Causal & Graph-Based Intrusion Detection
Detecting network and host intrusions with causal-mechanism modelling and graph-temporal fusion networks.
Graph visualization of network traffic flows with anomalous nodes highlighted
Overview
Most intrusion detection systems learn correlational patterns — which makes them fragile whenever real-world traffic drifts away from training conditions. This project line reframes intrusion detection around the underlying causal and relational structure of network and host activity, so detectors generalise better and stay auditable under resource constraints typical of real deployments.
Related publications
- Causal-IDS: Detecting Network Intrusions as Causal Mechanism Violations — 2026 40th International Conference on Information Networking (ICOIN)
- GT-FID: A Graph-Temporal Fusion Network for Host-Based Intrusion Detection from System Call Sequences — Proceedings of the 2025 10th International Conference on Cloud Computing and Internet of Things
- Explanation-Surface Governance in XAI-Enabled Network Intrusion Detection under Resource Constraints — Research Square preprint, 2026
Status
Active. Causal-IDS and GT-FID have been accepted for publication; work on explanation-surface governance for resource-constrained deployments is ongoing.