Home / Journals / CMC / Online First / doi:10.32604/cmc.2026.084993
Special Issues
Table of Content

Open Access

ARTICLE

TF-SAGE: Trust Filtered Graph Learning for Stable Internet of Things Intrusion Detection under Adversarial Attacks

Chin-Shiuh Shieh1, Thanh-Lam Nguyen1, Thanh-Tuan Nguyen2,*, Xuan-Huy Nguyen2, Chau-Tan-Phat Le2, Mong-Fong Horng1,*
1 Department of Electronic Engineering, National Kaohsiung University of Science and Technology, Kaohsiung, Taiwan
2 Department of Electrical and Electronic Engineering, School of Engineering and Technology, Nha Trang University, Khanh Hoa, Vietnam
* Corresponding Author: Thanh-Tuan Nguyen. Email: email; Mong-Fong Horng. Email: email
(This article belongs to the Special Issue: Deep Learning for Next-Generation Cybersecurity: Architectures, Robustness and Applications)

Computers, Materials & Continua https://doi.org/10.32604/cmc.2026.084993

Received 03 May 2026; Accepted 07 August 2026; Published online 28 August 2026

Abstract

Internet of Things (IoT) intrusion detection systems face increasing pressure from adversarial attacks that can manipulate not only feature vectors but also the relational structure on which graph based models rely. This paper proposes Trust Filtered GraphSAGE (TF-SAGE), a graph based intrusion detection system (IDS) pipeline in which edges are assigned trust scores, filtered before message passing, and coupled with uncertainty aware inference to reduce overconfident decisions under unstable neighborhoods. The model is evaluated on NF-ToN-IoT-v2 as the main benchmark and CICIIoT2025 as an independent confirmation benchmark under the same FSAA and GSAA evaluation protocol. The results show that TF-SAGE is not the top clean score model, yet it maintains substantially stronger stability under attack: on NF-ToN-IoT-v2, it reaches clean macro averaged F1 (Macro-F1) 0.9789, retains 0.9776 under Feature Space Adversarial Attack (FSAA), and achieves 0.9048 with attack success rate (ASR) 0.0941 under GSAA, while the graph baselines degrade more severely. Evidence from calibration and neighborhood recovery further indicates that these gains are mechanistically grounded rather than reducible to a single summary score. These findings position TF-SAGE as a practical resilience oriented design direction for IoT intrusion detection based on graph neural networks (GNNs).

Keywords

Internet of Things intrusion detection; graph neural networks; adversarial stability; trust filtered graph construction; uncertainty calibration; feature space adversarial attack; graph space adversarial attack
  • 80

    View

  • 9

    Download

  • 0

    Like

Share Link