DOI: 10.11648/j.mlr.20261102.13 ISSN: 2637-5680
Explainable Sequence-Aware Deep Learning Framework for Potential Zero-Day Attack Detection and Cross-Domain Generalization in Enterprise Network Intrusion Detection
Uchechukwu Nwankwo, Obi Nwokonkwo, Charles Ikerionwu, Udoka Eze, Adetokunbo John-Otumu Zero-day attacks remain a significant challenge in enterprise network security because their previously unseen characteristics can reduce the effectiveness of conventional signature-based intrusion detection systems. Although machine learning and deep learning have improved intrusion detection, many existing approaches are evaluated within a single dataset and often treat network traffic records as independent observations, providing limited evidence of temporal behavior and cross-domain generalization. This study proposes an Explainable Sequence-Aware Deep Learning Framework for Potential Zero-Day Attack Detection and Cross-Domain Generalization in Enterprise Network Intrusion Detection. The framework represents network traffic as overlapping sequences of 20 consecutive network-flow records and combines a one-dimensional convolutional neural network (1D-CNN), Bidirectional Long Short-Term Memory (Bi-LSTM), and four-head Multi-Head Self-Attention to learn local traffic characteristics, temporal dependencies, and informative relationships within network behavior. A shared representation supports both binary intrusion detection and multiclass attack classification, while SHAP and LIME provide global and local explanations of model decisions. CICIDS2017 serves as the source domain for model development, whereas UNSW-NB15 is maintained as an independent target domain for cross-domain evaluation. A stratified sample of 50,000 records is independently selected from each dataset, with SMOTE applied only to the CICIDS2017 training data. On the CICIDS2017 internal test set, the framework achieved 96.89% accuracy, 97.45% precision, 89.65% recall, 93.38% F1-score, 0.9961 ROC-AUC, and 0.9379 MCC for binary detection, while multiclass classification achieved 97.0% accuracy and 96.8% F1-score. On the independent UNSW-NB15 test set, binary detection achieved 87.70% accuracy and 90.56% F1-score, while multiclass detection achieved 80.35% accuracy and 59.57% F1-score. The findings demonstrate strong in-domain learning and useful cross-domain detection capability without retraining or fine-tuning. The cross-domain results also revealed the difficulty of transferring learned representations across different network environments. In this study, cross-domain evaluation is used to assess potential zero-day detection capability rather than to claim detection of a specifically verified zero-day attack.
More from our Archive
-
DOI: 10.68381/jca02008 2026
Proximal Smoothness and the Lower-C
2
Property F. H. Clarke, R. J. Stern, P. R. Wolenski
-
DOI: 10.68381/jca13044 2026
Characterizations of Prox-Regular Sets in Uniformly Convex Banach Spaces Frédéric Bernard, Lionel Thibault, Nadia Zlateva
-
DOI: 10.68381/jca15047 2026
Brøndsted-Rockafellar Property and Maximality of Monotone Operators Representable by Convex Functions in Non-Reflexive Banach Spaces Maicon Marques Alves, Benar Fux Svaiter
-
DOI: 10.68381/jca16027 2026
Proximal Smoothness and the Exterior Sphere Condition Chadi Nour, Ron J. Stern, Jean Takche
-
DOI: 10.68381/jca16053 2026
A New Old Class of Maximal Monotone Operators Maicon Marques Alves, Benar Fux Svaiter
-
DOI: 10.68381/jca13045 2026
Maximal Monotonicity via Convex Analysis Jonathan Borwein
-
DOI: 10.68381/jca08009 2026
Variational Inequalities and Regularity Properties of Closed Sets in Hilbert Spaces Giovanni Colombo, Vladimir V. Goncharov
-
DOI: 10.68381/jca17060 2026
Existence and Uniqueness of Solutions for Non-Autonomous Complementarity Dynamical Systems Bernard Brogliato, Lionel Thibault
-
DOI: 10.68381/jca01001 2026
Variational Sum of Monotone Operators H. Attouch, J.-B. Baillon, M. Théra
-
DOI: 10.68381/jca22017 2026
Weak Convexity of Sets and Functions in a Banach Space Grigorii E. Ivanov