Open Access iconOpen Access

ARTICLE

The Method of Malicious Traffic Detection for Internet of Things Based on Lightweight Graph Neural Networks

Baofeng Duan1, Xinghai Yu1, Peng Wang2, Tao Feng1, Yongbo Jiang1,*

1 School of Computer Science and Artificial Intelligence (College of Software), Lanzhou University of Technology, Lanzhou, China
2 School of Petrochemical Engineering, Lanzhou University of Technology, Lanzhou, China

* Corresponding Author: Yongbo Jiang. Email: email

Computers, Materials & Continua 2026, 89(2), 90 https://doi.org/10.32604/cmc.2026.086743

Abstract

With the sustained expansion of complex Internet of Things (IoT) ecosystems, malicious traffic detection has become critical for maintaining both cyber security and operational continuity. Modern IoT deployments contain heterogeneous devices, ubiquitous sensing layers, edge services, and autonomous assets, so abnormal communication may affect not only data confidentiality but also physical operations. To address the limitations of independent flow-level detection and heavy graph propagation, this paper proposes a Lightweight Graph-Attentive Network for Traffic Detection (LGNT). LGNT constructs a directed traffic-interaction graph from NetFlow records, where communication entities are represented as nodes and traffic sessions are represented as edges. Communication-strength-based auxiliary node supervision provides an activity-aware structural signal, while a compact backbone combining topology adaptive graph convolution (TAGConv) and graph attention v2 convolution (GATv2Conv) captures local topological dependencies and key communication relations. A structure-significance pruning strategy is further introduced to reduce the message-passing edge set and graph computation overhead. Experiments on NetFlow BoT-IoT (NF-BoT-IoT) and NetFlow ToN-IoT (NF-ToN-IoT) show that LGNT obtains effective results in both binary and multi-class detection tasks. Specifically, it achieves 94.28% accuracy, 97.36% area under the curve (AUC), and 86.88% F1 on NF-BoT-IoT, and 99.93% accuracy, 99.95% AUC, and 69.05% weighted F1 on NF-ToN-IoT. The per-class analysis further shows that long-tailed minority categories remain challenging in fine-grained NF-ToN-IoT recognition. Overall, LGNT improves the balance between traffic-interaction modeling, detection performance, and deployment efficiency while keeping the parameter scale at 0.236 million.

Keywords

Graph neural networks; Internet of Things; intrusion detection; lightweight models; malicious traffic detection; traffic interaction graphs

Cite This Article

APA Style
Duan, B., Yu, X., Wang, P., Feng, T., Jiang, Y. (2026). The Method of Malicious Traffic Detection for Internet of Things Based on Lightweight Graph Neural Networks. Computers, Materials & Continua, 89(2), 90. https://doi.org/10.32604/cmc.2026.086743
Vancouver Style
Duan B, Yu X, Wang P, Feng T, Jiang Y. The Method of Malicious Traffic Detection for Internet of Things Based on Lightweight Graph Neural Networks. Comput Mater Contin. 2026;89(2):90. https://doi.org/10.32604/cmc.2026.086743
IEEE Style
B. Duan, X. Yu, P. Wang, T. Feng, and Y. Jiang, “The Method of Malicious Traffic Detection for Internet of Things Based on Lightweight Graph Neural Networks,” Comput. Mater. Contin., vol. 89, no. 2, pp. 90, 2026. https://doi.org/10.32604/cmc.2026.086743



cc Copyright © 2026 The Author(s). Published by Tech Science Press.
This work is licensed under a Creative Commons Attribution 4.0 International License , which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.
  • 185

    View

  • 63

    Download

  • 0

    Like

Share Link