Skip to content
Open access

Explainable and Deployment-Aware Zero-Day Intrusion Detection for Cloud-Level Backend and Management Ecosystems in EV/V2X Cyber–Physical Systems

Sep 2026 · Computers · 0 citations · 23 references

TL;DR

A hybrid multi-layered intrusion detection framework combining traditional machine learning, Deep Neural Architectures (DenseNN), and ensemble methods to evaluate zero-day resilience within cloud-level backend connectivity interfacing EV and V2X management ecosystems is proposed.

Abstract

With the escalating frequency of sophisticated zero-day attacks, overcoming the critical limitations of signature-based Intrusion Detection Systems (IDSs) has become paramount. This study proposes a hybrid multi-layered intrusion detection framework combining traditional machine learning, Deep Neural Architectures (DenseNN), and ensemble methods to evaluate zero-day resilience within cloud-level backend connectivity interfacing EV and V2X management ecosystems. Using the comprehensive CSE-CIC-IDS2018 benchmark as a surrogate environment, a code-executed Leave-One-Attack-Out (LOAO) cross-validation protocol across 13 distinct attack families was implemented to assess unseen-attack-family generalization within the benchmark to unseen threats. Furthermore, Explainable Artificial Intelligence (XAI) auditing, utilizing SHapley Additive exPlanations (SHAP) and Integrated Gradients, was integrated to inspect decision boundaries and resolve feature-attribution failure modes. Critically, the audit identified an artifact-driven data leakage caused by the Timestamp and identifier features, demonstrating that models learned temporal schedules rather than behavioral network signatures. Re-executing all experiments post-leakage removal quantified performance drops across all classifiers (e.g., Gaussian NB dropping by up to 20.88 percentage points in accuracy (at the 60% training ratio; 18.30 points at the 80% ratio)). Under standard binary classification metrics, tree ensembles (Random Forest and Extra Trees) achieved high in-distribution detection (F1 > 0.95) with rapid inference latency (≈0.05–−0.07 ms/sample). However, the rigorous LOAO evaluation revealed a substantial generalization penalty on truly unseen zero-day families (e.g., SQL Injection and Infiltration), where simpler linear models demonstrated broader generalization robustness (mean LOAO F1 = 0.397) compared with complex tree-ensemble models. By rectifying dataset leakage and benchmarking deployment trade-offs (training runtime, throughput, and memory footprint), this study delivers actionable, transparent guidelines for deployment-oriented IDS evaluation in dynamic network infrastructures.

Read PDF

Similar papers

Open access 2026

Explainable Artificial Intelligence-Based Intrusion Detection for Zero-Day Cyber Attacks: A Hybrid Transformer–Long Short-Term Memory Framework with SHapley Additive exPlanations and Local Interpretable Model-Agnostic Explanations Interpretability

The findings indicate that embedding explainability directly into the zero-day detection pipeline, rather than treating it as an auxiliary diagnostic layer, materially improves both detection robustness and analyst-facing transparency without incurring prohibitive computational overhead.

Samuel Okechukwu Nnaji, Christabel Linda Uchenwa, Anyalebechi Felicia Nneamaka · 0 citations
#explainable ai Open access Sep 2026

Evaluating Explainable Hybrid Intrusion Detection Models Under Zero-Day Conditions

The study demonstrates that integrating deep learning with stable explainable AI offers a practical and trustworthy solution for zero-day intrusion detection, contributing validated evidence to an area where explanation reliability is rarely examined.

Sumayyamol Mukkil Muhammed Ismail, M. Ahmed, S. Begum · 0 citations
Sep 2026

SA-IDS: a self-supervised and adaptive intrusion detection system for edge-based IIoT security with label-free drift resilience

SA-IDS is proposed, a self-supervised and adaptive intrusion detection framework designed for resource-constrained IIoT edge devices that leverages contrastive self-supervised learning to learn robust representations of benign telemetry data without requiring labeled attacks.

Mahdi Ajdani, Maziar Asmani · 0 citations
Open access Aug 2026

TAE-IDS: a trust-aware explainable intrusion detection framework using attention-based meta-ensemble learning with blockchain validation

TAE-IDS, a Trust-Aware Explainable Intrusion Detection Framework that integrates attention-based meta-ensemble learning, SHapley Additive exPlanations (SHAP)-driven explainability, and blockchain-inspired tamper-evident validation within a unified cybersecurity architecture, is proposed.

S. Raj, M. Madiajagan · 0 citations
Open access Aug 2026

Intelligent DDOS Attack Detection and Mitigation Using Machine Learning Techniques

An intelligent DDoS detection and mitigation framework that combines classical Machine Learning (ML) classifiers with Deep Learning (DL) architectures to achieve high-fidelity, low-latency attack identification across heterogeneous network topologies is presented.

S. Singh, Alok Kumar · 0 citations
Open access Sep 2026

Intrusion detection in evolving internet of things environments using decentralized data systems

A hybrid IDS framework built on a stacking ensemble of four heterogeneous base classifiers, namely random forest, extreme gradient boosting, light gradient-boosting machine, and a shallow multi-layer perceptron (MLP), coupled with a PyTorch-based neural network meta-classifier, establishing that pairing meta-learning w...

Zobayer Alam, Arnab Bishakh Sarker, Jariatun Islam et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.