A Hybrid Deep Learning Framework for Real-Time Anomaly and Zero-Day Attack Detection in Cyber-Physical Manufacturing Systems
Abstract
Cyber-physical manufacturing systems (CPMSs) integrate industrial control, networked communication, sensing, computation, and automated decision-making, creating highly interconnected production environments but also expanding the attack surface available to sophisticated cyber threats. Conventional intrusion detection approaches frequently depend on predefined signatures or static classification boundaries, making them less effective against previously unseen and rapidly evolving attacks. This paper proposes a hybrid deep learning framework for real-time anomaly and zero-day attack detection in CPMSs. The proposed architecture combines heterogeneous feature extraction, temporal representation learning, anomaly scoring, ensemble decision fusion, and adaptive classification to distinguish normal operational deviations from malicious behavior. Its theoretical foundation integrates sequence-based deep learning with ensemble decision mechanisms and imbalance-aware learning. Insights from existing work on malicious URL detection, intrusion detection, traffic classification, deep learning, decision fusion, and oversampling are synthesized to formulate a CPMS-oriented architecture. The framework emphasizes low-latency inference, resilience to unknown attack patterns, and operational interpretability. Rather than claiming experimentally measured performance without an executed benchmark, the Results section presents analytically derived findings and expected evaluation behavior. The proposed framework provides a research foundation for developing adaptive security mechanisms capable of detecting both known and zero-day threats while maintaining compatibility with real-time manufacturing constraints.