The study demonstrates that integrating deep learning with stable explainable AI offers a practical and trustworthy solution for zero-day intrusion detection, contributing validated evidence to an area where explanation reliability is rarely examined.
Abstract
Zero-day network attacks pose a significant threat because their unknown signatures evade traditional detection mechanisms. This research develops an AI-enhanced intrusion detection system that aims to detect such attacks while providing interpretable outputs for security analysts. Four machine-learning models are evaluated under strict zero-day conditions using two benchmark datasets. SHAP and LIME are applied to produce instance-level explanations, and a formal stability assessment is conducted to determine their reliability. Experimental results show that the hybrid model combining anomaly-based detection with deep learning achieves the highest zero-day Recall, with statistically significant advantages over individual models in detecting previously unseen attacks, while the standalone LSTM achieves the strongest overall balance between Precision and Recall. The generated explanations consistently reveal security-relevant features, and stability analysis confirms their robustness across conditions. The study demonstrates that integrating deep learning with stable explainable AI offers a practical and trustworthy solution for zero-day intrusion detection, contributing validated evidence to an area where explanation reliability is rarely examined.
The findings indicate that embedding explainability directly into the zero-day detection pipeline, rather than treating it as an auxiliary diagnostic layer, materially improves both detection robustness and analyst-facing transparency without incurring prohibitive computational overhead.
Samuel Okechukwu Nnaji, Christabel Linda Uchenwa, Anyalebechi Felicia Nneamaka· International Journal Of Eng...· 0 citations
The speed of cyberattack evolution and the growing sophistication of new attacks have revealed critical limitations of traditional IDS, specifically in terms of adaptability and interpretability. Although modern machine learning models are highly accurate at detection, their black-box nature makes them opaque, reducing...
Alycia Sebastian, S. Priscila, B. M. Praveen· FMDB Transactions on Sustain...· 0 citations
A hybrid multi-layered intrusion detection framework combining traditional machine learning, Deep Neural Architectures (DenseNN), and ensemble methods to evaluate zero-day resilience within cloud-level backend connectivity interfacing EV and V2X management ecosystems is proposed.
H. Sakr, Ahmed A. El-Douh, M. Lapina et al.· Computers· 0 citations
An XAI-based anomaly detection framework tailored for DER networks (ExCYDER) that distinguished between coherent and inconsistent alerts without compromising detection accuracy, demonstrating that integrated verification within XAI-based ADS enhances interpretability, auditability, and operational robustness for DER-fo...
D. Popoola, S. Bhattacharya, M. Govindarasu· IEEE Power & Energy Society...· 1 citation
Related blog posts
MIT News · Artificial Intelligence· news.mit.eduOct 8, 2026
Exploring how generative AI could make machine vision more accessible to businesses. The post GenEye in a Box: Making Machine Vision Something You Can Just Ask For appeared first on GPT-Lab.
MIT News · Artificial Intelligence· news.mit.eduOct 8, 2026
Training AI agents with reinforcement learning can be challenging because their tools, context, and decision-making are managed by complex frameworks. Agent Lightning connects existing agents to RL training, making it easier to improve them without rebuilding them. The post Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses appeared first on Microsoft Research.
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.