Roberto Pazzi, Università degli Studi dell’Insubria, Italy
Davide Facheris, Università degli Studi dell’Insubria, Italy
Davide Tosi, Università degli Studi dell’Insubria, Italy
—Digital Twin (DT) ecosystems—including low-power IoT networks, cyber-physical systems, and virtual replicas of industrial assets—are highly vulnerable to zero-day threats that exploit the semantic gap between physical states and virtual expectations. These environments face challenges such as heterogeneous device topologies, evolving data distributions (concept drift), and limited computational resources, all of which undermine traditional Intrusion Detection Systems (IDSs). Existing methods often produce high false positives due to opaque statistical models that fail to distinguish benign traffic bursts from genuine attacks, or lack the adaptability to update their threat models in real-time. To address this, we introduce Ψ-Risk-DT, a neurosymbolic framework that integrates entropy-based anomaly detection with an Associated Random Neural Network (ARNN) and a semantic reasoning layer based on RDF/SPARQL. A key neurosymbolic operator, Ψ, couples neural pattern recognition with dynamic se mantic updates, triggering adaptive analysis when entropy spikes indicate potential zero-day behaviour. Additionally, a Modular Semantic Update (MSU) mechanism rewrites only the relevant portions of the knowledge graph, minimizing computational overhead in resource-constrained environments. The architecture is optimized via a hybrid loss function balancing detection accuracy, graph consistency, and semantic alignment. Evaluated on out-of-distribution variants of established IoT/DT benchmarks (Kitsune, WiseML 2024, Sec4ML 2023), Ψ-Risk-DT detects zero-day threat patterns without relying on known signatures, achieving 85–95% detection rates for unseen attacks. It reduces false positives by 20–40% compared to state of-the-art baselines, delivers sub-second latency (≈ 247ms, a 30% improvement over neural-only IDSs), and cuts symbolic processing load by up to 88% through MSU. Overall, Ψ-Risk-DT provides resilient and explainable protec tion for DT ecosystems, enabling real-time identification of zero day threats with low overhead and traceable reasoning pathways. This advances neurosymbolic cybersecurity for IoT and paves the way for adaptive defenses in critical infrastructures.