A hybrid multi-layered intrusion detection framework combining traditional machine learning, Deep Neural Architectures (DenseNN), and ensemble methods to evaluate zero-day resilience within cloud-level backend connectivity interfacing EV and V2X management ecosystems is proposed.
Abstract
With the escalating frequency of sophisticated zero-day attacks, overcoming the critical limitations of signature-based Intrusion Detection Systems (IDSs) has become paramount. This study proposes a hybrid multi-layered intrusion detection framework combining traditional machine learning, Deep Neural Architectures (DenseNN), and ensemble methods to evaluate zero-day resilience within cloud-level backend connectivity interfacing EV and V2X management ecosystems. Using the comprehensive CSE-CIC-IDS2018 benchmark as a surrogate environment, a code-executed Leave-One-Attack-Out (LOAO) cross-validation protocol across 13 distinct attack families was implemented to assess unseen-attack-family generalization within the benchmark to unseen threats. Furthermore, Explainable Artificial Intelligence (XAI) auditing, utilizing SHapley Additive exPlanations (SHAP) and Integrated Gradients, was integrated to inspect decision boundaries and resolve feature-attribution failure modes. Critically, the audit identified an artifact-driven data leakage caused by the Timestamp and identifier features, demonstrating that models learned temporal schedules rather than behavioral network signatures. Re-executing all experiments post-leakage removal quantified performance drops across all classifiers (e.g., Gaussian NB dropping by up to 20.88 percentage points in accuracy (at the 60% training ratio; 18.30 points at the 80% ratio)). Under standard binary classification metrics, tree ensembles (Random Forest and Extra Trees) achieved high in-distribution detection (F1 > 0.95) with rapid inference latency (≈0.05–−0.07 ms/sample). However, the rigorous LOAO evaluation revealed a substantial generalization penalty on truly unseen zero-day families (e.g., SQL Injection and Infiltration), where simpler linear models demonstrated broader generalization robustness (mean LOAO F1 = 0.397) compared with complex tree-ensemble models. By rectifying dataset leakage and benchmarking deployment trade-offs (training runtime, throughput, and memory footprint), this study delivers actionable, transparent guidelines for deployment-oriented IDS evaluation in dynamic network infrastructures.
The findings indicate that embedding explainability directly into the zero-day detection pipeline, rather than treating it as an auxiliary diagnostic layer, materially improves both detection robustness and analyst-facing transparency without incurring prohibitive computational overhead.
Samuel Okechukwu Nnaji, Christabel Linda Uchenwa, Anyalebechi Felicia Nneamaka· International Journal Of Eng...· 0 citations
The study demonstrates that integrating deep learning with stable explainable AI offers a practical and trustworthy solution for zero-day intrusion detection, contributing validated evidence to an area where explanation reliability is rarely examined.
Sumayyamol Mukkil Muhammed Ismail, M. Ahmed, S. Begum· Applied Informatics· 0 citations
SA-IDS is proposed, a self-supervised and adaptive intrusion detection framework designed for resource-constrained IIoT edge devices that leverages contrastive self-supervised learning to learn robust representations of benign telemetry data without requiring labeled attacks.
TAE-IDS, a Trust-Aware Explainable Intrusion Detection Framework that integrates attention-based meta-ensemble learning, SHapley Additive exPlanations (SHAP)-driven explainability, and blockchain-inspired tamper-evident validation within a unified cybersecurity architecture, is proposed.
S. Raj, M. Madiajagan· Frontiers in Artificial Inte...· 0 citations
An intelligent DDoS detection and mitigation framework that combines classical Machine Learning (ML) classifiers with Deep Learning (DL) architectures to achieve high-fidelity, low-latency attack identification across heterogeneous network topologies is presented.
S. Singh, Alok Kumar· International Journal of Com...· 0 citations
A hybrid IDS framework built on a stacking ensemble of four heterogeneous base classifiers, namely random forest, extreme gradient boosting, light gradient-boosting machine, and a shallow multi-layer perceptron (MLP), coupled with a PyTorch-based neural network meta-classifier, establishing that pairing meta-learning w...
Zobayer Alam, Arnab Bishakh Sarker, Jariatun Islam et al.· International Journal of Adv...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.