{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,20]],"date-time":"2026-06-20T09:31:38Z","timestamp":1781947898940,"version":"3.54.5"},"reference-count":53,"publisher":"Springer Science and Business Media LLC","issue":"15","license":[{"start":{"date-parts":[[2022,3,27]],"date-time":"2022-03-27T00:00:00Z","timestamp":1648339200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,3,27]],"date-time":"2022-03-27T00:00:00Z","timestamp":1648339200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"funder":[{"name":"Australian Research Council Discovery Project","award":["DP150104871"],"award-info":[{"award-number":["DP150104871"]}]},{"DOI":"10.13039\/501100004735","name":"Hunan Provincial Natural Science Foundation of China","doi-asserted-by":"crossref","award":["2020JJ0430"],"award-info":[{"award-number":["2020JJ0430"]}],"id":[{"id":"10.13039\/501100004735","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62172182"],"award-info":[{"award-number":["62172182"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Neural Comput &amp; Applic"],"published-print":{"date-parts":[[2022,8]]},"DOI":"10.1007\/s00521-022-07156-x","type":"journal-article","created":{"date-parts":[[2022,3,28]],"date-time":"2022-03-28T11:02:42Z","timestamp":1648465362000},"page":"13007-13027","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":23,"title":["Unsupervised anomaly detection for network traffic using artificial immune network"],"prefix":"10.1007","volume":"34","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1162-9675","authenticated-orcid":false,"given":"Yuanquan","family":"Shi","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hong","family":"Shen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,3,27]]},"reference":[{"key":"7156_CR1","unstructured":"Leung K, Leckie C (2005) Unsupervised anomaly detection in network intrusion detection using clusters. In: Proceedings of the Twenty-eighth Australasian conference on Computer Science Vol 38, pp 333\u2013342. Australian Computer Society, Inc"},{"issue":"9","key":"7156_CR2","doi-asserted-by":"publisher","first-page":"2519","DOI":"10.1109\/TC.2014.2375218","volume":"64","author":"Z Tan","year":"2015","unstructured":"Tan Z, Jamdagni A, He X, Nanda P, Liu RP, Jiankun H (2015) Detection of denial-of-service attacks based on computer vision techniques. IEEE Trans Comput 64(9):2519\u20132533","journal-title":"IEEE Trans Comput"},{"issue":"3","key":"7156_CR3","doi-asserted-by":"publisher","first-page":"566","DOI":"10.1109\/TMM.2019.2893549","volume":"21","author":"S Garg","year":"2019","unstructured":"Garg S, Kaur K, Kumar N, Rodrigues JJPC (2019) Hybrid deep learning-based anomaly detection scheme for suspicious flow detection in sdn: a social multimedia perspective. IEEE Trans Multimed 21(3):566\u2013578","journal-title":"IEEE Trans Multimed"},{"issue":"18","key":"7156_CR4","doi-asserted-by":"publisher","first-page":"3799","DOI":"10.1016\/j.ins.2007.03.025","volume":"177","author":"T Shon","year":"2007","unstructured":"Shon T, Moon J (2007) A hybrid machine learning approach to network anomaly detection. Inf Sci 177(18):3799\u20133821","journal-title":"Inf Sci"},{"issue":"8","key":"7156_CR5","doi-asserted-by":"publisher","first-page":"3127","DOI":"10.1109\/TNNLS.2019.2935975","volume":"31","author":"E Tolga","year":"2020","unstructured":"Tolga E, Serdar KS (2020) Unsupervised anomaly detection with lstm neural networks. IEEE Trans Neural Netw Learn Syst 31(8):3127\u20133141","journal-title":"IEEE Trans Neural Netw Learn Syst"},{"issue":"3","key":"7156_CR6","doi-asserted-by":"publisher","first-page":"924","DOI":"10.1109\/TNSM.2019.2927886","volume":"16","author":"S Garg","year":"2019","unstructured":"Garg S, Kaur K, Kumar N, Kaddoum G, Zomaya AY, Rajiv R (2019) A hybrid deep learning-based model for anomaly detection in cloud datacenter networks. IEEE Trans Netw Serv Manage 16(3):924\u2013935","journal-title":"IEEE Trans Netw Serv Manage"},{"key":"7156_CR7","doi-asserted-by":"publisher","first-page":"390","DOI":"10.1016\/j.eswa.2017.09.013","volume":"92","author":"HH