Wireless sensor networks are vulnerable to Sybil attacks because low-cost sensor nodes have restricted energy, computation and communication resources, while a malicious device may claim multiple identities and distort routing, localization and trust decisions. Existing Sybil attack detectors based only on identity verification or received signal strength indicator may be sensitive to radio-noise fluctuations and may ignore the energy and timing behaviour of interacting nodes. This paper develops a nonlinear graphbased received-signal-strength-indicator–energy anomaly model for Sybil attack detection in wireless sensor networks and combines it with support vector machine classification. The network is represented as a time-dependent weighted graph in which node interaction weights depend on received-signal-strength-indicator deviation, residual-energy variation, transmission-time inconsistency and duplicate identity or location evidence. A nonlinear anomaly map transforms the hybrid score into a bounded risk indicator, and the support vectormachine classifier is formulated as an optimization problemover the proposed feature space. Boundedness, monotonicity, threshold-separation and computational-complexity properties of the detector are established. Simulation experiments using networks of different sizes are used to evaluate the model under legitimate and Sybil-node populations, including ablation tests, threshold-sensitivity analysis and confusion-matrix based metrics. The results indicate that the proposed framework provides an interpretable and lightweight mathematical mechanism for malicious-node detection in resource-constrained wireless sensor networks, especially when explainability, low computational overhead and crosslayer feature integration are preferred over black-box detection alone.



