Hybrid dual-head IDS: A lightweight and explainable deep learning DDOS/DOS framework for zero-day and imbalanced attack detection in IoT networks
Saeed Ullah, Junsheng Wu, Mian Muhammad Kamal, Mohammed K. Alzaylaee, Mohammad Alibakhshikenari · Results in Engineering · 2026
The rapid expansion of IoT has escalated security risks of DDoS and DoS for cyber-physical systems, but deep learning-based Intrusion Detection Systems (IDS) face challenges like poor handling of imbalanced datasets, inability to detect zero-day attacks, lack of transparency and scalability. This paper proposes Hybrid Dual-Head IDS, a lightweight, explainable deep learning framework to address these issues. The framework employs a dataset-adaptive Wasserstein GAN with Gradient Penalty per class (auto-selecting jitter, bootstrapping, or WGAN-GP as determined by sample size ( N eff ) -scaled Kolmogorov–Smirnov test) and a functionally partitioned dual-head architecture with a hybrid loss function. A ZDS Ratio that is zero-day separation for vanishing FPR and per-class SHAP values (that can be linked to the dual-head thresholds) is used by the operational analysts. Evaluated on CIC-IoT2023, BoT-IoT, and ToN-IoT datasets, Hybrid Dual-Head IDS achieves over 99.5% accuracy and F1-scores, perfect scores on the imbalanced BoT-IoT dataset, and high zero-day detection capability. The evaluation is further strengthened by introducing a true zero-day holdout protocol, a component-wise ablation study, five-seed statistical validation, direct synthetic-data fidelity analysis, and ROC-AUC and threshold-sensitivity evaluation. In true zero-day holdout setting, the model achieved ZDS ratios of 175900.50x/1094.12x on CIC-IoT2023 (binary/multiclass), 7260770.86x/12791298.51x on BoT-IoT, and 223.95x on ToN-IoT. Results further show stable behavior across random seeds, high-quality synthetic augmentation where needed, and very low false positive rates under ROC-based threshold selection. The compact size (≈0.5 MB) enables efficient network protection through high throughput which provides an effective practical solution for IoT network security against known and unknown threats.