<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE ArticleSet PUBLIC "-//NLM//DTD PubMed 2.7//EN" "https://dtd.nlm.nih.gov/ncbi/pubmed/in/PubMed.dtd">
<ArticleSet>
<Article>
<Journal>
				<PublisherName>Iranian Society of Cryptology</PublisherName>
				<JournalTitle>The ISC International Journal of Information Security</JournalTitle>
				<Issn>2008-2045</Issn>
				<Volume></Volume>
				<Issue>Articles in Press</Issue>
				<PubDate PubStatus="epublish">
					<Year>2026</Year>
					<Month>05</Month>
					<Day>06</Day>
				</PubDate>
			</Journal>
<ArticleTitle>GAT-AID: A Graph Attention-Based Dual-Branch Framework for Scalable Anomaly and Intrusion Detection</ArticleTitle>
<VernacularTitle></VernacularTitle>
			<FirstPage></FirstPage>
			<LastPage></LastPage>
			<ELocationID EIdType="pii">243196</ELocationID>
			
<ELocationID EIdType="doi">10.22042/isecure.2026.542048.1244</ELocationID>
			
			<Language>EN</Language>
<AuthorList>
<Author>
					<FirstName>Nitin Wasudeorao</FirstName>
					<LastName>Wankhade</LastName>
<Affiliation>Thakur College of Engineering and Technology. Mumbai, Maharashtra.</Affiliation>

</Author>
<Author>
					<FirstName>Anand V</FirstName>
					<LastName>Khandare</LastName>
<Affiliation>professor, Thakur college of engineering, Mumbai</Affiliation>

</Author>
</AuthorList>
				<PublicationType>Journal Article</PublicationType>
			<History>
				<PubDate PubStatus="received">
					<Year>2025</Year>
					<Month>08</Month>
					<Day>18</Day>
				</PubDate>
			</History>
		<Abstract>Intrusion Detection Systems (IDS) are vital for defending modern networks against emerging cyber threats, including zero-day attacks. In this article, we introduce GAT-AID (Graph Attention-based Anomaly and Intrusion Detection), an IDS architecture that integrates Graph Attention Networks (GATs), Multi-Layer Perceptron (MLP) classifiers, and Autoencoders. The proposed methodology represents network traffic as a graph, allowing GAT to extract complex node-wise associations across traffic flows. The embeddings generated are further processed through a dual-branch architecture, an MLP-based classifier for identifying known attack types, and an Autoencoder-based anomaly detector for flagging zero-day intrusions. The proposed GAT-AID methodology is evaluated on two widely used benchmark datasets, namely CICIDS2017 and UNSW-NB15. The experiment results demonstrate that it outperforms conventional IDS baselines, including SVM, Random Forest, CNN, and GCN models, achieving higher detection rates, improved robustness against unseen threats, and greater adaptability to evolving network environments. These findings suggest that GAT-AID is an effective and scalable solution for intelligent, real-time intrusion detection. </Abstract>
		<ObjectList>
			<Object Type="keyword">
			<Param Name="value">Anomaly Detection</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Autoencoder</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">graph neural networks</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">intrusion detection systems</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Zero-Day Attacks</Param>
			</Object>
		</ObjectList>
<ArchiveCopySource DocType="pdf">https://www.isecure-journal.com/article_243196_e2bd8daaeea9bfac4bc36b9b940edea8.pdf</ArchiveCopySource>
</Article>
</ArticleSet>
