection techniques becomes essential. In this paper, we propose Graph-Temporal Adaptive Intrusion Detection-Non-Parametric (GTAID-NP), which is a novel graph-temporal framework that exploits degree-based graph structure, temporal periodicity extracted using Fast Fourier Transform, and non-parametric log-odds estimation. We evaluate our proposed model on the BCCC-DarkNet-2025 benchmark dataset that contains 22,795 flow records, among which 6,317 are encrypted and 16,478 are not encrypted, which are expressed by 427 features. An extensive ablation study on 192 experiment setups was done to analyze the influence of bin granularity, total-variation smoothing, feature selection strategy, top-K feature selection threshold, graph augmentation, temporal periodicity extraction, and leakage-guard correction based on an 80:20 stratified train-test split. Among all experimental setups, the best setup achieves an AUC of 0.878. The results suggest that fine granular binning, weak smoothing, and joint consideration of graph-structure and temporal properties contribute to better detection performance. We also conduct robustness evaluation of GTAID-NP through five different random seed runs, which achieve a mean AUC of 0.9074 ± 0.0036, showing the stable performance of GTAID-NP on various train/test splits. While the ensemble methods outperform our model on the benchmark score, GTAID-NP can be regarded as a transparent and lightweight approach for intrusion detection on encrypted traffic. Future research works include adversarial robustness, federated inference, and adaptive online learning.

Cite This Paper

Rohit B. Sadigale, Vidya S. Dandagi, Vijay H. Kalmani, "GTAID-NP: A Bin-wise Log-Odds Framework with Graph and FFT Features for Encrypted Traffic Anomaly Detection", International Journal of Wireless and Microwave Technologies(IJWMT), Vol.16, No.5, pp. 174-190, 2026. DOI:10.5815/ijwmt.2026.05.11

Reference

[1]Fatma S. Alrayes, Mohammed Zakariah, Syed Umar Amin, Zafar Iqbal Khan, and Jehad Saad Alqurni, “Network Security Enhanced with Deep Neural Network-Based Intrusion Detection System,” Computers, Materials and Continua, vol. 80, 2024.
[2]G. B. Veeresh, Vanita Jaitly, and V. Lokeswara Reddy, “Swish-Optimized trident fusion network for precise attack classification in software-defined networks,” Knowledge-Based Systems, vol. 332, 2026.
[3]Ayesha Alharthi, Meera Alaryani, and Sanaa Kaddoura, “A comparative study of machine learning and deep learning models in binary and multiclass classification for intrusion detection systems,” Array, vol. 26, 2025.
[4]Mehmet Ozdem, “A novel approach for real-time anomaly detection in dynamic computer networks using temporal graph networks and explainable artificial intelligence,” Alexandria Engineering Journal, vol. 132, 2025.
[5]Burak Aydin, Hakan Aydin, and Sedat Gormus, “Intrusion detection systems in IoT: A detailed review of threat categories, detection strategies, and future technologies,” Journal of Information Security and Applications, vol. 95, 2025.
[6]Mahdi Soltani, Behzad Ousat, Mahdi Jafari Siavoshani, and Amir Hossein Jahangir, “An adaptable deep learning-based intrusion detection system to zero-day attacks,” Journal of Information Security and Applications, vol. 76, 2023.
[7]Waqas Ishtiaq, Ashrafun Zannat, A. H. M. Shahariar Parvez, Md. Alamgir Hossain, Muntasir Hasan Kanchan, and Muhammad Masud Tarek, “CST-AFNet: A dual attention-based deep learning framework for intrusion detection in IoT networks,” Array, vol. 27, 2025.
[8]Akbar Telikani and Amir H. Gandomi, “Cost-sensitive stacked auto-encoders for intrusion detection in the Internet of Things,” Internet of Things, vol. 14, 2021.
[9]Huseyin Ahmetoglu and Resul Das, “A comprehensive review on detection of cyber-attacks: Data sets, methods, challenges, and future research directions,” Internet of Things, vol. 20, 2022.
