Open Access
ARTICLE
HADAR-UAV: Risk-Calibrated One-Class Learning Framework for Zero-Day Intrusion Detection in Unmanned Aerial Vehicle Networks
1 Software Engineering Department, Malatya Turgut Özal University, Malatya, Turkey
2 Centre for Intelligent Cloud Computing, COE for Advanced Cloud, Multimedia University, Melaka, 75450, Malaysia
3 Faculty of Computer Science and Information Technology, Universiti Tun Hussein Onn Malaysia, Parit Raja, Malaysia
* Corresponding Authors: Canan Batur Şahin. Email: ; Siti Fatimah Abdul Razak. Email:
Computers, Materials & Continua 2026, 89(1), 49 https://doi.org/10.32604/cmc.2026.080874
Received 27 February 2026; Accepted 03 May 2026; Issue published 13 August 2026
Abstract
Unmanned Aerial Vehicle (UAV) networks face escalating cybersecurity threats, especially from zero-day attacks that exploit previously unknown vulnerabilities. To address this, we present HADAR-UAV (Hybrid Anomaly Detection with Adaptive Risk-calibration for UAV). This novel intrusion detection framework integrates masked autoencoder representation learning with Deep Support Vector Data Description (Deep SVDD) under conformal prediction guarantees to calibrate risk. Our method overcomes three critical limitations of existing approaches: (i) over-reliance on attack signatures, (ii) lack of statistical guarantees on false alarm rates, and (iii) insufficient robustness in feature extraction under partial observation. Using a rigorous Leave-Two-Attack-Families-Out (L2AFO) evaluation protocol on the UAVIDS-2025 benchmark, HADAR-UAV achieves strong zero-day detection—0.997 ± 0.001 ROC-AUC and 0.992 ± 0.002 F1-Score—while empirically maintaining a target false alarm rate through conformal calibration applied to deterministic scores. All results are reported as mean ± standard deviation across 20 independent runs (5 seeds × 4 folds) and show statistically significant improvement (paired t-test, p < 0.01) over current one-class methods. Ablation studies confirm that every architectural component adds measurable value to the framework. Additional cross-dataset validation on NSL-KDD under a one-class zero-day-inspired setting further indicates that the proposed framework generalizes beyond MAVLink-specific traffic patterns.Keywords
Cite This Article
Copyright © 2026 The Author(s). Published by Tech Science Press.This work is licensed under a Creative Commons Attribution 4.0 International License , which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.


Submit a Paper
Propose a Special lssue
View Full Text
Download PDF
Downloads
Citation Tools