Related Experiment Videos
A hierarchical and privacy-preserving intrusion detection framework for SAGIN-enabled IIot using graph neural
Mueen Uddin1, Sonia Khan2, Fuhid Alanazi3
1College of Computing and IT, University of Doha for Science and Technology, Doha, 24449, Qatar.
None:
Space-Air-Ground Integrated Networks (SAGIN) supporting Industrial Internet of Things (IIoT) applications impose stringent requirements on intrusion detection due to node mobility, heterogeneous link characteristics, constrained edge resources, and cross-tier attack propagation. Most standard security methods rely on one main system or some fixed settings that makes it hard to respond quickly when the network changes or when there is not much power. This paper presents HSP-SR, a hierarchical intrusion detection and response framework structured according to the physical segmentation of SAGIN. At the ground tier, a compact autoencoder performs event-driven anomaly detection using an adaptive threshold conditioned on residual energy, temporal variation, and local entropy, thereby restricting unnecessary uplink transmissions. The air tier applies an attention-based fusion model that assigns normalized weights to incoming alerts according to dynamically updated trust scores, entropy measures, and temporal freshness, producing a filtered aggregate representation. At the space tier, a time-variant graph neural network models the SAGIN topology as a weighted graph and infers cross-domain intrusion patterns through multi-hop message passing and neighborhood statistics. Confidentiality of inter-tier communication is maintained through elliptic curve key exchange combined with AES-based payload encryption, while trust values are updated using hash-chain-derived credentials and divergence-aware drift control. Adaptive mitigation decisions are determined through a Deep Q-Network formulated within a Markov Decision Process, where the reward function jointly accounts for threat magnitude, latency overhead, and energy expenditure. The CSE-CIC-IDS2018 dataset underwent experimental testing under six different attack scenarios which produced a 99.42% detection accuracy and 0.72% false positive rate and 22.1% lower energy usage than previous benchmarks while keeping detection times under 130 milliseconds for all test scenarios.