<?xml version="1.0" encoding="UTF-8"?>
<article article-type="review-article" xml:lang="en" xmlns:xlink="http://www.w3.org/1999/xlink">
<front>
<journal-meta>
<journal-id journal-id-type="publisher">global-journal-of-computer-science-and-technology-e-network-web-security</journal-id>
<journal-title-group>
<journal-title>Global Journal of Computer Science and Technology - E: Network, Web &amp; Security</journal-title>
</journal-title-group>
<issn publication-format="print">0975-4350</issn>
<issn publication-format="electronic">0975-4172</issn>
<publisher><publisher-name>Global Journals Publishing Group Incorporated</publisher-name></publisher>
<self-uri xlink:href="https://globaljournals.org/journal-seo-export/jats/254066.xml" />
</journal-meta>
<article-meta>
<article-id pub-id-type="doi">10.34257/GJCSTE254066</article-id>
<article-id pub-id-type="publisher-id">254066</article-id>
<title-group>
<article-title>Unsupervised Deep Autoencoder for Zero-Day Anomaly Detection in Network Traffic: A Review by the Authors</article-title>
<subtitle>Deep Autoencoders for Zero-Day Anomaly Detection</subtitle>
</title-group>
<contrib-group>
<contrib contrib-type="author"><name><surname>Kanubhai</surname><given-names>Isamaliya</given-names></name><xref ref-type="aff" rid="aff1" />
</contrib>
<contrib contrib-type="author"><name><surname>Ghode</surname><given-names>Sushma</given-names></name><xref ref-type="aff" rid="aff2" />
</contrib>
<contrib contrib-type="author"><name><surname>Singh</surname><given-names>Chaitanya</given-names></name></contrib>
</contrib-group>
<aff id="aff1">India, Vidhyadeep University</aff>
<aff id="aff2">India, VIEAT</aff>
<pub-date publication-format="electronic" date-type="pub" iso-8601-date="2026-07-10">
<day>10</day>
<month>07</month>
<year>2026</year>
</pub-date>
<volume>26</volume>
<issue>1</issue>
<abstract><p>Zero-day attacks are among the most serious problems in today’s network security because these attacks exploit unknown vulnerabilities and are able to evade classical signature-based intrusion detection systems. Recently, great success has been achieved in the application of deep learning, especially unsupervised deep autoencoders, in detecting anomalous patterns in the traffic data without relying on labeled attack data. The autoencoders are able to learn the representation of normal traffic and detect anomalies based on reconstruction errors. This review presents a thorough examination of the existing unsupervised deep autoencoder-based methods and their combination models proposed for zero-day anomaly detection in network traffic. The relevant work is critically analyzed from the perspective of model design, datasets, validation practices, and the ability to handle unknown anomalies. The recent advancements in the field with the evolution of convolutional, variational, temporal, and attention-driven autoencoders are also presented. Although these models demonstrated excellent results, the problem of high false positives, unstandardized zero-day validation, lack of interpretability, and practical deployability limitations exists. Finally, the discussion ends with addressing future directions toward an adaptive and interpretable autoencoder-based intrusion detection system.</p></abstract>
<kwd-group kwd-group-type="author-generated">
<kwd>Deep Autoencoder</kwd>
<kwd>Zero-Day Attack</kwd>
<kwd>Unsupervised Learning</kwd>
<kwd>Intrusion Detection</kwd>
<kwd>Network Security</kwd>
<kwd>Anomaly Detection.</kwd>
</kwd-group>
<self-uri content-type="pdf" xlink:href="https://doc.globaljournals.org:/luona4_254066/article/deep-autoencoders-for-zero-day-anomaly-detection.pdf?v=2cd63b891fc8#" />
<self-uri content-type="html" xlink:href="https://globaljournals.org/scholarly-articles/unsupervised-deep-autoencoder-for-zero-day-anomaly-detection-in-network-traffic/" />
</article-meta>
</front>
<body>
<sec>
<title>Full Text</title>
<p>Zero-day attacks are among the most serious problems in today’s network security because these attacks exploit unknown vulnerabilities and are able to evade classical signature-based intrusion detection systems. Recently, great success has been achieved in the application of deep learning, especially unsupervised deep autoencoders, in detecting anomalous patterns in the traffic data without relying on labeled attack data. The autoencoders are able to learn the representation of normal traffic and detect anomalies based on reconstruction errors.
This review presents a thorough examination of the existing unsupervised deep autoencoder-based methods and their combination models proposed for zero-day anomaly detection in network traffic. The relevant work is critically analyzed from the perspective of model design, datasets, validation practices, and the ability to handle unknown anomalies. The recent advancements in the field with the evolution of convolutional, variational, temporal, and attention-driven autoencoders are also presented. Although these models demonstrated excellent results, the problem of high false positives, unstandardized zero-day validation, lack of interpretability, and practical deployability limitations exists. Finally, the discussion ends with addressing future directions toward an adaptive and interpretable autoencoder-based intrusion detection system.</p>
</sec>
</body>
</article>