A Graph Neural Network Approach for Lateral Movement Attack Detection on IoT Network — ISAISS 2026 | TechShield Publications
ISAISS 2026 · Conference Article

A Graph Neural Network Approach for Lateral Movement Attack Detection on IoT Network

Authors: Anfal Tariq, Nida Fatima, Aoun Muhammad, Umer Fayyaz, Sehrish Raza

Abstract

IoT networks have facilitated cognitive cities, industrial control systems, and healthcare systems; they have also posed very serious security risks due to device weaknesses, variety, and deficient security. Among these dangers, lateral movement attacks are very covert and rely on hacked IoT devices with legitimate user authentication for movement within networks. To fill these voids, this paper suggests a Graph Neural Network (GAT method) based edge classification for lateral movement detection on IoT networks. By portraying the network as a graph with IoT devices as nodes and communications as edges, the proposed approach uses self-attention to assign weights and highlight communications based on harmless and hostile traffic. The GAT approach on the TON-IoT dataset surpasses LSTM and CNN benchmarks with an accuracy and F1-score of 0.9970. Attention visualization assists analysis and highlights likely paths for attacks.

Graph Neural Networks (GNN) Graph Attention Network (GAT) Lateral Movement Detection IoT Security Edge Classification

Cite This Paper

A. Tariq, N. Fatima, A. Muhammad, U. Fayyaz, and S. Raza, “A Graph Neural Network Approach for Lateral Movement Attack Detection on IoT Network,” Proc. Int. Symp. on AI and Secure Systems (ISAISS 2026), University of Central Punjab, Bahawalpur, Jan. 2026, doi: 10.67535/tsp.000002.016.