Graph Attention-driven Transformer Model for Intelligent IoT Anomaly Classification
Anjitha, K and Saritha, A (2026) Graph Attention-driven Transformer Model for Intelligent IoT Anomaly Classification. International Journal of Intelligent Engineering and Systems, 19 (8): 1. pp. 442-466. ISSN 21853118
2026083123.pdf
Download (1MB)
Abstract
The rapid expansion of Internet of Things (IoT) networks has increased the vulnerability of connected devices to sophisticated cyber threats, necessitating accurate and reliable anomaly classification mechanisms. Conventional machine learning and signature-based intrusion detection approaches often struggle to capture complex feature interactions and long-range dependencies present in heterogeneous IoT traffic. To address these challenges,
this study proposes a hybrid deep learning framework that integrates a learnable Graph Neural Network (GNN) with
a Transformer encoder for intelligent IoT anomaly classification. The GNN branch dynamically learns inter-feature
relationships through a trainable soft adjacency matrix, enabling adaptive structural representation learning without
predefined graph connectivity. Simultaneously, the Transformer branch employs multi-head self-attention to model
contextual and long-range dependencies among traffic features. The embeddings generated by both branches are fused
to produce a discriminative representation for multi-class anomaly classification. The proposed framework was
evaluated on the CIC-IoT 2023 dataset containing seven major attack categories, including DDoS, DoS, spoofing,
brute force, reconnaissance, web attacks, and Mirai attacks. Experimental results achieved 97.51% accuracy, 97.56%
precision, 97.25% recall, and 97.40% F1-score, with a misclassification rate of 2.49%. Ablation studies verified the
effectiveness of the learnable adjacency mechanism and the hybrid architecture, while sensitivity analysis identified
eight attention heads as the optimal configuration. Robustness analysis across multiple random seeds demonstrated
stable performance, and external validation on the IoT-23 dataset achieved 96.24% accuracy, confirming strong
generalization capability. The results indicate that the proposed GNN–Transformer framework provides a robust,
scalable, and effective solution for anomaly classification in modern IoT security environments.
| Item Type: | Article |
|---|---|
| Subjects: | Computer Applications > Artificial Intelligence |
| Domains: | Computer Science Engineering |
| Depositing User: | IR Admin |
| Date Deposited: | 02 Sep 2026 10:06 |
| Last Modified: | 02 Sep 2026 10:06 |
| URI: | https://ir.vistas.ac.in/id/eprint/22340 |
Dimensions
Dimensions