Deep Learning-based Intrusion Detection Systems: A Survey
This paper addresses the limited generalization capability of deep learning–based intrusion detection systems (DL-IDS) in detecting zero-day attacks. To tackle this challenge, it presents the first holistic, full-stack analysis of DL-IDS technical evolution—spanning data acquisition, log parsing, behavioral graph modeling, attack detection, and forensic traceability. The authors propose a unified framework integrating convolutional neural networks (CNNs), recurrent neural networks (RNNs), graph neural networks (GNNs), and self-supervised representation learning, enhanced by structured log parsing and dynamic graph summarization techniques. The survey systematically categorizes 12 mainstream methodologies, benchmarks performance across 7 publicly available datasets, and identifies 5 fundamental challenges. As the first comprehensive panorama dedicated to zero-day attack generalization in DL-IDS, this work establishes both theoretical foundations and practical guidelines for intelligent, adaptive cybersecurity detection.