An Adaptive Explainable Hybrid Data Mining Framework for Zero-Day Cyber Threat Detection Using Network Traffic Analysis

Authors

  • Worud Mahdi Saleh General Directorate of Diyala Education, Ministry of Education, Diyala,32001, Iraq

DOI:

https://doi.org/10.71229/z7zrza79

Keywords:

Data Mining, Zero-Day Detection, Network Traffic Analysis, Ensemble Learning, Explainable AI

Abstract

Fast development of network infrastructures brought about increasing amount of network traffic and its diversification resulting in diversified possibilities while disclosing inability of traditional Intrusion Detection Systems (IDS) to cope with modern types of threats like Zero-Day, hi-tech attacks. In this paper there is presented a solution to this problem through the means of dossier mining and Adaptive Explainable Hybrid Data Mining Framework. Instead of traditional static, domain-dependent security models there is proposed to implement a data stream mining, active feature extraction and machine intelligence in explainable way. An unsupervised dossier mining stage is implemented using Isolation Forest algorithm as the first layer of anomaly detection and outliers’ investigation. It is complemented with a second stage of composite directed ensemble consisting of assembling three algorithms (XGBoost, LightGBM, and Random Forest) which constitute strong models for danger classification. In order to mine knowledge about time-dependent behavior patterns an adaptive feature selection approach is implemented by investigating extreme-spatial and clearly evolving network dossiers. Additionally, in order to solve the problem of black-box approach of complex dossier mining models an Explainable AI (XAI) layer was developed with usage of SHAP (Shapley Additive Explanations). Such an approach allows mining feature attributions and restrict them in order to make model interpretable from the viewpoint of humans explaining the rationales for each classification of traffic pattern and thus providing an early warning system for unknown attacks. Proposed solution was tested and compared to the traditional approaches on two benchmark datasets CSE-CIC-IDS2018 and UNSW-NB15. Results of experiments showed the efficiency of the framework achieving very high detection accuracy of 98.7% and F1 score of 98.2% for unknown attacks with significant drop in false positive rate and inference latency suitable for real-time streaming processing. Thus, the research demonstrates that using adaptive model with dossier mining approach, along with effective network signatures and model interpretability, a resistant and flexible protection measure may be implemented.

References

[1] Garcia, C. M., Abilio, R., Koerich, A. L., Britto Jr, A. D. S., & Barddal, J. P. (2025). Concept drift adaptation in text stream mining settings: A systematic review. ACM Transactions on Intelligent Systems and Technology, 16(2), 1-67, doi:org/10.1145/3704922.

[2] Ali, M., Raza, A., Akram, M. A., Arif, H., & Ali, A. (2025). Enhancing IOT Security: A review of Machine Learning-Driven Approaches to Cyber Threat Detection: Enhancing IOT Security: A review of Machine Learning-Driven Approaches to Cyber Threat Detection. Journal of Informatics and Interactive Technology, 2(1), 316-324, doi:org/10.63547/jiite.v2i1.64.

[3] Raja, M. C., & Al Mahri, M. M. B. (2025, October). Behavioral Anomaly Detection in Big Data Streams: An Attention-Enhanced LSTM Approach for Privacy-Aware Zero-Day Attack Detection. In 2025 7th International Conference on Innovative Data Communication Technologies and Application (ICIDCA) (pp. 1017-1030). IEEE, doi: 10.1109/ICIDCA66325.2025.11280566.

[4] Nawaal, B., Haider, U., Khan, I. U., & Fayaz, M. (2024). Signature-based intrusion detection system for IoT. In Cyber security for next-generation computing technologies (pp. 141-158). CRC Press, doi: 10.1201/9781003404361-8.

[5] Heidari, A., & Jabraeil Jamali, M. A. (2023). Internet of Things intrusion detection systems: a comprehensive review and future directions. Cluster Computing, 26(6), 3753-3780, doi:org/10.1007/s10586-022-03776-z.

[6] Mohamed, N. (2025). Artificial intelligence and machine learning in cybersecurity: a deep dive into state-of-the-art techniques and future paradigms. Knowledge and Information Systems, 67(8), 6969-7055, doi:org/10.1007/s10115-025-02429-y.

[7] Lu, H., Ma, Z., Li, X., Bi, S., He, X., & Wang, K. (2024, June). Traffichd: Efficient hyperdimensional computing for real-time network traffic analytics. In Proceedings of the 61st ACM/IEEE Design Automation Conference (pp. 1-6), doi:org/10.1145/3649329.3657330.

