TY - EJOU AU - Shieh, Chin-Shiuh AU - Nguyen, Thanh-Lam AU - Nguyen, Thanh-Tuan AU - Nguyen, Xuan-Huy AU - Le, Chau-Tan-Phat AU - Horng, Mong-Fong TI - TF-SAGE: Trust Filtered Graph Learning for Stable Internet of Things Intrusion Detection under Adversarial Attacks T2 - Computers, Materials \& Continua PY - VL - IS - SN - 1546-2226 AB - Internet of Things (IoT) intrusion detection systems face increasing pressure from adversarial attacks that can manipulate not only feature vectors but also the relational structure on which graph based models rely. This paper proposes Trust Filtered GraphSAGE (TF-SAGE), a graph based intrusion detection system (IDS) pipeline in which edges are assigned trust scores, filtered before message passing, and coupled with uncertainty aware inference to reduce overconfident decisions under unstable neighborhoods. The model is evaluated on NF-ToN-IoT-v2 as the main benchmark and CICIIoT2025 as an independent confirmation benchmark under the same FSAA and GSAA evaluation protocol. The results show that TF-SAGE is not the top clean score model, yet it maintains substantially stronger stability under attack: on NF-ToN-IoT-v2, it reaches clean macro averaged F1 (Macro-F1) 0.9789, retains 0.9776 under Feature Space Adversarial Attack (FSAA), and achieves 0.9048 with attack success rate (ASR) 0.0941 under GSAA, while the graph baselines degrade more severely. Evidence from calibration and neighborhood recovery further indicates that these gains are mechanistically grounded rather than reducible to a single summary score. These findings position TF-SAGE as a practical resilience oriented design direction for IoT intrusion detection based on graph neural networks (GNNs). KW - Internet of Things intrusion detection; graph neural networks; adversarial stability; trust filtered graph construction; uncertainty calibration; feature space adversarial attack; graph space adversarial attack DO - 10.32604/cmc.2026.084993