Anderson","year":"2018","unstructured":"Anderson HH, Luiz FC, Lucas DHS, Taufik A, Proenca ML Jr (2018) Network anomaly detection system using genetic algorithm and fuzzy logic. Expert Syst Appl 92:390\u2013402","journal-title":"Expert Syst Appl"},{"issue":"3","key":"7156_CR8","doi-asserted-by":"publisher","first-page":"15","DOI":"10.1145\/1541880.1541882","volume":"41","author":"V Chandola","year":"2009","unstructured":"Chandola V, Banerjee A, Kumar V (2009) Anomaly detection: a survey. ACM Comput Surv (CSUR) 41(3):15","journal-title":"ACM Comput Surv (CSUR)"},{"key":"7156_CR9","doi-asserted-by":"crossref","unstructured":"Jadidi Z, Muthukkumarasamy V, Sithirasenan E, Singh K (2015) Flow-based anomaly detection using semisupervised learning. In: Signal processing and communication systems (ICSPCS), 2015 9th international conference on, IEEE. pp 1\u20135","DOI":"10.1109\/ICSPCS.2015.7391760"},{"issue":"1","key":"7156_CR10","first-page":"1","volume":"33","author":"MH Bhuyan","year":"2014","unstructured":"Bhuyan MH, Bhattacharyya DK, Kalita JK (2014) Towards an unsupervised method for network anomaly detection in large datasets. Comput Inf 33(1):1\u201334","journal-title":"Comput Inf"},{"issue":"1","key":"7156_CR11","first-page":"95","volume":"5","author":"P Gogoi","year":"2010","unstructured":"Gogoi P, Borah B, Bhattacharyya DK (2010) Anomaly detection analysis of intrusion data using supervised and unsupervised approach. J Converg Inf Technol 5(1):95\u2013110","journal-title":"J Converg Inf Technol"},{"issue":"5","key":"7156_CR12","doi-asserted-by":"publisher","first-page":"283","DOI":"10.1002\/nem.1903","volume":"25","author":"J Mazel","year":"2015","unstructured":"Mazel J, Casas P, Fontugne R, Fukuda K, Owezarski P (2015) Hunting attacks in the dark: clustering and correlation analysis for unsupervised anomaly detection. Int J Netw Manage 25(5):283\u2013305","journal-title":"Int J Netw Manage"},{"key":"7156_CR13","doi-asserted-by":"crossref","unstructured":"Mazel J (2011)Unsupervised network anomaly detection. Thesis","DOI":"10.1007\/978-3-642-20305-3_2"},{"key":"7156_CR14","first-page":"40","volume-title":"International conference on research in networking","author":"P Casas","year":"2011","unstructured":"Casas P, Mazel J, Owezarski P (2011) Unada: unsupervised network anomaly detection using sub-space outliers ranking. International conference on research in networking. Springer, Berlin, pp 40\u201351"},{"key":"7156_CR15","unstructured":"Portnoy L, Eskin E, Stolfo S (2001)Intrusion detection with unlabeled data using clustering. In: In Proceedings of ACM CSS workshop on data mining applied to security (DMSA-2001)"},{"key":"7156_CR16","doi-asserted-by":"crossref","unstructured":"Eskin E, Arnold A, Prerau M, Portnoy L, Stolfo S (2002)A geometric framework for unsupervised anomaly detection, pp 77\u2013101. Springer, Berlin","DOI":"10.1007\/978-1-4615-0953-0_4"},{"key":"7156_CR17","doi-asserted-by":"crossref","unstructured":"Mnz G, Li S, Carle G (2007) Traffic anomaly detection using k-means clustering. GI\/ITG Workshop MMBnet","DOI":"10.1109\/IMSCCS.2007.52"},{"key":"7156_CR18","first-page":"166","volume-title":"Workshops on applications of evolutionary computation","author":"L Fang","year":"2005","unstructured":"Fang L, Le-Ping L (2005) Unsupervised anomaly detection based n an evolutionary artificial immune network. Workshops on applications of evolutionary computation. Springer, Berlin, pp 166\u2013174"},{"issue":"1","key":"7156_CR19","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1109\/TNSM.2016.2627340","volume":"14","author":"J Dromard","year":"2016","unstructured":"Dromard J, Roudiere G, Owezarski P (2016) Online and scalable unsupervised network anomaly detection method. IEEE Trans Netw Serv Manage 14(1):34\u201347","journal-title":"IEEE Trans Netw Serv Manage"},{"key":"7156_CR20","doi-asserted-by":"crossref","unstructured":"Lau H, Timmis J, Bate I (2009) Anomaly detection inspired by immune network theory: a proposal. In: 2009 IEEE congress on evolutionary computation, pp 3045\u20133051. IEEE","DOI":"10.1109\/CEC.2009.4983328"},{"key":"7156_CR21","unstructured":"Li K-L, Huang H-K, Tian S-F, Xu W (2003) Improving one-class svm for anomaly detection. In: Machine learning and cybernetics, 2003 international conference on, vol\u00a05, pp 3077\u20133081. IEEE"},{"issue":"3","key":"7156_CR22","first-page":"17","volume":"11","author":"D Ippoliti","year":"2016","unstructured":"Ippoliti D, Jiang C, Ding Z, Zhou X (2016) Online adaptive anomaly detection for augmented network flows. ACM Trans Autonom Adapt Syst (TAAS) 11(3):17","journal-title":"ACM Trans Autonom Adapt Syst (TAAS)"},{"key":"7156_CR23","unstructured":"Shyu M-L, Chen S-C, Sarinnapakorn K, Chang LW (2003) A novel anomaly detection scheme based on principal component classifier. Report, DTIC Document"},{"key":"7156_CR24","doi-asserted-by":"publisher","first-page":"217","DOI":"10.1145\/1090191.1080118","volume":"35","author":"A Lakhina","year":"2005","unstructured":"Lakhina A, Crovella M, Diot C (2005) Mining anomalies using traffic feature distributions. ACM SIGCOMM Comput Commun Rev 35:217\u2013228","journal-title":"ACM SIGCOMM Comput Commun Rev"},{"key":"7156_CR25","unstructured":"Huang L, Nguyen XL, Garofalakis M, Jordan MI, Joseph A, Taft N (2006) In-network pca and anomaly detection. In: NIPS, pp 617\u2013624"},{"key":"7156_CR26","doi-asserted-by":"publisher","first-page":"135","DOI":"10.1007\/978-3-642-30507-8_13","volume-title":"International conference on networked digital technologies","author":"I Syarif","year":"2012","unstructured":"Syarif I, Prugel-Bennett A, Wills G (2012) Unsupervised clustering approach for network anomaly detection. International conference on networked digital technologies. Springer, Berlin, pp 135\u2013145"},{"key":"7156_CR27","doi-asserted-by":"crossref","unstructured":"Zanero S, Savaresi SM (2004) Unsupervised learning techniques for an intrusion detection system. In: Proceedings of the 2004 ACM symposium on applied computing, pp 412\u2013419. ACM","DOI":"10.1145\/967900.967988"},{"issue":"1","key":"7156_CR28","doi-asserted-by":"publisher","first-page":"90","DOI":"10.1145\/1007730.1007731","volume":"6","author":"L Parsons","year":"2004","unstructured":"Parsons L, Haque E, Liu H (2004) Subspace clustering for high dimensional data: a review. ACM SIGKDD Explor Newsl 6(1):90\u2013105","journal-title":"ACM SIGKDD Explor Newsl"},{"issue":"7","key":"7156_CR29","doi-asserted-by":"publisher","first-page":"772","DOI":"10.1016\/j.comcom.2012.01.016","volume":"35","author":"P Casas","year":"2012","unstructured":"Casas P, Mazel J, Owezarski P (2012) Unsupervised network intrusion detection systems: detecting the unknown without knowledge. Comput Commun 35(7):772\u2013783","journal-title":"Comput Commun"},{"key":"7156_CR30","doi-asserted-by":"crossref","unstructured":"Dromard J, Roudire G, Owezarski P (2015) Unsupervised network anomaly detection in real-time on big data. In: East European conference on advances in databases and information systems, pp 197\u2013206. Springer, Berlin","DOI":"10.1007\/978-3-319-23201-0_22"},{"key":"7156_CR31","doi-asserted-by":"crossref","unstructured":"Yang C, Deng F, Yang H (2007) An unsupervised anomaly detection approach using subtractive clustering and hidden markov model. In: Communications and networking in China, 2007. CHINACOM\u201907. Second International Conference on, pp 313\u2013316. IEEE","DOI":"10.1109\/CHINACOM.2007.4469390"},{"key":"7156_CR32","doi-asserted-by":"crossref","unstructured":"Leon E, Nasraoui O, Gomez J (2004) Anomaly detection based on unsupervised niche clustering with application to network intrusion detection. In: Evolutionary Computation, 2004. CEC2004. Congress on, vol \u00a01, pp 502\u2013508. IEEE","DOI":"10.1109\/CEC.2004.1330898"},{"key":"7156_CR33","doi-asserted-by":"crossref","unstructured":"de\u00a0Castro LN, von Zuben FJ (2001) ainet: an artificial immune network for data analysis. Data Min Heuristic Approach 