AO-GAE: Aquila Optimizer-Tuned GRU Autoencoder for Robust Time-Series Cyber Anomaly Detection
The increasing sophistication of cyber threats necessitates advanced anomaly detection systems capable of modeling complex temporal patterns in network data. While Gated Recurrent Unit Autoencoders (GRU-AE) have shown promise for time-series anomaly detection, their performance is highly sensitive to hyperparameter selection and threshold calibration, and existing approaches relying on conventional or metaheuristic tuning methods (e.g., PSO, GA, GWO) often perform partial or static optimization. As a way of dealing with these limitations, the present study suggests an Aquila Optimizer (AO)-based GRU Autoencoder framework that implements a task-aware adaptive optimization method. In contrast to earlier methods, the given method puts AO into the training-validation loop and jointly optimizes both architectural, training, and anomaly detection parameters to be able to do search-space-conscious tuning in non-convex high-dimensional conditions. In addition, an anomaly scoring system based on hybrid ensembles is integrated by integrating reconstruction-based error and distribution-based Isolation Forest scores to enhance the separability of anomalies of imbalanced data sets. The experimental test is performed on a time-series network log of a synthetic and realistic network environment that simulates the actual conditions in the traffic, a variety of protocols are used (TCP, UDP, ICMP), and there are various types of applications-layer requests (HTTP, DNS, FTP, SMTP, SSH) and different patterns of traffic. The data set includes normal and malicious events with categorized types of intrusion and a large ratio between the two classes (normals and anomalies), which depicts realistic cybersecurity experience. Also, high-volume traffic in a continuous fashion, overlapping events, and variable payload distributions pose implicit noise and variability, and thus, the dataset proves to be a challenging and representative benchmark. As experiments show, the proposed method performs better than the baseline optimizers and reaches a validation score of 0.8451, precision of 0.78, recall of 0.81, F1-score of 0.79, and ROC-AUC of 0.87 and also finds a smaller architecture (128 hidden units, 2 layers). The framework has an enhanced robustness, less false negative and better generalization across several runs. These findings confirm the fact that the proposed solution is unified, adaptive, and performance-based and that it goes further than the current GRU/AE-based anomaly detection systems and can have a huge potential to be applied to the real-life scenario in terms of cybersecurity.
Authors
- Surjeet Dalal
- Arshad Hashmi
- Sandeep Kumar Sharma
- Getachew Abera Dessie (ORCID: https://orcid.org/0009-0003-3438-3580)
- Yogesh Kumar Sharma
- M. Pradeep
- Sultan Mesfer Aldossary
- Pallavi Joshi
Institutions
- Prince Sattam Bin Abdulaziz University (SA)
- University of the Gambia (GM)
- King Abdulaziz University (SA)
- Koneru Lakshmaiah Education Foundation (IN)
Publication Details
- Journal
- International Journal of Computational Intelligence Systems
- Published
- 2026-09-30
- DOI
- https://doi.org/10.1007/s44196-026-01604-5
- Primary Topic
- Anomaly Detection Techniques and Applications
- Type
- article
- Field-Weighted Citation Impact
- 0.00