{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,25]],"date-time":"2026-03-25T14:27:16Z","timestamp":1774448836409,"version":"3.50.1"},"reference-count":63,"publisher":"Springer Science and Business Media LLC","issue":"14","license":[{"start":{"date-parts":[[2022,3,16]],"date-time":"2022-03-16T00:00:00Z","timestamp":1647388800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,3,16]],"date-time":"2022-03-16T00:00:00Z","timestamp":1647388800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/100010661","name":"horizon 2020 framework programme","doi-asserted-by":"publisher","award":["101000427"],"award-info":[{"award-number":["101000427"]}],"id":[{"id":"10.13039\/100010661","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Universit\u00e0 degli Studi di Roma La Sapienza"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Neural Comput &amp; Applic"],"published-print":{"date-parts":[[2022,7]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Recent progress in machine learning has led to promising results in behavioral malware detection. Behavioral modeling identifies malicious processes via features derived by their runtime behavior. Behavioral features hold great promise as they are intrinsically related to the functioning of each malware, and are therefore considered difficult to evade. Indeed, while a significant amount of results exists on evasion of static malware features, evasion of dynamic features has seen limited work. This paper examines the robustness of behavioral ransomware detectors to evasion and proposes multiple novel techniques to evade them. Ransomware behavior differs significantly from that of benign processes, making it an ideal best case for behavioral detectors, and a difficult candidate for evasion. We identify and propose a set of novel attacks that distribute the overall malware workload across a small set of independent, cooperating processes in order to avoid the generation of significant behavioral features. Our most effective attack decreases the accuracy of a state-of-the-art classifier from 98.6 to 0% using only 18 cooperating processes. Furthermore, we show our attacks to be effective against commercial ransomware detectors in a black-box setting. Finally, we evaluate a detector designed to identify our most effective attack, as well as discuss potential directions to mitigate our most advanced attack.<\/jats:p>","DOI":"10.1007\/s00521-022-07096-6","type":"journal-article","created":{"date-parts":[[2022,3,16]],"date-time":"2022-03-16T15:04:15Z","timestamp":1647443055000},"page":"12077-12096","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":35,"title":["Evading behavioral classifiers: a comprehensive analysis on evading ransomware detection techniques"],"prefix":"10.1007","volume":"34","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9718-1044","authenticated-orcid":false,"given":"Fabio","family":"De Gaspari","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dorjan","family":"Hitaj","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Giulio","family":"Pagnotta","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lorenzo","family":"De Carli","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Luigi V.","family":"Mancini","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,3,16]]},"reference":[{"key":"7096_CR1","doi-asserted-by":"crossref","unstructured":"Moser A, Kruegel C, Kirda E (2007) Limits of static analysis for malware detection. In: Twenty-Third annual computer security applications conference (ACSAC 2007), IEEE, pp 421\u2013430","DOI":"10.1109\/ACSAC.2007.21"},{"issue":"5","key":"7096_CR2","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1109\/MSP.2011.98","volume":"9","author":"P