[10]Md. Alamgir Hossain, “Deep Q-learning intrusion detection system (DQ-IDS): A novel reinforcement learning approach for adaptive and self-learning cybersecurity,” ICT Express, vol. 11, 2025.
[11]Hamza Kheddar, “Transformers and large language models for efficient intrusion detection systems: A comprehensive survey,” Information Fusion, vol. 124, 2025.
[12]Phan The Duy, Do Thi Thu Hien, Tran Duc Luong, Nguyen Huu Quyen, and Van-Hau Pham, “Fed-Evolver: An automated evolving approach for federated Intrusion Detection System using adversarial autoencoder in SDN-enabled networks,” Internet of Things, vol. 28, 2024.
[13]Mohammad Arafah, Iain Phillips, Asma Adnane, Wael Hadi, Mohammad Alauthman, and Abedal-Kareem Al-Banna, “Anomaly-based network intrusion detection using denoising autoencoder and Wasserstein GAN synthetic attacks,” Applied Soft Computing, vol. 168, 2025. 
[14]Yufeng Zhang, Yulong Wang, and Liting Gao, “CNN-MHBiGRU: A two-stage deep learning framework with multi-attention mechanisms for IoT intrusion detection,” Ad Hoc Networks, vol. 181, 2026.
[15]Md. Khabir Uddin Ahamed and Abdul Karim, “Cascaded intrusion detection system using machine learning,” Systems and Soft Computing, vol. 7, 2025.
[16]Prem Kumar Santhanam, Himaja Chowdary Vellanki, Sai Rohith Reddy Bellapu, and K. Mithra, “QFlexiViT: A quantum-flexible vision transformer optimized by Octopus-inspired algorithm for intrusion detection,” Computers and Electrical Engineering, vol. 129, 2026.
[17]M. Baritha Begum, Yogeshwaran A, N. R. Nagarajan, and P. Rajalakshmi, “Dynamic network security leveraging efficient CoviNet with granger causality-inspired graph neural networks for data compression in cloud IoT Devices,” Knowledge-Based Systems, vol. 309, 2025.
[18]Ahmed Bensaoud and Jugal Kalita, “Optimized detection of cyber-attacks on IoT networks via hybrid deep learning models,” Ad Hoc Networks, vol. 170, 2025.
[19]Adel Binbusayyis and Mohemmed Sha, “Secure and privacy-preserving intrusion detection in smart networks via blockchain-based federated learning and optimized deep learning models,” High-Confidence Computing, 2026.
[20]Jyoti Prakash Sahoo, Binayak Kar, Ahmed M. Abdelmoniem, and Dimitris Chatzopoulos, “Choir-IDS: A federated learning framework for fidelity-calibrated explainable intrusion detection system for edge-IoT networks,” Information Fusion, vol. 125, 2026.
[21]Mohammad Arafah, Iain Phillips, Asma Adnane, Mohammad Alauthman, and Nauman Aslam, “An enhanced BiGAN architecture for network intrusion detection,” Knowledge-Based Systems, vol. 314, 2025.
[22]Batuhan Gul and Fatih Ertam, “In-vehicle communication cyber security: A comprehensive review of challenges and solutions,” Vehicular Communications, vol. 50, 2024.
[23]Jiqiang Zhai, Xinyu Wang, Zhonghui Zhai, Tao Xu, Zuming Qi, and Hailu Yang, “Industrial IoT intrusion attack detection based on composite attention-driven multi-layer pyramid features,” Computer Networks, vol. 263, 2025.
[24]Samia Saidane, Francesco Telch, Kussai Shahin, and Fabrizio Granelli, “Deep GraphSAGE enhancements for intrusion detection: Analyzing attention mechanisms and GCN integration,” Journal of Information Security and Applications, vol. 90, 2025.
[25]Yi Gao, Jun Zhao, Hong Wang, and Minglai Shao, “PHO-HGNN: Hypergraph neural network based on persistent homology optimization for class-imbalanced intrusion detection,” Knowledge-Based Systems, vol. 330, 2025.
