Transformer-Based Hybrid Intrusion Detection Framework for Real-Time Zero-Day Cyberattack Detection Using Deep Learning and Large Language Models
DOI:
https://doi.org/10.29304/jqcsm.2026.18.32889Keywords:
AI, , Deep learning, Cyber securityAbstract
Abstract
Due to the complexity of modern network infrastructures, cloud services, Internet of Things environments and cyber-physical systems, also conventional attack detection systems have been revealed to be inadequate. While machine learning and deep learning-based models can perform quite well on known attacks, the problem is that these techniques do not generalize greatly under diverse traffic distributions or zero-day scenarios. This work proposes a hybrid intrusion detection framework based on the transformer architecture integrating convolutional neural networks for spatial feature extraction, bidirectional long short-term memory networks to model temporal behavior, Transformer self-attention mechanisms to extract contextual dependencies, and an LLM-assisted reasoning proxy to semantically interpret uncertain traffic events between hosts (instances). Experimental evaluation employed CICIDS2018, CICIDS2017, and UNSW-NB15 datasets to compare Random Forest, Extra Trees, XGBoost, CNN, LSTM, BiLSTM, CNN-LSTM performance were presents; additionally, the proposed integration of CNN-BiLSTM-Transformer with a reasoning proxy using an LLMCompare overall result performance. Results: Ensemble models produced the strongest baseline performance For CICIDS2017, we achieved an accuracy of 92.33% and a weighted F1-score of 92.24%, while for UNSW-NB15 it was 66.80% and a weighted F1-score of 66.11%. The results are in accordance with which embodies the recent strength of ensemble baselines and underlines cross-dataset generalization as a challenging problem. In this regard, the proposed framework gives glimpse of a holistic architectural avenue for designing future zero-day-aware intrusion detection by weaving in a unified nature articulation for leveraging spatial, temporal, contextual and semantic learning mechanisms to embrace adaptable cybersecurity analysis tasks.
Downloads
References
Aldweesh, A., Derhab, A., & Emam, A. Z. (2020). Deep learning approaches for anomaly-based intrusion detection systems: A survey, taxonomy, and open issues. Knowledge-Based Systems, 189, 105124.
[2] Liu, H., & Lang, B. (2019). Machine learning and deep learning methods for intrusion detection systems: A survey. applied sciences, 9(20), 4396.
Karatas, G., Demir, O., & Sahingoz, O. K. (2018, December). Deep learning in intrusion detection systems. In 2018 international congress on big data, deep learning and fighting cyber terrorism (IBIGDELFT) (pp. 113-116). IEEE..
Otoum, S., Kantarci, B., & Mouftah, H. T. (2019). On the feasibility of deep learning in sensor network intrusion detection. IEEE Networking Letters, 1(2), 68-71.
Xin, Y., Kong, L., Liu, Z., Chen, Y., Li, Y., Zhu, H., ... & Wang, C. (2018). Machine learning and deep learning methods for cybersecurity. Ieee access, 6, 35365-35381.
Wang, W., Zhu, M., Zeng, X., Ye, X., & Sheng, Y. (2017, January). Malware traffic classification using convolutional neural network for representation learning. In 2017 International conference on information networking (ICOIN) (pp. 712-717). IEEE.
Muna, A. H., Moustafa, N., & Sitnikova, E. (2018). Identification of malicious activities in industrial internet of things based on deep learning models. Journal of information security and applications, 41, 1-11.
Farhan, B. I., & Jasim, A. D. (2022). Survey of Intrusion Detection Using Deep Learning in the Internetof Things. Iraqi Journal For Computer Science and Mathematics, 3(1), 9.
Biswas, T. K., Zannat, A., Ishtiaq, W., & Hossain, M. A. (2026). A novel unified lightweight temporal-spatial transformer approach for intrusion detection in drone networks. Scientific Reports.
Kheddar, H. (2025). Transformers and large language models for efficient intrusion detection systems: A comprehensive survey. Information Fusion, 124, 103347.
Ferrag, M. A., Alwahedi, F., Battah, A., Cherif, B., Mechri, A., Tihanyi, N., ... & Debbah, M. (2025). Generative AI in cybersecurity: A comprehensive review of LLM applications and vulnerabilities. Internet of Things and Cyber-Physical Systems, 5, 1-46..
Almadhor, A., Alsubai, S., Kryvinska, N., Hejaili, A. A., Ayari, M., Bouallegue, B., & Abbas, S. (2025). Evaluating large transformer models for anomaly detection of resource-constrained IoT devices for intrusion detection system. Scientific Reports, 15(1), 37972.
Shone, N., Ngoc, T. N., Phai, V. D., & Shi, Q. (2018). A deep learning approach to network intrusion detection. IEEE transactions on emerging topics in computational intelligence, 2(1), 41-50.vol. 2, no. 1, pp. 41–50, 2018.
Wu, K., Chen, Z., & Li, W. (2018). A novel intrusion detection model for a massive network using convolutional neural networks. Ieee Access, 6, 50850-50859.
Vinayakumar, R., Alazab, M., Soman, K. P., Poornachandran, P., Al-Nemrat, A., & Venkatraman, S. (2019). Deep learning approach for intelligent intrusion detection system. IEEE access, 7, 41525-41550.
Papamartzivanos, D., Mármol, F. G., & Kambourakis, G. (2019). Introducing deep learning self-adaptive misuse network intrusion detection systems. IEEE access, 7, 13546-13560.
Ieracitano, C., Adeel, A., Morabito, F. C., & Hussain, A. (2020). A novel statistical analysis and autoencoder driven intelligent intrusion detection approach. Neurocomputing, 387, 51-62.
Liu, L., Wang, P., Lin, J., & Liu, L. (2020). Intrusion detection of imbalanced network traffic based on machine learning and deep learning. IEEE access, 9, 7550-7563.
Nedeljkovic, D., & Jakovljevic, Z. (2022). CNN based method for the development of cyber-attacks detection algorithms in industrial control systems. Computers & Security, 114, 102585.
Deore, B., & Bhosale, S. (2022). Hybrid optimization enabled robust CNN-LSTM technique for network intrusion detection. Ieee Access, 10, 65611-65622.
Hnamte, V., & Hussain, J. (2023). DCNNBiLSTM: An efficient hybrid deep learning-based intrusion detection system. Telematics and Informatics Reports, 10, 100053.
Talukder, M. A., Islam, M. M., Uddin, M. A., Hasan, K. F., Sharmin, S., Alyami, S. A., & Moni, M. A. (2024). Machine learning-based network intrusion detection for big and imbalanced data using oversampling, stacking feature embedding and feature extraction. Journal of big data, 11(1), 33.
Xi, C., Wang, H., & Wang, X. (2024). A novel multi-scale network intrusion detection model with transformer. Scientific Reports, 14(1), 23239.
Zhao, X., Leng, X., Wang, L., Wang, N., & Liu, Y. (2025). Efficient anomaly detection in tabular cybersecurity data using large language models. Scientific Reports, 15(1), 3344.
Mehavilla, L., Rodríguez, M., García, J., & Alesanco, Á. (2026). Evaluating large language models effectiveness for flow-based intrusion detection: a comparative study with ML and DL baselines. Artificial Intelligence Review, 59(2), 50.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Hayder Makki Shakir , Alaa Abid Muslam Abid Ali

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.








