X-THREAT framework for adaptive and explainable deep learning-based minority-class and zero-day cyber threat detection
Abstract The dynamic nature of cyber threats—particularly minority-class and zero-day attacks—poses significant challenges to existing intrusion detection systems (IDS), which often lack adaptability, interpretability, and robustness. This paper presents X-THREAT, an adaptive and explainable deep learning framework designed to improve detection of rare and previously unseen cyber threats. Unlike prior approaches that treat detection, augmentation, and explainability separately, X-THREAT integrates these components within a unified pipeline. A hybrid VAE–GAN module enhances minority-class representation during training, while a CNN–BiLSTM–attention model performs threat detection, and a context-aware SHAP mechanism provides interpretable insights into model decisions. Experimental results on three benchmark datasets—CICIDS2017, UNSW-NB15, and ToN-IoT—show that X-THREAT consistently outperforms representative deep learning baselines. The model achieves 96.3% accuracy and 95.5% F1-score on CICIDS2017, 94.1% accuracy and 92.5% F1-score on UNSW-NB15, and 93.2% accuracy and 91.5% F1-score on ToN-IoT, along with improved minority-class recall and reduced false positive rates. AUC-ROC values of 0.97, 0.95, and 0.94 further demonstrate strong discriminative capability. Zero-day detection capability is evaluated using a leave-one-attack-class-out protocol, and interpretability is assessed through fidelity analysis and comparison with static SHAP and LIME methods. Results indicate consistent performance across independently evaluated datasets, suggesting potential for generalization. From a deployment perspective, computationally intensive components are restricted to offline training, while inference relies on the detection model with optional explanation. However, latency, resource usage, and edge deployment feasibility were not explicitly benchmarked and remain important directions for future work. Overall, X-THREAT provides a robust and interpretable framework for modern intrusion detection, with improved performance on minority-class and zero-day threat scenarios.
Authors
- Rania M. Alhazmi
- Mohammed Yahya Alghamdi
- Asad Masood Khattak (ORCID: https://orcid.org/0000-0002-0630-1264)
- Mona Alkhozae (ORCID: https://orcid.org/0000-0001-5600-3559)
- Sahar Badri (ORCID: https://orcid.org/0000-0003-3018-048X)
- Daniyal Alghazzawi (ORCID: https://orcid.org/0000-0002-5533-3203)
- Muhammad Zubair Asghar (ORCID: https://orcid.org/0000-0003-3320-2074)
- Abeer Almakky (ORCID: https://orcid.org/0000-0002-2498-9365)
- Samina Naz Qaisarani
Institutions
- Gomal University (PK)
- King Abdulaziz University (SA)
- Al Baha University (SA)
- Zayed University (AE)
Publication Details
- Journal
- Scientific Reports
- Published
- 2026-09-15
- DOI
- https://doi.org/10.1038/s41598-026-63529-5
- Primary Topic
- Network Security and Intrusion Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00