Skip to content
Conference

Agentic AI for Autonomous Zero-Day Threat Detection in Zero-Trust Enterprise Security Architectures

Aug 2026 · 2026 International Conference on Secure Information Systems and Technologies (ICSIST) · pp. 336-343 · 0 citations · 16 references

Abstract

Zero-day attacks exploit signature-based defenses since the key pieces of evidence used to identify attacks are not present during the training of the model. This paper proposes an Agentic Autonomous Zero-Trust (AAZT) framework that includes: Multimodal Open-set Detection, Evidence-grounded Multi-agent Investigation, Continuous Trust Evaluation and Policy-constrained Response. Self-supervised temporal and graph representations include network, endpoint, identity, cloud and asset-relationship telemetry. A calibrated novelty layer is based on a supervised attack probability, reconstruction deviation, distributional distance and model uncertainty. When something is observed that is suspicious, unique agents are given the task of recovering the telemetry, forming hypotheses, evaluating them and then devising a response plan. All proposed actions are reviewed via a zero-trust policy gate that considers identity assurance, device posture, asset criticality, confidence, reversibility and operational cost. The controlled leave one family out simulation yields an average F1-score of 80.7%, AUC of 97.7% and 1.72% of false positives. The results show that the consensus of the contextual agent enhances recall of unknown threats and the critic and policy gate decrease unsupported or disruptive actions. The paper introduces an end-to-end designed trustworthy autonomous enterprise defense protocol and testifies it.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.