Graph Neural Network Models for Multi-Stage Cyber Attack Detection in Industrial Control Systems: A Comparative Evaluation Framework Across SCADA-Grade Datasets
DOI:
https://doi.org/10.70917/ijcisim-2026-4813Keywords:
Industrial Control Systems, SCADA Security, Operational Technology, Cyber-Physical Systems, Multi-Stage Cyber Attack Detection, Graph Neural Networks, Graph Convolutional Network, Graph Attention Network, GraphSAGE, Graph Isomorphism Network, Intrusion Detection System, Critical Infrastructure ProtectionAbstract
Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) environments are vulnerable to multi-stage cyber attacks that evolve across interconnected devices, protocols, and physical processes. Detection is difficult because each stage of such an attack, evaluated in isolation, may resemble legitimate operational behaviour, while the malicious intent becomes evident only when the structural relationships among assets and the temporal progression of events are considered together. Traditional signature-based, anomaly-based, and classical machine learning approaches typically evaluate individual packets or short windows and therefore struggle with multi-stage campaigns. This paper proposes a comparative evaluation framework for Graph Neural Network (GNN) models, specifically Graph Convolutional Networks (GCN), Graph Attention Networks (GAT), GraphSAGE, and Graph Isomorphism Networks (GIN), applied to multi-stage attack detection in ICS environments. Industrial network traffic and process interactions are represented as graphs in which nodes correspond to controllers, sensors, actuators, engineering workstations, and network devices, and edges capture communication and control relationships. Attack stages are labelled at the node level so that detection becomes a structured classification problem. The paper does not report experimental results. Implementation and empirical benchmarking are planned as future work on publicly available SCADA-grade datasets including SWaT, WADI, HAI, and additional Power System and industrial datasets where available. The contribution is the proposed evaluation framework, the graph representation strategy for ICS environments, and the methodological groundwork for a rigorous future comparison.