A Deep Learning Approach to Detect Zero-Day Attacks Within Iot Networks (Published)
IoT networks contend with emerging threats where signature evasion zero-day attacks emerge faster than traditional methods can keep up with, and where traditional IDSes treat known-attack-classification and unknown-attack-detection as two disjoint problems at the expense of doubling memory footprint, latency, and maintenance overhead on resource-limited IoT gateways. In this work we introduce CBLA, a single deep-learning pipeline leveraging a CNN–BiLSTM–Attention encoder pretrained with an autoencoder that simultaneously addresses both tasks with a softmax attack-classification head and attack-reconstruction decoder fed from shared latent encoder activations in a single forward pass. We benchmark CBLA on the 34-class split of the CIC-IoT-2023 dataset which evenly divides its 19 known-attack and 15 zero-day attack classes across four high-level attack families designed to have maximally different structural characteristics (reconnaissance, web injection, malware, MITM). Following an unsupervised autoencoder pretraining stage, CBLA is jointly fine-tuned in a supervised manner, and zero-day alerts are raised based on reconstruction-error using a Youden-J ROC-optimal threshold determined on a held-out validation dataset. CBLA achieves 99.89% classification accuracy, and outperforms all existing single-pipeline solutions with a zero-day AUC-ROC of 0.972 and true-positive rate of 94.22%. We further ablate four model variants of CBLA to determine individual contributions of each architectural choice.
Keywords: CNN-BiLSTM, anomaly detection, autoencoder, cic-IoT-2023, deep learning, internet of things, intrusion detection system, network security, self-attention, zero-day attack detection