{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T06:10:06Z","timestamp":1784873406349,"version":"3.55.0"},"publisher-location":"Cham","reference-count":39,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032006264","type":"print"},{"value":"9783032006271","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-032-00627-1_18","type":"book-chapter","created":{"date-parts":[[2025,8,9]],"date-time":"2025-08-09T04:21:58Z","timestamp":1754713318000},"page":"365-386","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Augmented Tabular Adversarial Evasion Attacks with\u00a0Constraint Satisfaction Guarantees"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-4803-2744","authenticated-orcid":false,"given":"Nour","family":"Alhussien","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2609-1428","authenticated-orcid":false,"given":"Gagan","family":"Agrawal","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4337-1488","authenticated-orcid":false,"given":"Ahmed","family":"Aleroud","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,8,10]]},"reference":[{"key":"18_CR1","doi-asserted-by":"crossref","unstructured":"Abu-Nimeh, S., Nappa, D., Wang, X., Nair, S.: A comparison of machine learning techniques for phishing detection. In: Proceedings of the Anti-Phishing Working Groups 2nd Annual eCrime Researchers Summit, pp. 60\u201369 (2007)","DOI":"10.1145\/1299015.1299021"},{"key":"18_CR2","doi-asserted-by":"publisher","first-page":"14410","DOI":"10.1109\/ACCESS.2018.2807385","volume":"6","author":"N Akhtar","year":"2018","unstructured":"Akhtar, N., Mian, A.: Threat of adversarial attacks on deep learning in computer vision: a survey. IEEE Access 6, 14410\u201314430 (2018)","journal-title":"IEEE Access"},{"key":"18_CR3","doi-asserted-by":"crossref","unstructured":"Alhussien, N., Aleroud, A., Melhem, A., Khamaiseh, S.Y.: Constraining adversarial attacks on network intrusion detection systems: transferability and defense analysis. IEEE Trans. Netw. Serv. Manag. (2024)","DOI":"10.1109\/TNSM.2024.3357316"},{"key":"18_CR4","doi-asserted-by":"crossref","unstructured":"Almseidin, M., Alzubi, M., Kovacs, S., Alkasassbeh, M.: Evaluation of machine learning algorithms for intrusion detection system. In: 2017 IEEE 15th International Symposium on Intelligent Systems and Informatics (SISY), pp. 000277\u2013000282. IEEE (2017)","DOI":"10.1109\/SISY.2017.8080566"},{"issue":"2","key":"18_CR5","first-page":"226","volume":"5","author":"RH Alvi","year":"2021","unstructured":"Alvi, R.H., Rahman, M.H., Khan, A., Rahman, R.M.: Deep learning approach on tabular data to predict early-onset neonatal sepsis. J. Inf. Telecommun. 5(2), 226\u2013246 (2021)","journal-title":"J. Inf. Telecommun."},{"key":"18_CR6","doi-asserted-by":"publisher","unstructured":"Apruzzese, G., Conti, M., Yuan, Y.: Spacephish: the evasion-space of adversarial attacks against phishing website detectors using machine learning. In: Proceedings of the 38th Annual Computer Security Applications Conference, pp. 171\u2013185. ACM (2022). https:\/\/doi.org\/10.1145\/3564625.3567980","DOI":"10.1145\/3564625.3567980"},{"key":"18_CR7","unstructured":"Ballet, V., Renard, X., Aigrain, J., Laugel, T., Frossard, P., Detyniecki, M.: Imperceptible adversarial attacks on tabular data. arXiv preprint arXiv:1911.03274 (2019)"},{"key":"18_CR8","doi-asserted-by":"crossref","unstructured":"Behjati, M., Moosavi-Dezfooli, S.M., Baghshah, M.S., Frossard, P.: Universal adversarial attacks on text classifiers. In: ICASSP 2019-2019 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), pp. 7345\u20137349. IEEE (2019)","DOI":"10.1109\/ICASSP.2019.8682430"},{"key":"18_CR9","doi-asserted-by":"crossref","unstructured":"Ben-Tov, M., Deutch, D., Frost, N., Sharif, M.: