Adaptive Gated Multi-View Representation Learning for Zero-Day Intrusion Detection Under a Leakage-Controlled Evaluation Protocol
Keywords:
Adaptive gated fusion, deep reinforcement learning, intrusion detection systems, model calibration, multi-head attention, network security, reproducible benchmarking, selective prediction, wavelet denoising, zero-day attack detection.Abstract
Zero-day intrusions defeat signature-based defences by construction, yet the learned detectors proposed to replace them are frequently reported under evaluation protocols that inflate their apparent capability, so that architectural progress cannot be separated from protocol optimism. This article addresses both. An adaptive wavelet-projection autoencoder feeds a tri-branch detection network whose multi-head attentive, convolutional-recurrent and residual bidirectional branches encode complementary views of each traffic record and are combined by an input-conditioned gate that re-derives a convex mixture for every record instead of fixing it at design time. The architecture is embedded in a leakage-controlled protocol in which partitioning precedes every fitted transform and all selection criteria, scaling statistics and calibration parameters are estimated on the training partition alone. Eighteen classical, ensemble, convolutional, recurrent, hybrid and reinforcement-learning detectors are evaluated under identical conditions on a three-class ransomware corpus and a binary logistics zero-day corpus, along seven metric families spanning discrimination, calibration, robustness, latency and footprint. On the ransomware corpus the pool separates across a twenty-point accuracy range: a heterogeneous stacking ensemble leads at 0.9862 accuracy, gradient boosting attains 0.9993 area under the ROC curve, and the proposed architecture reaches 0.9565. A four-variant ablation isolates the projection stage as the only positively contributing component, and a per-record confidence analysis shows that a confidence-gated pipeline automates 89.84% of traffic with no observed error. On the binary corpus fourteen detectors attain unit accuracy under a demonstrably leakage-free pipeline, identifying the corpus rather than the models as the limiting factor.





