Sophisticated cyber-attacks have evolved so quickly that current threat propagation models are mostly based on static attack graphs, on a set of pre-defined attack signatures, or on single attack or intrusion detection approaches. These methods are ineffective when applied to dynamic attack behaviors, correctly model cascading threats, and autonomously defend against threats in a timely manner in heterogeneous network environments. A Multi-Layer Computational Resilience Model for Adaptive Threat Propagation Analysis and Autonomous Cyber Defense (MLCR-ATPAD), is introduced here as a mathematical model that brings together a computational stack comprising of hierarchical attack graph representation, adaptive threat propagation modeling, resilience-aware risk estimation, autonomous defense optimization, and recovery-aware system stabilization. The novelty of this proposed model is its multi-layer resilience formulation, which provides a rigorous framework through a set of interconnected mathematical functions to capture the evolution of attacks, adaptation of defenses, and dynamics of recovery, allowing for continuous resilience assessment as cyber threats evolve. Modern enterprise, Internet of Medical Things, and next-generation 5G network attack scenarios are used to validate the proposed framework by using contemporary benchmark datasets CICIoMT2024, 5G-NIDD 2024, and NF-UQ-NIDS-v2 (2025). The proposed model is then evaluated against the various computational defense approaches by comparing the attack detection accuracy, precision, recall, f1 score, threat propagation probability, resilience index, false alarm rate, defense response latency, recovery time and computational overhead. The evaluation proves that the proposed architecture provides superior level of resilience, adaptive threat containment, quick autonomous reaction, and cyber defense performance in multiple and changing network scenarios.
D. Jayawardena and K. Perera, “AI-Driven Cybersecurity Frameworks for Real-Time Intrusion Detection and Threat Intelligence,” Int. J. Comput. Sci. Inf. Syst., vol. 11, no. 7, pp. 60–77, Jul. 2026, doi: 10.55640/IJCSIS/VOLUME11ISSUE07-02.
P. C. Ike, U. C. Daniel, M. Adeoye, M. I. Amaechi, O. O. Odesola, and M. O. Ogunsakin, “Cognitive Cyber Defense Systems,” Int. J. Nature Sci. Adv. Res., Nov. 2025, doi: 10.70382/MEJNSAR.V10I9.075.
H. Jmal, F. B. Hmida, N. Basta, M. Ikram, M. A. Kaafar, and A. Walker, “SPGNN-API: A Transferable Graph Neural Network for Attack Paths Identification and Autonomous Mitigation,” IEEE Trans. Inf. Forensics Security, vol. 19, pp. 1601–1613, 2024, doi: 10.1109/TIFS.2023.3338965.
H. Wang, H. Xu, K. Li, L. Yao, Y. Liu, and Z. Fu, “Learning Autonomous Defense Strategies via Multi-Agent Graph Neural Networks in Dynamic Networked Environments,” in Proc. IEEE Int. Conf. Commun. Technol. (ICCT), Oct. 2025, pp. 1503–1508, doi: 10.1109/ICCT67417.2025.11374172.
X. Zhang and P. Bao, “Multi-view contrastive learning for graph adversarial defense,” Neural Netw., vol. 192, Art. no. 107868, Dec. 2025, doi: 10.1016/j.neunet.2025.107868.
Y. Shi, H. Zhang, L. Shi, and S. Xu, “Autonomous cyber defense for AIoT using Graph Attention Network-Enhanced reinforcement learning,” Comput. Commun., vol. 241, Art. no. 108265, Sep. 2025, doi: 10.1016/j.comcom.2025.108265.
R. Sumathy and A. Rinu Rija, “IoT and AI-Driven Adaptive Traffic Signal Control Using Deep Reinforcement Learning and Graph Neural Networks,” in Proc. Int. Conf. Smart Struct. Syst. (ICSSS), Dec. 2025, pp. 1–4, doi: 10.1109/ICSSS66939.2025.11346147.
