TransGraphNet: A Transformer‐Graph Hybrid Deep Learning Model for DDoS Attack Detection in Heterogeneous Networks
ABSTRACT DDoS attacks now spread across heterogeneous network environments, and this creates a concrete problem for detection systems: local or sequential models often miss complex, multi‐hop attack semantics. We propose TransGraphNet, a new end‐to‐end hybrid deep learning architecture built from three branches—Transformer networks, graph convolutional networks (GCNs), and dilated convolutional neural networks (CNNs). Each branch handles one aspect: the Transformer captures global topology‐agnostic relational dependencies; the GCN preserves explicit local structural topology; the dilated CNN learns fine‐grained spatial invariants from flow features. A gating module then weighs these three representations adaptively, suppressing whichever stream is less informative for a given node. On three benchmarks—CICIDS‐2017, CSE‐CIC‐IDS2018, and CIC‐IoT‐2023—the model reaches detection accuracies above 99.3%. Recall also stays high under severe class imbalance and environmental noise. The entire model uses 58,306 parameters and 3.17 ms per inference, so it can be deployed on resource‐limited devices without sacrificing detection accuracy.
Authors
- Ying Chen (ORCID: https://orcid.org/0000-0002-9520-3008)
- Wenhao Cai (ORCID: https://orcid.org/0009-0005-3756-7486)
Institutions
- Zhejiang Lab (CN)
- Taizhou University (CN)
Publication Details
- Journal
- Security and Privacy
- Published
- 2026-09-17
- DOI
- https://doi.org/10.1002/spy2.70250
- Primary Topic
- Network Security and Intrusion Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00