Repository logo
 

The Role of Graph Neural Networks, Transformers, and Reinforcement Learning in Network Threat Detection: A Systematic Literature Review

aut.relation.endpage4163
aut.relation.issue21
aut.relation.journalElectronics Switzerland
aut.relation.startpage4163
aut.relation.volume14
dc.contributor.authorDoremure Gamage, TP
dc.contributor.authorGutierrez, JA
dc.contributor.authorRay, SK
dc.date.accessioned2025-11-25T19:38:12Z
dc.date.available2025-11-25T19:38:12Z
dc.date.issued2025-10-24
dc.description.abstractTraditional network threat detection based on signatures is becoming increasingly inadequate as network threats and attacks continue to grow in their novelty and sophistication. Such advanced network threats are better handled by anomaly detection based on Machine Learning (ML) models. However, conventional anomaly-based network threat detection with traditional ML and Deep Learning (DL) faces fundamental limitations. Graph Neural Networks (GNNs) and Transformers are recent deep learning models with innovative architectures, capable of addressing these challenges. Reinforcement learning (RL) can facilitate adaptive learning strategies for GNN- and Transformer-based Intrusion Detection Systems (IDS). However, no systematic literature review (SLR) has jointly analyzed and synthesized these three powerful modeling algorithms in network threat detection. To address this gap, this SLR analyzed 36 peer-reviewed studies published between 2017 and 2025, collectively identifying 56 distinct network threats via the proposed threat classification framework by systematically mapping them to Enterprise MITRE ATT&CK tactics and their corresponding Cyber Kill Chain stages. The reviewed literature consists of 23 GNN-based studies implementing 19 GNN model types, 9 Transformer-based studies implementing 13 Transformer architectures, and 4 RL-based studies with 5 different RL algorithms, evaluated across 50 distinct datasets, demonstrating their overall effectiveness in network threat detection.
dc.identifier.citationElectronics Switzerland, ISSN: 2079-9292 (Print); 2079-9292 (Online), MDPI AG, 14(21), 4163-4163. doi: 10.3390/electronics14214163
dc.identifier.doi10.3390/electronics14214163
dc.identifier.issn2079-9292
dc.identifier.issn2079-9292
dc.identifier.urihttp://hdl.handle.net/10292/20209
dc.languageen
dc.publisherMDPI AG
dc.relation.urihttps://www.mdpi.com/2079-9292/14/21/4163
dc.rights© 2025 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
dc.rights.accessrightsOpenAccess
dc.subject40 Engineering
dc.subject4009 Electronics, Sensors and Digital Hardware
dc.subjectNetworking and Information Technology R&D (NITRD)
dc.subjectMachine Learning and Artificial Intelligence
dc.subjectBioengineering
dc.subject0906 Electrical and Electronic Engineering
dc.titleThe Role of Graph Neural Networks, Transformers, and Reinforcement Learning in Network Threat Detection: A Systematic Literature Review
dc.typeJournal Article
pubs.elements-id746028

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
The Role of Graph Neural Networks, Transformers, and Reinforcement Learning in Network Threat Detection_ A Systematic Literature Review.pdf
Size:
3.94 MB
Format:
Adobe Portable Document Format
Description:
Journal article

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.37 KB
Format:
Plain Text
Description: