PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
February 16, 2026Applied Sciences3 citationsOpen Access

A Comprehensive Review on Graph-Based Anomaly Detection: Approaches for Intrusion Detection

NDNimesha DiliniNSNan SunYMYuantian Miao

Key Points

  • The review aims to evaluate graph-based anomaly detection methods for intrusion detection and their effectiveness in addressing inherent challenges.
  • Reviewed 60 technical papers from 2019 to 2025 on graph-based anomaly detection approaches.
  • Analyzed two-stage and end-to-end methods, focusing on GNN-based techniques.
  • Investigated the datasets and evaluation metrics used in GBAD research.
  • 53% of studies utilized two-stage methods, while 47% employed end-to-end approaches.
  • GNN-based techniques were prevalent among end-to-end methods, appearing in 18 out of 28 papers.
  • Most studies measured success using precision, recall, and F1-score, with over 85% employing these metrics.

Abstract

Intrusion Detection Systems (IDSs) have evolved to safeguard networks and systems from cyber attacks. Anomaly-based Intrusion Detection Systems (A-IDS) have been commonly employed to detect known and unknown anomalies. However, conventional anomaly detection approaches encounter substantial challenges when dealing with large-scale and heterogeneous data sources. These challenges include high False Positive Rates (FPRs), imbalanced data behavior, complex data handling, resource constraints, limited interpretability, and difficulties with encrypted networks. This survey reviews 60 technical papers (2019–2025) on graph-based anomaly detection (GBAD) approaches, highlighting their ability to address these challenges by utilizing the inherent structure of graphs to capture and analyze network connectivity patterns. Our analysis reveals that 32 studies (53%) employ two-stage methods while 28 (47%) use end-to-end approaches. Among the end-to-end methods, GNN-based techniques dominate, accounting for 18 of the 28 papers. We present a phased graph-based anomaly detection methodology for intrusion detection. This includes phases of data capturing, graph construction, graph pre-processing, anomaly detection, and post-detection analysis. Furthermore, we examine the evaluation methods and datasets employed in GBAD research and provide an analysis of the types of attacks identified by these methods. The most utilized datasets include CICIDS, UNSW-NB15, and DARPA, while precision, recall, and F1-score are employed in over 85% of studies. Lastly, we outline the key challenges and future directions that require significant research efforts in this area, and we offer some recommendations to address them.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Dilini et al. (2026) studied this question.

synapsesocial.com/papers/6992b3fb9b75e639e9b08db6https://doi.org/10.3390/app16041906
Ask AI
Helpful
Bookmark
Share
View Full Paper