{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,23]],"date-time":"2026-07-23T21:32:23Z","timestamp":1784842343733,"version":"3.55.0"},"reference-count":45,"publisher":"Springer Science and Business Media LLC","issue":"9","license":[{"start":{"date-parts":[[2025,1,24]],"date-time":"2025-01-24T00:00:00Z","timestamp":1737676800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,24]],"date-time":"2025-01-24T00:00:00Z","timestamp":1737676800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Neural Comput &amp; Applic"],"published-print":{"date-parts":[[2025,3]]},"DOI":"10.1007\/s00521-025-10976-2","type":"journal-article","created":{"date-parts":[[2025,1,24]],"date-time":"2025-01-24T13:25:09Z","timestamp":1737725109000},"page":"6795-6818","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":14,"title":["CTMBIDS: convolutional Tsetlin machine-based intrusion detection system for DDoS attacks in an SDN environment"],"prefix":"10.1007","volume":"37","author":[{"given":"Rasoul","family":"Jafari Gohari","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Laya","family":"Aliahmadipour","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Marjan","family":"Kuchaki Rafsanjani","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,1,24]]},"reference":[{"key":"10976_CR1","doi-asserted-by":"publisher","unstructured":"Yang Z, Cui Y, Li B, Liu Y, Xu Y (2019) Software-defined wide area network (SD-WAN): architecture, advances and opportunities. 2019 28th International conference on computer communication and networks (ICCCN). Valencia, Spain, pp 1\u20139. https:\/\/doi.org\/10.1109\/ICCCN.2019.8847124","DOI":"10.1109\/ICCCN.2019.8847124"},{"issue":"24","key":"10976_CR2","doi-asserted-by":"publisher","first-page":"3187","DOI":"10.1007\/s10586-021-03311-6","volume":"24","author":"SS Jazaeri","year":"2021","unstructured":"Jazaeri SS, Jabbehdari S, Asghari P et al (2021) Edge computing in SDN-IoT networks: a systematic review of issues, challenges and solutions. Cluster Comput 24(24):3187\u20133228. https:\/\/doi.org\/10.1007\/s10586-021-03311-6","journal-title":"Cluster Comput"},{"issue":"27","key":"10976_CR3","doi-asserted-by":"publisher","first-page":"1792","DOI":"10.1007\/s11036-019-01397-2","volume":"27","author":"Q Long","year":"2022","unstructured":"Long Q, Chen Y, Zhang H et al (2022) Software defined 5G and 6G networks: a survey. Mobile Netw Appl 27(27):1792\u20131812. https:\/\/doi.org\/10.1007\/s11036-019-01397-2","journal-title":"Mobile Netw Appl"},{"key":"10976_CR4","doi-asserted-by":"publisher","first-page":"122016","DOI":"10.1109\/ACCESS.2021.3109564","volume":"9","author":"MB Jim\u00e9nez","year":"2021","unstructured":"Jim\u00e9nez MB, Fern\u00e1ndez D, Rivadeneira JE et al (2021) A survey of the main security issues and solutions for the SDN architecture. IEEE Access 9:122016\u2013122038. https:\/\/doi.org\/10.1109\/ACCESS.2021.3109564","journal-title":"IEEE Access"},{"key":"10976_CR5","doi-asserted-by":"publisher","unstructured":"Yang G, Shin C, Yoo Y, (2021) A Case for SDN-based Network Virtualization. et al (2021) 29th International symposium on modeling, analysis, and simulation of computer and telecommunication systems (MASCOTS). Houston, TX, USA, pp 1\u20138. https:\/\/doi.org\/10.1109\/MASCOTS53633.2021.9614291","DOI":"10.1109\/MASCOTS53633.2021.9614291"},{"key":"10976_CR6","unstructured":"Jafari Gohari R, Aliahmadipour L, Kuchaki Rafsanjani M (2022) Deep learning-based intrusion detection systems: a comprehensive survey of four main fields of cyber security. J Mahani Math Res"},{"key":"10976_CR7","doi-asserted-by":"publisher","first-page":"126","DOI":"10.1016\/j.future.2020.09.006","volume":"115","author":"O Yurekten","year":"2021","unstructured":"Yurekten O, Demirci M (2021) SDN-based cyber defense: a survey. Future Gen Comput Syst 