{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T15:52:48Z","timestamp":1784303568467,"version":"3.55.0"},"reference-count":38,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2023,3,15]],"date-time":"2023-03-15T00:00:00Z","timestamp":1678838400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2023,3,15]],"date-time":"2023-03-15T00:00:00Z","timestamp":1678838400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100001794","name":"The University of Queensland","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100001794","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2023,8]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>\n                    Machine learning (ML) models have proved efficient in classifying data samples into their respective categories. The standard ML evaluation methodology assumes that test data samples are derived from pre-observed classes used in the training phase. However, in applications such as Network Intrusion Detection Systems (NIDSs), obtaining data samples of all attack classes to be observed is challenging. ML-based NIDSs face new attack traffic known as zero-day attacks that are not used in training due to their non-existence at the time. Therefore, this paper proposes a novel zero-shot learning methodology to evaluate the performance of ML-based NIDSs in recognising zero-day attack scenarios. In the attribute learning stage, the learning models map network data features to semantic attributes that distinguish between known attacks and benign behaviour. In the inference stage, the models construct the relationships between known and zero-day attacks to detect them as malicious. A new evaluation metric is defined as\n                    <jats:italic>Zero-day Detection Rate (Z-DR)<\/jats:italic>\n                    to measure the effectiveness of the learning model in detecting unknown attacks. The proposed framework is evaluated using two key ML models and two modern NIDS data sets. The results demonstrate that for certain zero-day attack groups discovered in this paper, ML-based NIDSs are ineffective in detecting them as malicious. Further analysis shows that attacks with a low Z-DR have a significantly distinct feature distribution and a higher Wasserstein Distance range than the other attack classes.\n                  <\/jats:p>","DOI":"10.1007\/s10207-023-00676-0","type":"journal-article","created":{"date-parts":[[2023,3,26]],"date-time":"2023-03-26T19:26:04Z","timestamp":1679858764000},"page":"947-959","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":91,"title":["From zero-shot machine learning to zero-day attack detection"],"prefix":"10.1007","volume":"22","author":[{"given":"Mohanad","family":"Sarhan","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Siamak","family":"Layeghy","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Marcus","family":"Gallagher","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Marius","family":"Portmann","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2023,3,15]]},"reference":[{"issue":"7553","key":"676_CR1","doi-asserted-by":"publisher","first-page":"452","DOI":"10.1038\/nature14541","volume":"521","author":"Z Ghahramani","year":"2015","unstructured":"Ghahramani, Z.: Probabilistic machine learning and artificial intelligence. Nature 521(7553), 452\u2013459 (2015)","journal-title":"Nature"},{"key":"676_CR2","doi-asserted-by":"crossref","unstructured":"Panch, T.,\u00a0Szolovits, P.,\u00a0Atun, R.: Artificial intelligence, machine learning and health systems. J. Glob. Health 8(2) (2018)","DOI":"10.7189\/jogh.08.020303"},{"key":"676_CR3","doi-asserted-by":"crossref","unstructured":"Koza, J.\u00a0R., Bennett, F.\u00a0H.,\u00a0Andre, D., Keane, M.\u00a0A.: Automated Design of Both the Topology and Sizing of Analog Electrical Circuits Using Genetic Programming, pp.