TransGraphNet: A Transformer‐Graph Hybrid Deep Learning Model for DDoS Attack Detection in Heterogeneous Networks

ABSTRACT DDoS attacks now spread across heterogeneous network environments, and this creates a concrete problem for detection systems: local or sequential models often miss complex, multi‐hop attack semantics. We propose TransGraphNet, a new end‐to‐end hybrid deep learning architecture built from three branches—Transformer networks, graph convolutional networks (GCNs), and dilated convolutional neural networks (CNNs). Each branch handles one aspect: the Transformer captures global topology‐agnostic relational dependencies; the GCN preserves explicit local structural topology; the dilated CNN learns fine‐grained spatial invariants from flow features. A gating module then weighs these three representations adaptively, suppressing whichever stream is less informative for a given node. On three benchmarks—CICIDS‐2017, CSE‐CIC‐IDS2018, and CIC‐IoT‐2023—the model reaches detection accuracies above 99.3%. Recall also stays high under severe class imbalance and environmental noise. The entire model uses 58,306 parameters and 3.17 ms per inference, so it can be deployed on resource‐limited devices without sacrificing detection accuracy.

Authors

Institutions

Publication Details

Journal
Security and Privacy
Published
2026-09-17
DOI
https://doi.org/10.1002/spy2.70250
Primary Topic
Network Security and Intrusion Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

TransGraphNet: A Transformer‐Graph Hybrid Deep Learning Model for DDoS Attack Detection in Heterogeneous Networks

Ying Chen, Wenhao Cai
Security and Privacy
Network Security and Intrusion Detection
article

TransGraphNet: A Transformer‐Graph Hybrid Deep Learning Model for DDoS Attack Detection in Heterogeneous Networks

Ying Chen, Wenhao Cai
article en

Abstract

ABSTRACT DDoS attacks now spread across heterogeneous network environments, and this creates a concrete problem for detection systems: local or sequential models often miss complex, multi‐hop attack semantics. We propose TransGraphNet, a new end‐to‐end hybrid deep learning architecture built from three branches—Transformer networks, graph convolutional networks (GCNs), and dilated convolutional neural networks (CNNs). Each branch handles one aspect: the Transformer captures global topology‐agnostic relational dependencies; the GCN preserves explicit local structural topology; the dilated CNN learns fine‐grained spatial invariants from flow features. A gating module then weighs these three representations adaptively, suppressing whichever stream is less informative for a given node. On three benchmarks—CICIDS‐2017, CSE‐CIC‐IDS2018, and CIC‐IoT‐2023—the model reaches detection accuracies above 99.3%. Recall also stays high under severe class imbalance and environmental noise. The entire model uses 58,306 parameters and 3.17 ms per inference, so it can be deployed on resource‐limited devices without sacrificing detection accuracy.

Security and PrivacyVol. 9(6)
Zhejiang Lab (CN), Taizhou University (CN)
Openalex Percentile: Top 8%
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

TransGraphNet: A Transformer‐Graph Hybrid Deep Learning Model for DDoS Attack Detection in Heterogeneous Networks — Ying Chen, Wenhao Cai · Security and Privacy (2026) | TGRS Research Map | TGRS