Lightweight Relation-Aware Graph Neural Networks for Network Threat Detection in the Social Internet of Things

Network threat detection in the Internet of Things must exploit typed relations between devices: a device with unremarkable flow statistics may still be compromised relative to its ownership, co-location, and social ties. Existing graph-based intrusion detectors discard relation type, while lightweight detectors compress tabular rather than graph models. This paper presents Light-SIoT-GAD, a lightweight relation-aware graph detector that treats typed relations as first-class input. The model learns one scalar weight per relation, shares a small basis across relation transforms so that each additional relation type costs only a handful of mixing coefficients rather than a full weight matrix, and combines supervised feature selection, bounded neighbour sampling, and 8-bit post-training quantisation for gateway deployment. A dual-track evaluation isolates typed aggregation on a real 16,216-device SIoT relation graph with injected anomalies and tests attack detection on three labelled NetFlow v2 corpora against classical, deep tabular, and graph baselines, including cross-corpus transfer and ablations. Light-SIoT-GAD matches or exceeds the strongest untyped graph baselines on all three corpora, reaching an AUPRC of 0.9986 with 73,962 parameters, substantially fewer than the unshared R-GCN; on the sparsest corpus a gradient-boosted tabular ensemble still ranks better, which bounds the claim to graphs that carry usable structure. Whether the gain comes from the relation semantics or merely from having per-relation parameters is tested directly: permuting the relation labels leaves the dense corpora unchanged to four decimals and costs 0.0083 AUPRC only on the sparsest one, so the typed advantage is real there and is a capacity effect elsewhere. On the social track, where the anomalies are injected under a stated protocol rather than observed, removing message passing collapses AUPRC from 0.9990 to 0.4869 under that same injection, isolating propagation over the relation graph as the source of the gain; this track measures whether relational structure carries signal, not accuracy against real SIoT attacks. The quantised model occupies 85.4 KB at 14.38 ms per 1000 edges on CPU. The learned relation gates are shown to be identified only up to a per-relation rescaling, and a leave-one-relation-out intervention finds no relation of the SIoT taxonomy to be load-bearing under the injection protocol, so the social track supports the typed parameterisation and not a ranking of the relations.

Authors

Institutions

Publication Details

Journal
Symmetry
Published
2026-09-28
DOI
https://doi.org/10.3390/sym18101623
Primary Topic
Advanced Graph Neural Networks
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Lightweight Relation-Aware Graph Neural Networks for Network Threat Detection in the Social Internet of Things

Zheng Zhao, Yifan Qin
Symmetry
Advanced Graph Neural Networks
article

Lightweight Relation-Aware Graph Neural Networks for Network Threat Detection in the Social Internet of Things

Zheng Zhao, Yifan Qin
article en

Abstract

Network threat detection in the Internet of Things must exploit typed relations between devices: a device with unremarkable flow statistics may still be compromised relative to its ownership, co-location, and social ties. Existing graph-based intrusion detectors discard relation type, while lightweight detectors compress tabular rather than graph models. This paper presents Light-SIoT-GAD, a lightweight relation-aware graph detector that treats typed relations as first-class input. The model learns one scalar weight per relation, shares a small basis across relation transforms so that each additional relation type costs only a handful of mixing coefficients rather than a full weight matrix, and combines supervised feature selection, bounded neighbour sampling, and 8-bit post-training quantisation for gateway deployment. A dual-track evaluation isolates typed aggregation on a real 16,216-device SIoT relation graph with injected anomalies and tests attack detection on three labelled NetFlow v2 corpora against classical, deep tabular, and graph baselines, including cross-corpus transfer and ablations. Light-SIoT-GAD matches or exceeds the strongest untyped graph baselines on all three corpora, reaching an AUPRC of 0.9986 with 73,962 parameters, substantially fewer than the unshared R-GCN; on the sparsest corpus a gradient-boosted tabular ensemble still ranks better, which bounds the claim to graphs that carry usable structure. Whether the gain comes from the relation semantics or merely from having per-relation parameters is tested directly: permuting the relation labels leaves the dense corpora unchanged to four decimals and costs 0.0083 AUPRC only on the sparsest one, so the typed advantage is real there and is a capacity effect elsewhere. On the social track, where the anomalies are injected under a stated protocol rather than observed, removing message passing collapses AUPRC from 0.9990 to 0.4869 under that same injection, isolating propagation over the relation graph as the source of the gain; this track measures whether relational structure carries signal, not accuracy against real SIoT attacks. The quantised model occupies 85.4 KB at 14.38 ms per 1000 edges on CPU. The learned relation gates are shown to be identified only up to a per-relation rescaling, and a leave-one-relation-out intervention finds no relation of the SIoT taxonomy to be load-bearing under the injection protocol, so the social track supports the typed parameterisation and not a ranking of the relations.

SymmetryVol. 18(10)
The University of Sydney (AU), Civil Aviation University of China (CN)
Reduced inequalities
Openalex Percentile: Top 9%
Advanced Graph Neural Networks
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.