AI & Computingarticle2026-08-29

A layer-aware graph attention and patch transformer framework for multi-class IIoT attack classification

Open access0 citations

Abstract

The proliferation of IIoT devices has dramatically expanded the attack surface of critical infrastructure. IIoT systems span multiple communicating tiers from physical sensors to cloud back-ends, attackers increasingly exploit inter-tier boundaries in ways that single-layer detection cannot address. Existing intrusion detection approaches treat network traffic features as unordered, independent values, discarding the structural inter-feature relationships that are characteristic of attack behaviour in layered IIoT architectures. We propose LA-STGAT-PT (Layer-Aware Spatio-Temporal Graph Attention Network with Patch Transformer), an end-to-end deep learning framework for multi-class intrusion detection in IIoT environments. It integrates four components: (1) a Layer-Aware Graph that encodes statistically correlated and architecturally co-located features as a relational graph, enabling tier-aware reasoning over the IIoT protocol stack; (2) a Spatio-Temporal Graph Attention block (STGAT) that simultaneously models feature relationships across the graph and sequential patterns along the feature vector, then adaptively fuses both views; (3) a Patch Transformer Encoder that segments the fused embedding into sub-sequences and applies self-attention to capture long-range inter-group dependencies; and (4) a Dual-Head Output that jointly optimises for attack classification and normal-traffic reconstruction, using elevated reconstruction error as a secondary anomaly signal. Evaluated on the Edge-IIoTset benchmark across 14 attack classes and one normal class, LA-STGAT-PT achieves an overall accuracy of 99.96% and a macro-F1 score of 0.9955. Encoding IIoT protocol-layer topology as a relational graph and combining it with spatio-temporal feature modelling and patch-based self-attention yields state-of-the-art intrusion detection, demonstrating that structural domain knowledge can significantly improve deep learning-based NIDS.

// Source

View paper (DOI)Open access versionOpenAlexScientific ReportsPublished 2026-08-29

Authors: Ahmad Shaf, Tariq Ali, M. Khalid Awang, Mohammad Hijji, Husam S. Samkari, Mohammed F. Allehyani

Institutions: COMSATS University Islamabad, University of Tabuk, Sultan Zainal Abidin University