O\u2019Kane","year":"2011","unstructured":"O\u2019Kane P, Sezer S, McLaughlin K (2011) Obfuscation: the hidden malware. IEEE Secur Priv 9(5):41\u201347","journal-title":"IEEE Secur Priv"},{"key":"7096_CR3","doi-asserted-by":"crossref","unstructured":"Tian R, Islam R, Batten L, Versteeg S (2010) Differentiating malware from cleanware using behavioural analysis. In: 2010 5th international conference on malicious and unwanted software, IEEE, pp 23\u201330.","DOI":"10.1109\/MALWARE.2010.5665796"},{"key":"7096_CR4","doi-asserted-by":"crossref","unstructured":"Continella A, Guagnelli A, Zingaro G, De\u00a0Pasquale G, Barenghi A, Zanero S, Maggi F (2016) Shieldfs: a self-healing, ransomware-aware filesystem. In: Proceedings of the 32nd annual conference on computer security applications, pp 336\u2013347","DOI":"10.1145\/2991079.2991110"},{"key":"7096_CR5","doi-asserted-by":"crossref","unstructured":"Mehnaz S, Mudgerikar A, Bertino E (2018) Rwguard: a real-time detection system against cryptographic ransomware. In: International symposium on research in attacks, intrusions, and defenses, Springer, pp 114\u2013136.","DOI":"10.1007\/978-3-030-00470-5_6"},{"key":"7096_CR6","unstructured":"Kharaz A, Arshad S, Mulliner C, Robertson W, Kirda E (2016) $$\\{$$UNVEIL$$\\}$$: A $$\\{$$Large-Scale$$\\}$$, automated approach to detecting ransomware. In: 25th USENIX security symposium (USENIX Security 16), pp 757\u2013772"},{"key":"7096_CR7","doi-asserted-by":"crossref","unstructured":"Kharraz A, Kirda E (2017) Redemption: real-time protection against ransomware at end-hosts. In: International symposium on research in attacks, intrusions, and defenses, Springer, pp. 98\u2013119","DOI":"10.1007\/978-3-319-66332-6_5"},{"key":"7096_CR8","doi-asserted-by":"crossref","unstructured":"Piskozub M, De\u00a0Gaspari F, Barr-Smith F, Mancini L, Martinovic I (2021) Malphase: fine-grained malware detection using network flow data. In: Proceedings of the 2021 ACM Asia conference on computer and communications security, pp 774\u2013786","DOI":"10.1145\/3433210.3453101"},{"key":"7096_CR9","unstructured":"Atlanta Spent \\$2.6M to Recover From a \\$52,000 Ransomware Scare. https:\/\/www.wired.com\/story\/atlanta-spent-26m-recover-from-ransomware-scare\/ (2018)"},{"key":"7096_CR10","doi-asserted-by":"crossref","unstructured":"WannaCry cyber attack cost the NHS \u00a392m as 19,000 appointments cancelled. https:\/\/www.telegraph.co.uk\/technology\/2018\/10\/11\/wannacry-cyber-attack-cost-nhs-92m-19000-appointments-cancelled\/ (2018)","DOI":"10.1016\/S1361-3723(18)30102-7"},{"key":"7096_CR11","doi-asserted-by":"crossref","unstructured":"Gaspari FD, Hitaj D, Pagnotta G, Carli LD, Mancini LV (2020) The naked sun: malicious cooperation between benign-looking processes. In: International conference on applied cryptography and network security, Springer, pp 254\u2013274","DOI":"10.1007\/978-3-030-57878-7_13"},{"key":"7096_CR12","doi-asserted-by":"crossref","unstructured":"Biggio B, Rieck K, Ariu D, Wressnegger C, Corona I, Giacinto G, Roli F (2014) Poisoning behavioral malware clustering. In: Proceedings of the 2014 workshop on artificial intelligent and security workshop, pp 27\u201336","DOI":"10.1145\/2666652.2666666"},{"key":"7096_CR13","doi-asserted-by":"crossref","unstructured":"Papernot N, McDaniel P, Jha S, Fredrikson M, Celik ZB, Swami A (2016) The limitations of deep learning in adversarial settings. In: 2016 IEEE European symposium on security and privacy (EuroS&P), IEEE, pp 372\u2013387","DOI":"10.1109\/EuroSP.2016.36"},{"key":"7096_CR14","unstructured":"Kantchelian A, Tygar JD, Joseph A (2016) Evasion and hardening of tree ensemble