UNAD+: An Explainable Hybrid Framework for Unknown Network Attack Detection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Alzubi, Saif, Stahl, Frederic
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910246410125312
author Alzubi, Saif
Stahl, Frederic
author_facet Alzubi, Saif
Stahl, Frederic
contents The detection of previously unseen network attacks remains a major challenge for intrusion detection systems. Although supervised learning methods often perform well on known attack classes, they are limited when new attack types are not represented in the training data. Unsupervised methods are more suitable for detecting zero-day attacks, as they do not require labelled attack samples, but they often suffer from high false positive rates, which limits their real-world usefulness. This paper presents UNAD+, an enhanced framework for unknown network attack detection derived from the previously proposed Unknown Network Attack Detector (UNAD). UNAD+ combines a benign-only unsupervised ensemble with Weighted Majority Voting (WMV), a supervised refinement stage trained on pseudo-labelled detections, and a post hoc explainability layer that provides both local and global explanations. The framework was evaluated on the CICIDS2017 and NSL-KDD benchmark datasets. The results show that UNAD+ improves on the original UNAD framework, achieving F1-scores above 98% across the benchmark datasets while significantly reducing false positives and enhancing transparency and deployment suitability through integrated explainability.
format Preprint
id arxiv_https___arxiv_org_abs_2605_22621
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle UNAD+: An Explainable Hybrid Framework for Unknown Network Attack Detection
Alzubi, Saif
Stahl, Frederic
Cryptography and Security
Machine Learning
Networking and Internet Architecture
The detection of previously unseen network attacks remains a major challenge for intrusion detection systems. Although supervised learning methods often perform well on known attack classes, they are limited when new attack types are not represented in the training data. Unsupervised methods are more suitable for detecting zero-day attacks, as they do not require labelled attack samples, but they often suffer from high false positive rates, which limits their real-world usefulness. This paper presents UNAD+, an enhanced framework for unknown network attack detection derived from the previously proposed Unknown Network Attack Detector (UNAD). UNAD+ combines a benign-only unsupervised ensemble with Weighted Majority Voting (WMV), a supervised refinement stage trained on pseudo-labelled detections, and a post hoc explainability layer that provides both local and global explanations. The framework was evaluated on the CICIDS2017 and NSL-KDD benchmark datasets. The results show that UNAD+ improves on the original UNAD framework, achieving F1-scores above 98% across the benchmark datasets while significantly reducing false positives and enhancing transparency and deployment suitability through integrated explainability.
title UNAD+: An Explainable Hybrid Framework for Unknown Network Attack Detection
topic Cryptography and Security
Machine Learning
Networking and Internet Architecture
url https://arxiv.org/abs/2605.22621