2001(1):231\u2013259","DOI":"10.4018\/978-1-930708-25-9.ch012"},{"issue":"1","key":"7156_CR34","doi-asserted-by":"publisher","first-page":"11","DOI":"10.1016\/j.tcs.2008.02.011","volume":"403","author":"J Timmis","year":"2008","unstructured":"Timmis J, Hone A, Stibor T, Clark E (2008) Theoretical advances in artificial immune systems. Theoret Comput Sci 403(1):11\u201332","journal-title":"Theoret Comput Sci"},{"key":"7156_CR35","doi-asserted-by":"publisher","first-page":"110","DOI":"10.1016\/j.eswa.2019.04.034","volume":"132","author":"M Duma","year":"2019","unstructured":"Duma M, Twala B (2019) Sparseness reduction in collaborative filtering using a nearest neighbour artificial immune system with genetic algorithms. Expert Syst Appl 132:110\u2013125","journal-title":"Expert Syst Appl"},{"issue":"3","key":"7156_CR36","doi-asserted-by":"publisher","first-page":"172","DOI":"10.1007\/s00500-003-0342-7","volume":"9","author":"D Dasgupta","year":"2005","unstructured":"Dasgupta D, Yu S, Majumdar NS (2005) Milacmultilevel immune learning algorithm and its application to anomaly detection. Soft Comput 9(3):172\u2013184","journal-title":"Soft Comput"},{"issue":"4","key":"7156_CR37","doi-asserted-by":"publisher","first-page":"740","DOI":"10.1016\/j.comcom.2006.08.016","volume":"30","author":"F Seredynski","year":"2007","unstructured":"Seredynski F, Bouvry P (2007) Anomaly detection in tcp\/ip networks using immune systems paradigm. Comput Commun 30(4):740\u2013749","journal-title":"Comput Commun"},{"issue":"B","key":"7156_CR38","doi-asserted-by":"publisher","first-page":"515","DOI":"10.1016\/j.neucom.2014.08.022","volume":"149","author":"D Li","year":"2015","unstructured":"Li D, Liu S, Zhang H (2015) A negative selection algorithm with online adaptive learning under small samples for anomaly detection. Neurocomputing 149(B):515\u2013525","journal-title":"Neurocomputing"},{"issue":"3","key":"7156_CR39","first-page":"421","volume":"17","author":"YQ Shi","year":"2016","unstructured":"Shi YQ, Li R, Peng X, Yue G (2016) Network security situation prediction approach based on clonal selection and scgm(1 1)c model. J Int Technol 17(3):421\u2013429","journal-title":"J Int Technol"},{"issue":"2","key":"7156_CR40","doi-asserted-by":"publisher","first-page":"655","DOI":"10.1007\/s00521-020-05049-5","volume":"33","author":"Y Bo","year":"2021","unstructured":"Bo Y, Meifang Y (2021) Data-driven network layer security detection model and simulation for the internet of things based on an artificial immune system. Neural Comput Appl 33(2):655\u2013666","journal-title":"Neural Comput Appl"},{"issue":"9","key":"7156_CR41","doi-asserted-by":"publisher","first-page":"2056","DOI":"10.1109\/TCYB.2015.2461651","volume":"46","author":"S Qian","year":"2016","unstructured":"Qian S, Ye Y, Jiang B, Wang J (2016) Constrained multiobjective optimization algorithm based on immune system model. IEEE Trans Cybern 46(9):2056\u20132069","journal-title":"IEEE Trans Cybern"},{"issue":"1","key":"7156_CR42","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s11370-014-0160-z","volume":"8","author":"YQ Shi","year":"2015","unstructured":"Shi YQ, Li R, Zhang Y, Peng X (2015) An immunity-based time series prediction approach and its application for network security situation. Intell Serv Robot 8(1):1\u201322","journal-title":"Intell Serv Robot"},{"issue":"1","key":"7156_CR43","doi-asserted-by":"publisher","first-page":"116","DOI":"10.1109\/TEVC.2016.2586049","volume":"21","author":"G Dudek","year":"2017","unstructured":"Dudek G (2017) Artificial immune system with local feature selection for short-term load forecasting. IEEE Trans Evol Comput 21(1):116\u2013130","journal-title":"IEEE Trans Evol Comput"},{"issue":"5","key":"7156_CR44","doi-asserted-by":"publisher","first-page":"557","DOI":"10.1360\/04yf0140","volume":"48","author":"T Li","year":"2005","unstructured":"Li T (2005) An immunity based network security risk estimation. Sci China Ser F Inf Sci 48(5):557\u2013578","journal-title":"Sci China Ser F Inf