Three numbers beat twenty-one in a new test of attack-detecting algorithms.
Researchers built Natural Visibility Graphs out of network traffic, then measured 21 topological metrics describing each graph's shape. They ran four separate ranking methods, SHAP, grouped Permutation Importance, Boruta, and Recursive Feature Elimination, to figure out which metrics actually mattered, then merged the rankings into one consensus list. Using the CICIDS2018 attack dataset and a CNN classifier, they tested slimmed-down versions of the metric set, from all 21 down to just three. The top three, all variants of average clustering coefficient, hit 97.148% accuracy and an MCC of 0.9675, edging out the full 21-metric version's 95.999% accuracy and 0.9549 MCC.
That inverts the usual tradeoff story. More features didn't just fail to help, they actively hurt performance while costing more to compute. Runtime dropped from roughly 14,961 seconds to 589 seconds, a 96% cut, which matters for anyone trying to run this kind of detection close to real time instead of as an overnight batch job.
Worth remembering this is one dataset and one classifier. A compact graph signature beating a bloated one is a tidy result, but it needs to hold up outside CICIDS2018 before anyone strips metrics out of a production intrusion-detection system.