Open Access

A Hybrid Deep Learning Framework for Real-Time Anomaly and Zero-Day Attack Detection in Cyber-Physical Manufacturing Systems

4 Department of Cybersecurity and Intelligent Systems, Advanced Technology University, Riyadh, Saudi Arabia
4 Department of Artificial Intelligence and Security Analytics, Institute of Digital Security Studies, Jeddah, Saudi Arabia.

Abstract

Cyber-physical manufacturing systems (CPMSs) integrate industrial control, networked communication, sensing, computation, and automated decision-making, creating highly interconnected production environments but also expanding the attack surface available to sophisticated cyber threats. Conventional intrusion detection approaches frequently depend on predefined signatures or static classification boundaries, making them less effective against previously unseen and rapidly evolving attacks. This paper proposes a hybrid deep learning framework for real-time anomaly and zero-day attack detection in CPMSs. The proposed architecture combines heterogeneous feature extraction, temporal representation learning, anomaly scoring, ensemble decision fusion, and adaptive classification to distinguish normal operational deviations from malicious behavior. Its theoretical foundation integrates sequence-based deep learning with ensemble decision mechanisms and imbalance-aware learning. Insights from existing work on malicious URL detection, intrusion detection, traffic classification, deep learning, decision fusion, and oversampling are synthesized to formulate a CPMS-oriented architecture. The framework emphasizes low-latency inference, resilience to unknown attack patterns, and operational interpretability. Rather than claiming experimentally measured performance without an executed benchmark, the Results section presents analytically derived findings and expected evaluation behavior. The proposed framework provides a research foundation for developing adaptive security mechanisms capable of detecting both known and zero-day threats while maintaining compatibility with real-time manufacturing constraints.

How to Cite

Faisal Al-Harbi, & Nora Al-Qahtani. (2026). A Hybrid Deep Learning Framework for Real-Time Anomaly and Zero-Day Attack Detection in Cyber-Physical Manufacturing Systems. Frontiers in Emerging Computer Science and Information Technology, 3(08), 6–12. Retrieved from https://irjernet.com/index.php/fecsit/article/view/513

References

A. Alanazi and A. Gumaei, “A decision-fusion-based ensemble approach for malicious websites detection,” Appl. Sci., vol. 13, no. 18, Sep. 2023, Art. no. 10260.
A. Anagnostis et al., “A deep learning approach for anthracnose infected trees classification in walnut orchards,” Comput. Electron. Agric., vol. 182, Mar. 2021, Art. no. 105998.
M. M. Aljabri et al., “An assessment of lexical, network, and content-based features for detecting malicious urls using machine learning and deep learning models,” Comput. Intell. Neurosci., vol. 2022, no. 1, 2022, Art. no. 3241216.
M. Aljabri et al., “Detecting malicious URLs using machine learning techniques: Review and research directions,” IEEE Access, vol. 10, pp. 121395–121417, Aug. 2022.
R. Bayraktar, B. Haznedar, K. S. Bayram, and M. F. Haso ̆glu, “Plant disease detection by using adaptive neuro-fuzzy inference system,” Tamap J. Eng., vol. 2021, no. 125, pp. 1–10, Sep. 2021.
N. Bhadouria, “Malicious_URL’s_Dataset,” 2022. Accessed: Jun. 5, 2023. [Online]. Available: https://www.kaggle.com/datasets/naveenbhadouria/malicious
Govindarajan, V., Ahmed, F., Kamaluddin, K. et al. SecureRiskNet: An Advanced AI-Driven Framework for Intelligent Security Risk Detection in Heterogeneous Cloud-Fog Computing Networks. Int J Comput Intell Syst 19, 74 (2026).
T. Le, M. Y. Lee, J. R. Park, and S. W. Baik, “Oversampling techniques for bankruptcy prediction: Novel features from a transaction dataset,” Symmetry, vol. 10, no. 4, Mar. 2018, Art. no. 79.
O. V. Lee et al., “A malicious URLs detection system using optimization and machine learning classifiers,” Indones J. Electr. Eng. Comput. Sci., vol. 17, no. 3, pp. 1210–1214, Mar. 2020.
H. Liu and B. Lang, “Machine learning and deep learning methods for intrusion detection systems: A survey,” Appl. Sci., vol. 9, no. 20, Oct. 2019, Art. no. 4396.
A. R. Mohammed, S. A. Mohammed, and S. Shirmohammadi, “Machine learning and deep learning based traffic classification and prediction in software defined networking,” in IEEE Int. Symp. Meas. Netw. (M&N), Catania, Italy, Jul. 8–10, 2019, pp. 1–6.
Y. Mourtaji, M. Bouhorma, D. Alghazzawi, G. Aldabbagh, and A. Alghamdi, “Hybrid rule-based solution for phishing URL detection using convolutional neural network,” Wirel. Commun. Mob. Comput., vol. 2021, no. 1, pp. 1–24, 2021, Art. no. 8241104.
W. Yang, W. Zuo, and B. Cui, “Detecting malicious URLs via a keyword-based convolutional gated-recurrent-unit neural network,” IEEE Access, vol. 7, pp. 29891–29900, Jan. 2019.
Ramamurthy, K., Gumber, S., Abdelfattah, W.M. et al. Human AI trust modeling in cognitive systems via ensemble learning and advanced feature engineering. Discov Artif Intell 6, 366 (2026). https://doi.org/10.1007/s44163-026-01255-7
Philip, P. G. (2025). Explainable Artificial Intelligence (XAI) for Project Governance: Improving Transparency and Stakeholder Trust in Automated Project Decision. Journal of Project Management Studies, 2(1), 37–55. https://doi.org/10.58425/jpms.v2i1.570