classifiers. In: International conference on machine learning, PMLR, pp 2387\u20132396"},{"key":"7096_CR15","doi-asserted-by":"crossref","unstructured":"Xu W, Qi Y, Evans D (2016) Automatically evading classifiers: a case study on pdf malware classifiers. In: NDSS","DOI":"10.14722\/ndss.2016.23115"},{"key":"7096_CR16","unstructured":"Laskov P et\u00a0al. (2014) Practical evasion of a learning-based classifier: a case study. In: 2014 IEEE symposium on security and privacy, IEEE, pp 197\u2013211"},{"key":"7096_CR17","doi-asserted-by":"crossref","unstructured":"Biggio B, Corona I, Maiorca D, Nelson B, \u0160rndi\u0107 N, Laskov P, Giacinto G, Roli F (2013) Evasion attacks against machine learning at test time. In: Joint European conference on machine learning and knowledge discovery in databases, pp 387\u2013402","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"7096_CR18","doi-asserted-by":"crossref","unstructured":"Yang W, Kong D, Xie T, Gunter CA (2017) Malware detection in adversarial settings: Exploiting feature evolutions and confusions in android apps. In: Proceedings of the 33rd annual computer security applications conference, pp 288\u2013302","DOI":"10.1145\/3134600.3134642"},{"issue":"4","key":"7096_CR19","doi-asserted-by":"publisher","first-page":"711","DOI":"10.1109\/TDSC.2017.2700270","volume":"16","author":"A Demontis","year":"2017","unstructured":"Demontis A, Melis M, Biggio B, Maiorca D, Arp D, Rieck K, Corona I, Giacinto G, Roli F (2017) Yes, machine learning can be more secure! a case study on android malware detection. IEEE Trans Dependable Secur Comput 16(4):711\u2013724","journal-title":"IEEE Trans Dependable Secur Comput"},{"key":"7096_CR20","doi-asserted-by":"crossref","unstructured":"Grosse K, Papernot N, Manoharan P, Backes M, McDaniel P (2017) Adversarial examples for malware detection. In: European symposium on research in computer security, Springer, pp 62\u201379","DOI":"10.1007\/978-3-319-66399-9_4"},{"key":"7096_CR21","doi-asserted-by":"publisher","first-page":"101901","DOI":"10.1016\/j.cose.2020.101901","volume":"96","author":"D Maiorca","year":"2020","unstructured":"Maiorca D, Demontis A, Biggio B, Roli F, Giacinto G (2020) Adversarial detection of flash malware: limitations and open issues. Comput Secur 96:101901","journal-title":"Comput Secur"},{"key":"7096_CR22","doi-asserted-by":"crossref","unstructured":"Scaife N, Carter H, Traynor P, Butler KR (2016) Cryptolock (and drop it): stopping ransomware attacks on user data. In: 2016 IEEE 36th international conference on distributed computing systems (ICDCS), IEEE, pp 303\u2013312","DOI":"10.1109\/ICDCS.2016.46"},{"key":"7096_CR23","unstructured":"Introducing the Malwarebytes Anti-Ransomware Beta. https:\/\/blog.malwarebytes.com\/malwarebytes-news\/2016\/01\/introducing-the-malwarebytes-anti-ransomware-beta\/ (2016)"},{"key":"7096_CR24","unstructured":"Malwarebytes Anti-Ransomware for Business. https:\/\/www.malwarebytes.com\/business\/solutions\/ransomware\/ (2019)"},{"key":"7096_CR25","unstructured":"Ispoglou KK, Payer M (2016) $$\\{$$malWASH$$\\}$$: washing malware to evade dynamic analysis. In: 10th USENIX workshop on offensive technologies (WOOT 16)"},{"issue":"1","key":"7096_CR26","doi-asserted-by":"publisher","first-page":"145","DOI":"10.1109\/18.61115","volume":"37","author":"J Lin","year":"1991","unstructured":"Lin J (1991) Divergence measures based on the Shannon entropy. IEEE Trans Inf Theor 37(1):145\u2013151","journal-title":"IEEE Trans Inf Theor"},{"key":"7096_CR27","unstructured":"List of File Signatures. https:\/\/en.wikipedia.org\/wiki\/List_of_file_signatures (2019)"},{"key":"7096_CR28","doi-asserted-by":"crossref","unstructured":"Bellare