Zero-day attacks refer to advanced cyberattacks where there is exploitation of vulnerabilities that have not been discovered before and hence cannot be detected by signature-based and rule-based security systems. In this project, an AI-Based Zero-Day Attack Detection System Using Graph Neural Networks will be developed to detect any unusual and suspicious activity within the network. In this system, the different network entities such as the user, device, IP address, process, and network communications are modeled as nodes while the interactions between them as edges in the graph. The GNN system models learn the complex relations and normal patterns of communications within the network and detects deviations which can be seen to show the presence of new kinds of attacks. The steps in this system include data acquisition, data preprocessing, feature engineering, graph construction, GNN model training, anomaly detection, risk assessment, and security alerting. Evaluation of the system performance will be done using Accuracy, Precision, Recall, F1-Score, and False Positive Rate.
Introduction
The text proposes an AI-based zero-day cyberattack detection system using Graph Neural Networks (GNNs). The main motivation is that traditional signature-based intrusion detection systems are effective against known attacks but struggle to identify zero-day attacks, which exploit previously unknown vulnerabilities and therefore lack existing signatures or rules.
The proposed approach represents a computer network as a graph:
Nodes: users, devices, IP addresses, and processes.
Edges: communication and interactions between these entities.
GNN: learns normal patterns of relationships and communication.
Anomaly score: measures how much new activity deviates from learned normal behavior.
Alert: generated when the anomaly score exceeds a predefined threshold.
The study discusses several GNN techniques, including Graph Convolutional Networks (GCN), GraphSAGE, and Graph Attention Networks (GAT). These methods can capture relationships between interconnected network entities, which traditional machine-learning models such as Random Forest, SVM, and DNNs may not represent as effectively.
Proposed workflow
The system follows this general process:
Network traffic/log collection → preprocessing → feature extraction → graph construction → GNN training → normal-behavior learning → analysis of new activity → anomaly scoring → zero-day alert
Previous research, including approaches such as Anomal-E, GNN-IDS, WebWall, OPTIMAL, and MaGOS-IDS, is discussed to show how GNNs have been applied to intrusion and anomaly detection.
Main challenges
The proposed system faces several limitations:
Limited zero-day attack datasets, because previously unknown attacks are difficult to collect and label.
Large volumes of network data, which increase processing requirements.
Incomplete or irrelevant data during preprocessing.
Difficulty constructing accurate graphs that properly represent network relationships.
High computational requirements for training GNNs on large networks.
False positives and false negatives, meaning legitimate activity may be flagged or sophisticated attacks may be missed.
The model must be continuously updated because cyberattack techniques evolve over time.
Objectives
The project aims to:
Develop an AI/GNN framework for detecting unknown cyberattacks.
Represent network entities and their interactions as graphs.
Learn normal network behavior and identify deviations.
Calculate anomaly/risk scores and generate alerts for suspicious activity.
References
[1] T. N. Kipf and M. Welling, “Semi-Supervised Classification with Graph Convolutional Networks,” International Conference on Learning Representations (ICLR), 2017.
[2] W. L. Hamilton, R. Ying, and J. Leskovec, “Inductive Representation Learning on Large Graphs,” Advances in Neural Information Processing Systems (NeurIPS), 2017.
[3] P. Veli?kovi?, G. Cucurull, A. Casanova, A. Romero, P. Liò, and Y. Bengio, “Graph Attention Networks,” International Conference on Learning Representations (ICLR), 2018.
[4] N. Shone, T. N. Ngoc, V. D. Phai, and Q. Shi, “A Deep Learning Approach to Network Intrusion Detection,” IEEE Transactions on Emerging Topics in Computational Intelligence, vol. 2, no. 1, pp. 41–50, 2018.
[5] N. Moustafa and J. Slay, “UNSW-NB15: A Comprehensive Data Set for Network Intrusion Detection Systems,” Military Communications and Information Systems Conference (MilCIS), 2015
[6] E. Caville, W. W. Lo, S. Layeghy, and M. Portmann, “Anomal-E: A Self-Supervised Network Intrusion Detection System Based on Graph Neural Networks,” Knowledge-Based Systems, vol. 258, 2022, Art. no. 110030. DOI: 10.1016/j.knosys.2022.110030.
[7] Z. Sun, A. M. H. Teixeira, and S. Toor, “GNN-IDS: Graph Neural Network Based Intrusion Detection System,” 2024. DOI: 10.1145/3664476.3664515.
[8] “Anomaly Detection in Network Security Using Unsupervised Graph Neural Network,” 2025 International Conference on Advanced Computing Technologies (ICoACT), 2025. DOI: 10.1109/ICoACT63339.2025.11004728.
[9] “WebWall: Zero-Day Attack Detection in Web Traffic Using Spatial Graph Neural Network,” 2024 IEEE International Conference on Advanced Networks and Telecommunications Systems (ANTS), 2024. DOI: 10.1109/ANTS63515.2024.10898287.
[10] E. Caville, W. W. Lo, S. Layeghy, and M. Portmann, “Anomal-E: A Self-Supervised Network Intrusion Detection System Based on Graph Neural Networks,” Knowledge-Based Systems, 2022.
[11] “A Survey on Graph Neural Networks for Intrusion Detection Systems: Methods, Trends and Challenges,” Computers & Security, vol. 141, 2024, Art. no. 103821. DOI: 10.1016/j.cose.2024.103821.
[12] Y. Wang, Y. Zhang, Z. Zhang, L. Gao, and H. Pang, “OPTIMAL: Unsupervised Network Intrusion Detection Model Based on Optimized Graph Neural Network and Graph Contrastive Learning,” Computer Networks, vol. 280, 2026, Art. no. 112169. DOI: 10.1016/j.comnet.2026.112169.
[13] T.-T. Nguyen and M. Park, “MaGOS-IDS: A Mahalanobis-Enhanced OpenMax Method for Graph Neural Network-Based Intrusion Detection,” Electronics, vol. 15, no. 16, 2026, Art. no. 3667. DOI: 10.3390/electronics15163667