Edge-Aware GATv2-BiLSTM Framework for Spatiotemporal Intrusion Detection in Autonomous UAV Command-and-Control Networks

Authors

  • Jury Osama Balgoon, Mohammed Omar Baz

Keywords:

Graph Neural Networks (GNN), Bidirectional LSTM, UAV Cybersecurity, Spatiotemporal Learning, and Intrusion Detection Systems.

Abstract

Securing Unmanned Aerial Vehicle (UAV) networks against complex cyber threats is critical for ensuring the operational safety of autonomous command-and-control systems. Traditional intrusion detection systems (IDS) often treat traffic flows as independent records, limiting their ability to capture both relational communication dependencies and temporal attack evolution. For that purpose, this paper presents a hybrid framework that combines the ability of Graph Neural Networks (GNNs) to represent complex network structures with the power of Bidirectional Long Short-Term Memory (BiLSTM) units for learning sequential communication patterns. The proposed hybrid model architecture consists of two main parts: a deep graph encoder that encodes raw UAV communication flows as high-dimensional structural representations through edge-aware Graph Attention Network v2 (GATv2) layers, and a BiLSTM sequential framework that links spatial embeddings to a 10-step temporal window. The framework learns spatiotemporal representations that model cyber-threat evolution in both forward and backward temporal contexts. The framework was evaluated on the simulated UAVIDS-2025 ad hoc network dataset and the real T-ITS cyber-physical UAV Wi-Fi dataset. On UAVIDS-2025, the proposed GNN-BiLSTM + XGBoost pipeline achieved 98.05% accuracy and 98.18% F1-score, outperforming the strongest reported tabular XGBoost baseline by 2.05% and 2.18% points, respectively. On the T-ITS cyber dataset, the AE + GNN + BiLSTM pipeline achieved 99.16% multi-class accuracy and 99.57% weighted F1-score under the reported split. These results indicate that jointly modeling graph-based communication structure and temporal dependencies can improve UAV intrusion detection performance across simulated and real cyber-physical UAV communication settings.

Downloads

Download data is not yet available.

References

R. Shrestha, A. Omidkar, S. A. Roudi, R. Abbas, and S. Kim, “Machine-learning-enabled intrusion detection system for cellular connected UAV networks,” Electronics, vol. 10, no. 13, Art. no. 1549, 2021, doi: 10.3390/electronics10131549.

S. C. Hassler, U. A. Mughal, and M. Ismail, “Cyber-physical intrusion detection system for unmanned aerial vehicles,” IEEE Trans. Intell. Transp. Syst., vol. 25, no. 6, pp. 6106–6117, Jun. 2024, doi: 10.1109/TITS.2023.3339728.

S. N. Ashraf et al., “IoT empowered smart cybersecurity framework for intrusion detection in internet of drones,” Sci. Rep., vol. 13, no. 1, Art. no. 18422, 2023.

U. A. Mughal, R. Atat, and M. Ismail, “Graph neural network-based intrusion detection system for a swarm of UAVs,” in Proc. MILCOM 2024 IEEE Mil. Commun. Conf. (MILCOM), Oct. 2024, pp. 578–583.

D. H. Tran and M. Park, “FN-GNN: A novel graph embedding approach for enhancing graph neural networks in network intrusion detection systems,” Appl. Sci., vol. 14, no. 16, Art. no. 6932, 2024.

R. Wang et al., “Network traffic analysis based on graph neural networks: A scoping review,” Big Data Cogn. Comput., vol. 9, no. 11, Art. no. 270, 2025.

M. Homaei, I. Khazrak, R. Molano, A. Caro, and M. Avila, “Graph attention networks with physical constraints for anomaly detection,” arXiv preprint arXiv:2601.12426, 2026.

Q. Zeng, A. Bashir, and F. Nait-Abdesselam, “UAVIDS-2025: A benchmark dataset for intrusion detection in UAV networks using machine learning techniques,” in Proc. 2025 IEEE Conf. Commun. Netw. Secur. (CNS), Sep. 2025, pp. 1–9.

