Epistemic-Gated Transformer for Zero-Day Intrusion Mining in Network Traffic

Authors

  • sonal sharma lnct

Keywords:

Network Intrusion Detection System (NIDS), Zero-Day Attack Detection, Epistemic Uncertainty, Transformer Architecture, Contrastive Learning, Cyber security

Abstract

This paper proposes the Epistemic-Gated Transformer (EGT), a novel transformer-based data mining framework designed as the computational core of a Network-based Intrusion Detection System (NIDS) for effective zero-day attack detection. Conventional intrusion detection systems primarily rely on signature-based techniques or static machine learning classifiers, which exhibit limited capability in recognizing previously unseen attack patterns and adapting to rapidly evolving cyber threats. To overcome these limitations, the proposed EGT incorporates an epistemic uncertainty-guided multi-head self-attention mechanism that dynamically prioritizes uncertain network traffic during inference. The model employs a dual-output prediction head to simultaneously estimate class logits and Dirichlet concentration parameters from network flow tokens extracted through sliding windows. The differential entropy of the Dirichlet distribution provides a principled measure of epistemic uncertainty, which is transformed using a softplus-normalized gating function to modulate attention weights. This mechanism enables the model to emphasize suspicious or anomalous traffic while suppressing attention to well-characterized benign flows. Furthermore, EGT integrates a prototype-based contrastive mining module that maintains learnable anomaly prototypes within the latent feature space. A contrastive learning objective clusters high-uncertainty samples around their nearest prototypes, facilitating the discovery of previously unseen attack signatures and improving feature discrimination. The overall optimization objective combines cross-entropy classification loss, contrastive representation learning, and an uncertainty calibration regularizer to enhance robustness against out-of-distribution samples. During deployment, anomaly prototypes are continuously updated using an exponential moving average strategy, enabling online adaptation to evolving attack behaviors. Experimental evaluation demonstrates that the proposed framework achieves superior detection accuracy, robustness, scalability, and generalization, making it an effective solution for next-generation intelligent network intrusion detection.

References

[1] A. Patel, Q. Qassim, and C. Wills, “A survey of intrusion detection and prevention systems,” Information Management & Computer Security, 2010.

[2] W. Lee, S. Stolfo, P. Chan, E. Eskin, et al., “Real time data mining-based intrusion detection,” in DARPA information survivability conference and exposition II, 2001.

[3] A. Vaswani, N. Shazeer, N. Parmar, et al., “Attention is all you need,” in Advances in neural information processing systems, 2017.

[4] W. Bao, Q. Yu, and Y. Kong, “Evidential deep learning for open set action recognition,” in 2021 IEEE/CVF international conference on computer vision (ICCV), 2021.

[5] Y. Gal, J. Hron, and A. Kendall, “Concrete dropout,” in Advances in neural information processing systems, 2017.

[6] P. Covington, J. Adams, and E. Sargin, “Deep neural networks for YouTube recommendations,” in Proceedings of the 10th ACM conference on recommender systems, 2016, pp. 191–198.

[7] T. Su, H. Sun, J. Zhu, S. Wang, and Y. Li, “BAT: Deep learning methods on network intrusion detection using NSL-KDD dataset,” IEEe Access, 2020.

[8] J. Li, Y. Wang, A. Zhao, H. Yan, Z. Gu, et al., “A four-stage bayesian incremental learning framework for intrusion detection in real-world IoT environment,” IEEE Internet of Things Journal, 2026.

[9] A. Ridoy and A. Biswas, “Adaptive intrusion detection systems: Leveraging meta-learning for improved cybersecurity,” IEEE Transactions on Network and Service Management, 2026.

[10] M. Chan, M. Molina, et al., “Estimating epistemic and aleatoric uncertainty with a single model,” in Advances in neural information processing systems 37, 2024.

[11] K. Wang, F. Cuzzolin, S. Manchingal, et al., “Credal deep ensembles for uncertainty quantification,” in Advances in neural information processing systems 37, 2024.

[12] J. Li, C. Wang, W. Su, D. Ye, and Z. Wang, “Uncertainty-aware self-attention model for time series prediction with missing values,” Fractal and Fractional, 2025.

[13] W. Luo, P. Xing, Y. Cao, H. Yao, et al., “Ura-net: Uncertainty-integrated anomaly perception and restoration attention network for unsupervised anomaly detection,” IEEE Transactions on Circuits and Systems for Video Technology, 2025.

[14] P. Velickovic, W. Fedus, W. Hamilton, P. Liò, Y. Bengio, et al., “Deep graph infomax,” stat, 2018.

