FG-Net: A unified feature fusion graph-based framework for IoT intrusion attack classification
The Internet of Things (IoT) has emerged as a key enabler of intelligent systems, but it faces challenges related to security and privacy. Traditional Intrusion Detection Systems (IDSs) are not suitable to IoT environments due to constraints such as limited memory, processing power, and battery life. The majority of current models focus on homogeneous aggregation of network flows and neighbourhoods in the context of graph-based learning, making it impossible to distinguish malicious from benign flow representations and undermining the ability to capture attack specifics. To overcome these problems, the paper proposes FG-Net, a Fusion Graph-based Intrusion Detection framework that characterises intrusion detection as a flow-level graph learning problem. FG-Net proposes using multi-perspective graph aggregation, in which network flows are captured by multiple attention heads that capture different patterns of interactions, allowing the model to learn to differentiate attack-relevant correlations from weak attention weights. An adaptive fusion layer performs dynamic fusion on local and global representations, improving discriminative representation learning and resilience against coordinated and non-homogeneous attacks. The FG-Net is tested on four benchmark datasets, including ToN-IoT, BoT-IoT, CIC-IDS-2018, NF-UQ-NIDS achieving accuracy rates of 99.79%, 95.20%, 99.85%, and 98.38%, respectively, and 4.80% higher on ToN-IoT than the deep learning based state-of-the-art methods.
Authors
- Payal Khurana Batra (ORCID: https://orcid.org/0000-0003-1926-288X)
- Kajol Mittal
- Vikas Saxena
Institutions
- Jaypee Institute of Information Technology (IN)
Publication Details
- Journal
- Journal of Information Security and Applications
- Published
- 2026-09-24
- DOI
- https://doi.org/10.1016/j.jisa.2026.104648
- Primary Topic
- Network Security and Intrusion Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00