Explainable and Scalable Deep Learning Framework for Zero-Day Cyber Attack Detection in High-Dimensional Network Traffic
DOI:
https://doi.org/10.65204/djes.v3i3.845Keywords:
zero-day attack detection, explainable artificial intelligence, contrastive learning, intrusion detection systems , high-dimensional network traffic, SHAP, deep learningAbstract
The rapid evolution of network-based cyber threats particularly zero-day attacks presents fundamental challenges to intrusion detection systems (IDS). Existing deep learning approaches frequently sacrifice explainability and scalability, two properties essential for operational deployment. This paper presents EXSCAD (EXplainable and SCAlable Detection), a deep learning framework that integrates contrastive self-supervised pretraining, mutual-information-guided feature selection, supervised fine-tuning with open-set thresholding, and a KernelSHAP explainability layer for zero-day attack detection in high-dimensional network traffic. Evaluated on the CICIDS2018 and UNSW-NB15 benchmarks (~18.77 million flow records), EXSCAD achieves an F1-score of 98.07 ± 0.17% and zero-day recall of 87.34 ± 2.41%, statistically outperforming Random Forest , XGBoost, BiLSTM-IDS , CNN-IDS, and autoencoder baselines (Wilcoxon signed-rank, p < 0.0001). Ablation studies confirm that contrastive pretraining is the primary driver of zero-day generalisation. Inference latency of 39.2 ms per 1,000 samples supports real-time SOC deployment.
References
J. L. Ba, J. R. Kiros, and G. E. Hinton, "Layer normalization," arXiv:1607.06450, 2016.
L. Breiman, "Random forests," Machine Learning, vol. 45, no. 1, pp. 5–32, 2001.
V. Chandola, A. Banerjee, and V. Kumar, "Anomaly detection: A survey," ACM Comput. Surv., vol. 41, no. 3, Art. 15, 2009.
N. V. Chawla, K. W. Bowyer, L. O. Hall, and W. P. Kegelmeyer, "SMOTE: Synthetic minority over-sampling technique," J. Artif. Intell. Res., vol. 16, pp. 321–357, 2002.
T. Chen and C. Guestrin, "XGBoost: A scalable tree boosting system," in Proc. 22nd ACM SIGKDD, 2016, pp. 785–794.
T. Chen, S. Kornblith, M. Norouzi, and G. Hinton, "A simple framework for contrastive learning of visual representations," arXiv:2002.05709, 2020.
T. M. Cover and J. A. Thomas, Elements of Information Theory, 2nd ed. Wiley, 2006.
I. Goodfellow et al., "Generative adversarial nets," in Proc. NIPS, 2014, vol. 27.
K. He, H. Fan, Y. Wu, S. Xie, and R. Girshick, "Momentum contrast for unsupervised visual representation learning," in Proc. IEEE/CVF CVPR, 2020, pp. 9729–9738.
D. Hendrycks and K. Gimpel, "Gaussian error linear units (GELUs)," arXiv:1606.08415, 2016.
S. Hochreiter and J. Schmidhuber, "Long short-term memory," Neural Comput., vol. 9, no. 8, pp. 1735–1780, 1997.
E. Horowicz, T. Shapira, and Y. Shavitt, "Self-supervised traffic classification: Flow embedding and few-shot solutions," IEEE Trans. Netw. Serv. Manage., vol. 21, no. 3, pp. 3054–3067, 2024.
M. Keshk et al., "An explainable deep learning-enabled intrusion detection framework in IoT networks," Inf. Sci., vol. 639, Art. 119000, 2023.
A. Khraisat, I. Gondal, P. Vamplew, and J. Kamruzzaman, "Survey of intrusion detection systems: Techniques, datasets and challenges," Cybersecurity, vol. 2, no. 1, Art. 20, 2019.