[15] C. Gallicchio and S. Scardapane, “Deep randomized neural networks,” in International neural network society big data and deep learning conference, 2020.

[16] R. Panigrahi and S. Borah, “A detailed analysis of CICIDS2017 dataset for designing intrusion detection systems,” International Journal of Engineering and Advanced Technology, 2018.

[17] N. Moustafa and J. Slay, “UNSW-NB15: A comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set),” 2015 Military Communications and Information Systems Conference (MilCIS), 2015.

[18] K. Fawagreh, M. Gaber, and E. Elyan, “Random forests: From early developments to recent advancements,” Systems Science & Control Engineering, 2014.

[19] H. Altunay and Z. Albayrak, “A hybrid CNN+ LSTM-based intrusion detection system for industrial IoT networks,” Engineering Science and Technology, an International Journal, 2023.

[20] L. Ruff, R. Vandermeulen, N. Goernitz, et al., “Deep one-class classification,” in International conference on machine learning, 2018.

[21] A. Niculescu-Mizil and R. Caruana, “Predicting good probabilities with supervised learning,” in Proceedings of the 22nd international conference on machine learning - ICML ’05, 2005.

[22] D. Hutchins, I. Schlag, Y. Wu, E. Dyer, et al., “Block-recurrent transformers,” in Advances in neural information processing systems 35, 2022.

[23] C. Barker, D. Bethell, and S. Gerasimou, “Robust adversarial quantification via conflict-aware evidential deep learning,” in International conference on learning representations, 2026.

[24] P. Dong, Y. Xiao, C. Pun, F. Peng, et al., “Harnessing transferable adversarial examples via multi-layer attention-guided spatial transformations,” IEEE Transactions on Reliability, 2026.

[25] R. Qi, G. Liu, J. Zhang, and J. Hsiao, “Rethinking explainable AI: The gap between saliency-based explanation and user understanding for object detection models,” International Journal of Human-Computer Studies, 2026.

[26] P. Biecek, “DALEX: Explainers for complex predictive models in r,” Journal of Machine Learning Research, 2018.

[27] M. K. Bagwani, V. K. Tiwari, A. Gangwar, and K. Vishwakarma, "Real-time signature-based detection and prevention of DDOS attacks in cloud environments," International Journal of Science and Research Archive, vol. 12, no. 2, pp. 2929-2935, 2024.

[28] M. Bagwani, "Deploying a web application on AWS Amplify: A comprehensive guide," International Journal of Progressive Research in Engineering Management and Science, 2024.

[29] A. M. K. Bagwani and V. K. Tiwari, "Implementing GrapesJS in educational platforms for web development training on AWS," International Journal of Scientific Research in Multidisciplinary Studies, vol. 10, 2024.

[30] A. M. K. Bagwani and V. K. Tiwari, "Optimizing face detection performance with cloud machine learning services," Journal of Engineering and Technology Management, vol. 73, pp. 1167-1180, 2024.

[31] P. G. K. S. Mahesh Kumar Bagwani, "Performance comparison of REST API and GraphQL in a micro services architecture," International Conference on Data Science, Artificial Intelligence and Advanced Computing, 2024.

[32] M. K. Bagwani and G. K. Shrivastava, "Comparative analysis of microservices architectures: Evaluating performance, scalability, and maintenance," International Journal on Advances in Engineering Technology and Science, vol. 5, 2023.

[33] M. K. Bagwani, S. Dwivedi, V. Kumar, and P. Koshti, "Transmitting malware through QR codes: Risk analysis and a hybrid detection method," International Journal for Multidisciplinary Research, vol. 8, no. 3, pp. 1-25, 2026.

[34] A. M. K. Bagwani and V. K. Tiwari, "Preventing malware spread through QR codes: A detection and analysis approach," Journal of Engineering and Technology Management, vol. 73, pp. 1260-1268, 2024.

[35] A. M. K. Bagwani, V. K. Tiwari, and N. Singh, "Integrating GrapesJS with AWS: Building an educational platform for web development training," An Overview of Literature, Language and Education Research, vol. 10, pp. 106-124, 2025.

[36] M. Bagwani, "Building a cloud-native microservices based web application with GraphQL and Docker," School of Advanced Computing, Sanjeev Agrawal Global Educational University, 2024.

Downloads

Published

2026-09-01 — Updated on 2026-07-31

Versions

Issue

Section

Original Research Articles

How to Cite

Epistemic-Gated Transformer for Zero-Day Intrusion Mining in Network Traffic. (2026). IJAICET - International Journal of Artificial Intelligence, Cybersecurity and Emerging Technologies, 1(1), 33-41. https://ijaicet.com/index.php/ijaicet/article/view/14 (Original work published 2026)