Augelli, Federico
(2026)
Topology-Adaptive Continual Graph Neural Networks for Intrusion Detection.
[Laurea magistrale], Università di Bologna, Corso di Studio in
Informatica [LM-DM270], Documento full-text non disponibile
Il full-text non è disponibile per scelta dell'autore.
(
Contatta l'autore)
Abstract
...
The goal of this thesis is to realize a continual learning framework within an intrusion detection
system scenario in which new data chunks introduce new classes of attacks. Previous work has
oversimplified this approach by using predefined classes and performing binary classification,
which significantly simplifies the task with regard to the data imbalance problem. Our propose
uses a graph neural network called GraphSAGE with residual connections. This network mod-
els a graph where the nodes are IP addresses and the edges are data streams. The network’s
classification head dynamically expands whenever a new attack appears without compromising
performance on old classes. We also use an experience replay method called ER-GNN to miti-
gate catastrophic forgetting. This allows the network to learn new attack classes without losing
knowledge of previous ones. We address the problem of severe data imbalance through topo-
logical solutions, such as Topology-Aware Margin Loss (TAM), as well as a new loss function
introduced in this thesis: Topology-Adaptive Focal Loss (TAFocal). TAFocal calculates the
importance of each sample based on the degree of its nodes. Finally, we use various strategies,
such as nonlinear node subsampling, to help ensure model stability, prevent sudden collapses
caused by extremely imbalanced classes, and maintain the model’s ability to generalize. We
compared various continual learning strategies based on distillation, replay, and regulariza-
tion. Our approach outperforms the baseline and other strategies on all metrics, especially in
accuracy, precision and recall, something the others fails to do.
Abstract
...
The goal of this thesis is to realize a continual learning framework within an intrusion detection
system scenario in which new data chunks introduce new classes of attacks. Previous work has
oversimplified this approach by using predefined classes and performing binary classification,
which significantly simplifies the task with regard to the data imbalance problem. Our propose
uses a graph neural network called GraphSAGE with residual connections. This network mod-
els a graph where the nodes are IP addresses and the edges are data streams. The network’s
classification head dynamically expands whenever a new attack appears without compromising
performance on old classes. We also use an experience replay method called ER-GNN to miti-
gate catastrophic forgetting. This allows the network to learn new attack classes without losing
knowledge of previous ones. We address the problem of severe data imbalance through topo-
logical solutions, such as Topology-Aware Margin Loss (TAM), as well as a new loss function
introduced in this thesis: Topology-Adaptive Focal Loss (TAFocal). TAFocal calculates the
importance of each sample based on the degree of its nodes. Finally, we use various strategies,
such as nonlinear node subsampling, to help ensure model stability, prevent sudden collapses
caused by extremely imbalanced classes, and maintain the model’s ability to generalize. We
compared various continual learning strategies based on distillation, replay, and regulariza-
tion. Our approach outperforms the baseline and other strategies on all metrics, especially in
accuracy, precision and recall, something the others fails to do.
Tipologia del documento
Tesi di laurea
(Laurea magistrale)
Autore della tesi
Augelli, Federico
Relatore della tesi
Correlatore della tesi
Scuola
Corso di studio
Indirizzo
CURRICULUM A: TECNICHE DEL SOFTWARE
Ordinamento Cds
DM270
Parole chiave
GNN,Graph Neural Network,Intrusion Detection System,IDS,CL,Continual Learning,Incremental Learning,Class-Incremental Learning,Topology-Aware,Topology-Adaptive,Topology,Graph,GraphSAGE,Graph Attention Network,Graph Convolution Network,GAT,GCN,TAFocal,TAM,CIC-IDS
Data di discussione della Tesi
16 Luglio 2026
URI
Altri metadati
Tipologia del documento
Tesi di laurea
(NON SPECIFICATO)
Autore della tesi
Augelli, Federico
Relatore della tesi
Correlatore della tesi
Scuola
Corso di studio
Indirizzo
CURRICULUM A: TECNICHE DEL SOFTWARE
Ordinamento Cds
DM270
Parole chiave
GNN,Graph Neural Network,Intrusion Detection System,IDS,CL,Continual Learning,Incremental Learning,Class-Incremental Learning,Topology-Aware,Topology-Adaptive,Topology,Graph,GraphSAGE,Graph Attention Network,Graph Convolution Network,GAT,GCN,TAFocal,TAM,CIC-IDS
Data di discussione della Tesi
16 Luglio 2026
URI
Gestione del documento: