Home / Archives / Vol. 5 No. 2 / Articles
XAI-Guard: An Explainable Self-Supervised Deep Autoencoder Framework for Zero-Day Network Traffic Anomaly Detection
N. Nandhagoapl
Professor, Department of Computer Science and Engineering, Nandha College of Technology, India.
Dharshinipriya. G
Student, Department of Electronics and Communication Engineering, Nandha College of Technology, India.
Keywords:
Intrusion Detection, Explainable Artificial Intelligence, Self-Supervised
Learning, Deep Autoencoder, Zero-Day Attack, Network Traffic Analysis, Cybersecurity
Abstract
The number of cyberattacks has grown tremendously due to the accelerated growth of cloud computing, IoT (Internet of Things) devices, smart infrastructures, and extensive digital communication networks. Ransomware, denial-of-service, botnets, data breaches, and zero-day attacks are increasing threats to modern organizations that may significantly disrupt operations and confidential information. Conventional signature matching-based intrusion detection systems can only detect known threats, whereas machine learning-based intrusion detection systems that are supervised need a large amount of correctly labelled attack data, which is frequently costly to acquire and rapidly obsolete. Secondly, most deep learning-based IDS models are not interpretable, which makes them less likely to be trusted and used in a real-life cybersecurity setup. To deal with these problems, this paper suggests XAI-Guard, an explainable self-supervised deep autoencoder model of zero-day network traffic anomalies. The suggested model is trained with self supervised reconstruction learning to learn normal traffic behavior without the need for labelled attack samples. The analysis of reconstruction error is used to identify suspicious traffic flows, whereas an integrated explainability layer is used to show the most significant traffic features that led to the detection of anomalies. The evaluation of the framework was done based on an evaluation of the UNSW-NB15 benchmark dataset that had a realistic malicious and benign network traffic record. It has been found that the experimental results were high in detection performance with a 96.84% accuracy, 99.76% precision, 56.13% F1 score and 84.27% ROC-AUC. Comparative analysis also revealed that the proposed model, compared to various conventional anomaly detection baselines, performed better. The results prove that XAI-Guard is an effective, scalable, and explainable solution to contemporary intrusion detection systems. The model is especially appropriate in dynamic cybersecurity settings where zero-day attacks are unknown and dynamic and need to be identified with little reliance on labelled training information.
Details
Published
2026-04-27
Pages
1-16
Issue
Vol. 5 No. 2 (2026):
IJRTTE - 05 - 02
Section
Articles