CGGM: a conditional graph generation model with adaptive sparsity for node anomaly detection in IoT networks

Munan Li , Xianshi Su , Runze Ma , Tongbang Jiang , Zijian Li , Tony Q.S. Quek

›› 2026, Vol. 12 ›› Issue (4) : 686 -697.

PDF (2687KB)
›› 2026, Vol. 12 ›› Issue (4) :686 -697. DOI: 10.1016/j.dcan.2025.05.013
Research Article
research-article
CGGM: a conditional graph generation model with adaptive sparsity for node anomaly detection in IoT networks
Author information +
History +
PDF (2687KB)

Abstract

Dynamic graphs are increasingly utilized for detecting anomalous behaviors in nodes within the Internet of Things (IoT). Graph generative models play a pivotal role in addressing the challenge of imbalanced node categories in dynamic graphs. However, these models encounter several limitations, including the monotonicity of adjacency relationships, the complexity in constructing multi-dimensional features for nodes, and the absence of an end-to-end method for generating multiple categories of nodes. In this study, we introduce a novel graph generation model, designated as Conditional Graph Generation Model (CGGM), aimed specifically at generating samples from minority classes. The architecture comprises two principal modules: a conditional graph generation module and a graph-based anomaly detection module. The generative module adjusts to matrix sparsity by downsampling a noise adjacency matrix and integrates a multi-dimensional feature encoder based on multi-head self-attention to capture latent feature dependencies. Furthermore, a latent space constraint coupled with distribution distance is utilized to approximate the latent distribution of real data. The graph-based anomaly detection module employs the generated balanced dataset to predict node behaviors. Extensive experiments demonstrate that CGGM surpasses contemporary state-of-the-art methods in accuracy and divergence. The results further reveal that CGGM can produce diverse data categories, thereby enhancing the performance in multi-category classification tasks.

Keywords

Anomaly detection / Graph neural network / Temporal graph embedding / Network traffic / Graph generation

Cite this article

Download citation ▾
Munan Li, Xianshi Su, Runze Ma, Tongbang Jiang, Zijian Li, Tony Q.S. Quek. CGGM: a conditional graph generation model with adaptive sparsity for node anomaly detection in IoT networks. , 2026, 12 (4) : 686-697 DOI:10.1016/j.dcan.2025.05.013

登录浏览全文

4963

注册一个新账户 忘记密码

CRediT authorship contribution statement

Munan Li: Writing -- review & editing, Supervision, Resources, Project administration, Methodology, Investigation, Funding acquisition, Conceptualization. Xianshi Su: Writing -- original draft, Software, Data curation. Runze Ma: Writing -- review & editing, Validation. Tongbang Jiang: Writing -- review & editing. Zijian Li: Writing -- review & editing, Supervision, Conceptualization. Tony Q.S. Quek: Writing -- review & editing.

Declaration of competing interest

The authors declare the following financial interests/personal relationships which may be considered as potential competing interests: Tony Q.S. Quek is an editorial board member for Digital Communications and Networks and was not involved in the editorial review or the decision to publish this article. All authors declare that there are no competing interests. If there are other authors, they declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.

Acknowledgement

This work was supported by the Liaoning Provincial Natural Science Foundation (Grant No. 2024-BS-015), and in part by China Postdoctoral Science Foundation (No. 2024M750295).

References

[1]

R. Kale, V.L. Thing, Few—shot weakly—supervised cybersecurity anomaly detection, Comput. Secur. 130 (2023) 103194.

[2]

M. Iliofotou, M. Faloutsos, M. Mitzenmacher, Exploiting dynamicity in graph—based traffic analysis: techniques and applications, in: Proceedings of the 5th International Conference on Emerging Networking Experiments and Technologies, 2009, pp. 241-252.

[3]

W.W. Lo, G. Kulatilleke, M. Sarhan, S. Layeghy, M. Portmann, XG—BoT: an explainable deep graph neural network for botnet detection and forensics, Internet of Things 22 (2023) 100747.

[4]

G. Douzas, F. Bacao, Effective data generation for imbalanced learning using conditional generative adversarial networks, Expert Syst. Appl. 91 (2018) 464-471.

[5]

Exploiting complex network—based clustering for personalization—enhanced hierarchical federated edge learning.

[6]

S. Guan, Z. He, S. Ma, M. Gao, Multivariate time series anomaly detection with variational autoencoder and spatial—temporal graph network, Comput. Secur. 142 (2024) 103877.

