Generative AI Based Intelligent Multi Stage ZeroDay Intrusion Detection Using Behavioural Attack Modelling
Keywords:
Zero-Day Intrusion Detection, Generative Artificial Intelligence, Behavioural Attack Modelling, Multi-Stage Attack Detection, Deep Learning, Convolutional Neural Network, Transformer, Generative Adversarial Network, Variational Autoencoder, Graph Neural Network, Reinforcement Learning, Explainable Artificial Intelligence, Cybersecurity.Abstract
Traditional Intrusion Detection Systems (IDSs) are inefficient at dealing with advanced attacks, such as zero day attacks, due to the use of signature matching and static anomaly detection. The proliferation of the cloud computing environment, the Internet of Things (IoT), the Industrial Internet of Things (IIoT) and distributed enterprise infrastructure have increased the surface area for attack even more, making previously unknown attacks more difficult to detect. Despite the good performance of the recently developed intrusion detection (ID) techniques based on Artificial Intelligence (AI), most current methods are effective only against a single attack, without considering the sequential nature of behaviour-driven attacks that is characteristic of multi-stage intrusions. Existing learning models also don't generalise well because there aren't any representative samples of zero-day attacks. To solve these problems, this paper proposes a Generative AI-Based Intelligent Multi-Stage Zero-Day Intrusion Detection Using Behavioural Attack Modelling (GAIM-ZID) framework which incorporates all the above techniques into one adaptive IDS.The proposed methodology comprises seven modules: intelligent data acquisition and pre-processing; hybrid behavioural feature extraction using CNN and Transformer networks; Generative AI-based attack modelling using Generative Adversarial Networks (GANs), Variational Auto encoders (VAEs) and Large Language Models (LLMs); multi-stage behavioural learning using BiLSTM and Temporal Transformer architectures; Graph Neural Network (GNN)-based behavioural threat correlation; an attention-driven explainable decision engine; and continuous adaptive learning via Reinforcement Learning (RL). The framework is designed to learn attacker behaviour throughout the entire life cycle of a cyberattack, which enables it to proactively identify new, unseen zero-day attacks, and evolve to capture new attack patterns. The proposed model was evaluated using the benchmark intrusion detection datasets such as CICIDS2017, CSE-CIC-IDS2018, UNSW-NB15, BoT-IoT, TON_IoT and Edge-IIoTset. The GAIM-ZID framework had an overall accuracy of 99.21%, precision of 98.94%, recall of 98.81%, F1-score of 98.87% and an AUC of 99.54%, which are higher than some of the state-of-the-art deep-learning-based intrusion detection approaches. The integration of Generative AI with behavioural attack modelling significantly enhanced zero-day detection accuracy, reduced false positives, provided increased transparency via Explainable Artificial Intelligence (XAI) and allowed for real-time adaptation to emerging cyber threats. The findings show that GAIM-ZID is an effective, scalable and intelligent solution for intrusion detection in cloud computing, Internet of Things and enterprise networks, as well as in other vital cyber infrastructures.





