Skip to search boxSkip to navigationSkip to main content

Uncertainty-aware intrusion detection via Bayesian transformers with causal attack graph learning

  • Mohammad Emad Arafah(corresponding author)
    ,
  • Dena Abu Laila
    ,
  • Israa Abuzaid
    ,
  • Mohammad Ahmad
*Corresponding author for this work
  • University of Petra
    ,
  • Zarqa Technical Intermediate College
    ,
  • University of Jordan
Research Output:
Chapter in Book/Report/Conference proceeding
Conference contribution
Peer-review

Abstract

Advanced Persistent Threats (APTs) pose significant challenges to network security because of their sophisticated and constantly evolving attack patterns. Traditional intrusion detection systems often fail to quantify prediction uncertainty and lack the ability to model causal relationships among different attack categories, which limits both their reliability and interpretability. This paper presents a hierarchical Bayesian transformer network that integrates uncertainty quantification, causal structure learning, and dynamic Bayesian inference for robust network intrusion detection. The proposed framework includes a Bayesian transformer encoder with Monte Carlo dropout for calibrated epistemic uncertainty estimation, a causal discovery module based on the NOTEARS algorithm that learns directed acyclic graph structures representing dependencies among attack categories, and a dynamic Bayesian network layer that performs probabilistic inference over the learned causal structures. Experimental evaluation on the CIC-IDS-2017 and UNSW-NB15 benchmark datasets shows that the approach achieves 96.32 percent plus or minus 0.48 percent accuracy and 95.62 percent plus or minus 0.55 percent F1-score, outperforming state-of-the-art methods. The framework provides well-calibrated uncertainty estimates with an Expected Calibration Error (ECE) of 0.045, enabling reliable, confidence-aware decision making. The learned causal graphs reveal interpretable relationships among attack categories, offering security analysts actionable insights into attack patterns and supporting more effective threat mitigation strategies.

Publication Information

Output type

Research Output:
Chapter in Book/Report/Conference proceeding
Conference contribution
Peer-review

Original language

English

Publication milestones

  • Published - 08/06/2026

Publication status

Published - 08/06/2026

Publisher

Institute of Electrical and Electronics Engineers Inc., United States

Publication series

  • Publication series name: 2026 2nd International Conference on Computational Intelligence Approaches and Applications, ICCIAA 2026 - Proceedings

ISBN (Electronic)

9798331556587

Publication IDs

  • Scopus: 105042410973

Host publication title

2026 2nd International Conference on Computational Intelligence Approaches and Applications, ICCIAA 2026 - Proceedings