D. P. Kingma and J. Ba, "Adam: A method for stochastic optimization," arXiv:1412.6980, 2015.
D. P. Kingma and M. Welling, "Auto-encoding variational Bayes," arXiv:1312.6114, 2014.
F. T. Liu, K. M. Ting, and Z.-H. Zhou, "Isolation forest," in Proc. 8th IEEE ICDM, 2008, pp. 413–422.
Z. Long et al., "A Transformer-based network intrusion detection approach for cloud security," J. Cloud Comput., vol. 13, p. 5, 2024.
S. M. Lundberg and S.-I. Lee, "A unified approach to interpreting model predictions," in Proc. NIPS, 2017, vol. 30.
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, "Towards deep learning models resistant to adversarial attacks," arXiv:1706.06083, 2018.
H. B. McMahan et al., "Communication-efficient learning of deep networks from decentralized data," in Proc. AISTATS, 2017, pp. 1273–1282.
Y. Mirsky, T. Doitshman, Y. Elovici, and A. Shabtai, "Kitsune: An ensemble of autoencoders for online network intrusion detection," in Proc. NDSS, 2018.
N. Moustafa and J. Slay, "UNSW-NB15: A comprehensive data set for network intrusion detection systems," in Proc. MilCIS, 2015, pp. 1–6.
M. T. Ribeiro, S. Singh, and C. Guestrin, "'Why should I trust you?': Explaining the predictions of any classifier," in Proc. 22nd ACM SIGKDD, 2016, pp. 1135–1144.
M. Roesch, "Snort – Lightweight intrusion detection for networks," in Proc. USENIX LISA, 1999, pp. 229–238.
S. Sattar et al., "Anomaly detection in encrypted network traffic using self-supervised learning," Sci. Rep., vol. 15, Art. 26585, 2025.
W. J. Scheirer, A. de Rezende Rocha, A. Sapkota, and T. E. Boult, "Toward open set recognition," IEEE Trans. Pattern Anal. Mach. Intell., vol. 35, no. 7, pp. 1757–1772, 2013.
I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, "Toward generating a new intrusion detection dataset and intrusion traffic characterization," in Proc. ICISSP, 2018, pp. 108–116.
N. Srivastava, G. Hinton, A. Krizhevsky, I. Sutskever, and R. Salakhutdinov, "Dropout: A simple way to prevent neural networks from overfitting," J. Mach. Learn. Res., vol. 15, no. 1, pp. 1929–1958, 2014.
M. Sundararajan, A. Taly, and Q. Yan, "Axiomatic attribution for deep networks," in Proc. ICML, 2017, pp. 3319–3328.
D. M. J. Tax and R. P. W. Duin, "Support vector data description," Machine Learning, vol. 54, no. 1, pp. 45–66, 2004.
M. Tavallaee, E. Bagheri, W. Lu, and A. A. Ghorbani, "A detailed analysis of the KDD CUP 99 data set," in Proc. IEEE CISDA, 2009, pp. 1–6.
F. Ullah, S. Ullah, G. Srivastava, and J. C.-W. Lin, "IDS-INT: Intrusion detection system using transformer-based transfer learning for imbalanced network traffic," Digit. Commun. Netw., vol. 10, no. 1, pp. 190–204, 2024.
A. Vaswani et al., "Attention is all you need," in Proc. NIPS, 2017, vol. 30.
W. Wang et al., "Malware traffic classification using convolutional neural network for representation learning," in Proc. ICOIN, 2017, pp. 712–717.
R. Xu et al., "Applying self-supervised learning to network intrusion detection for network flows with graph neural network," Comput. Netw., vol. 248, Art. 110495, 2024.
C. Yin, Y. Zhu, J. Fei, and X. He, "A deep learning approach for intrusion detection using recurrent neural networks," IEEE Access, vol. 5, pp. 21954–21961, 2017.
H. Zhou et al., "HiViT-IDS: An efficient network intrusion detection method based on Vision Transformer," Sensors, vol. 25, no. 6, Art. 1752, 2025.