M, Ristenpart T, Rogaway P, Stegers T (2009) Format-preserving encryption. In: International workshop on selected areas in cryptography, Springer, pp 295\u2013312","DOI":"10.1007\/978-3-642-05445-7_19"},{"key":"7096_CR29","unstructured":"I\/O request packets. https:\/\/docs.microsoft.com\/en-us\/windows-hardware\/drivers\/gettingstarted\/i-o-request-packets (2017)"},{"key":"7096_CR30","unstructured":"Pavithran J, Patnaik M, Rebeiro C (2019) $$\\{$$D-TIME$$\\}$$: distributed threadless independent malware execution for runtime obfuscation. In: 13th USENIX workshop on offensive technologies (WOOT 19)"},{"key":"7096_CR31","doi-asserted-by":"crossref","unstructured":"Lv Z, Zhao Y, Zhang C, Li H (2020) Dramd: detect advanced dram-based stealthy communication channels with neural networks. In: IEEE INFOCOM 2020-IEEE Conference on computer communications, IEEE, pp 1907\u20131916","DOI":"10.1109\/INFOCOM41043.2020.9155515"},{"key":"7096_CR32","doi-asserted-by":"publisher","first-page":"322","DOI":"10.1016\/j.neucom.2020.08.063","volume":"417","author":"Z Chen","year":"2020","unstructured":"Chen Z, Zhang B, Stojanovic V, Zhang Y, Zhang Z (2020) Event-based fuzzy control for TS fuzzy networked systems with various data missing. Neurocomputing 417:322\u2013332","journal-title":"Neurocomputing"},{"key":"7096_CR33","doi-asserted-by":"crossref","unstructured":"Cheng P, He S, Stojanovic V, Luan X, Liu F (2021) Fuzzy fault detection for markov jump systems with partly accessible hidden information: an event-triggered approach. IEEE transactions on cybernetics","DOI":"10.1109\/TCYB.2021.3050209"},{"key":"7096_CR34","doi-asserted-by":"crossref","unstructured":"Milajerdi SM, Gjomemo R, Eshete B, Sekar R, Venkatakrishnan V (2019) Holmes: real-time apt detection through correlation of suspicious information flows. In: 2019 IEEE symposium on security and privacy (SP), IEEE, pp 1137\u20131152","DOI":"10.1109\/SP.2019.00026"},{"key":"7096_CR35","doi-asserted-by":"crossref","unstructured":"Manzoor E, Milajerdi SM, Akoglu L (2016) Fast memory-efficient anomaly detection in streaming heterogeneous graphs. In: Proceedings of the 22nd ACM SIGKDD international conference on knowledge discovery and data mining, pp 1035\u20131044","DOI":"10.1145\/2939672.2939783"},{"key":"7096_CR36","doi-asserted-by":"crossref","unstructured":"Han X, Pasquier T, Bates A, Mickens J, Seltzer M (2020) Unicorn: runtime provenance-based detector for advanced persistent threats. In: Proceedings of the 2020 network and distributed system security symposium","DOI":"10.14722\/ndss.2020.24046"},{"key":"7096_CR37","unstructured":"Gu G, Porras PA, Yegneswaran V, Fong MW, Lee W (2007) Bothunter: detecting malware infection through ids-driven dialog correlation. In: USENIX security symposium, vol. 7, pp 1\u201316"},{"issue":"3","key":"7096_CR38","doi-asserted-by":"publisher","first-page":"559","DOI":"10.1145\/2508148.2485970","volume":"41","author":"J Demme","year":"2013","unstructured":"Demme J, Maycock M, Schmitz J, Tang A, Waksman A, Sethumadhavan S, Stolfo S (2013) On the feasibility of online malware detection with performance counters. ACM SIGARCH Comput Archit News 41(3):559\u2013570","journal-title":"ACM SIGARCH Comput Archit News"},{"key":"7096_CR39","doi-asserted-by":"crossref","unstructured":"Khasawneh KN, Abu-Ghazaleh N, Ponomarev D, Yu L (2017) Rhmd: evasion-resilient hardware malware detectors. In: Proceedings of the 50th annual IEEE\/ACM international symposium on microarchitecture, pp 315\u2013327","DOI":"10.1145\/3123939.3123972"},{"key":"7096_CR40","doi-asserted-by":"crossref","unstructured":"Zhou B, Gupta A, Jahanshahi R, Egele M, Joshi A (2018) Hardware performance counters can