A new study published on arXiv on October 5, 2026 (arXiv:2610.02342) demonstrates that pruning graph topological metrics can accelerate cyber attack detection by 96% while improving classification accuracy compared to utilizing the full metric set. The research addresses computational overhead when analyzing network traffic via Natural Visibility Graph (NVG), a technique frequently hindered by the cost of extracting extensive structural descriptors.
According to arXiv, NVG-based analysis maps network traffic time series into graphs to extract topological metrics reflecting structural properties. However, individual metrics contribute unevenly to cyber-attack classification, and extracting the full set of 21 metrics significantly increases computational overhead.
To identify the optimal metric subset, the study integrated four distinct importance analysis methods—SHAP, grouped Permutation Importance, Boruta, and Recursive Feature Elimination (RFE)—using a Consensus Ranking strategy. Based on this ranking, the authors evaluated six subset configurations: Full21, Top15, Top10, Top7, Top5, and Top3.
Experiments were conducted on the CICIDS2018 cybersecurity dataset using a Convolutional Neural Network (CNN) classifier with stratified 5-fold cross-validation. The top three ranked metrics all belong to the clustering coefficient family: avg_clustering_coeff_median, avg_clustering_coeff_std, and avg_clustering_coeff_mean.
Experimental results indicate that the Top3 configuration achieved the highest mean predictive performance. Specifically, Top3 recorded 97.148% accuracy, a 97.055% weighted F1 score, and a Matthews correlation coefficient (MCC) of 0.9675, outperforming Full21 (95.999% accuracy, 95.521% F1, and 0.9549 MCC). Crucially, total runtime dropped from 14,961.39 seconds under Full21 to 589.22 seconds with Top3, representing a 96.06% reduction in computational cost.