Sci"},{"issue":"11","key":"7156_CR45","doi-asserted-by":"publisher","first-page":"3799","DOI":"10.1109\/TCYB.2016.2582384","volume":"47","author":"E Alizadeh","year":"2016","unstructured":"Alizadeh E, Meskin N, Khorasani K (2016) A negative selection immune system inspired methodology for fault diagnosis of wind turbines. IEEE Trans Cybern 47(11):3799\u20133813","journal-title":"IEEE Trans Cybern"},{"key":"7156_CR46","first-page":"373","volume":"125","author":"NK Jerne","year":"1974","unstructured":"Jerne NK (1974) Towards a network theory of the immune system. Annales d\u2019immunologie 125:373\u2013389","journal-title":"Annales d\u2019immunologie"},{"issue":"3","key":"7156_CR47","first-page":"147","volume":"3","author":"MA Rassam","year":"2012","unstructured":"Rassam MA, Maarof MA (2012) Artificial immune network clustering approach for anomaly intrusion detection. J Adv Inf Technol 3(3):147\u2013154","journal-title":"J Adv Inf Technol"},{"issue":"3","key":"7156_CR48","doi-asserted-by":"publisher","first-page":"357","DOI":"10.1016\/j.cose.2011.12.012","volume":"31","author":"A Shiravi","year":"2012","unstructured":"Shiravi A, Shiravi H, Tavallaee M, Ghorbani AA (2012) Toward developing a systematic approach to generate benchmark datasets for intrusion detection. Comput Security 31(3):357\u2013374","journal-title":"Comput Security"},{"key":"7156_CR49","doi-asserted-by":"crossref","unstructured":"Tavallaee M, Bagheri E, Lu W, Ghorbani A-A (2009) A detailed analysis of the kdd cup 99 data set. 2009 IEEE symposium on computational intelligence for security and defense applications, pp 1\u20136","DOI":"10.1109\/CISDA.2009.5356528"},{"issue":"3\u20134","key":"7156_CR50","doi-asserted-by":"publisher","first-page":"599","DOI":"10.1007\/s00521-012-1263-0","volume":"24","author":"M Sheikhan","year":"2014","unstructured":"Sheikhan M, Jadidi Z (2014) Flow-based anomaly detection in high-speed links using modified gsa-optimized neural network. Neural Comput Appl 24(3\u20134):599\u2013611","journal-title":"Neural Comput Appl"},{"issue":"6","key":"7156_CR51","doi-asserted-by":"publisher","first-page":"790","DOI":"10.1016\/j.comnet.2008.11.016","volume":"53","author":"W Li","year":"2009","unstructured":"Li W, Canini M, Moore AW, Bolla R (2009) Efficient application identification and the temporal and spatial stability of classification schema. Comput Netw 53(6):790\u2013809","journal-title":"Comput Netw"},{"issue":"1\u20133","key":"7156_CR52","doi-asserted-by":"publisher","first-page":"59","DOI":"10.1007\/s10994-014-5473-9","volume":"101","author":"F Iglesias","year":"2015","unstructured":"Iglesias F, Zseby T (2015) Analysis of network traffic features for anomaly detection. Mach Learn 101(1\u20133):59\u201384","journal-title":"Mach Learn"},{"key":"7156_CR53","unstructured":"Maloof MA (2005) Machine learning and data mining for computer security: methods and applications. pp 23\u201345. Springer-Verlag, New York"}],"container-title":["Neural Computing and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00521-022-07156-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s00521-022-07156-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00521-022-07156-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,21]],"date-time":"2024-09-21T03:26:34Z","timestamp":1726889194000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s00521-022-07156-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,3,27]]},"references-count":53,"journal-issue":{"issue":"15","published-print":{"date-parts":[[2022,8]]}},"alternative-id":["7156"],"URL":"https:\/\/doi.org\/10.1007\/s00521-022-07156-x","relation":{},"ISSN":["0941-0643","1433-3058"],"issn-type":[{"value":"0941-0643","type":"print"},{"value":"1433-3058","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,3,27]]},"assertion":[{"value":"8 February 2021","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"28 February 2022","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"27 March 2022","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}]}}