In practical Network Intrusion Detection System(NIDS) deployments, detecting anomalies is only the first step,while determining the exact nature of those anomalies is equallyimportant. Commonly, anomalous traffic is forwarded to asupervised multiclass classifier trained to identify known attackcategories. While effective for known threats, this step presents asignificant limitation, as zero-day attacks can be misclassified asknown attacks. Therefore, there is a need for approaches that gobeyond standard classification and can reliably recognize when aninput does not conform to any learned attack pattern, i.e., zeroday attacks. To tackle this problem, we propose a novel detectionstrategy that leverages per-instance feature importance scoresfrom an explainable Artificial Intelligence (XAI) framework andprediction uncertainty estimates derived from an ensemble classifier. To evaluate our approach, we conduct extensive experimentsusing a leave-one-attack-out strategy across three benchmarkdatasets, CICIoT2023, NF–TON–IoT, and CIC–DDoS2019, andtest performance under two underlying classifiers, namely XGBoost and Random Forest, demonstrating the model-agnosticnature of our method. Experimental results show that ourapproach achieves best-case AUROC gains approaching 40%and F1-score improvements of up to 73%, while maintainingpositive or near-neutral worst-case performance across datasets,highlighting the effectiveness and robustness of jointly modelingexplanation-driven reconstruction error and predictive uncertainty for reliable zero-day threat identification.
Fawaz, H., Talpini, J., Savi, M., Giordano, S., Ayoub, O. (2026). Detecting Zero-Day Attacks via Reconstruction of Feature Influence and Model Uncertainty. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 1-16 [10.1109/tnsm.2026.3731401].
Detecting Zero-Day Attacks via Reconstruction of Feature Influence and Model Uncertainty
Talpini, Jacopo;Savi, Marco;
2026
Abstract
In practical Network Intrusion Detection System(NIDS) deployments, detecting anomalies is only the first step,while determining the exact nature of those anomalies is equallyimportant. Commonly, anomalous traffic is forwarded to asupervised multiclass classifier trained to identify known attackcategories. While effective for known threats, this step presents asignificant limitation, as zero-day attacks can be misclassified asknown attacks. Therefore, there is a need for approaches that gobeyond standard classification and can reliably recognize when aninput does not conform to any learned attack pattern, i.e., zeroday attacks. To tackle this problem, we propose a novel detectionstrategy that leverages per-instance feature importance scoresfrom an explainable Artificial Intelligence (XAI) framework andprediction uncertainty estimates derived from an ensemble classifier. To evaluate our approach, we conduct extensive experimentsusing a leave-one-attack-out strategy across three benchmarkdatasets, CICIoT2023, NF–TON–IoT, and CIC–DDoS2019, andtest performance under two underlying classifiers, namely XGBoost and Random Forest, demonstrating the model-agnosticnature of our method. Experimental results show that ourapproach achieves best-case AUROC gains approaching 40%and F1-score improvements of up to 73%, while maintainingpositive or near-neutral worst-case performance across datasets,highlighting the effectiveness and robustness of jointly modelingexplanation-driven reconstruction error and predictive uncertainty for reliable zero-day threat identification.| File | Dimensione | Formato | |
|---|---|---|---|
|
Fawaz et al-2026-IEEE Transactions on Network and Service Management-AAM.pdf
accesso aperto
Tipologia di allegato:
Author’s Accepted Manuscript, AAM (Post-print)
Licenza:
Licenza open access specifica dell’editore
Dimensione
4.94 MB
Formato
Adobe PDF
|
4.94 MB | Adobe PDF | Visualizza/Apri |
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.


