Search

Ψ-Risk-DT: A Neurosymbolic Framework for Adaptive Zero-Day Threat Detection in Digital Twin Ecosystems

Contribution type: article

Title: Ψ-Risk-DT: A Neurosymbolic Framework for Adaptive Zero-Day Threat Detection in Digital Twin Ecosystems

Authors:

Roberto Pazzi, Università degli Studi dell’Insubria, Italy
Davide Facheris, Università degli Studi dell’Insubria, Italy
Davide Tosi, Università degli Studi dell’Insubria, Italy

Keywords: Digital Twins; Zero-Day Threat Detection; Neurosymbolic Cybersecurity; Entropy-Based Anomaly Detection; Explainable Intrusion Detection

Abstract:

—Digital Twin (DT) ecosystems—including low-power IoT networks, cyber-physical systems, and virtual replicas of industrial assets—are highly vulnerable to zero-day threats that exploit the semantic gap between physical states and virtual expectations. These environments face challenges such as heterogeneous device topologies, evolving data distributions (concept drift), and limited computational resources, all of which undermine traditional Intrusion Detection Systems (IDSs). Existing methods often produce high false positives due to opaque statistical models that fail to distinguish benign traffic bursts from genuine attacks, or lack the adaptability to update their threat models in real-time. To address this, we introduce Ψ-Risk-DT, a neurosymbolic framework that integrates entropy-based anomaly detection with an Associated Random Neural Network (ARNN) and a semantic reasoning layer based on RDF/SPARQL. A key neurosymbolic operator, Ψ, couples neural pattern recognition with dynamic se mantic updates, triggering adaptive analysis when entropy spikes indicate potential zero-day behaviour. Additionally, a Modular Semantic Update (MSU) mechanism rewrites only the relevant portions of the knowledge graph, minimizing computational overhead in resource-constrained environments. The architecture is optimized via a hybrid loss function balancing detection accuracy, graph consistency, and semantic alignment. Evaluated on out-of-distribution variants of established IoT/DT benchmarks (Kitsune, WiseML 2024, Sec4ML 2023), Ψ-Risk-DT detects zero-day threat patterns without relying on known signatures, achieving 85–95% detection rates for unseen attacks. It reduces false positives by 20–40% compared to state of-the-art baselines, delivers sub-second latency (≈ 247ms, a 30% improvement over neural-only IDSs), and cuts symbolic processing load by up to 88% through MSU. Overall, Ψ-Risk-DT provides resilient and explainable protec tion for DT ecosystems, enabling real-time identification of zero day threats with low overhead and traceable reasoning pathways. This advances neurosymbolic cybersecurity for IoT and paves the way for adaptive defenses in critical infrastructures.

Publication Date: June 7, 2026

Presented during:

Dates: June 7, 2026 to June 11, 2026

Location: Porto, Portugal

Venue:

Hotel Novotel Porto Gaia

Rua Martir Sao Sebastiao, Afurada,
4400-499 Vila Nova de Gaia

Hotel website

Copyright (c) DTR Society, 2026

Contact Us

Proposals

The submission system is currently being prepared. We invite you to subscribe to the newsletter so you will be the first to know when it goes online.