Autonomous Anomaly Edge Verification Via Symmetric Deep Autoencoders with Post-Hoc Interpretability for Zero-Day Threat Isolation
Main Article Content
Abstract
Contemporary enterprise network environments are increasingly exposed to sophisticated zero-day exploits that bypass traditional signature-based security perimeters due to the lack of historical threat profiles. To address this paradigm shift, unsupervised machine learning presents a viable defense strategy by modeling the intrinsic statistical behavior of legitimate network traffic and identifying structural anomalies as security breaches. This paper introduces an unsupervised perimeter defense framework utilizing symmetric deep Autoencoder architectures. Evaluated on the standardized NSL-KDD benchmark, our model is trained exclusively on uncompromised network transactions to establish an optimized baseline behavior. During testing, hidden zero-day threats introduce distinct reconstruction discrepancies, yielding an optimal accuracy of 93.2% and an F1-score of 92.7%. Furthermore, to mitigate the opaque nature inherent to multi-layered neural configurations, we integrate a Local Interpretable Model-agnostic Explanations (LIME) framework. This post-hoc layer maps elevated reconstruction errors to granular, interpretable feature attributions, empowering analysts with immediate structural visibility into flagged vectors