T. C. Vuong et al., “Effective intrusion detection for UAV communications using autoencoder-based feature extraction and machine learning approach,” arXiv preprint arXiv:2410.02827, 2024.

R. A. Ramadan, A. H. Emara, M. Al-Sarem, and M. Elhamahmy, “Internet of drones intrusion detection using deep learning,” Electronics, vol. 10, no. 21, Art. no. 2633, 2021.

L. Kou, S. Ding, T. Wu, W. Dong, and Y. Yin, “An intrusion detection model for drone communication network in SDN environment,” Drones, vol. 6, no. 11, Art. no. 342, 2022.

M. Aldossary, I. Alzamil, and J. Almutairi, “Enhanced intrusion detection in drone networks: A cross-layer convolutional attention approach for drone-to-drone and drone-to-base station communications,” Drones, vol. 9, no. 1, Art. no. 46, 2025.

S. Brody, U. Alon, and E. Yahav, “How attentive are graph attention

networks?,” arXiv preprint arXiv:2105.14491, 2021.

Y. Zhang, C. Yang, K. Huang, and Y. Li, “Intrusion detection of

industrial internet-of-things based on reconstructed graph neural networks,” IEEE Trans. Netw. Sci. Eng., vol. 10, no. 5, pp. 2894–2905, 2023.

F. Kong, J. Li, B. Jiang, H. Wang, and H. Song, “Integrated generative model for industrial anomaly detection via bidirectional LSTM and attention mechanism,” IEEE Trans. Ind. Informat., vol. 19, no. 1, pp. 541–550, Jan. 2023.

F. S. Alrayes, M. Zakariah, S. U. Amin, Z. I. Khan, and M. Helal, “Intrusion detection in IoT systems using denoising autoencoder,” IEEE Access, vol. 12, pp. 122401–122425, 2024.

Y. Sun, “An XGBoost-Softmax framework for multi-class DDoS network attack detection,” in Proc. 2025 Int. Conf. Intell. Commun. Netw. Comput. Techn. (ICICNCT), Sep. 2025, pp. 1–5.

S. Xie, C. Zhan, J. Li, and Y. Li, “Intrusion detection method based on graph edge attention and focal loss,” in Proc. 2025 4th Int. Conf. Cryptography, Netw. Secur. Commun. Technol., Jan. 2025, pp. 21–28.

H. Elwahsh et al., “Hyperparameter optimization of XGBoost and hybrid CNN-SVM for cyber threat detection using modified Harris

hawks algorithm,” PeerJ Comput. Sci., vol. 11, Art. no. e3169, 2025. [20] A. H. Hamad, N. K. Hussein, and A. M. Abdulghani, “A deep learning

paradigm for intrusion detection in unmanned aerial vehicle networks using extended LSTM,” Int. J. Intell. Eng. Syst., vol. 18, no. 4, 2025.

K. Takahashi, K. Yamamoto, A. Kuchiba, and T. Koyama, “Confidence interval for micro-averaged F1 and macro-averaged F1 scores,” Appl. Intell., vol. 52, no. 5, pp. 4961–4972, 2022.

H. M. Attaullah, I. U. Khan, M. M. Alam, and K. Kaushik, “RoboLSTM-IDS: Multi-dataset evaluation of deep learning framework for UAV network,” PeerJ Comput. Sci., vol. 12, Art. no. e3500, 2026.

Downloads

Published

25.08.2026

How to Cite

Jury Osama Balgoon. (2026). Edge-Aware GATv2-BiLSTM Framework for Spatiotemporal Intrusion Detection in Autonomous UAV Command-and-Control Networks. International Journal of Intelligent Systems and Applications in Engineering, 14(1s), 2405 –. Retrieved from https://ijisae.org/index.php/IJISAE/article/view/8549

Issue

Section

Research Article