detect malware: myth or fact? In: Proceedings of the 2018 on Asia conference on computer and communications security, pp 457\u2013468","DOI":"10.1145\/3196494.3196515"},{"key":"7096_CR41","doi-asserted-by":"crossref","unstructured":"Das S, Werner J, Antonakakis M, Polychronakis M, Monrose F (2019) Sok: the challenges, pitfalls, and perils of using hardware performance counters for security. In: 2019 IEEE symposium on security and privacy (SP), IEEE, pp 20\u201338","DOI":"10.1109\/SP.2019.00021"},{"key":"7096_CR42","unstructured":"Tong L, Li B, Hajaj C, Xiao C, Vorobeychik Y (2017) Hardening classifiers against evasion: the good, the bad, and the ugly. CoRR, arXiv:1708.08327"},{"key":"7096_CR43","doi-asserted-by":"crossref","unstructured":"Carlini N, Wagner D (2017) Adversarial examples are not easily detected: bypassing ten detection methods, pp 3\u201314","DOI":"10.1145\/3128572.3140444"},{"key":"7096_CR44","doi-asserted-by":"crossref","unstructured":"Palisse A, Durand A, Le\u00a0Bouder H, Le Guernic C, Lanet J-L (2017) Data Aware Defense (DaD): Towards a Generic and Practical Ransomware Countermeasure. In: Secure IT systems vol. 10674, Springer, Cham, pp 192\u2013208","DOI":"10.1007\/978-3-319-70290-2_12"},{"key":"7096_CR45","doi-asserted-by":"crossref","unstructured":"Mbol F, Robert J-M, Sadighian A (2016) An Efficient Approach to Detect TorrentLocker Ransomware in Computer Systems. In: Cryptology and Network Security vol. 10052, pp. 532\u2013541. Springer, Cham","DOI":"10.1007\/978-3-319-48965-0_32"},{"key":"7096_CR46","doi-asserted-by":"crossref","unstructured":"De\u00a0Gaspari F, Hitaj D, Pagnotta G, De\u00a0Carli L, Mancini LV (2020) Encod: distinguishing compressed and encrypted file fragments. In: Network and system security, pp 42\u201362","DOI":"10.1007\/978-3-030-65745-1_3"},{"key":"7096_CR47","doi-asserted-by":"crossref","unstructured":"De\u00a0Gaspari F, Hitaj D, Pagnotta G, De\u00a0Carli L, Mancini LV (2021) Reliable detection of compressed and encrypted data. arXiv preprint arXiv:2103.17059","DOI":"10.1007\/s00521-022-07586-7"},{"key":"7096_CR48","doi-asserted-by":"crossref","unstructured":"Gen\u00e7 ZA, Lenzini G, Sgandurra D (2019) On deception-based protection against cryptographic ransomware. In: International conference on detection of intrusions and malware, and vulnerability assessment, Springer, pp 219\u2013239","DOI":"10.1007\/978-3-030-22038-9_11"},{"key":"7096_CR49","doi-asserted-by":"crossref","unstructured":"Moore C (2016) Detecting ransomware with honeypot techniques. In: CCC","DOI":"10.1109\/CCC.2016.14"},{"key":"7096_CR50","doi-asserted-by":"crossref","unstructured":"Moussaileb R, Bouget B, Palisse A, Le\u00a0Bouder H, Cuppens N, Lanet J-L (2018) Ransomware\u2019s early mitigation mechanisms. In: Proceedings of the 13th international conference on availability, reliability and security, pp 1\u201310","DOI":"10.1145\/3230833.3234691"},{"key":"7096_CR51","unstructured":"WannaCry Analysis and Cracking. https:\/\/medium.com\/@codingkarma\/wannacry-analysis-and-cracking-6175b8cd47d4 (2018)"},{"key":"7096_CR52","unstructured":"\u201cPetya-like\u201d Ransomware Analysis. https:\/\/www.nyotron.com\/wp-content\/uploads\/2017\/06\/NARC-Report-Petya-like-062017-for-Web.pdf (2017)"},{"key":"7096_CR53","unstructured":"Cerber Starts Evading Machine Learning. https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/cerber-starts-evading-machine-learning\/ (2017)"},{"key":"7096_CR54","doi-asserted-by":"crossref","unstructured":"Gen\u00e7 ZA, Lenzini G, Ryan PYA (2018) Next generation cryptographic ransomware. In: Secure IT systems vol. 11252, Springer, Cham, pp 385\u2013401.","DOI":"10.1007\/978-3-030-03638-6_24"},{"key":"7096_CR55","unstructured":"Anderson