[7]

M. Adiban, S.M. Siniscalchi, G. Salvi, A step—by—step training method for multi generator gans with application to anomaly detection and cybersecurity, Neurocomputing 537 (2023) 296-308.

[8]

M. Simonovsky, N. Komodakis, GraphVAE: towards generation of small graphs using variational autoencoders, in: Artificial Neural Networks and Machine Learning—ICANN 2018: 27th International Conference on Artificial Neural Networks, Springer, 2018, pp. 412-422.

[9]

A. Bojchevski, O. Shchur, D. Zügner, S. Günnemann, Netgan: generating graphs via random walks, in: International Conference on Machine Learning, PMLR, 2018, pp. 610-619.

[10]

N. Park, M. Mohammadi, K. Gorde, S. Jajodia, H. Park, Y. Kim, Data synthesis based on generative adversarial networks, arXiv preprint, arXiv:1806.03384.

[11]

L. Xu, M. Skoularidou, A. Cuesta—Infante, K. Veeramachaneni, Modeling tabular data using conditional GAN, Adv. Neural Inf. Process. Syst. 32 (2019).

[12]

J. Atwood, S. Pal, D. Towsley, A. Swami, Sparse diffusion—convolutional neural networks, arXiv preprint, arXiv:1710.09813.

[13]

K. Lei, M. Qin, B. Bai, G. Zhang, M. Yang, GCN—GAN: a non—linear temporal link prediction model for weighted dynamic networks, in: IEEE INFOCOM 2019—IEEE Conference on Computer Communications, IEEE, 2019, pp. 388-396.

[14]

X. Guo, L. Zhao, C. Nowzari, S. Rafatirad, H. Homayoun, S.M.P. Dinakarrao, Deep multi—attributed graph translation with node—edge co—evolution, in: 2019 IEEE International Conference on Data Mining (ICDM), IEEE, 2019, pp. 250-259.

[15]

J. You, R. Ying, X. Ren, W. Hamilton, J. Leskovec, GraphRNN: generating realistic graphs with deep auto—regressive models, in: International Conference on Machine Learning, PMLR, 2018, pp. 5708-5717.

[16]

F. Zola, L. Segurola—Gil, J.L. Bruse, M. Galar, R. Orduna—Urrutia, Network traffic analysis through node behaviour classification: a graph—based approach with temporal dissection and data—level preprocessing, Comput. Secur. 115 (2022) 102632.

[17]

Y. Chen, C. Zhang, R. Bai, T. Sun, W. Ding, R. Wang, A Review of Medical Text Analysis: Theory and Practice, Information Fusion, 2025, p. 103024.

[18]

Z. Wang, X. Li, H. Duan, Y. Su, X. Zhang, X. Guan, Medical image fusion based on convolutional neural networks and non—subsampled contourlet transform, Expert Syst. Appl. 171 (2021) 114574.

[19]

Z. Li, Z. Chen, X. Wei, S. Gao, C. Ren, T.Q. Quek, HPFL—CN: Communication—efficient hierarchical personalized federated edge learning via complex network feature clustering, in: 2022 19th Annual IEEE International Conference on Sensing, Communication, and Networking (SECON), IEEE, 2022, pp. 325-333.

[20]

Y. Wang, J. Zhang, S. Guo, H. Yin, C. Li, H. Chen, Decoupling representation learning and classification for GNN—based anomaly detection, in: Proceedings of the 44th International ACM SIGIR Conference on Research and Development in Information Retrieval, 2021, pp. 1239-1248.

[21]

C. Ding, S. Sun, J. Zhao, MST—GAT: a multimodal spatial—temporal graph attention network for time series anomaly detection, Inf. Fusion 89 (2023) 527-536.

[22]

S. Qin, L. Chen, Y. Luo, G. Tao, Multiview graph contrastive learning for multivariate time—series anomaly detection in IoT, IEEE Internet Things J. 10 (24) (2023) 22401-22414.

[23]

G. Duan, H. Lv, H. Wang, G. Feng, Application of a dynamic line graph neural network for intrusion detection with semisupervised learning, IEEE Trans. Inf. Forensics Secur. 18 (2022) 699-714.

[24]

Y. Wu, H.—N. Dai, H. Tang, Graph neural networks for anomaly detection in industrial Internet of things, IEEE Internet Things J. 9 (12) (2021) 9214-9231.

[25]

Y. Wang, X. Lin, J. Wu, A.K. Bashir, W. Yang, J. Li, M. Imran, Contrastive GNN—based traffic anomaly analysis against imbalanced dataset in IoT—based its, in: GLOBECOM 2022—2022 IEEE Global Communications Conference, IEEE, 2022, pp. 3557-3562.

