{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,9]],"date-time":"2026-05-09T22:10:11Z","timestamp":1778364611564,"version":"3.51.4"},"publisher-location":"Cham","reference-count":29,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032190987","type":"print"},{"value":"9783032190994","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-19099-4_33","type":"book-chapter","created":{"date-parts":[[2026,5,9]],"date-time":"2026-05-09T22:08:09Z","timestamp":1778364489000},"page":"471-483","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["From One to\u00a0Many: Few-Shot Deep Ensembles for\u00a0Slow DoS Attack Detection"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2660-1432","authenticated-orcid":false,"given":"Alberto","family":"Falcone","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7711-9833","authenticated-orcid":false,"given":"Massimo","family":"Guarascio","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9402-7375","authenticated-orcid":false,"given":"Angelica","family":"Liguori","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2922-0835","authenticated-orcid":false,"given":"Francesco Sergio","family":"Pisani","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-5224-0910","authenticated-orcid":false,"given":"Francesco","family":"Scala","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,4,1]]},"reference":[{"issue":"1","key":"33_CR1","doi-asserted-by":"publisher","DOI":"10.1002\/ett.4150","volume":"32","author":"Z Ahmad","year":"2021","unstructured":"Ahmad, Z., Shahid Khan, A., Wai Shiang, C., Abdullah, J., Ahmad, F.: Network intrusion detection system: a systematic study of machine learning and deep learning approaches. Trans. Emerging Telecommun. Technol. 32(1), e4150 (2021)","journal-title":"Trans. Emerging Telecommun. Technol."},{"key":"33_CR2","doi-asserted-by":"crossref","unstructured":"AL-Essa, M., Andresini, G., Appice, A., Malerba, D.: PANACEA: a neural model ensemble for cyber-threat detection. Mach. Learn. 113(8), 5379\u20135422 (2024)","DOI":"10.1007\/s10994-023-06470-2"},{"key":"33_CR3","doi-asserted-by":"publisher","first-page":"706","DOI":"10.1016\/j.ins.2021.05.016","volume":"569","author":"G Andresini","year":"2021","unstructured":"Andresini, G., Appice, A., Malerba, D.: Autoencoder-based deep metric learning for network intrusion detection. Inf. Sci. 569, 706\u2013727 (2021)","journal-title":"Inf. Sci."},{"key":"33_CR4","doi-asserted-by":"crossref","unstructured":"Andresini, G., Pendlebury, F., Pierazzi, F., Loglisci, C., Appice, A., Cavallaro, L.: INSOMNIA: towards concept-drift robustness in network intrusion detection. In: Proceedings of the 14th ACM Workshop on Artificial Intelligence and Security, p. 111\u2013122 (2021)","DOI":"10.1145\/3474369.3486864"},{"key":"33_CR5","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2021.108399","volume":"199","author":"EM B\u00e5rli","year":"2021","unstructured":"B\u00e5rli, E.M., Yazidi, A., Viedma, E.H., Haugerud, H.: DoS and DDoS mitigation using Variational Autoencoders. Comput. Netw. 199, 108399 (2021)","journal-title":"Comput. Netw."},{"key":"33_CR6","doi-asserted-by":"crossref","unstructured":"Benedetti, G., Caviglione, L., Falcone, A., Ficco, M., Guarascio, M., Guerriero, A.: Detecting DDoS attacks in microservice architectures via AI-based agents. In: Computational Science and Its Applications - ICCSA 2025 Workshops, pp. 3\u201315 (2025)","DOI":"10.1007\/978-3-031-97603-2_1"},{"key":"33_CR7","doi-asserted-by":"crossref","unstructured":"Cassavia, N., Folino, F., Guarascio, M.: Detecting DoS and DDoS attacks through sparse U-Net-like autoencoders. In: 34th IEEE International Conference on Tools with Artificial Intelligence, pp. 1342\u20131346 (2022)","DOI":"10.1109\/ICTAI56018.2022.00203"},{"key":"33_CR8","doi-asserted-by":"crossref","unstructured":"Coppolillo, E., Liguori, A., Guarascio, M., Pisani, F.S., Manco, G.: Generative methods for out-of-distribution prediction and applications for threat detection and analysis: a short review. In: Digital Sovereignty in Cyber Security: New Challenges in Future Vision (CyberSec4Europe 2022), vol. 1807, pp. 65\u201379 (2022)","DOI":"10.1007\/978-3-031-36096-1_5"},{"key":"33_CR9","unstructured":"ENISA: ENISA Threat Landscape 2020 - List of top 15 threats (2020)"},{"key":"33_CR10","doi-asserted-by":"publisher","first-page":"48","DOI":"10.1016\/j.inffus.2021.02.007","volume":"72","author":"F Folino","year":"2021","unstructured":"Folino, F., Folino, G., Guarascio, M., Pisani, F., Pontieri, L.: On learning effective ensembles of deep neural networks for intrusion detection. Inf. Fusion 72, 48\u201369 (2021)","journal-title":"Inf. Fusion"},{"key":"33_CR11","doi-asserted-by":"publisher","first-page":"30","DOI":"10.1016\/j.future.2022.04.028","volume":"135","author":"M Guarascio","year":"2022","unstructured":"Guarascio, M., Cassavia, N., Pisani, F.S., Manco, G.: Boosting cyber-threat intelligence via collaborative intrusion detection. Futur. Gener. Comput. Syst. 135, 30\u201343 (2022)","journal-title":"Futur. Gener. Comput. Syst."},{"key":"33_CR12","first-page":"634","volume":"1\u20133","author":"M Guarascio","year":"2018","unstructured":"Guarascio, M., Manco, G., Ritacco, E.: Deep learning. Encyclopedia of Bioinformatics and Computational Biology: ABC of Bioinformatics 1\u20133, 634\u2013647 (2018)","journal-title":"Encyclopedia of Bioinformatics and Computational Biology: ABC of Bioinformatics"},{"key":"33_CR13","doi-asserted-by":"publisher","first-page":"35","DOI":"10.1016\/j.comnet.2019.04.027","volume":"158","author":"S Hosseini","year":"2019","unstructured":"Hosseini, S., Azizi, M.: The hybrid technique for DDoS detection with supervised learning algorithms. Comput. Netw. 158, 35\u201345 (2019)","journal-title":"Comput. Netw."},{"key":"33_CR14","doi-asserted-by":"crossref","unstructured":"Iliyasu, A.S., Abdurrahman, U.A., Zheng, L.: Few-shot network intrusion detection using discriminative representation learning with supervised autoencoder. Appl. Sci. 12(5) (2022)","DOI":"10.3390\/app12052351"},{"issue":"15","key":"33_CR15","doi-asserted-by":"publisher","first-page":"9731","DOI":"10.1007\/s00500-021-05893-0","volume":"25","author":"G Kocher","year":"2021","unstructured":"Kocher, G., Kumar, G.: Machine learning and deep learning methods for intrusion detection systems: recent developments and challenges. Soft. Comput. 25(15), 9731\u20139763 (2021)","journal-title":"Soft. Comput."},{"key":"33_CR16","doi-asserted-by":"crossref","unstructured":"Lin, T.Y., Goyal, P., Girshick, R., He, K., Doll\u00e1r, P.: Focal loss for dense object detection. In: 2017 IEEE International Conference on Computer Vision, pp. 2999\u20133007 (2017)","DOI":"10.1109\/ICCV.2017.324"},{"key":"33_CR17","doi-asserted-by":"crossref","unstructured":"Mabel, P., Nagappasetty, R.: An intelligent system to detect slow denial of service attacks in software-defined networks. Int. J. Electr. Comput. Eng. 13, 3099 (06 2023)","DOI":"10.11591\/ijece.v13i3.pp3099-3110"},{"issue":"2","key":"33_CR18","doi-asserted-by":"publisher","first-page":"275","DOI":"10.1007\/s10462-012-9338-y","volume":"42","author":"S Masoudnia","year":"2014","unstructured":"Masoudnia, S., Ebrahimpour, R.: Mixture of experts: a literature survey. Artif. Intell. Rev. 42(2), 275\u2013293 (2014)","journal-title":"Artif. Intell. Rev."},{"issue":"1","key":"33_CR19","doi-asserted-by":"publisher","first-page":"686","DOI":"10.1109\/COMST.2018.2847722","volume":"21","author":"P Mishra","year":"2019","unstructured":"Mishra, P., Varadharajan, V., Tupakula, U., Pilli, E.S.: A detailed investigation and analysis of using machine learning techniques for intrusion detection. IEEE Commun. Surv. Tutorials 21(1), 686\u2013728 (2019)","journal-title":"IEEE Commun. Surv. Tutorials"},{"key":"33_CR20","doi-asserted-by":"crossref","unstructured":"Nugraha, B., Murthy, R.N.: Deep Learning-based Slow DDoS Attack Detection in SDN-based Networks. In: 2020 IEEE Conference on Network Function Virtualization and Software Defined Networks, pp. 51\u201356 (2020)","DOI":"10.1109\/NFV-SDN50289.2020.9289894"},{"key":"33_CR21","doi-asserted-by":"crossref","unstructured":"Rios, V., Inacio, P., Magoni, D., Freire, M.: Detection of slowloris attacks using machine learning algorithms. In: Proceedings of the 39th ACM\/SIGAPP Symposium on Applied Computing, p. 1321\u20131330 (2024)","DOI":"10.1145\/3605098.3635919"},{"issue":"4","key":"33_CR22","doi-asserted-by":"publisher","first-page":"427","DOI":"10.1016\/j.ipm.2009.03.002","volume":"45","author":"M Sokolova","year":"2009","unstructured":"Sokolova, M., Lapalme, G.: A systematic analysis of performance measures for classification tasks. Inform. Process. Manage. 