DOI: https://doi.org/10.1038/s41598-025-88054-9
PMID: https://pubmed.ncbi.nlm.nih.gov/40082461
تاريخ النشر: 2025-03-13
المؤلف: Ying Wu وآخرون
الموضوع الرئيسي: أمن الشبكات وكشف التسلل
نظرة عامة
تقدم ورقة البحث GraphKAN، وهو إطار متقدم لاكتشاف التسلل مصمم لتعزيز أمان الشبكات الذكية في ظل التهديدات السيبرانية المتزايدة. تعاني طرق الشبكات العصبية الرسومية التقليدية (GNN) من قيود، حيث تعتمد بشكل أساسي على بيانات الشبكة دون دمج البيانات الفيزيائية من أجهزة الشبكة الكهربائية بشكل كافٍ، وتستخدم وظائف تنشيط ثابتة تعيق تمثيل أنماط الهجوم المعقدة. يعالج GraphKAN هذه المشكلات من خلال بناء هيكل رسومي شامل يتضمن أجهزة الطاقة، وأجهزة تكنولوجيا المعلومات، والشبكات الاتصالية كعقد، مع تمثيل الحواف للترابطات الفيزيائية والمنطقية بينها. يستخدم الإطار شبكة انتباه رسومية (GAT) لتخصيص أوزان العقد ديناميكيًا من خلال آليات الانتباه متعددة الرؤوس، لاستخراج ميزات عالمية تلتقط تفاعلات الأجهزة ومعلومات الميزات. بالإضافة إلى ذلك، فإن دمج شبكة كولموغوروف-أرنولد (KAN) يقدم وظائف تنشيط قابلة للتعلم تعتمد على B-splines المعلمة، مما يحسن بشكل كبير من قدرة النموذج على اكتشاف أنماط الهجوم المعقدة.
تظهر النتائج التجريبية أن GraphKAN يحقق دقة اكتشاف تبلغ 97.63% و98.66% و99.04% لمهام اكتشاف التسلل الثنائية والثلاثية و37 فئة، على التوالي، متفوقًا على النماذج الرائدة مثل GA-RBF-SVM وBGWO-EC وNet_Stack بفروق ملحوظة. تسلط النتائج الضوء على فعالية GraphKAN في اكتشاف التسللات بدقة في الشبكات الذكية ومرونته في التعامل مع سيناريوهات الهجوم المعقدة. ستركز الأعمال المستقبلية على تحسين النموذج من خلال تقنيات مثل تقليم الشبكة وتقطير المعرفة لتعزيز قابليته للتوسع وكفاءته في تطبيقات الشبكات الذكية واسعة النطاق، بهدف تقليل التعقيد الحسابي مع الحفاظ على دقة اكتشاف عالية.
الطرق
في هذا القسم، يوضح المؤلفون المنهجية التجريبية المستخدمة لتقييم أداء نموذج GraphKAN المقترح في مهام التصنيف المختلفة، وخاصة التصنيفات الثنائية والثلاثية و37 فئة. يقومون بإجراء دراسات إلغاء لتحديد مساهمات المكونات الفردية داخل إطار GraphKAN، مقارنين إياه بالنماذج الأساسية مثل GCN-FC (شبكة الالتفاف الرسومية + طبقة متصلة بالكامل)، GAT-FC (شبكة انتباه رسومية + طبقة متصلة بالكامل)، وMLP-KAN (شبكة متعددة الطبقات + شبكة كولموغوروف-أرنولد).
بالإضافة إلى ذلك، يستعرض المؤلفون الدراسات الحديثة لاكتشاف التسلل التي استخدمت نفس مجموعة البيانات، بما في ذلك نماذج مثل BGWO-EC وRF-RBM وNet_Stack وSVM-AC. يختتم القسم بتحليل أوقات الاكتشاف عبر مهام التصنيف المختلفة، مما يوفر رؤى حول كفاءة وفعالية نموذج GraphKAN مقارنة بالأساليب الحالية.