115:126\u2013149. https:\/\/doi.org\/10.1016\/j.future.2020.09.006","journal-title":"Future Gen Comput Syst"},{"key":"10976_CR8","doi-asserted-by":"publisher","unstructured":"Acun B, Murphy M, Wang X, (2021) Understanding training efficiency of deep learning recommendation models at scale. In: IEEE International symposium on high-performance computer architecture (HPCA), Seoul. Korea (South), pp 802\u2013814. https:\/\/doi.org\/10.1109\/HPCA51647.2021.00072","DOI":"10.1109\/HPCA51647.2021.00072"},{"issue":"64","key":"10976_CR9","first-page":"3197","volume":"64","author":"H Xiong","year":"2022","unstructured":"Xiong H, Li X, Li X et al (2022) Interpretable deep learning: interpretation, interpretability, trustworthiness, and beyond. Knowl Inf Syst 64(64):3197\u20133234","journal-title":"Knowl Inf Syst"},{"key":"10976_CR10","unstructured":"Granmo O-C (2019) The Tsetlin machine - a game theoretic bandit driven approach to optimal pattern recognition with propositional logic. arXiv:1804.01508"},{"key":"10976_CR11","doi-asserted-by":"publisher","first-page":"115134","DOI":"10.1109\/ACCESS.2019.2935416","volume":"7","author":"GT Berge","year":"2019","unstructured":"Berge GT, Granmo O-C, Tveit TO et al (2019) Using the Tsetlin machine to learn human-interpretable rules for high-accuracy text categorization with medical applications. IEEE Access 7:115134\u2013115146. https:\/\/doi.org\/10.1109\/ACCESS.2019.2935416","journal-title":"IEEE Access"},{"key":"10976_CR12","unstructured":"Granmo O-C, Glimsdal S, Jiao L et al (2019) The convolutional Tsetlin machine. arXiv preprint arXiv:1905.09688"},{"key":"10976_CR13","doi-asserted-by":"publisher","unstructured":"Tunheim SA, Jiao L, Shafik R (2022) A convolutional Tsetlin machine-based field programmable gate array accelerator for image classification. In: International Symposium on the Tsetlin Machine (ISTM). Grimstad, Norway, pp 21\u201328. https:\/\/doi.org\/10.1109\/ISTM54910.2022.00013","DOI":"10.1109\/ISTM54910.2022.00013"},{"key":"10976_CR14","doi-asserted-by":"publisher","unstructured":"Ahmad A, Harjula E, Ylianttila M, Ahmad I (2020) Evaluation of machine learning techniques for security in SDN. In: IEEE Globecom workshops (GC Wkshps). Taipei, Taiwan, pp 1\u20136. https:\/\/doi.org\/10.1109\/GCWkshps50303.2020.9367477","DOI":"10.1109\/GCWkshps50303.2020.9367477"},{"issue":"3","key":"10976_CR15","doi-asserted-by":"publisher","first-page":"1956","DOI":"10.1109\/COMST.2021.3060582","volume":"23","author":"N Anerousis","year":"2021","unstructured":"Anerousis N, Chemouil P, Lazar AA et al (2021) The origin and evolution of open programmable networks and SDN. IEEE Commun Surv Tutor 23(3):1956\u20131971. https:\/\/doi.org\/10.1109\/COMST.2021.3060582","journal-title":"IEEE Commun Surv Tutor"},{"key":"10976_CR16","doi-asserted-by":"publisher","first-page":"100279","DOI":"10.1016\/j.cosrev.2020.100279","volume":"37","author":"J Singh","year":"2020","unstructured":"Singh J, Behal S (2020) Detection and mitigation of DDoS attacks in SDN: a comprehensive review, research challenges and future directions. Comput Sci Rev 37:100279. https:\/\/doi.org\/10.1016\/j.cosrev.2020.100279","journal-title":"Comput Sci Rev"},{"key":"10976_CR17","doi-asserted-by":"publisher","unstructured":"Facchini H, Perez S, Blanchet R et al (2021) Experimental performance contrast between SDN and traditional networks. In: 2021 IEEE CHILEAN conference on electrical, electronics engineering, information and communication technologies (CHILECON), Valpara\u00edso, Chile, pp 1\u20136. https:\/\/doi.org\/10.1109\/CHILECON54041.2021.9702982","DOI":"10.1109\/CHILECON54041.2021.9702982"},{"issue":"4","key":"10976_CR18","doi-asserted-by":"publisher","first-page":"3542","DOI":"10.1109\/COMST.2018.2839348","volume":"20","author":"A Abdou","year":"2018","unstructured":"Abdou A, van Oorschot PC, Wan T (2018) Comparative analysis of control plane security of SDN and conventional networks. IEEE Commun Surv Tutor 20(4):3542\u20133559. https:\/\/doi.org\/10.1109\/COMST.2018.2839348","journal-title":"IEEE Commun Surv Tutor"},{"issue":"29","key":"10976_CR19","doi-asserted-by":"publisher","first-page":"9","DOI":"10.1007\/s10922-020-09575-4","volume":"29","author":"S Ahmad","year":"2021","unstructured":"Ahmad S, Mir AH (2021) Scalability, consistency, reliability and security in sdn controllers: a survey of diverse SDN controllers. J Netw Syst Manage 29(29):9","journal-title":"J Netw Syst Manage"},{"key":"10976_CR20","doi-asserted-by":"publisher","first-page":"325","DOI":"10.1109\/COMST.2016.2618874","volume":"19","author":"DB Rawat","year":"2017","unstructured":"Rawat DB, Reddy SR (2017) Software defined networking architecture, security and energy efficiency: a survey. IEEE Commun Surv Tutor 19:325\u2013346","journal-title":"IEEE Commun Surv Tutor"},{"key":"10976_CR21","doi-asserted-by":"publisher","first-page":"102595","DOI":"10.1016\/j.jnca.2020.102595","volume":"159","author":"JC Correa Chica","year":"2020","unstructured":"Correa Chica JC, Cuatindioy Imbachi J, Botero Vega JF (2020) Security in SDN: a comprehensive survey. J Network Comput Appl 159:102595","journal-title":"J Network Comput Appl"},{"key":"10976_CR22","doi-asserted-by":"publisher","first-page":"149","DOI":"10.1016\/j.future.2021.03.011","volume":"122","author":"LF Eliyan","year":"2021","unstructured":"Eliyan LF, Pietro RD (2021) DoS and DDoS attacks in software defined networks: a survey of existing solutions and research challenges. Future Gen Comput Syst 122:149\u2013171","journal-title":"Future Gen Comput Syst"},{"key":"10976_CR23","unstructured":"University of California (1999) Cup KDD 1999 Data. https:\/\/kdd.ics.uci.edu\/databases\/kddcup99\/kddcup99.html"},{"key":"10976_CR24","doi-asserted-by":"crossref","unstructured":"Tavallaee M, Bagheri E, Lu W, Ghorbani AA (2009) A detailed analysis of the KDD CUP 99 Data Set. In: 2009 Proceedings of the second IEEE symposium on computational intelligence for security and defense applications (CISDA\u201909). Ottawa, ON, Canada, pp 1\u20136","DOI":"10.1109\/CISDA.2009.5356528"},{"key":"10976_CR25","doi-asserted-by":"publisher","unstructured":"University of Southern California-Information Sciences Institute. https:\/\/doi.org\/10.23721\/109\/1358116","DOI":"10.23721\/109\/1358116"},{"key":"10976_CR26","unstructured":"CAIDA (2007) The CAIDA DDoS Attack 2007Dataset, 2007. https:\/\/www.caida.org\/catalog\/datasets\/ddos-20070804_dataset\/"},{"key":"10976_CR27","doi-asserted-by":"crossref","unstructured":"Moustafa N, Slay J (2015) UNSW-NB15: a comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). In: 2015 Military communications and information systems conference (MilCIS)","DOI":"10.1109\/MilCIS.2015.7348942"},{"issue":"2018","key":"10976_CR28","first-page":"108","volume":"1","author":"I Sharafaldin","year":"2018","unstructured":"Sharafaldin I, Lashkari AH, Ghorbani AA (2018) Toward generating a new intrusion detection dataset and intrusion traffic characterization. ICISSP 1(2018):108\u2013116","journal-title":"ICISSP"},{"key":"10976_CR29","doi-asserted-by":"publisher","first-page":"779","DOI":"10.1016\/j.future.2019.05.041","volume":"100","author":"N Koroniotis","year":"2019","unstructured":"Koroniotis N, Moustafa N, Sitnikova E, Turnbull B (2019) Towards the development of a realistic botnet dataset in the Internet of Things for network forensic analytics: BoT-IoU dataset. Future Generat. Comput. Syst. 100:779\u2013796. https:\/\/doi.org\/10.1016\/j.future.2019.05.041","journal-title":"Future Generat. Comput. Syst."