Transformer-Based Hybrid Intrusion Detection Framework for Real-Time Zero-Day Cyberattack Detection Using Deep Learning and Large Language Models

Authors

  • Hayder Makki Shakir Department of Computer Information Systems, Faculty of Computer Science and Information Technology, University of Al-Qadisiyah, Iraq
  • Alaa Abid Muslam Abid Ali Cyber Security Department, Faculty of Computer Science and Information Technology, Al-Qadisiyah University, Iraq.

DOI:

https://doi.org/10.29304/jqcsm.2026.18.32889

Keywords:

AI, , Deep learning, Cyber security

Abstract

Abstract                                                                                                                             

Due to the complexity of modern network infrastructures, cloud services, Internet of Things environments and cyber-physical systems, also conventional attack detection systems have been revealed to be inadequate. While machine learning and deep learning-based models can perform quite well on known attacks, the problem is that these techniques do not generalize greatly under diverse traffic distributions or zero-day scenarios. This work proposes a hybrid intrusion detection framework based on the transformer architecture integrating convolutional neural networks for spatial feature extraction, bidirectional long short-term memory networks to model temporal behavior, Transformer self-attention mechanisms to extract contextual dependencies, and an LLM-assisted reasoning proxy to semantically interpret uncertain traffic events between hosts (instances). Experimental evaluation employed CICIDS2018, CICIDS2017, and UNSW-NB15 datasets to compare Random Forest, Extra Trees, XGBoost, CNN, LSTM, BiLSTM, CNN-LSTM performance were presents; additionally, the proposed integration of CNN-BiLSTM-Transformer with a reasoning proxy using an LLMCompare overall result performance. Results: Ensemble models produced the strongest baseline performance For CICIDS2017, we achieved an accuracy of 92.33% and a weighted F1-score of 92.24%, while for UNSW-NB15 it was 66.80% and a weighted F1-score of 66.11%. The results are in accordance with which embodies the recent strength of ensemble baselines and underlines cross-dataset generalization as a challenging problem. In this regard, the proposed framework gives glimpse of a holistic architectural avenue for designing future zero-day-aware intrusion detection by weaving in a unified nature articulation for leveraging spatial, temporal, contextual and semantic learning mechanisms to embrace adaptable cybersecurity analysis tasks.                                       

 

Downloads

Download data is not yet available.

References

Aldweesh, A., Derhab, A., & Emam, A. Z. (2020). Deep learning approaches for anomaly-based intrusion detection systems: A survey, taxonomy, and open issues. Knowledge-Based Systems, 189, 105124.

‏ [2] Liu, H., & Lang, B. (2019). Machine learning and deep learning methods for intrusion detection systems: A survey. applied sciences, 9(20), 4396.‏

Karatas, G., Demir, O., & Sahingoz, O. K. (2018, December). Deep learning in intrusion detection systems. In 2018 international congress on big data, deep learning and fighting cyber terrorism (IBIGDELFT) (pp. 113-116). IEEE.‏.

Otoum, S., Kantarci, B., & Mouftah, H. T. (2019). On the feasibility of deep learning in sensor network intrusion detection. IEEE Networking Letters, 1(2), 68-71.‏

Xin, Y., Kong, L., Liu, Z., Chen, Y., Li, Y., Zhu, H., ... & Wang, C. (2018). Machine learning and deep learning methods for cybersecurity. Ieee access, 6, 35365-35381.

Wang, W., Zhu, M., Zeng, X., Ye, X., & Sheng, Y. (2017, January). Malware traffic classification using convolutional neural network for representation learning. In 2017 International conference on information networking (ICOIN) (pp. 712-717). IEEE.

