In practical Network Intrusion Detection System(NIDS) deployments, detecting anomalies is only the first step,while determining the exact nature of those anomalies is equallyimportant. Commonly, anomalous traffic is forwarded to asupervised multiclass classifier trained to identify known attackcategories. While effective for known threats, this step presents asignificant limitation, as zero-day attacks can be misclassified asknown attacks. Therefore, there is a need for approaches that gobeyond standard classification and can reliably recognize when aninput does not conform to any learned attack pattern, i.e., zeroday attacks. To tackle this problem, we propose a novel detectionstrategy that leverages per-instance feature importance scoresfrom an explainable Artificial Intelligence (XAI) framework andprediction uncertainty estimates derived from an ensemble classifier. To evaluate our approach, we conduct extensive experimentsusing a leave-one-attack-out strategy across three benchmarkdatasets, CICIoT2023, NF–TON–IoT, and CIC–DDoS2019, andtest performance under two underlying classifiers, namely XGBoost and Random Forest, demonstrating the model-agnosticnature of our method. Experimental results show that ourapproach achieves best-case AUROC gains approaching 40%and F1-score improvements of up to 73%, while maintainingpositive or near-neutral worst-case performance across datasets,highlighting the effectiveness and robustness of jointly modelingexplanation-driven reconstruction error and predictive uncertainty for reliable zero-day threat identification.

Fawaz, H., Talpini, J., Savi, M., Giordano, S., Ayoub, O. (2026). Detecting Zero-Day Attacks via Reconstruction of Feature Influence and Model Uncertainty. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 1-16 [10.1109/tnsm.2026.3731401].

Detecting Zero-Day Attacks via Reconstruction of Feature Influence and Model Uncertainty

Talpini, Jacopo;Savi, Marco;
2026

Abstract

In practical Network Intrusion Detection System(NIDS) deployments, detecting anomalies is only the first step,while determining the exact nature of those anomalies is equallyimportant. Commonly, anomalous traffic is forwarded to asupervised multiclass classifier trained to identify known attackcategories. While effective for known threats, this step presents asignificant limitation, as zero-day attacks can be misclassified asknown attacks. Therefore, there is a need for approaches that gobeyond standard classification and can reliably recognize when aninput does not conform to any learned attack pattern, i.e., zeroday attacks. To tackle this problem, we propose a novel detectionstrategy that leverages per-instance feature importance scoresfrom an explainable Artificial Intelligence (XAI) framework andprediction uncertainty estimates derived from an ensemble classifier. To evaluate our approach, we conduct extensive experimentsusing a leave-one-attack-out strategy across three benchmarkdatasets, CICIoT2023, NF–TON–IoT, and CIC–DDoS2019, andtest performance under two underlying classifiers, namely XGBoost and Random Forest, demonstrating the model-agnosticnature of our method. Experimental results show that ourapproach achieves best-case AUROC gains approaching 40%and F1-score improvements of up to 73%, while maintainingpositive or near-neutral worst-case performance across datasets,highlighting the effectiveness and robustness of jointly modelingexplanation-driven reconstruction error and predictive uncertainty for reliable zero-day threat identification.
Articolo in rivista - Articolo scientifico
Explainable AI; Network Intrusion Detection; Uncertainty Quantification; Zero-day Attacks
English
7-set-2026
2026
1
16
11683510
open
Fawaz, H., Talpini, J., Savi, M., Giordano, S., Ayoub, O. (2026). Detecting Zero-Day Attacks via Reconstruction of Feature Influence and Model Uncertainty. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 1-16 [10.1109/tnsm.2026.3731401].
File in questo prodotto:
File Dimensione Formato  
Fawaz et al-2026-IEEE Transactions on Network and Service Management-AAM.pdf

accesso aperto

Tipologia di allegato: Author’s Accepted Manuscript, AAM (Post-print)
Licenza: Licenza open access specifica dell’editore
Dimensione 4.94 MB
Formato Adobe PDF
4.94 MB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/10281/627306
Citazioni
  • Scopus 0
  • ???jsp.display-item.citation.isi??? ND
Social impact