• e - ISSN No : 2832-4277
IJRTTE Logo

INTERNATIONAL JOURNAL OF RECENT TRENDS IN TECHNOLOGY AND ENGINEERING (IJRTTE)

XAI-Guard: An Explainable Self-Supervised Deep Autoencoder Framework for Zero-Day Network Traffic Anomaly Detection

N. Nandhagoapl
Professor, Department of Computer Science and Engineering, Nandha College of Technology, India.
Dharshinipriya. G
Student, Department of Electronics and Communication Engineering, Nandha College of Technology, India.

Keywords: Intrusion Detection, Explainable Artificial Intelligence, Self-Supervised Learning, Deep Autoencoder, Zero-Day Attack, Network Traffic Analysis, Cybersecurity

Abstract

The number of cyberattacks has grown tremendously due to the accelerated growth of cloud computing, IoT (Internet of Things) devices, smart infrastructures, and extensive digital communication networks. Ransomware, denial-of-service, botnets, data breaches, and zero-day attacks are increasing threats to modern organizations that may significantly disrupt operations and confidential information. Conventional signature matching-based intrusion detection systems can only detect known threats, whereas machine learning-based intrusion detection systems that are supervised need a large amount of correctly labelled attack data, which is frequently costly to acquire and rapidly obsolete. Secondly, most deep learning-based IDS models are not interpretable, which makes them less likely to be trusted and used in a real-life cybersecurity setup. To deal with these problems, this paper suggests XAI-Guard, an explainable self-supervised deep autoencoder model of zero-day network traffic anomalies. The suggested model is trained with self supervised reconstruction learning to learn normal traffic behavior without the need for labelled attack samples. The analysis of reconstruction error is used to identify suspicious traffic flows, whereas an integrated explainability layer is used to show the most significant traffic features that led to the detection of anomalies. The evaluation of the framework was done based on an evaluation of the UNSW-NB15 benchmark dataset that had a realistic malicious and benign network traffic record. It has been found that the experimental results were high in detection performance with a 96.84% accuracy, 99.76% precision, 56.13% F1 score and 84.27% ROC-AUC. Comparative analysis also revealed that the proposed model, compared to various conventional anomaly detection baselines, performed better. The results prove that XAI-Guard is an effective, scalable, and explainable solution to contemporary intrusion detection systems. The model is especially appropriate in dynamic cybersecurity settings where zero-day attacks are unknown and dynamic and need to be identified with little reliance on labelled training information.
Download Certificate
Details