Muna, A. H., Moustafa, N., & Sitnikova, E. (2018). Identification of malicious activities in industrial internet of things based on deep learning models. Journal of information security and applications, 41, 1-11.‏

Farhan, B. I., & Jasim, A. D. (2022). Survey of Intrusion Detection Using Deep Learning in the Internetof Things. Iraqi Journal For Computer Science and Mathematics, 3(1), 9.‏

Biswas, T. K., Zannat, A., Ishtiaq, W., & Hossain, M. A. (2026). A novel unified lightweight temporal-spatial transformer approach for intrusion detection in drone networks. Scientific Reports.‏

Kheddar, H. (2025). Transformers and large language models for efficient intrusion detection systems: A comprehensive survey. Information Fusion, 124, 103347.‏

Ferrag, M. A., Alwahedi, F., Battah, A., Cherif, B., Mechri, A., Tihanyi, N., ... & Debbah, M. (2025). Generative AI in cybersecurity: A comprehensive review of LLM applications and vulnerabilities. Internet of Things and Cyber-Physical Systems, 5, 1-46.‏.

Almadhor, A., Alsubai, S., Kryvinska, N., Hejaili, A. A., Ayari, M., Bouallegue, B., & Abbas, S. (2025). Evaluating large transformer models for anomaly detection of resource-constrained IoT devices for intrusion detection system. Scientific Reports, 15(1), 37972.‏

Shone, N., Ngoc, T. N., Phai, V. D., & Shi, Q. (2018). A deep learning approach to network intrusion detection. IEEE transactions on emerging topics in computational intelligence, 2(1), 41-50.‏vol. 2, no. 1, pp. 41–50, 2018.

Wu, K., Chen, Z., & Li, W. (2018). A novel intrusion detection model for a massive network using convolutional neural networks. Ieee Access, 6, 50850-50859.‏

Vinayakumar, R., Alazab, M., Soman, K. P., Poornachandran, P., Al-Nemrat, A., & Venkatraman, S. (2019). Deep learning approach for intelligent intrusion detection system. IEEE access, 7, 41525-41550.‏

Papamartzivanos, D., Mármol, F. G., & Kambourakis, G. (2019). Introducing deep learning self-adaptive misuse network intrusion detection systems. IEEE access, 7, 13546-13560.‏

Ieracitano, C., Adeel, A., Morabito, F. C., & Hussain, A. (2020). A novel statistical analysis and autoencoder driven intelligent intrusion detection approach. Neurocomputing, 387, 51-62.‏

Liu, L., Wang, P., Lin, J., & Liu, L. (2020). Intrusion detection of imbalanced network traffic based on machine learning and deep learning. IEEE access, 9, 7550-7563.‏

Nedeljkovic, D., & Jakovljevic, Z. (2022). CNN based method for the development of cyber-attacks detection algorithms in industrial control systems. Computers & Security, 114, 102585.‏

Deore, B., & Bhosale, S. (2022). Hybrid optimization enabled robust CNN-LSTM technique for network intrusion detection. Ieee Access, 10, 65611-65622.‏

Hnamte, V., & Hussain, J. (2023). DCNNBiLSTM: An efficient hybrid deep learning-based intrusion detection system. Telematics and Informatics Reports, 10, 100053.‏

Talukder, M. A., Islam, M. M., Uddin, M. A., Hasan, K. F., Sharmin, S., Alyami, S. A., & Moni, M. A. (2024). Machine learning-based network intrusion detection for big and imbalanced data using oversampling, stacking feature embedding and feature extraction. Journal of big data, 11(1), 33.‏

Xi, C., Wang, H., & Wang, X. (2024). A novel multi-scale network intrusion detection model with transformer. Scientific Reports, 14(1), 23239.‏

Zhao, X., Leng, X., Wang, L., Wang, N., & Liu, Y. (2025). Efficient anomaly detection in tabular cybersecurity data using large language models. Scientific Reports, 15(1), 3344.‏

Mehavilla, L., Rodríguez, M., García, J., & Alesanco, Á. (2026). Evaluating large language models effectiveness for flow-based intrusion detection: a comparative study with ML and DL baselines. Artificial Intelligence Review, 59(2), 50.‏

Downloads

Published

2026-09-30

How to Cite

Shakir , H. M., & Abid Muslam Abid Ali, A. (2026). Transformer-Based Hybrid Intrusion Detection Framework for Real-Time Zero-Day Cyberattack Detection Using Deep Learning and Large Language Models. Journal of Al-Qadisiyah for Computer Science and Mathematics, 18(3), Comp 379–402. https://doi.org/10.29304/jqcsm.2026.18.32889

Issue

Section

Computer Articles