HADAR-UAV: Risk-Calibrated One-Class Learning Framework for Zero-Day Intrusion Detection in Unmanned Aerial Vehicle Networks

Citation

Şahin, Canan Batur and Razak, Siti Fatimah Abdul and Ullah, Arif and Gündüz, Ali Fatih and Nawi, Nazri Mohd (2026) HADAR-UAV: Risk-Calibrated One-Class Learning Framework for Zero-Day Intrusion Detection in Unmanned Aerial Vehicle Networks. Computers, Materials & Continua, 89 (1). pp. 1-10. ISSN 1546-2226

[img] Text
HADAR-UAV_ Risk-Calibrated One-Class Learning Framework for Zero-Day Intrusion Detection in Unmanned Aerial Vehicle Networks.pdf - Published Version
Restricted to Repository staff only

Download (3MB)

Abstract

Unmanned Aerial Vehicle (UAV) networks face escalating cybersecurity threats, especially from zero-day attacks that exploit previously unknown vulnerabilities. To address this, we present HADAR-UAV (Hybrid Anomaly Detection with Adaptive Risk-calibration for UAV). This novel intrusion detection framework integrates masked autoencoder representation learning with Deep Support Vector Data Description (Deep SVDD) under conformal prediction guarantees to calibrate risk. Our method overcomes three critical limitations of existing approaches: (i) over- reliance on attack signatures, (ii) lack of statistical guarantees on false alarm rates, and (iii) insufficient robustness in feature extraction under partial observation. Using a rigorous Leave-Two-Attack-Families-Out (L2AFO) evaluation protocol on the UAVIDS-2025 benchmark, HADAR-UAV achieves strong zero-day detection—0.997 ± 0.001 ROC- AUC and 0.992 ± 0.002 F1-Score—while empirically maintaining a target false alarm rate through conformal calibration applied to deterministic scores. All results are reported as mean ± standard deviation across 20 independent runs (5 seeds × 4 folds) and show statistically significant improvement (paired t-test, p < 0.01) over current one-class methods. Ablation studies confirm that every architectural component adds measurable value to the framework. Additional cross-dataset validation on NSL-KDD under a one-class zero-day-inspired setting further indicates that the proposed framework generalizes beyond MAVLink-specific traffic patterns.

Item Type: Article
Uncontrolled Keywords: UAV cybersecurity, intrusion detection
Subjects: Q Science > QA Mathematics > QA71-90 Instruments and machines > QA75.5-76.95 Electronic computers. Computer science
Divisions: Faculty of Information Science and Technology (FIST)
Depositing User: Ms Rosnani Abd Wahab
Date Deposited: 04 Sep 2026 02:45
Last Modified: 04 Sep 2026 02:45
URII: http://shdl.mmu.edu.my/id/eprint/16688

Downloads

Downloads per month over past year

View ItemEdit (login required)