AN INTELLIGENT GRAPH ATTENTION NETWORK–BIGRU FRAMEWORK FOR REAL-TIME CYBERSECURITY MONITORING, MULTICLASS INTRUSION DETECTION, AND ADAPTIVE ATTACK RESPONSE IN IOT-ENABLED INDUSTRIAL CONTROL SYSTEMS
Keywords:
Industrial control systems; IoT cybersecurity; graph attention network; bidirectional gated recurrent unit; multiclass intrusion detection; real-time monitoring; adaptive attack response; risk-based decision-making.Abstract
The growing connectivity of Internet of Things (IoT) devices in industrial control systems (ICS) expands the attack surface of operational networks and enables threats to spread across interconnected equipment. This study presents a Graph Attention Network–Bidirectional Gated Recurrent Unit (GAT–BiGRU) framework for real-time cybersecurity monitoring, multiclass intrusion detection, and adaptive attack response in IoT-enabled ICS. Devices are represented as graph nodes and their communications as edges, allowing graph attention to identify influential interactions. The BiGRU captures evolving patterns in network traffic, authentication events, and process measurements. A risk-scoring module integrates the predicted attack class, model confidence, and operational context to assign a response tier. The framework was evaluated using 285,000 time-stamped records comprising normal activity and six attack classes: denial-of-service, false-data injection, command injection, device spoofing, malware intrusion, and unauthorized access. The records were divided chronologically into training, validation, and independent test sets containing 70%, 15%, and 15% of observations, respectively. This chronological design reflects operational deployment, in which later events must be classified using patterns learned from earlier data. Performance was assessed through classification metrics, false alarms, inference time, and response-tier assignment accuracy. Standalone GAT and BiGRU models served as baselines, while ablation analyses assessed the contributions of graph and temporal modeling. On the independent test set, the GAT–BiGRU framework achieved 98.2% accuracy, 97.6% macro-precision, 97.1% macro-recall, and 97.3% macro-F1. Its false alarm rate was 1.8%, and median inference time was 24 ms per observation window. Macro-F1 exceeded that of the standalone GAT and BiGRU models by 3.4 and 2.7 percentage points, respectively. The response module assigned the intended action tier in 95.1% of labeled scenarios. Ablation findings showed that joint graph and temporal modeling improved detection of coordinated device activity and evolving process anomalies. These results demonstrate the value of combining communication structure with temporal operational behavior for timely multiclass intrusion detection. By linking classifications to context-aware response tiers, the framework supports cybersecurity decisions that account for conditions within connected industrial environments.


