Skip to content

An Adversarial Zero-Shot Learning Approach for Anomaly Detection in Multivariate IoT Traffic Data

Sep 2026 · 0 citations · 27 references
Computer Science

TL;DR

This paper proposes a novel framework for multivariate time-series anomaly detection that leverages adversarial learning and contrastive loss within a sequence-based Variational Autoencoder (VAE) architecture, and introduces encoder and decoder adaptor layers that align feature distributions across domains while preserving contextual semantics.

Abstract

Anomaly detection in Internet of Things (IoT) networks presents unique challenges due to the diversity of devices, lack of labeled data, and domain variability across environments. In this paper, we propose a novel framework for multivariate time-series anomaly detection that leverages adversarial learning and contrastive loss within a sequence-based Variational Autoencoder (VAE) architecture. Our method enables zero-shot domain adaptation by jointly optimizing domain-invariant latent representations and semantically structured embedding spaces, without requiring labeled data or raw feature transfer. To address the heterogeneity of IoT deployments, we introduce encoder and decoder adaptor layers that align feature distributions across domains while preserving contextual semantics. Additionally, we propose a destination-based segmentation strategy to better model real-world communication structures in IoT traffic. Our framework is comprehensively evaluated on six distinct datasets spanning industrial, enterprise, general-purpose, smart home, and military automation domains across 44 transfer scenarios. Experimental results demonstrate strong zero-shot generalization in several cross-domain settings and competitive performance against a contrastive domain-adaptation baseline under realistic, heterogeneous, and privacy-constrained IoT conditions.

View source

Similar papers

Open access Sep 2026

Unsupervised Domain Adaptation for Malicious Network Traffic Detection in Heterogeneous Internet Environments

The increasing heterogeneity of network traffic and the rapid evolution of cyberattacks pose significant challenges for malicious traffic detection. Traditional intrusion detection approaches, which rely on handcrafted features and static assumptions about traffic distributions, often exhibit limited robustness when ap...

Mukhtar Ahmed, Jin-Fu Chen, Ajmal Latif et al. · 0 citations
Open access Aug 2026

Zero-Shot Cross-Domain Anomaly Detection for Water ICS: A PLC-Based Dataset and Transfer Learning Evaluation Across Heterogeneous Benchmarks

This study proposes a zero-shot cross-domain intrusion detection framework for industrial control systems (ICS) using a canonical feature representation and domain-adversarial learning. While prior approaches relied on labeled target data, the proposed method generalizes across heterogeneous SCADA datasets without targ...

Tosin Akinsowon, Razaq Jinad, Amar Rasheed et al. · 1 citation
2026

STNet: Multi-Scale Spatiotemporal Learning and Adaptive Fusion for Few-Shot Tor Traffic Classification

The Tor network’s anonymity is increasingly exploited for cybercrime, creating a demand for accurate traffic classification under strict few-shot constraints. While recent efforts like WF-Transformer demonstrate strong temporal modeling capabilities, they still require abundant labeled data and struggle to generalize u...

De-Peng Xu, Guo-Zhen Cheng, Hong-Chao Hu et al. · 0 citations
Open access Aug 2026

Unsupervised deep learning for IoT botnet detection in a surveillance VLAN via multi-source traffic, threat intelligence and honeypot corroboration

The increase in internet of thing devices, especially within VLANs in corporate networks, introduces significant security risks from advanced botnet attacks. Traditional signature-based detection methods struggle to identify encrypted, stealthy command-and-control traffic, while high false-positive rates overwhelm secu...

Özkan Zeybek, Hasan Güler · 0 citations
Open access Sep 2026

A variational autoencoder attention fusion model for zero-day exploit behavior detection VAE-AttNet

Zero-day exploit (ZDE) attacks are among the most severe threats to critical infrastructures such as cloud computing, industrial control, smart grids, and connected vehicles, owing to their unknown, stealthy, and highly destructive nature. Traditional signature- and rule-based intrusion detection is largely ineffective...

Xian-Jun Yang, Zheng Zhao, Li-Peng Wang et al. · 0 citations
Open access Sep 2026

AD-FIT: industrial anomaly detection via fusion of IoT sensing and network traffic data

Anomaly detection is an important research topic in the Industrial Internet of Things (IIoT). In recent years, deep learning has been exploited to analyze complex IIoT data and build anomaly detection models. Due to the lack of abnormal samples and the difficulty of labeling industrial data, unsupervised deep learning...

Fei Wang, Lei Wang, Ming-Qi Lv et al. · 0 citations

Related blog posts

MIT News · Artificial Intelligence Oct 7, 2026

Discovering the value of humanistic inquiry

Students in MIT’s Concourse program delve deeply into the human condition, debate challenging questions, and learn to develop judgment about issues that can’t be quantified.

Microsoft Research Blog Oct 7, 2026

Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses

Training AI agents with reinforcement learning can be challenging because their tools, context, and decision-making are managed by complex frameworks. Agent Lightning connects existing agents to RL training, making it easier to improve them without rebuilding them. The post Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses appeared first on Microsoft Research.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.