HS, Kharkar A, Filar B, Roth P (2017) Evading machine learning malware detection 2017:6"},{"key":"7096_CR56","doi-asserted-by":"crossref","unstructured":"Rosenberg I, Shabtai A, Rokach L, Elovici Y (2018) Generic black-box end-to-end attack against state of the art API call based malware classifiers. In: International symposium on research in attacks, intrusions, and defenses, Springer, pp 490\u2013510","DOI":"10.1007\/978-3-030-00470-5_23"},{"key":"7096_CR57","unstructured":"Hu W, Tan Y (2017) Generating adversarial malware examples for black-box attacks based on GAN. arXiv:1702.05983 [cs] . arXiv: 1702.05983. Accessed 2018-09-07"},{"key":"7096_CR58","doi-asserted-by":"crossref","unstructured":"Hitaj B, Gasti P, Ateniese G, Perez-Cruz F (2019) Passgan: a deep learning approach for password guessing. In: International conference on applied cryptography and network security, pp 217\u2013237","DOI":"10.1007\/978-3-030-21568-2_11"},{"key":"7096_CR59","doi-asserted-by":"crossref","unstructured":"Pagnotta G, Hitaj D, De\u00a0Gaspari F, Mancini LV (2021) Passflow: guessing passwords with generative flows. arXiv preprint arXiv:2105.06165","DOI":"10.1109\/DSN53405.2022.00035"},{"key":"7096_CR60","doi-asserted-by":"crossref","unstructured":"Dang H, Huang Y, Chang E-C (2017) Evading classifiers by morphing in the dark. In: Proceedings of the 2017 ACM SIGSAC conference on computer and communications security, pp 119\u2013133","DOI":"10.1145\/3133956.3133978"},{"key":"7096_CR61","unstructured":"Rosenberg I, Shabtai A, Elovici Y, Rokach L (2018) Query-efficient gan based black-box attack against sequence based machine and deep learning classifiers. arXiv:1804.08778 [cs]. Accessed 2018-11-01"},{"key":"7096_CR62","unstructured":"Hu W, Tan Y (2018) Black-box attacks against RNN based malware detection algorithms"},{"key":"7096_CR63","doi-asserted-by":"crossref","unstructured":"Fredrikson M, Jha S, Christodorescu M, Sailer R, Yan X (2010) Synthesizing near-optimal malware specifications from suspicious behaviors. In: 2010 IEEE symposium on security and privacy, IEEE, pp 45\u201360","DOI":"10.1109\/SP.2010.11"}],"container-title":["Neural Computing and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00521-022-07096-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s00521-022-07096-6\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00521-022-07096-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,26]],"date-time":"2022-07-26T07:09:55Z","timestamp":1658819395000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s00521-022-07096-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,3,16]]},"references-count":63,"journal-issue":{"issue":"14","published-print":{"date-parts":[[2022,7]]}},"alternative-id":["7096"],"URL":"https:\/\/doi.org\/10.1007\/s00521-022-07096-6","relation":{},"ISSN":["0941-0643","1433-3058"],"issn-type":[{"value":"0941-0643","type":"print"},{"value":"1433-3058","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,3,16]]},"assertion":[{"value":"31 July 2021","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"14 February 2022","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"16 March 2022","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"27 July 2022","order":4,"name":"change_date","label":"Change Date","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"Update","order":5,"name":"change_type","label":"Change Type","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"Missing Open Access funding information has been added in the Funding Note","order":6,"name":"change_details","label":"Change Details","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}]}}