AO-GAE: Aquila Optimizer-Tuned GRU Autoencoder for Robust Time-Series Cyber Anomaly Detection

The increasing sophistication of cyber threats necessitates advanced anomaly detection systems capable of modeling complex temporal patterns in network data. While Gated Recurrent Unit Autoencoders (GRU-AE) have shown promise for time-series anomaly detection, their performance is highly sensitive to hyperparameter selection and threshold calibration, and existing approaches relying on conventional or metaheuristic tuning methods (e.g., PSO, GA, GWO) often perform partial or static optimization. As a way of dealing with these limitations, the present study suggests an Aquila Optimizer (AO)-based GRU Autoencoder framework that implements a task-aware adaptive optimization method. In contrast to earlier methods, the given method puts AO into the training-validation loop and jointly optimizes both architectural, training, and anomaly detection parameters to be able to do search-space-conscious tuning in non-convex high-dimensional conditions. In addition, an anomaly scoring system based on hybrid ensembles is integrated by integrating reconstruction-based error and distribution-based Isolation Forest scores to enhance the separability of anomalies of imbalanced data sets. The experimental test is performed on a time-series network log of a synthetic and realistic network environment that simulates the actual conditions in the traffic, a variety of protocols are used (TCP, UDP, ICMP), and there are various types of applications-layer requests (HTTP, DNS, FTP, SMTP, SSH) and different patterns of traffic. The data set includes normal and malicious events with categorized types of intrusion and a large ratio between the two classes (normals and anomalies), which depicts realistic cybersecurity experience. Also, high-volume traffic in a continuous fashion, overlapping events, and variable payload distributions pose implicit noise and variability, and thus, the dataset proves to be a challenging and representative benchmark. As experiments show, the proposed method performs better than the baseline optimizers and reaches a validation score of 0.8451, precision of 0.78, recall of 0.81, F1-score of 0.79, and ROC-AUC of 0.87 and also finds a smaller architecture (128 hidden units, 2 layers). The framework has an enhanced robustness, less false negative and better generalization across several runs. These findings confirm the fact that the proposed solution is unified, adaptive, and performance-based and that it goes further than the current GRU/AE-based anomaly detection systems and can have a huge potential to be applied to the real-life scenario in terms of cybersecurity.

Authors

Institutions

Publication Details

Journal
International Journal of Computational Intelligence Systems
Published
2026-09-30
DOI
https://doi.org/10.1007/s44196-026-01604-5
Primary Topic
Anomaly Detection Techniques and Applications
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

AO-GAE: Aquila Optimizer-Tuned GRU Autoencoder for Robust Time-Series Cyber Anomaly Detection

Surjeet Dalal, Arshad Hashmi, Sandeep Kumar Sharma, Getachew Abera Dessie et al.
International Journal of Computational Intelligence Systems
Anomaly Detection Techniques and Applications
article

AO-GAE: Aquila Optimizer-Tuned GRU Autoencoder for Robust Time-Series Cyber Anomaly Detection

Surjeet Dalal, Arshad Hashmi, Sandeep Kumar Sharma, Getachew Abera Dessie, Yogesh Kumar Sharma, M. Pradeep, Sultan Mesfer Aldossary, Pallavi Joshi
article en

Abstract

The increasing sophistication of cyber threats necessitates advanced anomaly detection systems capable of modeling complex temporal patterns in network data. While Gated Recurrent Unit Autoencoders (GRU-AE) have shown promise for time-series anomaly detection, their performance is highly sensitive to hyperparameter selection and threshold calibration, and existing approaches relying on conventional or metaheuristic tuning methods (e.g., PSO, GA, GWO) often perform partial or static optimization. As a way of dealing with these limitations, the present study suggests an Aquila Optimizer (AO)-based GRU Autoencoder framework that implements a task-aware adaptive optimization method. In contrast to earlier methods, the given method puts AO into the training-validation loop and jointly optimizes both architectural, training, and anomaly detection parameters to be able to do search-space-conscious tuning in non-convex high-dimensional conditions. In addition, an anomaly scoring system based on hybrid ensembles is integrated by integrating reconstruction-based error and distribution-based Isolation Forest scores to enhance the separability of anomalies of imbalanced data sets. The experimental test is performed on a time-series network log of a synthetic and realistic network environment that simulates the actual conditions in the traffic, a variety of protocols are used (TCP, UDP, ICMP), and there are various types of applications-layer requests (HTTP, DNS, FTP, SMTP, SSH) and different patterns of traffic. The data set includes normal and malicious events with categorized types of intrusion and a large ratio between the two classes (normals and anomalies), which depicts realistic cybersecurity experience. Also, high-volume traffic in a continuous fashion, overlapping events, and variable payload distributions pose implicit noise and variability, and thus, the dataset proves to be a challenging and representative benchmark. As experiments show, the proposed method performs better than the baseline optimizers and reaches a validation score of 0.8451, precision of 0.78, recall of 0.81, F1-score of 0.79, and ROC-AUC of 0.87 and also finds a smaller architecture (128 hidden units, 2 layers). The framework has an enhanced robustness, less false negative and better generalization across several runs. These findings confirm the fact that the proposed solution is unified, adaptive, and performance-based and that it goes further than the current GRU/AE-based anomaly detection systems and can have a huge potential to be applied to the real-life scenario in terms of cybersecurity.

International Journal of Computational Intelligence Systems
Prince Sattam Bin Abdulaziz University (SA), University of the Gambia (GM), King Abdulaziz University (SA), Koneru Lakshmaiah Education Foundation (IN)
Life in Land
Openalex Percentile: Top 9%
Anomaly Detection Techniques and Applications
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.