[8] Mirsadeghi, S. M. H., Bahsi, H., Vaarandi, R., & Inoubli, W. (2023). Learning from few cyber-attacks: Addressing the class imbalance problem in machine learning-based intrusion detection in software-defined networking. IEEE Access, 11, 140428-140442, doi:10.1109/ACCESS.2023.3341755.

[9] Mu, H., Aljeri, N., & Boukerche, A. (2024). Spatio-temporal feature engineering for deep learning models in traffic flow forecasting. IEEE Access, 12, 76555-76578, doi: 10.1109/ACCESS.2024.3403516.

[10] Tian, S., Wang, X., Zhang, Z., Chen, H., & Zhu, W. (2026). Out-of-distribution generalized graph anomaly detection with homophily-aware environment mixup. Advances in Neural Information Processing Systems, 38, 65681-65705, doi: 10.52202/085713-2203.

[11] Mansur, M. A. (2025). National security and cyber defense in the rise of artificial super intelligence. European Scientific Journal, 21(10), 116, doi:10.19044/esj.2025.v21n10p116.

[12] Arreche, O., Guntur, T. R., Roberts, J. W., & Abdallah, M. (2024). E-XAI: Evaluating black-box explainable AI frameworks for network intrusion detection. IEEE Access, 12, 23954-23988, doi:10.1109/ACCESS.2024.3365140.

[13] Jaigirdar, F. T., Tan, B., Rudolph, C., & Bain, C. (2023). Security-aware provenance for transparency in IoT data propagation. IEEE Access, 11, 55677-55691, doi:10.1109/ACCESS.2023.3280928.

[14] Rahman, M. A., & Haque, B. T. (2025). Adaptive Cybersecurity Threat Intelligence Using Explainable Artificial Intelligence for Resilient Protection of US Critical Information Systems. American Journal of Advanced Technology and Engineering Solutions, 1(02), 216-261, doi:org/10.63125/wbaw3w65.

[15] Khan, F. M., Zeb, A., Rahman, T., Al-Khasawneh, M. A., Daradkeh, Y. I., Siddiqui, I. F., ... & Ullah, I. (2026). XAI-driven Data Mining for Self-defending IoT Systems: Enhancing Cybersecurity Transparency in the Age of Smart Cities. Cognitive Computation, 18(1), 16, doi:org/10.1007/s12559-026-10559-w.

[16] Surianarayanan, C., Kunasekaran, S., & Chelliah, P. R. (2024). A high-throughput architecture for anomaly detection in streaming data using machine learning algorithms. International Journal of Information Technology, 16(1), 493-506, doi:org/10.1007/s41870-023-01585-0.

[17] Yab, L. Y., Wahid, N., & Hamid, R. A. (2022). A meta-analysis survey on the usage of meta-heuristic algorithms for feature selection on high-dimensional datasets. IEEE Access, 10, 122832-122856, 10.1109/ACCESS.2022.3221194, doi:10.1109/ACCESS.2022.3221194.

[18] Tripathy, S. S., Behera, B., Kollie, D. S., Barik, R. C., Priyadarshi, R., & Ranjan, R. (2026). Enhancing anomaly-based zero-day attack detection framework using CNN-driven feature extraction and OC-SVM. Scientific Reports, doi:org/10.1038/s41598-026-55170-z.

[19] Ododo, F. R., & Sadiq, R. R. (2025). A review of outlier detection techniques in cybersecurity: A machine learning perspective. Journal of Science Innovation and Technology Research, doi: 10.70382/ajsitr.v7i9.034.

[20] Abbasi, M., Florez, S. L., Shahraki, A., Taherkordi, A., Prieto, J., & Corchado, J. M. (2025). Class imbalance in network traffic classification: An adaptive weight ensemble-of-ensemble learning method. IEEE Access, doi:10.1109/ACCESS.2025.3538170.

fig 1

Downloads

Published

2026-09-02

Issue

Section

Original Articles

How to Cite

An Adaptive Explainable Hybrid Data Mining Framework for Zero-Day Cyber Threat Detection Using Network Traffic Analysis. (2026). Al-Noor Journal of Engineering Management and Computer Science, 2(4), 104-114. https://doi.org/10.71229/z7zrza79

Similar Articles

11-20 of 85

You may also start an advanced similarity search for this article.