Pertanika Journal of Science & Technology
Pertanika Journal Home Facebook
Pertanika · Universiti Putra Malaysia Press

Pertanika Journal of Science & Technology

Official journal of Universiti Putra Malaysia for scholarly work across science, engineering and related technologies.

e-ISSN 2231-8526 ISSN 0128-7680
Research article

A Zero-shot Foundation Model Approach for Real-time Adaptive Cyber Threat Detection

Muhmmad Al-Khiza’ay and Noora Alallaq

https://doi.org/10.47836/pjst.34.3.09
KeywordsAdaptive intrusion detection, foundation models for security, LLM-driven threat intelligence, real-time semantic cyber defence, zero-shot cyber threat detection
Article content

Abstract

In view of the fundamental limitations of standard machine learning methods, which primarily depend on actual and labelled attack data, the identification of novel and zero-day cyber-attacks continues to be an essential and continuing difficulty in cybersecurity. Techniques become vulnerable to emerging attack vectors, considering these models often do not apply beyond identified threat classes. To overcome this limitation, present ZTFER (Zero-Shot Threat Identification through Foundation model-aided Embedding and Reasoning), a Zero-Shot threat identification model which utilises the basis model semantic embedding to detect threats which had not been observed before without needing retraining. Through combining natural language threat characterisations and real-time system activity into a common semantic space, ZTFER implements zero-shot learning and makes it achievable to classify unnoticed threats by considering contextual similarities. Furthermore, present A-SENT, a real-time responsive inference method which dynamically evaluates and addresses threat conduct through integrating Large Language Model (LLM) reasoning in real-time threat analysis updates. The proposed ZTFER model obtained a zero-day detection score of 58.9% and an accuracy of classifying 91.3%, outperforming the traditional and few-shot baselines. The experimental results demonstrate that ZTFER can be more effective and have better generalisation capability for detecting known and unknown cyber-attacks. The proposed framework does away with the requirement for continuing retraining and enables quick response to emerging threats. Creating powerful, scalable, and smart defence mechanisms able to recognise and understand new security threats in real time becomes achievable in a significant way by this research.