Open Access
ARTICLE
TF-SAGE: Trust Filtered Graph Learning for Stable Internet of Things Intrusion Detection under Adversarial Attacks
1 Department of Electronic Engineering, National Kaohsiung University of Science and Technology, Kaohsiung, Taiwan
2 Department of Electrical and Electronic Engineering, School of Engineering and Technology, Nha Trang University, Khanh Hoa, Vietnam
* Corresponding Authors: Thanh-Tuan Nguyen. Email: ; Mong-Fong Horng. Email:
(This article belongs to the Special Issue: Deep Learning for Next-Generation Cybersecurity: Architectures, Robustness and Applications)
Computers, Materials & Continua 2026, 89(2), 73 https://doi.org/10.32604/cmc.2026.084993
Received 03 May 2026; Accepted 07 August 2026; Issue published 15 September 2026
Abstract
Internet of Things (IoT) intrusion detection systems face increasing pressure from adversarial attacks that can manipulate not only feature vectors but also the relational structure on which graph based models rely. This paper proposes Trust Filtered GraphSAGE (TF-SAGE), a graph based intrusion detection system (IDS) pipeline in which edges are assigned trust scores, filtered before message passing, and coupled with uncertainty aware inference to reduce overconfident decisions under unstable neighborhoods. The model is evaluated on NF-ToN-IoT-v2 as the main benchmark and CICIIoT2025 as an independent confirmation benchmark under the same FSAA and GSAA evaluation protocol. The results show that TF-SAGE is not the top clean score model, yet it maintains substantially stronger stability under attack: on NF-ToN-IoT-v2, it reaches clean macro averaged F1 (Macro-F1) 0.9789, retains 0.9776 under Feature Space Adversarial Attack (FSAA), and achieves 0.9048 with attack success rate (ASR) 0.0941 under GSAA, while the graph baselines degrade more severely. Evidence from calibration and neighborhood recovery further indicates that these gains are mechanistically grounded rather than reducible to a single summary score. These findings position TF-SAGE as a practical resilience oriented design direction for IoT intrusion detection based on graph neural networks (GNNs).Keywords
Cite This Article
Copyright © 2026 The Author(s). Published by Tech Science Press.This work is licensed under a Creative Commons Attribution 4.0 International License , which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.


Submit a Paper
Propose a Special lssue
View Full Text
Download PDF
Downloads
Citation Tools