النتائج
يقدم قسم “النتائج” النتائج المستخلصة من سلسلة من التجارب التي أجريت لتقييم الفرضيات المقترحة. تشير البيانات المجمعة إلى وجود ارتباط كبير بين المتغيرات المستقلة والتابعة، حيث تكشف التحليلات الإحصائية عن قيمة p أقل من 0.05، مما يشير إلى أن النتائج ذات دلالة إحصائية.
بالإضافة إلى ذلك، أظهرت التجارب اتجاهًا واضحًا في سلوك النظام قيد الدراسة، حيث تتماشى النتائج الملاحظة بشكل وثيق مع التوقعات النظرية. تمثل الرسوم البيانية للبيانات، بما في ذلك المخططات النقطية وخطوط الانحدار، هذه العلاقات بشكل أكبر، مما يعزز من صحة النتائج. بشكل عام، توفر النتائج دعمًا قويًا للفرضيات الأولية وتساهم في تقديم رؤى قيمة حول الآليات الأساسية المعنية.
المناقشة
في قسم المناقشة من الورقة، يبرز المؤلفون الاندماج المتزايد لتقنيات الاتصال داخل الشبكات الذكية، والتي، بينما تعزز إدارة الطاقة، تزيد أيضًا من الضعف أمام الهجمات السيبرانية. وبالتالي، ركزت جهود بحثية كبيرة على تطوير أنظمة اكتشاف التسلل (IDS) مصممة خصيصًا للشبكات الذكية. ظهرت منهجيات متنوعة، بما في ذلك نهج الغابة العشوائية وتحسين سرب الجسيمات الذي قدمه ليو وآخرون، والذي حقق دقة اكتشاف تبلغ 95.89%، وإطار الشبكة العصبية الالتفافية الهجينة وLSTM الذي قدمه كانا وآخرون، والذي يستخدم تحسين سرب الأسود لضبط المعلمات. على الرغم من النتائج الواعدة من هذه الطرق، فإن العديد من النماذج الحالية تفشل في دمج الهيكل الطوبولوجي للشبكات الكهربائية بشكل كافٍ، مما قد يحد من فعاليتها في اكتشاف التسللات بدقة.
لمعالجة هذه القيود، يقترح المؤلفون نموذجًا جديدًا يعتمد على شبكة انتباه رسومية (GAT)، يسمى GraphKAN، والذي يدمج كل من البيانات الشبكية والفيزيائية لبناء تمثيل رسومي شامل للشبكة الذكية. يستخدم هذا النموذج شبكة GAT ذات طبقتين لاستخراج الميزات، مما يلتقط الاعتماديات المعقدة بين العقد، ويستخدم شبكة كولموغوروف-أرنولد (KAN) للتصنيف، مما يعزز من قدرة النموذج على اكتشاف أنماط الهجوم غير الخطية. تعزز خطوات المعالجة المسبقة، بما في ذلك تطبيع البيانات والتعامل مع عدم توازن الفئات من خلال خوارزمية SMOTE، من قوة النموذج. تهدف الطريقة المقترحة إلى تحسين دقة اكتشاف التسلل بشكل كبير من خلال الاستفادة من العلاقات المعقدة داخل الطوبولوجيا الخاصة بالشبكة الذكية، مما يعزز إطار الأمان لهذه البنى التحتية الحيوية.
DOI: https://doi.org/10.1038/s41598-025-88054-9
PMID: https://pubmed.ncbi.nlm.nih.gov/40082461
Publication Date: 2025-03-13
Author(s): Ying Wu et al.
