Explainable Hybrid Framework for Zero Day Web Attack Detection Using Anomaly Detection and Classification ModelsThe rise in the usage of web applications has elevated the risk of cyber attacks, specifically zero day web attacks. Zero day web attacks are t
DOI:
https://doi.org/10.70917/ijcisim-2026-4621Keywords:
Zero day web attack, Anomaly Detection, Classification Models, Explainable AI (XAI)Abstract
The rise in the usage of web applications has elevated the risk of cyber attacks, specifically zero day web attacks. Zero day web attacks are the unseen and unusual attacks which traditional methods fail to detect. This essay's primary goal is to build a system that detects zero day web attacks efficiently. The proposed system utilises CICIDS2017 dataset and applies SMOTE method for creating artificial samples to balance the class. For anomaly detection, the system utilizes unsupervised techniques like autoencoder and isolation forest. The study aims to implement supervised algorithms as well, such as Logistic regression, linear support vector machines, and random forests and XGBoost respectively. Among all these models, XGBoost outperforms with 0.99 accuracy, 0.98 precision, 1.00 recall and 0.99 F1-score. The system classifies the traffic as normal or attack enabling efficient detection of cyber attack. Explainable AI (XAI) techniques like SHaply Addictive exPlanations (SHAP) and Local Interpretable Model-agnostic Explanations (LIME) are applied To enhance the interpretability. It is observed that SHAP is the higher suitable technique for explaining the identification of attacks. The paper mainly focuses on improving the detection capability of the setup and maintaining transparency in decision making. This study marks its contribution in providing important perspectives in the area of cybersecurity for efficient detection of zero day web attacks.