},{"key":"10976_CR30","doi-asserted-by":"publisher","first-page":"165263","DOI":"10.1109\/ACCESS.2020.3022633","volume":"8","author":"MS Elsayed","year":"2020","unstructured":"Elsayed MS, Le-Khac NA, Jurcut AD (2020) InSDN: A novel SDN intrusion dataset. IEEE Access 8:165263\u2013165284. https:\/\/doi.org\/10.1109\/ACCESS.2020.3022633","journal-title":"IEEE Access"},{"issue":"10","key":"10976_CR31","doi-asserted-by":"publisher","first-page":"6345","DOI":"10.1109\/TPAMI.2021.3085591","volume":"44","author":"X Zhang","year":"2022","unstructured":"Zhang X, Jiao L, Granmo O-C, Goodwin M (2022) On the convergence of Tsetlin machines for the IDENTITY- and NOT operators. IEEE Trans Pattern Anal Mach Intell 44(10):6345\u20136359. https:\/\/doi.org\/10.1109\/TPAMI.2021.3085591","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"10976_CR32","unstructured":"Bhattarai B, Granmo O-C, Jiao L (2022) ConvTextTM: An explainable convolutional Tsetlin machine framework for text classification. In: Proceedings of the thirteenth language resources and evaluation conference (LREC). pp 3761\u20133770"},{"key":"10976_CR33","doi-asserted-by":"publisher","first-page":"203","DOI":"10.3390\/s19010203","volume":"19","author":"X Tan","year":"2019","unstructured":"Tan X, Su S, Huang Z et al (2019) wireless sensor networks intrusion detection based on SMOTE and the random forest algorithm. Sensors 19:203. https:\/\/doi.org\/10.3390\/s19010203","journal-title":"Sensors"},{"key":"10976_CR34","doi-asserted-by":"publisher","first-page":"10859","DOI":"10.1007\/s13369-020-04504-w","volume":"45","author":"R Wazirali","year":"2020","unstructured":"Wazirali R (2020) An improved intrusion detection system based on KNN Hyperparameter tuning and cross-validation. Arab J Sci Eng 45:10859\u201310873. https:\/\/doi.org\/10.1007\/s13369-020-04504-w","journal-title":"Arab J Sci Eng"},{"key":"10976_CR35","doi-asserted-by":"publisher","unstructured":"Anton SDD, Sinha S, Schotten HD (2019) Anomaly-based intrusion detection in industrial data with SVM and random forests. In: 2019 International conference on software, telecommunications and computer networks (SoftCOM), pp 1\u20136. https:\/\/doi.org\/10.23919\/SOFTCOM.2019.8903672","DOI":"10.23919\/SOFTCOM.2019.8903672"},{"key":"10976_CR36","doi-asserted-by":"publisher","first-page":"138432","DOI":"10.1109\/ACCESS.2021.3118573","volume":"9","author":"T Wisanwanichthan","year":"2021","unstructured":"Wisanwanichthan T, Thammawichai M (2021) A double-layered hybrid approach for network intrusion detection system using combined Naive Bayes and SVM. IEEE Access 9:138432\u2013138450. https:\/\/doi.org\/10.1109\/ACCESS.2021.3118573","journal-title":"IEEE Access"},{"key":"10976_CR37","doi-asserted-by":"publisher","first-page":"652801","DOI":"10.3389\/fenrg.2021.652801","volume":"9","author":"M Chen","year":"2021","unstructured":"Chen M, Fan C, Wang X et al (2021) A review on data preprocessing techniques toward efficient and reliable knowledge discovery from building operational data. Front Energy Res. 9:652801. https:\/\/doi.org\/10.3389\/fenrg.2021.652801","journal-title":"Front Energy Res."},{"key":"10976_CR38","doi-asserted-by":"publisher","first-page":"3669","DOI":"10.1007\/s12652-018-1093-8","volume":"10","author":"E Besharati","year":"2019","unstructured":"Besharati E, Naderan M, Namjoo E (2019) LR-HIDS: logistic regression host-based intrusion detection system for cloud environments. J Ambient Intell Human Comput 10:3669\u20133692. https:\/\/doi.org\/10.1007\/s12652-018-1093-8","journal-title":"J Ambient Intell Human Comput"},{"key":"10976_CR39","doi-asserted-by":"publisher","unstructured":"Abdallah M, Khac NL, Jahromi H et al (2021) A hybrid CNN-LSTM based approach for anomaly detection systems in SDNs. In: Proceedings of the 16th international conference on availability, reliability and security (ARES \u201921). Vienna, Austria, pp 34\u201341. https:\/\/doi.org\/10.1145\/3465481.3469190","DOI":"10.1145\/3465481.3469190"},{"key":"10976_CR40","doi-asserted-by":"publisher","unstructured":"Abeyrathna