Autonomous Anomaly Edge Verification Via Symmetric Deep Autoencoders with Post-Hoc Interpretability for Zero-Day Threat Isolation

Main Article Content

Aravind Chagantipati

Abstract

Contemporary enterprise network environments are increasingly exposed to sophisticated zero-day exploits that bypass traditional signature-based security perimeters due to the lack of historical threat profiles. To address this paradigm shift, unsupervised machine learning presents a viable defense strategy by modeling the intrinsic statistical behavior of legitimate network traffic and identifying structural anomalies as security breaches. This paper introduces an unsupervised perimeter defense framework utilizing symmetric deep Autoencoder architectures. Evaluated on the standardized NSL-KDD benchmark, our model is trained exclusively on uncompromised network transactions to establish an optimized baseline behavior. During testing, hidden zero-day threats introduce distinct reconstruction discrepancies, yielding an optimal accuracy of 93.2% and an F1-score of 92.7%. Furthermore, to mitigate the opaque nature inherent to multi-layered neural configurations, we integrate a Local Interpretable Model-agnostic Explanations (LIME) framework. This post-hoc layer maps elevated reconstruction errors to granular, interpretable feature attributions, empowering analysts with immediate structural visibility into flagged vectors

Article Details

Issue
Section
Articles