Sunday, September 13, 2026
Detecting Zero-Day Cyberattacks with Deep Reinforcement Learning: An Open-Set Intrusion Detection Approach | Research Work
Hi everyone, I am posting something on this blog after a decade. Good to see that my 11-year-old posts are still getting some views and is still somehow relevant even in the age of AI....
Open-Set Intrusion Detection and Semantic Analysis of Zero-Day Network Attacks Using Deep Reinforcement Learning and Large Language Models
by Shreyash Tiwari
The increasing prevalence of zero-day cyberattacks presents a significant challenge for modern Intrusion Detection Systems (IDS), as previously unseen network traffic often falls outside the distribution of supervised training data. Traditional deep learning-based IDS solutions operate under a closed-set assumption, requiring all attack categories to be known during training.
Consequently, novel attacks may be misclassified as benign traffic or incorrectly assigned to known attack classes, reducing the effectiveness of network defense mechanisms. Although recent open-set recognition approaches improve the detection of unknown traffic, they typically provide limited insight into the behavioral characteristics of detected anomalies, requiring additional manual investigation by security analysts.
This thesis presents a unified framework for open-set intrusion detection and semantic analysis of unknown network traffic by combining deep learning, reinforcement learning, and large language models. The proposed framework employs a Convolutional Neural Network (CNN) to learn feature representations from known network traffic classes and a Deep Q-Network (DQN) that uses SoftMax-derived uncertainty metrics, including maximum probability, probability gap, and Shannon entropy, to dynamically distinguish known from unknown traffic without manually defined confidence thresholds. To improve interpretability, a selective Large Language Model (LLM) reasoning module is applied only to traffic identified as unknown by the CNN-DQN pipeline. Unlike existing approaches that focus solely on detection or apply computationally expensive LLM reasoning across all traffic, the proposed framework combines efficient open-set detection with targeted semantic interpretation of suspicious network behavior.
Experimental evaluation was conducted using the CICIDS-2017 and UNSW-NB15 intrusion detection datasets. The CNN-DQN framework achieved a binary F1-score of 97.83% for known-versus-unknown traffic separation while maintaining strong performance on known attack classes and effectively identifying previously unseen attacks. Cross-dataset experiments demonstrated the framework’s ability to generalize to traffic distributions not observed during training. The LLM-assisted reasoning stage generated behaviorally aligned explanations for 77.5% of DQN-flagged unknown traffic samples and provided meaningful behavioral insights for an additional 22.1% of samples, demonstrating its effectiveness in supporting contextual interpretation of suspicious network activity.
The proposed framework contributes to the development of adaptive, explainable, and deployable intrusion detection systems capable of addressing evolving cyber threats. By combining uncertainty-aware open-set detection with semantic reasoning, the system enables security analysts, network administrators, and cybersecurity researchers to not only identify previously unseen attacks but also understand their underlying behavioral characteristics. This capability can support faster incident response, improved threat intelligence generation, and enhanced protection of enterprise, cloud, Internet of Things (IoT), and critical infrastructure environments against emerging cyber threats.
DOI: https://doi.org/10.62791/20638
Research Gate: https://www.researchgate.net/profile/Shreyash-Tiwari-6
Sunday, September 13, 2026 by Shreyash Tiwari · 0
Tuesday, August 11, 2015
simple problem easy solution recently i faced the same problem so i got the solution for everyone, hey bloggers if you are facing this problem don't worry here is a simple video tutorial for your problem!
Tuesday, August 11, 2015 by Shreyash Tiwari · 0
Monday, October 13, 2014
CAUTION:
don't update your idm!
Monday, October 13, 2014 by Shreyash Tiwari · 0
Saturday, October 11, 2014
hi... it's being a long time for me to post anything! but the wait is over here, i am with latest blog post!!!!!!!!!!!!!
idm full 6.21 free
proof:
Saturday, October 11, 2014 by Shreyash Tiwari · 0
Wednesday, December 4, 2013
they send a request to unknown people !

don't worry i have a solution just follow these simple steps.
![]() |
| Error message ! |
1. Here are the steps !
a) Open new text document (.txt) in notepad.
b) Add all the email addresses separated by a comma ( , ).
c) Now save that file with the extension .vcfNow this is your contact file.
2. Upload this file to Facebook. and you will be prompted to send friend request.
NOTE: To upload contact file and follow these steps.
http://www.facebook.com/?sk=ff Go to this link! In that the last option is of ‘other tools’ in which you will find the next option to upload the file!
3. Click “OK”and u are done.
Simple & effective trick
don'tcare about fbzzzzz blocks !
Wednesday, December 4, 2013 by Shreyash Tiwari · 0
Monday, November 4, 2013
here are some symlink video suggestion !!!! ..
--> not my property !
Monday, November 4, 2013 by Shreyash Tiwari · 0
Tuesday, September 10, 2013
*Internet Explorer
*Firefox
*Google Chrome
*Opera
*Safari
*Windows - Recycle Bin, Recent Documents, Temporary files and Log files.
*Registry cleaner
*Third-party applications
*100% Spyware FREE
Release Notes:
- Added command line option to reboot after cleaning (/AUTO /RESTART).
- Improved Firefox cleaning: Site Preferences, History and Startup items.
- Improved Internet Explorer 10 cleaning: Saved Passwords, Userdata Cookies and Last Download Location.
- Improved Internet Explorer 9 Last Download Location cleaning.
- Improved Opera Cache cleaning.
- Updated Startup items detection for Firefox and Google Chrome.
- Added Cookie management for multiple users (Pro Version).
- Improved Startup item management for multiple users on Windows 8 (Pro Version).
- Added cleaning for Express Scribe, Gom Player, Skype Metro App, Twitter Metro and Adobe Reader Touch.
- Improved cleaning for Microsoft Office 2013.
- Added Thai translation.
- Improved localization and language support.
1] Install The App
2] Use Cracker to Upgrade to Professional or Business Edition
3] Enjoy This Release!!
![]() |
| SCREENSHOT OF MY PC..!!!! :Download Here |
Tuesday, September 10, 2013 by Shreyash Tiwari · 0
Monday, September 9, 2013
What Is A Botnet ?
the botnet becomes more powerful.
it can be used for stealing data , sniff forms,keyloggers,bitcoin mining,ddos attacks.. etc!
Legal botnets
Illegal botnets
Concept of Botnet& how they work ?


Monday, September 9, 2013 by Shreyash Tiwari · 0
DroidSQLi supports the following injection techniques:
- Time based injection
- Blind injection
- Error based injection
- Normal injection
It automatically selects the best technique to use and employs some simple filter evasion methods.
Legal notice: this application is for educational purposes ONLY. No warranties of any kind are expressed or implied. Use at your own risk!
by Shreyash Tiwari · 0
Friday, September 6, 2013


Password: TRICKS4INDYA
Friday, September 6, 2013 by Shreyash Tiwari · 0
Blog Warning:
THIS WEBSITE IS BUILD BY ME ONLY FOR EDUCATIONAL PURPOSE I JUST WANT TO PROVIDE CYBER TIPS SO IF U USE THESE INFORMATION TO HARM ANY SUBSTANCE,COMMUNITY OR PERSON AND GOT CAUGHT THEN I AM NOT RESPONSIBLE FOR IT SO MIND MY WORDS HACKING IS A CYBER CRIME DON'T CHEAT OTHERS WITH YOUR POWERS
KNOWLEDGE IS FOR SHARING ASK-SHARE
STSHREYASH50@GMAIL.COM






