Open Access
ARTICLE
A Framework for Simulated Zero-Day Detection Using Synthetic Attack Generation and Out-of-Distribution Evaluation
School of Computing and Information Technology, Jomo Kenyatta University of Agriculture and Technology, Nairobi, Kenya
* Corresponding Authors: Peter Kipngeno Langat. Email: ,
(This article belongs to the Special Issue: Next-Generation Cyber Defense: Agentic AI, Autonomous Threat Response, and Identity-Aware Security in the Cloud Era)
Journal of Cyber Security 2026, 8, 541-558. https://doi.org/10.32604/jcs.2026.083592
Received 07 April 2026; Accepted 03 August 2026; Issue published 21 August 2026
Abstract
Zero-day attacks pose a significant threat to computer systems and networks as they exploit weaknesses that have not been recognized by security professionals or software creators and for which there are no existing protective measures. This study introduced an innovative method for identifying Zero-day attacks through a Recurrent neural network model. To effectively mitigate these risks, not only is continuous monitoring essential, but also the implementation of machine learning. The model was trained on network traffic data and leveraged on the ability of Recurrent Neural Networks (RNNs) to learn complex patterns and identify anomalies that may indicate the presence of a Zero-day attack. To enhance the model’s ability to generalize and accurately identify novel attack vectors that traditional methods may overlook, we trained it on a dataset that includes both known and synthetically generated Zero-day attack signatures. Our methodology involves preprocessing network traffic data to extract relevant features, which are then fed into an RNN architecture. The RNN model was trained on a labeled dataset containing both normal and attack traffic samples, allowing it to learn the fundamental patterns of benign and malicious network activity. The Recurrent architecture of the model enables it to retain a memory of previous observations, making it well-suited for identifying deviations from the expected network behavior in real-time. By leveraging the temporal dimension of network traffic data, we enhanced the ability to identify novel threats and bolster the security of computer systems and networks. This approach held the promise for mitigating the ever-evolving landscape of cyber threats and ensuring the integrity and availability of critical digital infrastructure.Keywords
Cite This Article
Copyright © 2026 The Author(s). Published by Tech Science Press.This work is licensed under a Creative Commons Attribution 4.0 International License , which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.


Submit a Paper
Propose a Special lssue
View Full Text
Download PDF
Downloads
Citation Tools