CaFa: cost-aware, feasible attacks with database constraints against neural tabular classifiers. In: 2024 IEEE Symposium on Security and Privacy (SP), pp. 227\u2013227. IEEE Computer Society (2024)","DOI":"10.1109\/SP54263.2024.00218"},{"key":"18_CR10","unstructured":"Cartella, F., Anunciacao, O., Funabiki, Y., Yamaguchi, D., Akishita, T., Elshocht, O.: Adversarial attacks for tabular data: application to fraud detection and imbalanced data. arXiv preprint arXiv:2101.08030 (2021)"},{"key":"18_CR11","doi-asserted-by":"publisher","unstructured":"Chen, J., Jordan, M.I., Wainwright, M.J.: HopSkipJumpAttack: a query-efficient decision-based adversarial attack. In: 2020 IEEE Symposium on Security and Privacy, pp. 1277\u20131294. IEEE (2020). https:\/\/doi.org\/10.1109\/SP40000.2020.00045","DOI":"10.1109\/SP40000.2020.00045"},{"key":"18_CR12","doi-asserted-by":"publisher","unstructured":"Chen, P.Y., Zhang, H., Sharma, Y., Yi, J., Hsieh, C.J.: ZOO: zeroth order optimization based black-box attacks to deep neural networks without training substitute models. In: Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security, pp. 15\u201326. ACM (2017). https:\/\/doi.org\/10.1145\/3128572.3140448","DOI":"10.1145\/3128572.3140448"},{"issue":"4","key":"18_CR13","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3544746","volume":"25","author":"A Chernikova","year":"2022","unstructured":"Chernikova, A., Oprea, A.: FENCE: feasible evasion attacks on neural networks in constrained environments. ACM Trans. Priv. Secur. 25(4), 1\u201334 (2022). https:\/\/doi.org\/10.1145\/3544746","journal-title":"ACM Trans. Priv. Secur."},{"key":"18_CR14","unstructured":"Clements, J.M., Xu, D., Yousefi, N., Efimov, D.: Sequential deep learning for credit risk monitoring with tabular financial data. arXiv preprint arXiv:2012.15330 (2020)"},{"key":"18_CR15","doi-asserted-by":"publisher","first-page":"50426","DOI":"10.1109\/ACCESS.2021.3068854","volume":"9","author":"X Dastile","year":"2021","unstructured":"Dastile, X., Celik, T.: Making deep learning-based predictions for credit scoring explainable. IEEE Access 9, 50426\u201350440 (2021)","journal-title":"IEEE Access"},{"key":"18_CR16","doi-asserted-by":"publisher","unstructured":"Granados, A., Miah, M.S., Ortiz, A., Kiekintveld, C.: A realistic approach for network traffic obfuscation using adversarial machine learning. In: Decision and Game Theory for Security, pp. 45\u201357. Springer (2020). https:\/\/doi.org\/10.1007\/978-3-030-64793-3_3","DOI":"10.1007\/978-3-030-64793-3_3"},{"key":"18_CR17","doi-asserted-by":"crossref","unstructured":"Guo, C., Sablayrolles, A., J\u00e9gou, H., Kiela, D.: Gradient-based adversarial attacks against text transformers. arXiv preprint arXiv:2104.13733 (2021)","DOI":"10.18653\/v1\/2021.emnlp-main.464"},{"key":"18_CR18","doi-asserted-by":"publisher","first-page":"104347","DOI":"10.1016\/j.engappai.2021.104347","volume":"104","author":"A Hannousse","year":"2021","unstructured":"Hannousse, A., Yahiouche, S.: Towards benchmark datasets for machine learning based website phishing detection: an experimental study. Eng. Appl. Artif. Intell. 104, 104347 (2021). https:\/\/doi.org\/10.1016\/j.engappai.2021.104347","journal-title":"Eng. Appl. Artif. Intell."