Graph Neural Network–Based Early Warning System for Predicting and Disrupting Multi-Stage Cyberattacks on U.S. Energy and Water Critical Infrastructure
DOI:
https://doi.org/10.63125/jxz1wp91Keywords:
Cybersecurity, Graph Networks, Early-Warning, Cyberattacks, InfrastructureAbstract
Cyberattacks targeting energy and water critical infrastructure increasingly involve coordinated, multi-stage progression across interconnected information technology and operational technology environments, requiring predictive systems capable of identifying malicious activity before operational disruption. This study developed and quantitatively evaluated a graph neural network–based early-warning framework for predicting and disrupting multi-stage cyberattacks across energy and water infrastructure. The final analytical dataset contained 8,391,226 observations from 12 infrastructure datasets, 38 network environments, and 684 verified attack scenarios, with 99.3% data completeness. Cyber-physical interactions were represented through 63,600 temporal graph snapshots containing 18,426 nodes and 1,286,374 relational edges. Conventional machine-learning, deep-learning, and multiple GNN architectures were comparatively evaluated. GNN-GRU achieved the strongest binary detection performance, with 99.2% accuracy, 99.0% precision, 98.8% recall, 98.9% F1-score, 0.997 ROC-AUC, and 0.993 PR-AUC. Attack-stage prediction achieved 94.6% accuracy, next-stage prediction reached 91.7%, and attack-path prediction reached 92.8%. Mean time-to-detection was 8.6 minutes, providing a 23.1-minute warning lead time before critical-asset penetration; 92.4% of attacks were identified before OT penetration and 96.1% before final disruption. GNNExplainer recovered 91.8% of verified attack-path nodes and achieved 91.2% path agreement. Combined defensive interventions reduced predicted attack-success probability from 72.8% to 12.6%, critical-asset reachability from 78.3% to 15.7%, and operational disruption risk from 68.4% to 14.1%. Statistical and robustness analyses confirmed significant model-performance differences while identifying degradation under adversarial perturbations, unseen attacks, concept drift, and cross-sector transfer. Overall, temporal graph learning integrated with explainability, attack-path analysis, and defensive disruption provided an effective quantitative framework for proactive critical-infrastructure cybersecurity.