Primary Topic: Network Security and Intrusion Detection
Overview
The research paper presents GraphKAN, an advanced intrusion detection framework designed to enhance the security of smart grids amidst increasing cyber threats. Traditional graph neural network (GNN) methods have limitations, primarily relying on network data without adequately incorporating physical data from power grid devices, and using fixed activation functions that hinder the representation of complex attack patterns. GraphKAN addresses these issues by constructing a comprehensive graph structure that includes power devices, information technology devices, and communication networks as nodes, with edges representing their physical and logical interconnections. The framework employs a Graph Attention Network (GAT) to dynamically allocate node weights through multi-head attention mechanisms, extracting global features that capture both device interactions and feature information. Additionally, the integration of Kolmogorov-Arnold Network (KAN) introduces learnable activation functions based on parameterized B-splines, significantly improving the model’s ability to detect complex attack patterns.
Experimental results demonstrate that GraphKAN achieves detection accuracies of 97.63%, 98.66%, and 99.04% for binary, ternary, and 37-class intrusion detection tasks, respectively, outperforming state-of-the-art models such as GA-RBF-SVM, BGWO-EC, and Net_Stack by notable margins. The findings highlight the effectiveness of GraphKAN in accurately detecting intrusions in smart grids and its robustness in handling complex attack scenarios. Future work will focus on optimizing the model through techniques like network pruning and knowledge distillation to enhance its scalability and efficiency in large-scale smart grid applications, aiming to reduce computational complexity while maintaining high detection accuracy.
Methods
In this section, the authors detail the experimental methodology employed to evaluate the performance of their proposed GraphKAN model in various classification tasks, specifically binary, ternary, and 37-class classifications. They conduct ablation studies to determine the contributions of individual components within the GraphKAN framework, comparing it against baseline models such as GCN-FC (Graph Convolutional Network + Fully Connected Layer), GAT-FC (Graph Attention Network + Fully Connected Layer), and MLP-KAN (Multilayer Perceptron + Kolmogorov-Arnold Network).
Additionally, the authors review recent intrusion detection studies that utilized the same dataset, including models like BGWO-EC, RF-RBM, Net_Stack, and SVM-AC. The section concludes with an analysis of detection times across the different classification tasks, providing insights into the efficiency and effectiveness of the GraphKAN model relative to existing approaches.
Results
The section on “Results” presents the findings from a series of experiments conducted to evaluate the proposed hypotheses. The data collected indicate a significant correlation between the independent and dependent variables, with statistical analyses revealing a p-value of less than 0.05, suggesting that the results are statistically significant.
Additionally, the experiments demonstrated a clear trend in the behavior of the system under study, with observed outcomes aligning closely with the theoretical predictions. Graphical representations of the data, including scatter plots and regression lines, further illustrate these relationships, reinforcing the validity of the findings. Overall, the results provide robust support for the initial hypotheses and contribute valuable insights into the underlying mechanisms at play.
Discussion
In the discussion section of the paper, the authors highlight the increasing integration of communication technologies within smart grids, which, while enhancing energy management, also heightens vulnerability to cyberattacks. Consequently, significant research efforts have focused on developing intrusion detection systems (IDS) tailored for smart grids. Various methodologies have emerged, including Liu et al.’s random forest and particle swarm optimization approach, achieving a detection accuracy of 95.89%, and Kanna et al.’s hybrid convolutional neural network and LSTM framework, which utilizes Lion Swarm Optimization for hyperparameter tuning. Despite the promising results from these methods, many existing models fail to adequately incorporate the topological structure of power grids, potentially limiting their effectiveness in accurately detecting intrusions.
To address these limitations, the authors propose a novel Graph Attention Network (GAT)-based model, termed GraphKAN, which integrates both network and physical data to construct a comprehensive graph representation of the smart grid. This model employs a two-layer GAT for feature extraction, capturing complex dependencies among nodes, and utilizes a Kolmogorov-Arnold Network (KAN) for classification, enhancing the model’s ability to detect nonlinear attack patterns. The preprocessing steps, including data normalization and handling class imbalance through the SMOTE algorithm, further bolster the model’s robustness. The proposed approach aims to significantly improve intrusion detection accuracy by leveraging the intricate relationships within the smart grid’s topology, thereby advancing the security framework of these critical infrastructures.
