Quantitative Study Finds Automated Graph Representations Dominate Cyber Attack Detection Research
Summary
This study quantitatively examines how graph construction and representation strategies are used in graph-based cyber attack detection. The authors coded 37 original studies published from 2019 through 2026 by publication year, cybersecurity application domain, graph representation type, feature extraction strategy, learning paradigm, algorithm, and dataset. They used frequency analysis, cross-tabulation, and statistical association tests to compare the coded studies. Automated representation learning was used in 73.0% of the studies, while 27.0% used handcrafted representations. A Fisher-Freeman-Halton exact test found a statistically significant association between application domain and representation strategy, with exact p = 0.008 and Cramer's V = 0.540. The result indicates that automated representation learning is the dominant strategy in the analyzed literature, but that representation choices are not distributed uniformly across cybersecurity application domains.