Agentic intelligence-driven visual analytics with human-in-the-loop for zero-day attack detection towards a secure future economy

May Altulyan, Karthiyayini Murugesan, Thavavel Vaiyapuri · International Journal of Data and Network Science · 2026

Zero-day and emerging cyber threats are difficult to detect in digital infrastructure due to evolving attack patterns, class imbalances, and the limited interpretability of traditional intrusion detection systems (IDSs). As such, the primary objective of this research is to develop an agentic intelligence-driven visual analytics framework for detecting zero-day cyberthreats in digital infrastructure as a basis for future economic development. The framework combines long short-term memory (LSTM)-based temporal modeling with threat severity scoring, entropy-based uncertainty estimation, and embedding-based structural analysis to move beyond conventional class-label prediction. It further incorporates orchestrated decision support and human-in-the-loop reasoning to help analysts interpret suspicious traffic, prioritize high-risk events, and validate uncertain cases. Experimental results on NSL-KDD, where R2L and U2R were treated as unseen zero-day attacks, achieved 96.40% accuracy. Additional cross-dataset evaluation on ToN-IoT, using MITM, Backdoor, and Ransomware as unseen attacks, confirmed the framework's applicability to modern IoT environments. The findings demonstrate that integrating machine intelligence with analyst-guided reasoning improves zero-day detection, interpretability, and adaptive cyberthreat analysis.

Read the paper · More papers on PaperTik