KD, Pussewalage HSG, Ranasinghe SN (2020) Intrusion detection with interpretable rules generated using the Tsetlin machine. In: 2020 IEEE symposium series on computational intelligence (SSCI). Canberra, ACT, Australia, pp 1121\u20131130. https:\/\/doi.org\/10.1109\/SSCI47803.2020.9308206","DOI":"10.1109\/SSCI47803.2020.9308206"},{"issue":"2","key":"10976_CR41","doi-asserted-by":"publisher","first-page":"233","DOI":"10.18280\/ria.360207","volume":"36","author":"MA Mohsin","year":"2022","unstructured":"Mohsin MA, Hamad AH (2022) Performance evaluation of SDN DDoS attack detection and mitigation based random forest and K-nearest neighbors machine learning algorithms. Revue d Intell Artif 36(2):233\u2013240. https:\/\/doi.org\/10.18280\/ria.360207","journal-title":"Revue d Intell Artif"},{"key":"10976_CR42","doi-asserted-by":"publisher","unstructured":"Megantara AA, Ahmad T (2020) Feature importance ranking for increasing performance of intrusion detection system. In: 2020 3rd International conference on computer and informatics engineering (IC2IE), Yogyakarta, Indonesia, pp 37\u201342. https:\/\/doi.org\/10.1109\/IC2IE50715.2020.9274570","DOI":"10.1109\/IC2IE50715.2020.9274570"},{"key":"10976_CR43","doi-asserted-by":"publisher","unstructured":"Abeyrathna KD, Granmo OC, Zhang X, Goodwin M (2019) A scheme for continuous input to the Tsetlin machine with applications to forecasting disease outbreaks. In: Advances and trends in artificial intelligence. From theory to practice. IEAAIE 2019, 11606. Springer, Cham. https:\/\/doi.org\/10.1007\/978-3-030-22999-3_49","DOI":"10.1007\/978-3-030-22999-3_49"},{"key":"10976_CR44","doi-asserted-by":"publisher","unstructured":"Pal K, Patel BV (2020) Data classification with k-fold cross validation and holdout accuracy estimation methods with 5 different machine learning techniques. In: 2020 Fourth International conference on computing methodologies and communication (ICCMC), Erode, India, pp 83\u201387. https:\/\/doi.org\/10.1109\/ICCMC48092.2020.ICCMC-00016","DOI":"10.1109\/ICCMC48092.2020.ICCMC-00016"},{"key":"10976_CR45","unstructured":"Memory Profiler. https:\/\/pypi.org\/project\/memory-profiler\/"}],"container-title":["Neural Computing and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00521-025-10976-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s00521-025-10976-2\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00521-025-10976-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,6]],"date-time":"2025-03-06T17:35:34Z","timestamp":1741282534000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s00521-025-10976-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,1,24]]},"references-count":45,"journal-issue":{"issue":"9","published-print":{"date-parts":[[2025,3]]}},"alternative-id":["10976"],"URL":"https:\/\/doi.org\/10.1007\/s00521-025-10976-2","relation":{},"ISSN":["0941-0643","1433-3058"],"issn-type":[{"value":"0941-0643","type":"print"},{"value":"1433-3058","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,1,24]]},"assertion":[{"value":"2 April 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"3 January 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"24 January 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have no financial or proprietary interests in any material discussed in this article.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"This research utilizes the KDDCup99 dataset, which is publicly available for academic use. We adhere to ethical principles throughout our research. We prioritize data privacy, responsible use, and avoiding potential harm, focusing our methods on modeling based on KDDCup99 dataset without any unethical irresponsibility.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical approval"}}]}}