[26]

M. Ring, D. Schlör, D. Landes, A. Hotho, Flow—based network traffic generation using generative adversarial networks, Comput. Secur. 82 (2019) 156-172.

[27]

X. Guo, L. Wu, L. Zhao, Deep graph translation, IEEE Trans. Neural Netw. Learn. Syst. 34 (2022) 8225-8234.

[28]

Z. Wang, L. Zhao, J. Zhang, R. Song, H. Song, J. Meng, S. Wang, Multi—text guidance is important: multi—modality image fusion via large generative vision—language model, Int. J. Comput. Vis. (2025) 1-23.

[29]

N. Chen, H. Tu, H. Zeng, Y. Ou, Anomaly detection for key performance indicators by fusing self—supervised spatio—temporal graph attention networks, Knowl.—Based Syst. 300 (2024) 112167.

[30]

H. Wang, J. Wang, J. Wang, M. Zhao, W. Zhang, F. Zhang, X. Xie, M. Guo, Graphgan: graph representation learning with generative adversarial nets, in: Proceedings of the AAAI Conference on Artificial Intelligence, vol. 32, 2018.

[31]

N. Nauata, K.—H. Chang, C.—Y. Cheng, G. Mori, Y. Furukawa, House—GAN: Relational Generative Adversarial Networks for Graph—Constrained House Layout Generation, in: Computer Vision—ECCV 2020: 16th European Conference, Glasgow, UK, August 23—28, 2020, Proceedings, Part I 16, Springer, 2020, pp. 162-177.

[32]

K.—H. Chang, C.—Y. Cheng, J. Luo, S. Murata, M. Nourbakhsh, Y. Tsuji, Building—GAN: Graph—conditioned architectural volumetric design generation, in: Proceedings of the IEEE/CVF International Conference on Computer Vision, 2021, pp. 11956-11965.

[33]

D. Guo, Z. Liu, R. Li, Regraphgan: a graph generative adversarial network model for dynamic network anomaly detection, Neural Netw. 166 (2023) 273-285.

[34]

M. Iliofotou, P. Pappu, M. Faloutsos, M. Mitzenmacher, S. Singh, G. Varghese, Network monitoring using traffic dispersion graphs (tdgs), in: Proceedings of the 7th ACM SIGCOMM Conference on Internet Measurement, 2007, pp. 315-320.

[35]

A. Vaswani, N. Shazeer, N. Parmar, J. Uszkoreit, L. Jones, A.N. Gomez, Ł. Kaiser, I. Polosukhin, Attention is all you need, Adv. Neural Inf. Process. Syst. 30 (2017).

[36]

J. Engelmann, S. Lessmann, Conditional Wasserstein GAN—based oversampling of tabular data for imbalanced learning, Expert Syst. Appl. 174 (2021) 114582.

[37]

A. Basati, M.M. Faghih, PDAE: efficient network intrusion detection in IoT using parallel deep auto—encoders, Inf. Sci. 598 (2022) 57-74.

[38]

R. Chapaneri, S. Shah, Enhanced detection of imbalanced malicious network traffic with regularized generative adversarial networks, J. Netw. Comput. Appl. 202 (2022) 103368.

[39]

Y. Rubner, C. Tomasi, L.J. Guibas, The Earth mover’s distance as a metric for image retrieval, Int. J. Comput. Vis. 40 (2000) 99-121.

[40]

C. Strickland, C. Saha, M. Zakar, S. Nejad, N. Tasnim, D. Lizotte, A. Haque, DRL—GAN: a hybrid approach for binary and multiclass network intrusion detection, arXiv preprint, arXiv:2301.03368.

[41]

A. Gretton, K.M. Borgwardt, M.J. Rasch, B. Schölkopf, A. Smola, A kernel two—sample test, J. Mach. Learn. Res. 13 (1) (2012) 723-773.

[42]

M. Ding, J. Tang, J. Zhang, Semi—supervised learning on graphs with generative adversarial nets, in: Proceedings of the 27th ACM International Conference on Information and Knowledge Management, 2018, pp. 913-922.

[43]

T.N. Kipf, M. Welling, Semi—supervised classification with graph convolutional networks, arXiv preprint, arXiv:1609.02907.

[44]

W. Hamilton, Z. Ying, J. Leskovec, Inductive representation learning on large graphs, Adv. Neural Inf. Process. Syst. 30 (2017).

PDF (2687KB)

11

Accesses

0

Citation

Detail

Sections
Recommended

/