The growing complexity of network attacks has outpaced the capabilities of traditional intrusion detection systems (IDS), which often rely on flat data structures that fail to capture complex relationships within networks. To address this limitation, we propose IDS-NGNN, a novel IDS that integrates hardware-offload SmartNIC preprocessing with a nested graph neural network (NGNN) architecture. Unlike standard Graph Neural Networks (GNN), IDS-NGNN jointly captures local and global dependencies using a three-layer design: an internal GNN for host-level activity, a nested graph module for hierarchical aggregation, and an external GNN for inter-host communication. SmartNIC acceleration enables efficient real-time processing of large-scale graph-structured network data at the edge. We evaluate IDS-NGNN on six public IDS datasets, including CIC-IDS-2017, CSE-CIC-IDS-2018, and ToN-IoT. Experimental results demonstrate that IDS-NGNN achieves up to 95% accuracy and 92% F1-score, while maintaining efficiency suitable for real-time 100 Gbps deployments.

IDS-NGNN: A SmartNIC-based Intrusion Detection System Based on Reduce and Merge Nested Graph Neural Networks

Bakar, Rana Abu
Primo
;
Paolucci, Francesco;Cugini, Filippo;Olmos, Juan Jose Vegas;De Marinis, Lorenzo
Ultimo
2025-01-01

Abstract

The growing complexity of network attacks has outpaced the capabilities of traditional intrusion detection systems (IDS), which often rely on flat data structures that fail to capture complex relationships within networks. To address this limitation, we propose IDS-NGNN, a novel IDS that integrates hardware-offload SmartNIC preprocessing with a nested graph neural network (NGNN) architecture. Unlike standard Graph Neural Networks (GNN), IDS-NGNN jointly captures local and global dependencies using a three-layer design: an internal GNN for host-level activity, a nested graph module for hierarchical aggregation, and an external GNN for inter-host communication. SmartNIC acceleration enables efficient real-time processing of large-scale graph-structured network data at the edge. We evaluate IDS-NGNN on six public IDS datasets, including CIC-IDS-2017, CSE-CIC-IDS-2018, and ToN-IoT. Experimental results demonstrate that IDS-NGNN achieves up to 95% accuracy and 92% F1-score, while maintaining efficiency suitable for real-time 100 Gbps deployments.
File in questo prodotto:
File Dimensione Formato  
IDS-NGNN_A_SmartNIC-based_Intrusion_Detection_System_Based_on_Reduce_and_Merge_Nested_Graph_Neural_Networks.pdf

solo utenti autorizzati

Tipologia: Documento in Pre-print/Submitted manuscript
Licenza: Altro
Dimensione 1.1 MB
Formato Adobe PDF
1.1 MB Adobe PDF   Visualizza/Apri   Richiedi una copia

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11382/588434
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
social impact