N. Kumar, M. S. Kumar, R. Suhasini, M. Lakshman, N. Anbalagan, and D. R. Krithika, “A Graph Neural Network Framework for Real Time Cyber Threat Intelligence and Risk Analysis,” in Proc. IEEE Int. Conf. Adv. Comput. Technol. (ICACT), Sep. 2025, pp. 630–636, doi: 10.1109/ICACT67549.2025.11351388.
H. Narne, “Enhancing IoT Cybersecurity with Graph Neural Networks: Advanced Anomaly Detection and Threat Mitigation,” Int. J. Sci. Res., vol. 12, no. 8, pp. 2571–2575, Aug. 2023, doi: 10.21275/SR23086105929.
L. Li, F. Qiang, and L. Ma, “Advancing Cybersecurity: Graph Neural Networks in Threat Intelligence Knowledge Graphs,” in Proc. Int. Conf. Algorithms Softw. Eng. Netw. Security, Apr. 2024, pp. 737–741, doi: 10.1145/3677182.3677314.
Y. Wang, N. Li, D. Qiu, B. Cao, H. Xiao, and P. Zhou, “Integrating Graph Neural Networks and Dynamic Community Characterization for Advanced Persistent Threat Detection and Attack Provenance Reconstruction,” Int. J. Pattern Recognit. Artif. Intell., vol. 40, no. 7, Mar. 2026, doi: 10.1142/S0218001425570289.
M. Cui et al., “MGDA: A provenance graph-based framework for threat detection and attack scenario reconstruction,” Comput. Netw., vol. 274, Art. no. 111806, Jan. 2026, doi: 10.1016/j.comnet.2025.111806.
E. Manohar and K. B. Reddy, “ZT-GNN-MARL: A Zero-Trust Adaptive Cyber Défense Framework Using Graph Neural Networks and Multi-Agent Reinforcement Learning,” in Proc. Int. Conf. Knowl. Eng. Commun. Syst. (ICKECS), Apr. 2026, pp. 1–6, doi: 10.1109/ICKECS70176.2026.11527884.
S. Saklani, D. K. Chohan, and R. Sharma, “Zero Trust Cloud Security Using Federated Graph Neural Networks (Fed-GNN),” in Proc. Int. Conf. Intell. Sustainable Syst. (ICISS), Mar. 2026, pp. 393–398, doi: 10.1109/ICISS67859.2026.11453752.
J. Yao and B. Koirala, “Defense-Aware Temporal Graph Neural Network for fault-tolerant intrusion detection in IIoT–5G environments,” Cluster Comput., vol. 29, no. 5, Jun. 2026, doi: 10.1007/S10586-026-06037-5.
H. Hayouni and F. Jbali, “Lightweight Neuromorphic-Temporal Graph Framework for Proactive Defense Against Evolving Cyber Attacks,” Security Privacy, vol. 9, no. 1, Dec. 2025, doi: 10.1002/SPY2.70163.
CRediT Author Statement
The author reviewed the results and approved the final version of the manuscript.
Acknowledgements
The author(s) received no financial support for the research, authorship, and/or publication of this article.
Funding
No funding was received to assist with the preparation of this manuscript.
Ethics Declarations
Conflict of interest
The authors have no conflicts of interest to declare that are relevant to the content of this article.
Availability of Data and Materials
Data sharing is not applicable to this article as no new data were created or analysed in this study.
Author Information
Contributions
All authors have equal contribution in the paper and all authors have read and agreed to the published version of the manuscript.
Corresponding Author
Byoung Tak Zhang
Department of Computer Science and Technology, Tsinghua University, 30 Shuangqing Road, Beijing 100084, China.
Open Access This article is licensed under a Creative Commons Attribution NoDerivs is a more restrictive license. It allows you to redistribute the material commercially or non-commercially but the user cannot make any changes whatsoever to the original, i.e. no derivatives of the original work. To view a copy of this license, visit: https://creativecommons.org/licenses/by-nc-nd/4.0/
Cite this Article
Byoung Tak Zhang, “Adaptive Cyber Defense Using Dynamic Attack Graphs and Graph Neural Networks”, Elaris Computing Nexus, pp. 094-108, 2026, doi: 10.65148/ECN/2026008.