A Graph Neural Network-Driven Large Language Agent Framework for Autonomous Zero-Day Cyber Threat Detection and Adaptive Incident Response

Authors

  • Radha Rani. K 1 , Madhavi Godi 2 Author

DOI:

https://doi.org/10.62643/

Abstract

The rapid digital transformation of enterprise computing, cloud-native infrastructures, Industrial Internet of Things (IIoT), Software-Defined Networks (SDNs), edge computing, and critical cyber-physical systems has significantly expanded the modern cyberattack surface. Organizations increasingly rely on interconnected digital infrastructures comprising heterogeneous devices, distributed applications, cloud services, and intelligent autonomous systems that continuously exchange massive volumes of sensitive information. While this connectivity improves operational efficiency and business agility, it simultaneously creates opportunities for sophisticated cyber adversaries to exploit previously unknown software vulnerabilities, referred to as zero-day vulnerabilities. Zero-day attacks are particularly dangerous because they exploit vulnerabilities before security vendors release patches or detection signatures, rendering conventional signature-based intrusion detection systems, antivirus software, and rule-based security information and event management (SIEM) platforms largely ineffective. Furthermore, Advanced Persistent Threats (APTs) increasingly employ multi-stage attack strategies involving lateral movement, privilege escalation, command-and-control communication, and stealthy persistence, making early detection extremely challenging. This paper proposes a Graph Neural Network-Driven Large Language Agent Framework for autonomous zero-day cyber threat detection and adaptive incident response. The proposed architecture integrates Graph Neural Networks, Large Language Agents, Retrieval-Augmented Cyber Threat Intelligence, Knowledge Graphs, Reinforcement Learning, Explainable Artificial Intelligence (XAI), and autonomous Security Orchestration, Automation, and Response (SOAR) into a unified cybersecurity framework. The Graph Neural Network continuously learns structural relationships among network entities to detect anomalous behaviors indicative of zero-day attacks, while the Large Language Agent interprets threat intelligence, reasons over attack chains, generates incident reports, recommends mitigation strategies, and autonomously coordinates adaptive response actions. Experimental evaluation demonstrates significant improvements in zero-day attack detection accuracy, threat reasoning capability, false positive reduction, incident response time, explainability, and autonomous security orchestration compared with existing deep learning-based cybersecurity solutions. The proposed framework provides a scalable, intelligent, and trustworthy foundation for next-generation autonomous cyber defense systems capable of protecting complex enterprise and critical infrastructure environments.

Downloads

Published

19-03-2026

How to Cite

A Graph Neural Network-Driven Large Language Agent Framework for Autonomous Zero-Day Cyber Threat Detection and Adaptive Incident Response. (2026). International Journal of Engineering Research and Science & Technology, 22(1), 1929-1945. https://doi.org/10.62643/