ZD-HybridNet integrates transformer and LSTM models for explainable zero day cyber attack detection
The exponential growth of interconnected systems has dramatically expanded the attack surface of modern networks, making zero-day attacks, which exploit previously unknown vulnerabilities, a critical threat to organizational security. Traditional signature-based and anomaly detection systems often struggle to identify such previously unseen attack patterns, and while deep learning (DL) offers promising detection capabilities, existing DL-based intrusion detection systems (IDS) suffer from poor generalization to novel attacks and operate as opaque black boxes, lacking interpretability for security analysts. To address these limitations, this paper proposes ZD-HybridNet (Zero-Day Hybrid Attention Network), a novel explainable deep learning framework for large-scale network traffic analysis. ZD-HybridNet integrates a Transformer encoder branch for capturing global feature dependencies and an LSTM branch for modeling sequential traffic patterns, dynamically fused via an adaptive attention-based gating mechanism. This architecture is coupled with an integrated explainability framework that combines model-internal attention and fusion signals with SHAP-based feature attribution to support interpretation of detection decisions. Evaluated on the UNSW-NB15 dataset under a controlled category-holdout protocol in which Shellcode and Worms are entirely excluded from training and validation, ZD-HybridNet achieves an accuracy of 94.04%, a precision of 96.76%, a recall of 93.96%, and an F1-score of 95.34%, outperforming standalone LSTM, Transformer, FT-Transformer, and 1D CNN baselines under the same experimental protocol. Precision-recall, ROC, zero-day-specific, ablation, and SHAP-based analyses further support the model’s detection performance and interpretability within the defined Shellcode–Worms holdout setting, while deployment-oriented computational validation remains necessary.
Authors
- Rakibul Islam (ORCID: https://orcid.org/0000-0002-6877-8703)
- Sakib Salam Jamee
- Khadeza Yesmin Lucky (ORCID: https://orcid.org/0009-0002-6186-485X)
- Furqaan Mujtahid (ORCID: https://orcid.org/0009-0008-7065-9691)
- Alfaiz Madhiya
- Mohiuddin Mehedi (ORCID: https://orcid.org/0009-0007-4228-6253)
- S. M. Rezvi
- Vijay Solanki
Institutions
- University of Pittsburgh (US)
- Campbellsville University (US)
Publication Details
- Journal
- Discover Artificial Intelligence
- Published
- 2026-10-05
- DOI
- https://doi.org/10.1007/s44163-026-02258-0
- Primary Topic
- Network Security and Intrusion Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00