An Adaptive Explainable Hybrid Data Mining Framework for Zero-Day Cyber Threat Detection Using Network Traffic Analysis
Unknown authors
Sep 2026· Al-Noor Journal of Engineering Management and Computer Science· 0 citations· 12 references
TL;DR
The research demonstrates that using adaptive model with dossier mining approach, along with effective network signatures and model interpretability, a resistant and flexible protection measure may be implemented.
Abstract
Fast development of network infrastructures brought about increasing amount of network traffic and its diversification resulting in diversified possibilities while disclosing inability of traditional Intrusion Detection Systems (IDS) to cope with modern types of threats like Zero-Day, hi-tech attacks. In this paper there is presented a solution to this problem through the means of dossier mining and Adaptive Explainable Hybrid Data Mining Framework. Instead of traditional static, domain-dependent security models there is proposed to implement a data stream mining, active feature extraction and machine intelligence in explainable way. An unsupervised dossier mining stage is implemented using Isolation Forest algorithm as the first layer of anomaly detection and outliers’ investigation. It is complemented with a second stage of composite directed ensemble consisting of assembling three algorithms (XGBoost, LightGBM, and Random Forest) which constitute strong models for danger classification. In order to mine knowledge about time-dependent behavior patterns an adaptive feature selection approach is implemented by investigating extreme-spatial and clearly evolving network dossiers. Additionally, in order to solve the problem of black-box approach of complex dossier mining models an Explainable AI (XAI) layer was developed with usage of SHAP (Shapley Additive Explanations). Such an approach allows mining feature attributions and restrict them in order to make model interpretable from the viewpoint of humans explaining the rationales for each classification of traffic pattern and thus providing an early warning system for unknown attacks. Proposed solution was tested and compared to the traditional approaches on two benchmark datasets CSE-CIC-IDS2018 and UNSW-NB15. Results of experiments showed the efficiency of the framework achieving very high detection accuracy of 98.7% and F1 score of 98.2% for unknown attacks with significant drop in false positive rate and inference latency suitable for real-time streaming processing. Thus, the research demonstrates that using adaptive model with dossier mining approach, along with effective network signatures and model interpretability, a resistant and flexible protection measure may be implemented.
The method, ECCOLA, is presented, which aims at making the high-level AI ethics principles more practical, making it possible for developers to more easily implement them in practice.
Ville Vakkuri, Kai-Kristian Kemell, P. Abrahamsson· EUROMICRO Conference on Soft...· 64 citations· ⚡6
The goal is to not only refine the accuracy of the LLM-based tool but also to underscore its potential in streamlining the software development lifecycle through proactive code improvement and education.
Z. Rasheed, Malik Abdul Sami, Muhammad Waseem et al.· arXiv.org· 62 citations· ⚡3
The use of large language models to automatically improve the user story quality in Austrian Post Group IT agile teams is explored, with a reference model for an Autonomous LLM-based Agent System developed and implemented at the company.
Zheying Zhang, M. Rayhan, Tomas Herda et al.· International Conference on...· 48 citations· ⚡4
This paper introduces a novel multi-AI-agent system designed to fully automate SLRs, and demonstrates how it substantially reduces the time and effort traditionally required for SLRs while maintaining comprehensiveness and precision.
Abdul Malik Sami, Z. Rasheed, Kai-Kristian Kemell et al.· arXiv.org· 44 citations· ⚡2
The proposed LLM-based multi-agent system automates qualitative data analysis process, creating opportunities for researchers and practitioners, and future improvements focus on enhancing multilingual performance and integrating continuous expert feedback.
Z. Rasheed, Muhammad Waseem, Aakash Ahmad et al.· arXiv.org· 41 citations
AI is making software generation faster, but speed does not remove the need for expertise. As more work is delegated to AI, tacit knowledge may become one of the most important human advantages in software engineering. The post Beyond Prompt Engineering: The Role of Tacit Knowledge in Software Engineering appeared first on GPT-Lab.
MIT News · Artificial Intelligence· news.mit.eduSep 16, 2026
The “HardFlow” algorithm could help generative AI models produce high-quality outputs that obey strict requirements when “pretty close” doesn’t cut it.
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.