A graph representation learning intrusion detection method for class imbalance scenarios
By constructing a source graph and performing node embedding representation, cross-window streaming clustering, and GoG message propagation, the problems of node dilution, cross-window association, and class imbalance in APT attack detection in existing technologies are solved, achieving efficient real-time detection and source tracing of APT attacks.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- TIANJIN UNIV
- Filing Date
- 2026-03-30
- Publication Date
- 2026-07-17
AI Technical Summary
Existing source graph-based IDS suffers from several problems when facing APT attacks. These problems include node representation diluting the initial intrusion information, lack of cross-window correlation ability in streaming detection, and class imbalance, resulting in insufficient model generalization ability and difficulty in capturing the weak features of hidden threats.
By constructing a source graph, generating node embedding representations, adopting Word2Vec mapping semantics, introducing root path encoding and cross-window streaming clustering, constructing GoG for message propagation, jointly modeling semantic and structural information, and outputting real-time detection results.
It enables effective detection and tracing of APT attacks in imbalanced environments, improves the model's ability to identify rare malicious samples and its detection accuracy, reduces the risk of false positives and false negatives, and ensures the system's detection reliability and analysis stability.
Smart Images

Figure CN122419829A_ABST