A GRAPH CONVOLUTIONAL NETWORK–BILSTM FRAMEWORK FOR MULTICLASS INTRUSION DETECTION AND ADAPTIVE ATTACK RESPONSE IN IOT-ENABLED INDUSTRIAL CONTROL SYSTEMS

Authors

  • Azaan Athar
  • Azka Athar
  • Kashif Ahmad
  • Usama Ahmad Mughal

Keywords:

Industrial control systems; Industrial Internet of Things; Graph Convolutional Network; Bidirectional Long Short-Term Memory; multiclass intrusion detection; cyberattack classification; adaptive attack response; risk-based alert prioritization.

Abstract

The increasing connectivity of IoT-enabled industrial control systems exposes critical operations to cyberattacks that can spread across devices and evolve over time. Accurate identification of attack types is essential for timely response, yet methods focused only on individual records may overlook device relationships and temporal behavior. This study proposes a Graph Convolutional Network–Bidirectional Long Short-Term Memory (GCN–BiLSTM) framework for multiclass intrusion detection and adaptive attack response. A device communication graph represents industrial components as nodes and their interactions as edges. The GCN extracts features from these relationships, while the BiLSTM learns temporal patterns from network traffic, authentication events, and process measurements. Their combined features support attack classification and a risk-scoring module that prioritizes response actions according to predicted attack type and operational severity. The framework was evaluated using 285,000 time-stamped records comprising normal activity and six attack classes: denial-of-service, false-data injection, command injection, device spoofing, malware intrusion, and unauthorized access. To preserve temporal order and limit data leakage, records were divided chronologically into training (70%; 199,500 records), validation (15%; 42,750 records), and independent test (15%; 42,750 records) sets. On the test set, the framework achieved 98.2% accuracy, 97.6% macro-precision, 97.1% macro-recall, and 97.3% macro-F1, with a 1.8% false-alarm rate. The risk-scoring module translated detection outputs into response tiers, allowing high-priority alerts to be escalated for immediate investigation or containment while lower-risk events remained under enhanced monitoring. These findings indicate that combining graph-based representations of device interactions with bidirectional temporal learning can support accurate multiclass intrusion detection in industrial environments. By linking classification results to prioritized response decisions, the framework provides a practical structure for cybersecurity monitoring and incident handling in IoT-enabled industrial control systems. Future evaluation across independent industrial sites and attack conditions would help establish its robustness and operational transferability.

Downloads

Published

2026-02-22

How to Cite

Azaan Athar, Azka Athar, Kashif Ahmad, & Usama Ahmad Mughal. (2026). A GRAPH CONVOLUTIONAL NETWORK–BILSTM FRAMEWORK FOR MULTICLASS INTRUSION DETECTION AND ADAPTIVE ATTACK RESPONSE IN IOT-ENABLED INDUSTRIAL CONTROL SYSTEMS. Spectrum of Engineering Sciences, 4(2), 2261–2287. Retrieved from https://thesesjournal.com.medicalsciencereview.com/index.php/1/article/view/3949