Explainable Sequence-Aware Deep Learning Framework for Potential Zero-Day Attack Detection and Cross-Domain Generalization in Enterprise Network Intrusion Detection

Zero-day attacks remain a significant challenge in enterprise network security because their previously unseen characteristics can reduce the effectiveness of conventional signature-based intrusion detection systems. Although machine learning and deep learning have improved intrusion detection, many existing approaches are evaluated within a single dataset and often treat network traffic records as independent observations, providing limited evidence of temporal behavior and cross-domain generalization. This study proposes an Explainable Sequence-Aware Deep Learning Framework for Potential Zero-Day Attack Detection and Cross-Domain Generalization in Enterprise Network Intrusion Detection. The framework represents network traffic as overlapping sequences of 20 consecutive network-flow records and combines a one-dimensional convolutional neural network (1D-CNN), Bidirectional Long Short-Term Memory (Bi-LSTM), and four-head Multi-Head Self-Attention to learn local traffic characteristics, temporal dependencies, and informative relationships within network behavior. A shared representation supports both binary intrusion detection and multiclass attack classification, while SHAP and LIME provide global and local explanations of model decisions. CICIDS2017 serves as the source domain for model development, whereas UNSW-NB15 is maintained as an independent target domain for cross-domain evaluation. A stratified sample of 50,000 records is independently selected from each dataset, with SMOTE applied only to the CICIDS2017 training data. On the CICIDS2017 internal test set, the framework achieved 96.89% accuracy, 97.45% precision, 89.65% recall, 93.38% F1-score, 0.9961 ROC-AUC, and 0.9379 MCC for binary detection, while multiclass classification achieved 97.0% accuracy and 96.8% F1-score. On the independent UNSW-NB15 test set, binary detection achieved 87.70% accuracy and 90.56% F1-score, while multiclass detection achieved 80.35% accuracy and 59.57% F1-score. The findings demonstrate strong in-domain learning and useful cross-domain detection capability without retraining or fine-tuning. The cross-domain results also revealed the difficulty of transferring learned representations across different network environments. In this study, cross-domain evaluation is used to assess potential zero-day detection capability rather than to claim detection of a specifically verified zero-day attack.

Authors

Institutions

Publication Details

Journal
Machine Learning Research
Published
2026-09-30
DOI
https://doi.org/10.11648/j.mlr.20261102.13
Primary Topic
Network Security and Intrusion Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Explainable Sequence-Aware Deep Learning Framework for Potential Zero-Day Attack Detection and Cross-Domain Generalization in Enterprise Network Intrusion Detection

Udoka Felista Eze, Charles Ikerionwu, Adetokunbo MacGregor John-Otumu, Obi Nwokonkwo et al.
Machine Learning Research
Network Security and Intrusion Detection
article

Explainable Sequence-Aware Deep Learning Framework for Potential Zero-Day Attack Detection and Cross-Domain Generalization in Enterprise Network Intrusion Detection

Udoka Felista Eze, Charles Ikerionwu, Adetokunbo MacGregor John-Otumu, Obi Nwokonkwo, Nwankwo Samuel
article en

Abstract

Zero-day attacks remain a significant challenge in enterprise network security because their previously unseen characteristics can reduce the effectiveness of conventional signature-based intrusion detection systems. Although machine learning and deep learning have improved intrusion detection, many existing approaches are evaluated within a single dataset and often treat network traffic records as independent observations, providing limited evidence of temporal behavior and cross-domain generalization. This study proposes an Explainable Sequence-Aware Deep Learning Framework for Potential Zero-Day Attack Detection and Cross-Domain Generalization in Enterprise Network Intrusion Detection. The framework represents network traffic as overlapping sequences of 20 consecutive network-flow records and combines a one-dimensional convolutional neural network (1D-CNN), Bidirectional Long Short-Term Memory (Bi-LSTM), and four-head Multi-Head Self-Attention to learn local traffic characteristics, temporal dependencies, and informative relationships within network behavior. A shared representation supports both binary intrusion detection and multiclass attack classification, while SHAP and LIME provide global and local explanations of model decisions. CICIDS2017 serves as the source domain for model development, whereas UNSW-NB15 is maintained as an independent target domain for cross-domain evaluation. A stratified sample of 50,000 records is independently selected from each dataset, with SMOTE applied only to the CICIDS2017 training data. On the CICIDS2017 internal test set, the framework achieved 96.89% accuracy, 97.45% precision, 89.65% recall, 93.38% F1-score, 0.9961 ROC-AUC, and 0.9379 MCC for binary detection, while multiclass classification achieved 97.0% accuracy and 96.8% F1-score. On the independent UNSW-NB15 test set, binary detection achieved 87.70% accuracy and 90.56% F1-score, while multiclass detection achieved 80.35% accuracy and 59.57% F1-score. The findings demonstrate strong in-domain learning and useful cross-domain detection capability without retraining or fine-tuning. The cross-domain results also revealed the difficulty of transferring learned representations across different network environments. In this study, cross-domain evaluation is used to assess potential zero-day detection capability rather than to claim detection of a specifically verified zero-day attack.

Machine Learning ResearchVol. 11(2)
Federal University of Technology Owerri (NG)
Openalex Percentile: Top 9%
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.