X-THREAT framework for adaptive and explainable deep learning-based minority-class and zero-day cyber threat detection

Abstract The dynamic nature of cyber threats—particularly minority-class and zero-day attacks—poses significant challenges to existing intrusion detection systems (IDS), which often lack adaptability, interpretability, and robustness. This paper presents X-THREAT, an adaptive and explainable deep learning framework designed to improve detection of rare and previously unseen cyber threats. Unlike prior approaches that treat detection, augmentation, and explainability separately, X-THREAT integrates these components within a unified pipeline. A hybrid VAE–GAN module enhances minority-class representation during training, while a CNN–BiLSTM–attention model performs threat detection, and a context-aware SHAP mechanism provides interpretable insights into model decisions. Experimental results on three benchmark datasets—CICIDS2017, UNSW-NB15, and ToN-IoT—show that X-THREAT consistently outperforms representative deep learning baselines. The model achieves 96.3% accuracy and 95.5% F1-score on CICIDS2017, 94.1% accuracy and 92.5% F1-score on UNSW-NB15, and 93.2% accuracy and 91.5% F1-score on ToN-IoT, along with improved minority-class recall and reduced false positive rates. AUC-ROC values of 0.97, 0.95, and 0.94 further demonstrate strong discriminative capability. Zero-day detection capability is evaluated using a leave-one-attack-class-out protocol, and interpretability is assessed through fidelity analysis and comparison with static SHAP and LIME methods. Results indicate consistent performance across independently evaluated datasets, suggesting potential for generalization. From a deployment perspective, computationally intensive components are restricted to offline training, while inference relies on the detection model with optional explanation. However, latency, resource usage, and edge deployment feasibility were not explicitly benchmarked and remain important directions for future work. Overall, X-THREAT provides a robust and interpretable framework for modern intrusion detection, with improved performance on minority-class and zero-day threat scenarios.

Authors

Institutions

Publication Details

Journal
Scientific Reports
Published
2026-09-15
DOI
https://doi.org/10.1038/s41598-026-63529-5
Primary Topic
Network Security and Intrusion Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

X-THREAT framework for adaptive and explainable deep learning-based minority-class and zero-day cyber threat detection

Rania M. Alhazmi, Mohammed Yahya Alghamdi, Asad Masood Khattak, Mona Alkhozae et al.
Scientific Reports
Network Security and Intrusion Detection
article

X-THREAT framework for adaptive and explainable deep learning-based minority-class and zero-day cyber threat detection

Rania M. Alhazmi, Mohammed Yahya Alghamdi, Asad Masood Khattak, Mona Alkhozae, Sahar Badri, Daniyal Alghazzawi, Muhammad Zubair Asghar, Abeer Almakky, Samina Naz Qaisarani
article en

Abstract

Abstract The dynamic nature of cyber threats—particularly minority-class and zero-day attacks—poses significant challenges to existing intrusion detection systems (IDS), which often lack adaptability, interpretability, and robustness. This paper presents X-THREAT, an adaptive and explainable deep learning framework designed to improve detection of rare and previously unseen cyber threats. Unlike prior approaches that treat detection, augmentation, and explainability separately, X-THREAT integrates these components within a unified pipeline. A hybrid VAE–GAN module enhances minority-class representation during training, while a CNN–BiLSTM–attention model performs threat detection, and a context-aware SHAP mechanism provides interpretable insights into model decisions. Experimental results on three benchmark datasets—CICIDS2017, UNSW-NB15, and ToN-IoT—show that X-THREAT consistently outperforms representative deep learning baselines. The model achieves 96.3% accuracy and 95.5% F1-score on CICIDS2017, 94.1% accuracy and 92.5% F1-score on UNSW-NB15, and 93.2% accuracy and 91.5% F1-score on ToN-IoT, along with improved minority-class recall and reduced false positive rates. AUC-ROC values of 0.97, 0.95, and 0.94 further demonstrate strong discriminative capability. Zero-day detection capability is evaluated using a leave-one-attack-class-out protocol, and interpretability is assessed through fidelity analysis and comparison with static SHAP and LIME methods. Results indicate consistent performance across independently evaluated datasets, suggesting potential for generalization. From a deployment perspective, computationally intensive components are restricted to offline training, while inference relies on the detection model with optional explanation. However, latency, resource usage, and edge deployment feasibility were not explicitly benchmarked and remain important directions for future work. Overall, X-THREAT provides a robust and interpretable framework for modern intrusion detection, with improved performance on minority-class and zero-day threat scenarios.

Scientific ReportsVol. 16(1)
Gomal University (PK), King Abdulaziz University (SA), Al Baha University (SA), Zayed University (AE)
Reduced inequalities
Openalex Percentile: Top 8%
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.