Collaborative Zone-Adaptive Zero-Day Intrusion Detection for IoBT
Amirmohammad Pasdar, Shabnam Kasra Kermanshahi, Nour Moustafa, Van-Thuan Pham

TL;DR
This paper introduces ZAID, a collaborative, zone-adaptive intrusion detection framework for IoBT that effectively detects unseen cyber attacks using federated learning and lightweight adaptation modules.
Contribution
ZAID is the first to combine universal traffic models, autoencoder anomaly signals, and lightweight adapters for zone-specific intrusion detection in disrupted IoBT networks.
Findings
Achieves up to 83.16% accuracy on unseen attack traffic.
Transfers detection capabilities to different datasets with up to 71.64% accuracy.
Demonstrates effective zero-day attack detection in contested environments.
Abstract
The Internet of Battlefield Things (IoBT) relies on heterogeneous, bandwidth-constrained, and intermittently connected tactical networks that face rapidly evolving cyber threats. In this setting, intrusion detection cannot depend on continuous central collection of raw traffic due to disrupted links, latency, operational security limits, and non-IID traffic across zones. We present Zone-Adaptive Intrusion Detection (ZAID), a collaborative detection and model-improvement framework for unseen attack types, where "zero-day" refers to previously unobserved attack families and behaviours (not vulnerability disclosure timing). ZAID combines a universal convolutional model for generalisable traffic representations, an autoencoder-based reconstruction signal as an auxiliary anomaly score, and lightweight adapter modules for parameter-efficient zone adaptation. To support cross-zone…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Software-Defined Networks and 5G · Opportunistic and Delay-Tolerant Networks