References

  1. Yang, J., Jiang, X., Liang, G., Li, S., & Ma, Z. (2023). Malicious Traffic Identification with Self-Supervised Contrastive Learning. Sensors, 23(16), 7215. https://doi.org/10.3390/s23167215
  2. Lewandowski, B., & Paffenroth, R. (2023). Autoencoder Feature Residuals for Network Intrusion Detection: One-Class Pretraining for Improved Performance. Machine Learning and Knowledge Extraction, 5(3), 868–890. https://doi.org/10.3390/make5030046
  3. Sattar, S., Khan, S., Khan, M. I., Akhmediyarova, A., Mamyrbayev, O., Kassymova, D., Oralbekova, D., & Alimkulova, J. (2025). Anomaly detection in encrypted network traffic using self-supervised learning. Scientific Reports, 15(1), 26585. https://doi.org/10.1038/s41598-025-08568-0
  4. Mozaffari, M., Doshi, K., & Yilmaz, Y. (2023). Self-Supervised Learning for Online Anomaly Detection in High-Dimensional Data Streams. Electronics, 12(9), 1971. https://doi.org/10.3390/electronics12091971
  5. Caville, E., Lo, W. W., Layeghy, S., & Portmann, M. (2022). Anomal-E: A self-supervised network intrusion detection system based on graph neural networks. Knowledge-Based Systems, 258, 110030. https://doi.org/10.1016/j.knosys.2022.110030
  6. Hacılar, H., Dedeturk, B. K., Bakir-Gungor, B., & Gungor, V. C. (2024). Network anomaly detection using Deep Autoencoder and parallel Artificial Bee Colony algorithm-trained neural network. PeerJ Computer Science, 10, e2333. https://doi.org/10.7717/peerj-cs.2333
  7. Liu, L., & Xu, M. (2025). A network intrusion detection method based on contrastive learning and Bayesian Gaussian Mixture Model. Cybersecurity, 8(1), 59. https://doi.org/10.1186/s42400-025-00364-7
  8. Zahoor, A., Abbasi, W., Babar, M. Z., & Aljohani, A. (2025). Robust IoT security using isolation forest and one-class SVM algorithms. Scientific Reports, 15(1), 36586. https://doi.org/10.1038/s41598-025-20445-4
  9. Zhou, P. (2025). A survey of streaming data anomaly detection in network security. PeerJ Computer Science, 11, e3066. https://doi.org/10.7717/peerj-cs.3066
  10. Almuqren, L., Maashi, M. S., Alamgeer, M., Mohsen, H., Hamza, M. A., & Abdelmageed, A. A. (2023). Explainable Artificial Intelligence Enabled Intrusion Detection Technique for Secure Cyber-Physical Systems. Applied Sciences, 13(5), 3081. https://doi.org/10.3390/app13053081
  11. Georgiades, M., & Hussain, F. (2025). An Explainable AI Approach for Interpretable Cross-Layer Intrusion Detection in Internet of Medical Things. Electronics, 14(16), 3218. https://doi.org/10.3390/electronics14163218
  12. Yu, H., Yang, W., Cui, B., Sui, R., & Wu, X. (2024). Renyi entropy-driven network traffic anomaly detection with dynamic threshold. Cybersecurity, 7(1), 64. https://doi.org/10.1186/s42400-024-00249-1
  13. Mahmoud, M. M., Youssef, Y. O., & Abdel-Hamid, A. A. (2025). XI2S-IDS: An Explainable Intelligent 2-Stage Intrusion Detection System. Future Internet, 17(1), 25. https://doi.org/10.3390/fi17010025
  14. Bella, K., Guezzaz, A., Benkirane, S., Azrour, M., Fouad, Y., Benyeogor, M. S., & Innab, N. (2024). An efficient intrusion detection system for IoT security using CNN decision forest. PeerJ Computer Science, 10, e2290. https://doi.org/10.7717/peerj-cs.2290
  15. More, S., Idrissi, M., Mahmoud, H., & Asyhari, A. T. (2024). Enhanced Intrusion Detection Systems Performance with UNSW-NB15 Data Analysis. Algorithms, 17(2), 64. https://doi.org/10.3390/a17020064
  16. Kummerow, A., Abrha, E., Eisenbach, M., & Rösch, D. (2024). Unsupervised Anomaly Detection and Explanation in Network Traffic with Transformers. Electronics, 13(22), 4570. https://doi.org/10.3390/electronics13224570
  17. Alrayes, F. S., Amin, S. U., & Hakami, N. (2025). An Adaptive Framework for Intrusion Detection in IoT Security Using MAML (Model-Agnostic Meta-Learning). Sensors, 25(8), 2487. https://doi.org/10.3390/s25082487
  18. Yu, B., Zhang, Y., Xie, W., Zuo, W., Zhao, Y., & Wei, Y. (2023). A Network Traffic Anomaly Detection Method Based on Gaussian Mixture Model. Electronics, 12(6), 1397. https://doi.org/10.3390/electronics12061397
  19. Wawrowski, Ł., Białas, A., Kajzer, A., Kozłowski, A., Kurianowicz, R., Sikora, M., Szymańska-Kwiecień, A., Uchroński, M., Białczak, M., Olejnik, M., & Michalak, M. (2023). Anomaly Detection Module for Network Traffic Monitoring in Public Institutions. Sensors, 23(6), 2974. https://doi.org/10.3390/s23062974
  20. Salman, E. H., Taher, M. A., Hammadi, Y. I., Mahmood, O. A., Muthanna, A., & Koucheryavy, A. (2022). An Anomaly Intrusion Detection for High-Density Internet of Things Wireless Communication Network Based Deep Learning Algorithms. Sensors, 23(1), 206. https://doi.org/10.3390/s23010206
  21. El-Shafeiy, E., Elsayed, W. M., Elwahsh, H., Alsabaan, M., Ibrahem, M. I., & Elhady, G. F. (2024). Deep Complex Gated Recurrent Networks-Based IoT Network Intrusion Detection Systems. Sensors, 24(18), 5933. https://doi.org/10.3390/s24185933
  22. Zhao, Y., Liu, Z., & Pang, J. (2025). Anomaly Detection in Network Traffic via Cross-Domain Federated Graph Representation Learning. Applied Sciences, 15(11), 6258. https://doi.org/10.3390/app15116258
  23. Wang, Z., Chen, H., Yang, S., Luo, X., Li, D., & Wang, J. (2023). A lightweight intrusion detection method for IoT based on deep learning and dynamic quantization. PeerJ Computer Science, 9, e1569. https://doi.org/10.7717/peerj-cs.1569
  24. Ben Ncir, C. E., Ben HajKacem, M. A., & Alattas, M. (2024). Enhancing intrusion detection performance using explainable ensemble deep learning. PeerJ Computer Science, 10, e2289. https://doi.org/10.7717/peerj-cs.2289
  25. Choi, K., Yi, J., Mok, J., & Yoon, S. (2024). Self-supervised time-series anomaly detection using learnable data augmentation. arXiv:2406.12260. https://doi.org/10.48550/arXiv.2406.12260
  26. Li, E., Shang, Z., Gungor, O., & Rosing, T. (2025). SAFE: Self-supervised anomaly detection framework for intrusion detection. arXiv:2502.07119. https://doi.org/10.48550/arXiv.2502.07119
  27. Khan, N., Ahmad, K., Al Tamimi, A., Alani, M. M., Bermak, A., & Khalil, I. (2025). Explainable AI-Based Intrusion Detection Systems for Industry 5.0 and Adversarial XAI: A Systematic Review. Information, 16(12), 1036. https://doi.org/10.3390/info16121036
  28. Ebrahimi, F., Javidan, R., Akbari, R., et al. (2025). Intrusion detection in the Internet of Things using convolutional neural networks: An explainable AI approach. Cybersecurity, 8, 66. https://doi.org/10.1186/s42400-025-00369-2
  29. Hussein, S. A., & Répás, S. R. (2026). A Hybrid Intrusion Detection Framework Using Deep Autoencoder and Machine Learning Models. AI, 7(2), 39. https://doi.org/10.3390/ai7020039
  30. Sharma, K. P., Nagpal, T., Vora, T., et al. (2025). Interpretable intrusion detection for IoT environments using a self-attention-based explainable AI framework. Scientific Reports, 15, 39937. https://doi.org/10.1038/s41598-025-23750-0