},{"key":"18_CR19","doi-asserted-by":"publisher","unstructured":"Hashemi, M.J., Cusack, G., Keller, E.: Towards evaluation of NIDSs in adversarial setting. In: Proceedings of the 3rd ACM CoNEXT Workshop on Big DAta, Machine Learning and Artificial Intelligence for Data Communication Networks, pp. 14\u201321. ACM (2019). https:\/\/doi.org\/10.1145\/3359992.3366642","DOI":"10.1145\/3359992.3366642"},{"key":"18_CR20","unstructured":"Kaggle: All lending club loan data (2019). https:\/\/www.kaggle.com\/datasets\/wordsforthewise\/lending-club"},{"key":"18_CR21","doi-asserted-by":"crossref","unstructured":"Kireev, K., Kulynych, B., Troncoso, C.: Adversarial robustness for tabular data through cost and utility awareness. arXiv preprint arXiv:2208.13058 (2022)","DOI":"10.14722\/ndss.2023.24924"},{"key":"18_CR22","unstructured":"Kurakin, A., Goodfellow, I., Bengio, S.: Adversarial Machine Learning at Scale. arXiv preprint arXiv:1611.01236 (2016)"},{"key":"18_CR23","doi-asserted-by":"publisher","unstructured":"Li, J., Yang, Y., Sun, J.S., Tomsovic, K., Qi, H.: ConAML: constrained adversarial machine learning for cyber-physical systems. In: Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security, pp. 52\u201366. ACM (2021). https:\/\/doi.org\/10.1145\/3433210.3437513","DOI":"10.1145\/3433210.3437513"},{"key":"18_CR24","doi-asserted-by":"publisher","first-page":"107332","DOI":"10.1016\/j.patcog.2020.107332","volume":"110","author":"X Ma","year":"2021","unstructured":"Ma, X., et al.: Understanding adversarial attacks on deep learning based medical image analysis systems. Pattern Recogn. 110, 107332 (2021). https:\/\/doi.org\/10.1016\/j.patcog.2020.107332","journal-title":"Pattern Recogn."},{"key":"18_CR25","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. In: International Conference on Learning Representations, pp. 1\u201323. OpenReview (2018). https:\/\/openreview.net\/forum?id=rJzIBfZAb"},{"key":"18_CR26","doi-asserted-by":"publisher","unstructured":"Moustafa, N., Creech, G., Slay, J.: Big data analytics for intrusion detection system: statistical decision-making using finite dirichlet mixture models. In: Data Analytics and Decision Support for Cybersecurity, pp. 127\u2013156. Springer (2017). https:\/\/doi.org\/10.1007\/978-3-319-59439-2_5","DOI":"10.1007\/978-3-319-59439-2_5"},{"key":"18_CR27","doi-asserted-by":"publisher","unstructured":"Moustafa, N., Slay, J.: UNSW-NB15: a comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). In: 2015 Military Communications and Information Systems Conference (MilCIS), pp.\u00a01\u20136. IEEE (2015). https:\/\/doi.org\/10.1109\/MilCIS.2015.7348942","DOI":"10.1109\/MilCIS.2015.7348942"},{"issue":"1\u20133","key":"18_CR28","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1080\/19393555.2015.1125974","volume":"25","author":"N Moustafa","year":"2016","unstructured":"Moustafa, N., Slay, J.: The evaluation of network anomaly detection systems: statistical analysis of the UNSW-NB15 data set and the comparison with the KDD99 data set. Inf. Secur. J. A Glob. Perspect. 25(1\u20133), 18\u201331 (2016). https:\/\/doi.org\/10.1080\/19393555.2015.1125974","journal-title":"Inf. Secur. J. A Glob. Perspect."},{"issue":"4","key":"18_CR29","doi-asserted-by":"publisher","first-page":"481","DOI":"10.1109\/TBDATA.2017.2715166","volume":"5","author":"N Moustafa","year":"2017","unstructured":"Moustafa, N., Slay, J., Creech, G.: Novel geometric area analysis technique for anomaly detection using trapezoidal area estimation on large-scale networks. IEEE Trans. Big Data 5(4), 481\u2013494 (2017). https:\/\/doi.org\/10.1109\/TBDATA.2017.2715166","journal-title":"IEEE Trans. Big Data"},{"key":"18_CR30","unstructured":"Nicolae, M.