45(4), 427\u2013437 (2009)","journal-title":"Inform. Process. Manage."},{"issue":"4","key":"33_CR23","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1371\/journal.pone.0284632","volume":"18","author":"H Sun","year":"2023","unstructured":"Sun, H., Wan, L., Liu, M., Wang, B.: Few-Shot network intrusion detection based on prototypical capsule network with attention mechanism. PLoS ONE 18(4), 1\u201318 (2023)","journal-title":"PLoS ONE"},{"key":"33_CR24","first-page":"1","volume":"10","author":"D Tang","year":"2020","unstructured":"Tang, D., Dai, R., Tang, L., Li, X.: Low-rate DoS attack detection based on two-step cluster analysis and UTR analysis. HCIS 10, 1\u201320 (2020)","journal-title":"HCIS"},{"key":"33_CR25","doi-asserted-by":"publisher","DOI":"10.1016\/j.adhoc.2020.102145","volume":"102","author":"D Tang","year":"2020","unstructured":"Tang, D., Man, J., Tang, L., Feng, Y., Yang, Q.: WEDMS: An advanced mean shift clustering algorithm for LDoS attacks detection. Ad Hoc Netw. 102, 102145 (2020)","journal-title":"Ad Hoc Netw."},{"key":"33_CR26","doi-asserted-by":"publisher","first-page":"229","DOI":"10.1016\/j.ins.2021.02.038","volume":"565","author":"D Tang","year":"2021","unstructured":"Tang, D., Zhang, S., Chen, J., Wang, X.: The detection of low-rate DoS attacks using the SADBSCAN algorithm. Inf. Sci. 565, 229\u2013247 (2021)","journal-title":"Inf. Sci."},{"key":"33_CR27","first-page":"93185","volume":"15","author":"C Xu","year":"2025","unstructured":"Xu, C., Zhang, F., Yang, Z., Zhou, Z., Zheng, Y.: A few-shot network intrusion detection method based on mutual information maximization. Sci. Rep. 15, 93185 (2025)","journal-title":"Sci. Rep."},{"key":"33_CR28","doi-asserted-by":"publisher","first-page":"49730","DOI":"10.1109\/ACCESS.2020.2980136","volume":"8","author":"Y Yu","year":"2020","unstructured":"Yu, Y., Bian, N.: An Intrusion Detection Method Using Few-Shot Learning. IEEE Access 8, 49730\u201349740 (2020)","journal-title":"IEEE Access"},{"key":"33_CR29","doi-asserted-by":"crossref","unstructured":"Zuppelli, M., Guarascio, M., Caviglione, L., Liguori, A.: No country for leaking containers: detecting exfiltration of secrets through AI and syscalls. In: Proceedings of the 19th International Conference on Availability, Reliability and Security, pp. 78:1\u201378:8 (2024)","DOI":"10.1145\/3664476.3670884"}],"container-title":["Communications in Computer and Information Science","Machine Learning and Principles and Practice of Knowledge Discovery in Databases"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-19099-4_33","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,9]],"date-time":"2026-05-09T22:08:15Z","timestamp":1778364495000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-19099-4_33"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9783032190987","9783032190994"],"references-count":29,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-19099-4_33","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"value":"1865-0929","type":"print"},{"value":"1865-0937","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"1 April 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ECML PKDD","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Joint European Conference on Machine Learning and Knowledge Discovery in Databases","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Porto","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Portugal","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"15 September 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19 September 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ecml2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/ecmlpkdd.org\/2025\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}