[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-81568-en":3,"doc-seo-81568-105":30,"detail-sidebar-cat-0-en-105":95},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},81568,549758146520,"Patrick","https://ap-avatar.wpscdn.com/avatar/80002397d8c0411e94?_k=1775819394049821470",8,"Research & Report","AutoGraphAD Unsupervised network anomaly detection using Variational Graph Autoencoders","Network Intrusion Detection Systems (NIDS) are crucial for identifying attacks and intrusions, but supervised machine learning depends on costly, accurately labelled datasets and is constrained by limited or outdated public data with frequent mislabelling. AutoGraphAD addresses this with an unsupervised method based on a Heterogeneous Variational Graph Autoencoder over connection and IP nodes. Trained via unsupervised and contrastive learning, it combines weighted losses into an anomaly score, matching or improving Anomal-E while avoiding costly downstream detectors, delivering markedly faster training and inference for operational deployment.","AutoGraphAD: Unsupervised network anomaly detection using Variational Graph Autoencoders  \nGeorgios Anyfantis  \nDepartment of Computer Architecture Universitat Polite`cnica de Catalunya Barcelona, Spain [georgios.anyfantis@upc.edu](georgios.anyfantis@upc.edu)  \nPere Barlet-Ros  \nDepartment of Computer Architecture Universitat Polite`cnica de Catalunya Barcelona, Spain [pere.barlet@upc.edu](pere.barlet@upc.edu)  \narXiv :2511 . 17 1 13v 3 [ cs .CR] 10 Jul 2026  \nAbstract—Network Intrusion Detection Systems (NIDS) are essential tools for detecting network attacks and intrusions. While extensive research has explored the use of supervised Machine Learning for attack detection and characterisation, these methods require accurately labelled datasets, which are very costly to obtain. Moreover, existing public datasets have limited and/or outdated attacks, and many of them suffer from mislabelled data. To reduce the reliance on labelled data, we propose AutoGraphAD, a novel unsupervised anomaly detection approach based on a Heterogeneous Variational Graph Autoencoder. AutoGraphAD operates on heterogeneous graphs, made from connection and IP nodes that represent network activity. The model is trained using unsupervised and contrastive learning, without relying on any labelled data. The model’s losses are then weighted and combined in an anomaly score used for anomaly detection. Overall, AutoGraphAD yields the same, and in some cases better, results than Anomal-E, but without requiring costly downstream anomaly detectors. As a result, AutoGraphAD achieves around 1.18 orders of magnitude faster training and 1.03 orders of magnitude faster inference, which represents a significant advantage for operational deployment.  \nIndex Terms—Graph Neural Networks, Intrusion Detection System, Unsupervised Learning, Graph Variational Autoencoders, Anomaly Detection  \nI. INTRODUCTION  \nIn recent years, attacks and intrusions have been a growing problem. The attacks reported each year have been growing exponentially, with attacks becoming more and more sophisticated [1] . Thus, more robust Network Intrusion Detection Systems (NIDS) are needed to deal with the increasing volume and complexity of network attacks.  \nA substantial body of research has explored the use of Machine Learning (ML) to detect and characterise attacks [2]–[5] . However, most of these approaches are susceptible to adversarial attacks and therefore do not suit real-life deployment [6] . Graph Neural Networks (GNNs) are known to be more robust against adversarial attacks, as they use both network data and learn the structures and relationships among network traffic flows [7]–[9] .  \nIn the NIDS domain, the number of datasets that can be used to create and train ML models remains limited [10] . Many public NIDS datasets contain synthetic elements, outdated attacks, or labelling limitations, creating a distorted image of how attacks are structured and work [11] .  \nLabelling datasets is a costly and laborious task, which explains the scarcity of high-quality labelled data sets [12] . The main challenge is that each network flow must be examined and annotated by a domain expert, such as a Security Analyst [13] . This makes labelling large real-world network data almost impossible, which is why most research in this area relies on synthetic datasets [13] .  \nAnomaly detection is a good approach to mitigate reliance on labelled datasets, as we only need normal data to establish a baseline, and anything that deviates from it is considered anomalous. Anomal-E is arguably the most representative and influential approach in graph-based network anomaly detection [14] .  \nIn the case of Anomal-E and other approaches [15], [16], they rely on traditional downstream anomaly detection algorithms, which are often not suitable for a streaming environment [17], making them very difficult to implement in realworld networks. This is an additional layer of computation that needs to be retuned often to ac","cbCaiiAVkPBDPTQM","https://ap.wps.com/l/cbCaiiAVkPBDPTQM","pdf",325271,2,1,6,"English","en",105,"# Introduction\n## Motivation and limitations of supervised NIDS\n## Dataset scarcity and labelling cost\n## Anomaly detection and graph-based alternatives\n## Motivation for avoiding downstream estimators\n## Proposed approach: AutoGraphAD","[{\"question\":\"What problem does AutoGraphAD target in network intrusion detection?\",\"answer\":\"It targets the reliance on costly, accurately labelled datasets in supervised NIDS, along with limitations of public datasets that are often outdated or mislabelled.\"},{\"question\":\"How does AutoGraphAD represent network traffic for anomaly detection?\",\"answer\":\"It models network traffic as a heterogeneous graph with two node types: IP nodes and Connection nodes representing network activity.\"},{\"question\":\"How is AutoGraphAD trained without labelled data?\",\"answer\":\"The VGAE is trained using unsupervised and contrastive learning, without requiring any labelled anomalies or attacks.\"},{\"question\":\"How are anomalies scored in AutoGraphAD and what advantage does it provide?\",\"answer\":\"Anomaly scores are derived by weighting and combining the model’s losses, relying on reconstruction errors and related metrics rather than downstream anomaly detectors, which improves training and inference efficiency.\"}]",1784174374,15,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":90,"head_meta":92,"extra_data":94,"updated_unix":28},"autographad-unsupervised-network-anomaly-detection-using-variational-graph-autoencoders","",{"@graph":36,"@context":89},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/autographad-unsupervised-network-anomaly-detection-using-variational-graph-autoencoders/81568/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-25","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81,85],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does AutoGraphAD target in network intrusion detection?","Question",{"text":75,"@type":76},"It targets the reliance on costly, accurately labelled datasets in supervised NIDS, along with limitations of public datasets that are often outdated or mislabelled.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does AutoGraphAD represent network traffic for anomaly detection?",{"text":80,"@type":76},"It models network traffic as a heterogeneous graph with two node types: IP nodes and Connection nodes representing network activity.",{"name":82,"@type":73,"acceptedAnswer":83},"How is AutoGraphAD trained without labelled data?",{"text":84,"@type":76},"The VGAE is trained using unsupervised and contrastive learning, without requiring any labelled anomalies or attacks.",{"name":86,"@type":73,"acceptedAnswer":87},"How are anomalies scored in AutoGraphAD and what advantage does it provide?",{"text":88,"@type":76},"Anomaly scores are derived by weighting and combining the model’s losses, relying on reconstruction errors and related metrics rather than downstream anomaly detectors, which improves training and inference efficiency.","https://schema.org",{"og:url":51,"og:type":91,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":93,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":96},[97,101,105,109,114,118,123,126,131,134,138],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":106,"show_sort_weight":107,"slug":108},"Exam",70,"exam",{"id":110,"doc_module":4,"doc_module_name":46,"category_name":111,"show_sort_weight":112,"slug":113},5,"Comic",60,"comic",{"id":22,"doc_module":4,"doc_module_name":46,"category_name":115,"show_sort_weight":116,"slug":117},"Technology",50,"technology",{"id":119,"doc_module":4,"doc_module_name":46,"category_name":120,"show_sort_weight":121,"slug":122},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":124,"slug":125},30,"research-report",{"id":127,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":129,"slug":130},9,"Religion & Spirituality",20,"religion-spirituality",{"id":129,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":129,"slug":133},"World Cup","world-cup",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":135,"slug":137},10,"Lifestyle","lifestyle",{"id":139,"doc_module":4,"doc_module_name":46,"category_name":140,"show_sort_weight":110,"slug":141},19,"General","general"]