NetFlow-JEPA: Temporal Self Supervised Graph Based Network Intrusion Detection
Abstract
Network intrusion detection systems must learn useful representations from highly imbalanced, temporally structured network traffic while remaining robust to changes in attack distribution. We present NetFlow-JEPA, a self-supervised framework for learning graph representations of network traffic using a Joint-Embedding Predictive Architecture (JEPA). Network flows are organized into temporal graphs, and the model is pretrained without attack labels by predicting latent representations of target graph context from observed context. The resulting encoder is evaluated through frozen linear and multilayer-perceptron probes for binary and multiclass intrusion classification. We study representation quality on NF-CSE-CIC-IDS2018-v3 and evaluate cross-dataset transfer to the other independently processed NetFlow v3 datasets. Across these experiments, NetFlow-JEPA learns representations that retain substantial information relevant to intrusion detection without supervised encoder training, while nonlinear probes consistently extract additional discriminative structure beyond linear evaluation. These results provide evidence that predictive self-supervised graph learning is a viable approach for learning reusable network-traffic representations and motivate further investigation of JEPA-style objectives for label-efficient and cross-domain intrusion detection.