[26]Erivan Laranjeira Pimentel, Cristiano Antonio de Souza, and Carlos Becker Westphall, “Detecting attacks in Fog and cloud computing environments using Deep Learning: A systematic literature review,” Computer Networks, vol. 264, 2025.
[27]Amina Khacha, Zibouda Aliouat, Yasmine Harbi, Chirihane Gherbi, Rafika Saadouni, and Saad Harous, “Landscape of learning techniques for intrusion detection system in IoT: A systematic literature review,” Computers and Electrical Engineering, vol. 120, 2024.
[28]Yashar Pourardebil Khah, Mirsaeid Hosseini Shirvani, and Javid Taheri, “A survey study on meta-heuristic-based feature selection approaches of intrusion detection systems in distributed networks,” Computer Standards & Interfaces, vol. 96, 2026.
[29]A. Villafranca and Maria-Dolores Cano, “A lightweight edge-DL intrusion detection system for IoT sustainable smart-agriculture,” Internet of Things, vol. 34, 2025. 
[30]Haydar Abdulameer Marhoon, Rafid Sagban, Atheer Y. Oudah, and Saadaldeen Rashid Ahmed, “A Barrier-Based Machine Learning Approach for Intrusion Detection in Wireless Sensor Networks,” Computers, Materials and Continua, vol. 82, 2025.
[31]Jizhao Liu and Minghao Guo, “DIGNN-A: Real-Time Network Intrusion Detection with Integrated Neural Networks Based on Dynamic Graph,” Computers, Materials and Continua, vol. 82, 2025.
[32]Yang Li, Zhengming Li, and Mengyao Li, “A comprehensive survey on intrusion detection algorithms,” Computers and Electrical Engineering, vol. 121, 2025.
[33]Adit Sharma and Arash Habibi Lashkari, “Hybrid attention-enhanced explainable model for encrypted traffic detection and classification,” International Journal of Information Security, vol. 24, 2025, Article 144.
[34]Z. Liu, Q. Wei, Q. Song, and C. Duan, “Fine-Grained Encrypted Traffic Classification Using Dual Embedding and Graph Neural Networks,” Electronics, vol. 14, no. 4, p. 778, 2025. doi: 10.3390/electronics14040778.
[35]Z. Chen, X. Wei, and Y. Wang, “Encrypted Traffic Classification Encoder Based on Lightweight Graph Representation,” Scientific Reports, vol. 15, no. 1, p. 28564, 2025. doi: 10.1038/s41598-025-05225-4.
[36]A. Ferriyan, A. H. Thamrin, K. Takeda, and J. Murai, “Encrypted Malicious Traffic Detection Based on Word2Vec,” Electronics, vol. 11, no. 5, p. 679, 2022. doi: 10.3390/electronics11050679.
[37]D. Shamsimukhametov, A. Kurapov, M. Liubogoshchev, and E. Khorov, “Is Encrypted ClientHello a Challenge for Traffic Classification?”, IEEE Access, vol. 10, pp. 77883–77897, 2022. doi: 10.1109/ACCESS.2022.3191431.
[38]Z. Liu, Y. Xie, Y. Luo, Y. Wang, and X. Ji, “TransECA-Net: A Transformer-Based Model for Encrypted Traffic Classification,” Applied Sciences, vol. 15, no. 6, p. 2977, 2025. doi: 10.3390/app15062977.
[39]X. Zhang, M. Zhao, J. Wang, S. Li, Y. Zhou, and S. Zhu, “Deep-Forest-Based Encrypted Malicious Traffic Detection,” Electronics, vol. 11, no. 7, p. 977, 2022. doi: 10.3390/electronics11070977.
[40]B. Wu, D. M. Divakaran, and M. Gurusamy, “UniNet: A Unified Multi-Granular Traffic Modeling Framework for Network Security,” IEEE Transactions on Cognitive Communications and Networking, vol. 12, pp. 2424–2438, 2026. doi: 10.1109/TCCN.2025.3585170.