-I., et al.: Adversarial robustness toolbox v1.15.0 (2023). https:\/\/github.com\/Trusted-AI\/adversarial-robustness-toolbox"},{"key":"18_CR31","doi-asserted-by":"crossref","unstructured":"Rusch, N., Jodeiri\u00a0Akbarfam, A., Maleki, H., Agrawal, G., Dorai, G.: Classify me correctly if you can: evaluating adversarial machine learning threats in NIDS. In: Security and Privacy in Communication Networks. Springer (2023)","DOI":"10.1007\/978-3-031-64948-6_1"},{"key":"18_CR32","doi-asserted-by":"publisher","unstructured":"Sarhan, M., Layeghy, S., Moustafa, N., Portmann, M.: NetFlow datasets for machine learning-based network intrusion detection systems. In: Big Data Technologies and Applications, pp. 117\u2013135. Springer (2020). https:\/\/doi.org\/10.1007\/978-3-030-72802-1_9","DOI":"10.1007\/978-3-030-72802-1_9"},{"key":"18_CR33","doi-asserted-by":"crossref","unstructured":"Sch\u00f6nherr, L., Kohls, K., Zeiler, S., Holz, T., Kolossa, D.: Adversarial attacks against automatic speech recognition systems via psychoacoustic hiding. arXiv preprint arXiv:1808.05665 (2018)","DOI":"10.14722\/ndss.2019.23288"},{"key":"18_CR34","unstructured":"Sheatsley, R., Papernot, N., Weisman, M., Verma, G., McDaniel, P.: Adversarial examples in constrained domains. arXiv preprint arXiv:2011.01183 (2020)"},{"key":"18_CR35","doi-asserted-by":"publisher","unstructured":"Simonetto, T., Dyrmishi, S., Ghamizi, S., Cordy, M., Le\u00a0Traon, Y.: A unified framework for adversarial attack and defense in constrained feature space. In: Proceedings of the Thirty-First International Joint Conference on Artificial Intelligence, IJCAI-22, pp. 1313\u20131319. International Joint Conferences on Artificial Intelligence Organization (2022). https:\/\/doi.org\/10.24963\/ijcai.2022\/183","DOI":"10.24963\/ijcai.2022\/183"},{"key":"18_CR36","unstructured":"Simonetto, T., Dyrmishi, S., Ghamizi, S., Cordy, M., Le\u00a0Traon, Y.: Constrained attacks (C-PGD) source code, v0.1.2 (2023). https:\/\/github.com\/serval-uni-lu\/constrained-attacks"},{"key":"18_CR37","unstructured":"Simonetto, T., Ghamizi, S., Cordy, M.: Constrained adaptive attack: effective adversarial attack against deep neural networks for tabular data. arXiv preprint arXiv:2406.00775 (2024)"},{"key":"18_CR38","doi-asserted-by":"publisher","unstructured":"Taori, R., Kamsetty, A., Chu, B., Vemuri, N.: Targeted adversarial examples for black box audio systems. In: 2019 IEEE Security and Privacy Workshops (SPW), pp. 15\u201320. IEEE (2019). https:\/\/doi.org\/10.1109\/SPW.2019.00012","DOI":"10.1109\/SPW.2019.00012"},{"key":"18_CR39","doi-asserted-by":"publisher","unstructured":"Teuffenbach, M., Piatkowska, E., Smith, P.: Subverting network intrusion detection: crafting adversarial examples accounting for domain-specific constraints. In: Machine Learning and Knowledge Extraction, pp. 301\u2013320. Springer (2020). https:\/\/doi.org\/10.1007\/978-3-030-57321-8_17","DOI":"10.1007\/978-3-030-57321-8_17"}],"container-title":["Lecture Notes in Computer Science","Availability, Reliability and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-00627-1_18","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,8]],"date-time":"2025-09-08T18:26:21Z","timestamp":1757355981000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-00627-1_18"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9783032006264","9783032006271"],"references-count":39,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-00627-1_18","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"10 August 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ARES","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Availability, Reliability and Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Ghent","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Belgium","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"11 August 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 August 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ares-12025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/2025.ares-conference.eu","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}