ZD-HybridNet integrates transformer and LSTM models for explainable zero day cyber attack detection

The exponential growth of interconnected systems has dramatically expanded the attack surface of modern networks, making zero-day attacks, which exploit previously unknown vulnerabilities, a critical threat to organizational security. Traditional signature-based and anomaly detection systems often struggle to identify such previously unseen attack patterns, and while deep learning (DL) offers promising detection capabilities, existing DL-based intrusion detection systems (IDS) suffer from poor generalization to novel attacks and operate as opaque black boxes, lacking interpretability for security analysts. To address these limitations, this paper proposes ZD-HybridNet (Zero-Day Hybrid Attention Network), a novel explainable deep learning framework for large-scale network traffic analysis. ZD-HybridNet integrates a Transformer encoder branch for capturing global feature dependencies and an LSTM branch for modeling sequential traffic patterns, dynamically fused via an adaptive attention-based gating mechanism. This architecture is coupled with an integrated explainability framework that combines model-internal attention and fusion signals with SHAP-based feature attribution to support interpretation of detection decisions. Evaluated on the UNSW-NB15 dataset under a controlled category-holdout protocol in which Shellcode and Worms are entirely excluded from training and validation, ZD-HybridNet achieves an accuracy of 94.04%, a precision of 96.76%, a recall of 93.96%, and an F1-score of 95.34%, outperforming standalone LSTM, Transformer, FT-Transformer, and 1D CNN baselines under the same experimental protocol. Precision-recall, ROC, zero-day-specific, ablation, and SHAP-based analyses further support the model’s detection performance and interpretability within the defined Shellcode–Worms holdout setting, while deployment-oriented computational validation remains necessary.

Authors

Institutions

Publication Details

Journal
Discover Artificial Intelligence
Published
2026-10-05
DOI
https://doi.org/10.1007/s44163-026-02258-0
Primary Topic
Network Security and Intrusion Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

ZD-HybridNet integrates transformer and LSTM models for explainable zero day cyber attack detection

Rakibul Islam, Sakib Salam Jamee, Khadeza Yesmin Lucky, Furqaan Mujtahid et al.
Discover Artificial Intelligence
Network Security and Intrusion Detection
article

ZD-HybridNet integrates transformer and LSTM models for explainable zero day cyber attack detection

Rakibul Islam, Sakib Salam Jamee, Khadeza Yesmin Lucky, Furqaan Mujtahid, Alfaiz Madhiya, Mohiuddin Mehedi, S. M. Rezvi, Vijay Solanki
article en

Abstract

The exponential growth of interconnected systems has dramatically expanded the attack surface of modern networks, making zero-day attacks, which exploit previously unknown vulnerabilities, a critical threat to organizational security. Traditional signature-based and anomaly detection systems often struggle to identify such previously unseen attack patterns, and while deep learning (DL) offers promising detection capabilities, existing DL-based intrusion detection systems (IDS) suffer from poor generalization to novel attacks and operate as opaque black boxes, lacking interpretability for security analysts. To address these limitations, this paper proposes ZD-HybridNet (Zero-Day Hybrid Attention Network), a novel explainable deep learning framework for large-scale network traffic analysis. ZD-HybridNet integrates a Transformer encoder branch for capturing global feature dependencies and an LSTM branch for modeling sequential traffic patterns, dynamically fused via an adaptive attention-based gating mechanism. This architecture is coupled with an integrated explainability framework that combines model-internal attention and fusion signals with SHAP-based feature attribution to support interpretation of detection decisions. Evaluated on the UNSW-NB15 dataset under a controlled category-holdout protocol in which Shellcode and Worms are entirely excluded from training and validation, ZD-HybridNet achieves an accuracy of 94.04%, a precision of 96.76%, a recall of 93.96%, and an F1-score of 95.34%, outperforming standalone LSTM, Transformer, FT-Transformer, and 1D CNN baselines under the same experimental protocol. Precision-recall, ROC, zero-day-specific, ablation, and SHAP-based analyses further support the model’s detection performance and interpretability within the defined Shellcode–Worms holdout setting, while deployment-oriented computational validation remains necessary.

Discover Artificial IntelligenceVol. 6(1)
University of Pittsburgh (US), Campbellsville University (US)
Openalex Percentile: Top 9%
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.