

de Recherche et d’Innovation
en Cybersécurité et Société
Merzouki, K.; Hadi, Y.; Elghazi, H.; Moudoud, H.; Houda, Z. A. El
Graph Neural Network Framework for Advanced Persistent Threat Detection in IIoT Environments Article d'actes
Dans: F., El Bouanani; F., Ayoub (Ed.): Int. Conf. Adv. Commun. Technol. Netw., CommNet - Proc., Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 979-833155781-2 (ISBN), (Journal Abbreviation: Int. Conf. Adv. Commun. Technol. Netw., CommNet - Proc.).
Résumé | Liens | BibTeX | Étiquettes: Advanced persistent threat, Advanced Persistent Threats, Anomaly detection, CICAPT-IIoT2024, Deep learning, extraction, Feature extraction, Features extraction, Graph Neural Networks, Graphic methods, IIoT, Industrial infrastructure, Industrial internet of thing, Learning systems, Message passing, Network architecture, Network frameworks, Network security, Relational learning, Threat detection
@inproceedings{merzoukiGraphNeuralNetwork2025,
title = {Graph Neural Network Framework for Advanced Persistent Threat Detection in IIoT Environments},
author = {K. Merzouki and Y. Hadi and H. Elghazi and H. Moudoud and Z. A. El Houda},
editor = {El Bouanani F. and Ayoub F.},
url = {https://www.scopus.com/pages/publications/105032074689?origin=resultslist},
doi = {10.1109/CommNet68224.2025.11288886},
isbn = {979-833155781-2 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Int. Conf. Adv. Commun. Technol. Netw., CommNet - Proc.},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {The increasing reliance of industrial infrastructures on the Industrial Internet of Things (IIoT) has made them more vulnerable to complex cyberattacks, especially Advanced Persistent Threats (APTs). To recognize and analyze these multi-stage incursions, we require computational models that can capture both structural and temporal connections in IIoT network architectures. This paper presents a framework based on Graph Neural Networks (GNNs) for detecting and classifying APTs in IIoT settings. We use the CICAPT-IIoT2024 dataset, which provides realistic multi-phase APT attack scenarios. The approach models system components, network communications, and process interactions as nodes and edges in a dynamic graph, allowing for relational learning and context-aware feature extraction. The GNN architecture leverages graph connectivity patterns and message-passing techniques to identify attack phases with greater accuracy and robustness. Experimental results show that this method outperforms traditional deep learning techniques and ensemble methods, particularly in early-stage anomaly detection. This paper highlights the potential of graph-based learning as an effective way to enhance IIoT infrastructure security against the changing behaviors of advanced persistent threats. © 2025 IEEE.},
note = {Journal Abbreviation: Int. Conf. Adv. Commun. Technol. Netw., CommNet - Proc.},
keywords = {Advanced persistent threat, Advanced Persistent Threats, Anomaly detection, CICAPT-IIoT2024, Deep learning, extraction, Feature extraction, Features extraction, Graph Neural Networks, Graphic methods, IIoT, Industrial infrastructure, Industrial internet of thing, Learning systems, Message passing, Network architecture, Network frameworks, Network security, Relational learning, Threat detection},
pubstate = {published},
tppubtype = {inproceedings}
}