\u00a0151\u2013170. Springer Netherlands, Dordrecht (1996)","DOI":"10.1007\/978-94-009-0279-4_9"},{"issue":"1","key":"676_CR4","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1186\/s40537-014-0007-7","volume":"2","author":"MM Najafabadi","year":"2015","unstructured":"Najafabadi, M.M., Villanustre, F., Khoshgoftaar, T.M., Seliya, N., Wald, R., Muharemagic, E.: Deep learning applications and challenges in big data analytics. J. Big Data 2(1), 1\u201321 (2015)","journal-title":"J. Big Data"},{"issue":"9","key":"676_CR5","doi-asserted-by":"publisher","first-page":"82","DOI":"10.1109\/MC.2019.2914775","volume":"52","author":"R Bloomfield","year":"2019","unstructured":"Bloomfield, R., Khlaaf, H., Conmy, P.R., Fletcher, G.: Disruptive innovations and disruptive assurance: assuring machine learning and autonomy. Computer 52(9), 82\u201389 (2019)","journal-title":"Computer"},{"issue":"2","key":"676_CR6","doi-asserted-by":"publisher","first-page":"1153","DOI":"10.1109\/COMST.2015.2494502","volume":"18","author":"AL Buczak","year":"2015","unstructured":"Buczak, A.L., Guven, E.: A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Commun. Surv. Tutorials 18(2), 1153\u20131176 (2015)","journal-title":"IEEE Commun. Surv. Tutorials"},{"key":"676_CR7","doi-asserted-by":"crossref","unstructured":"Alrashdi, I.,\u00a0Alqazzaz, A.,\u00a0Aloufi, E.,\u00a0Alharthi, R.,\u00a0Zohdy, M.,\u00a0Ming, H.: Ad-iot: Anomaly detection of iot cyberattacks in smart city using machine learning. In: 2019 IEEE 9th Annual Computing and Communication Workshop and Conference (CCWC), pp.\u00a00305\u20130310, IEEE (2019)","DOI":"10.1109\/CCWC.2019.8666450"},{"key":"676_CR8","doi-asserted-by":"crossref","unstructured":"Dua, S.,\u00a0Du, X.: Data mining and machine learning in cybersecurity. CRC press (2016)","DOI":"10.1201\/b10867"},{"key":"676_CR9","doi-asserted-by":"crossref","unstructured":"Apruzzese, G.\u00a0Colajanni, M.,\u00a0Ferretti, L.,\u00a0Guido, A.,\u00a0Marchetti, M.: On the effectiveness of machine and deep learning for cyber security. In: 2018 10th International Conference on Cyber Conflict (CyCon), pp.\u00a0371\u2013390, IEEE (2018)","DOI":"10.23919\/CYCON.2018.8405026"},{"issue":"3","key":"676_CR10","doi-asserted-by":"publisher","first-page":"26","DOI":"10.1109\/65.283931","volume":"8","author":"B Mukherjee","year":"1994","unstructured":"Mukherjee, B., Heberlein, L.T., Levitt, K.N.: Network intrusion detection. IEEE Netw. 8(3), 26\u201341 (1994)","journal-title":"IEEE Netw."},{"issue":"3","key":"676_CR11","first-page":"35","volume":"1","author":"V Kumar","year":"2012","unstructured":"Kumar, V., Sangwan, O.P.: Signature based intrusion detection system using snort. Int. J. Comput. Appl. Inf. Technol. 1(3), 35\u201341 (2012)","journal-title":"Int. J. Comput. Appl. Inf. Technol."},{"key":"676_CR12","doi-asserted-by":"crossref","unstructured":"Garcia-Teodoro, P.,\u00a0Diaz-Verdejo, J.,\u00a0Maci\u00e1-Fern\u00e1ndez, G.,\u00a0V\u00e1zquez, E.: Anomaly-based network intrusion detection: techniques, systems and challenges. comput. Security 28(1\u20132), pp.\u00a018\u201328 (2009)","DOI":"10.1016\/j.cose.2008.08.003"},{"key":"676_CR13","doi-asserted-by":"crossref","unstructured":"Bilge, L.,\u00a0Dumitra\u015f, T.: Before we knew it: an empirical study of zero-day attacks in the real world. In: Proceedings of the 2012 ACM Conference on Computer and Communications Security, pp.\u00a0833\u2013844 (2012)","DOI":"10.1145\/2382196.2382284"},{"key":"676_CR14","doi-asserted-by":"crossref","unstructured":"Stellios, I.,\u00a0Kotzanikolaou, P.,\u00a0Psarakis, M.: Advanced persistent threats and zero-day exploits in industrial internet of things. In: Security and Privacy Trends in the Industrial Internet of Things, pp.\u00a047\u201368, Springer (2019)","DOI":"10.1007\/978-3-030-12330-7_3"},{"key":"676_CR15","doi-asserted-by":"crossref","unstructured":"Mell, P.,\u00a0Grance, T.: Use of the common vulnerabilities and exposures (cve) vulnerability naming scheme, tech. rep., National Inst of Standards and Technology Gaithersburg MD Computer Security Div (2002)","DOI":"10.6028\/NIST.SP.800-51"},{"key":"676_CR16","doi-asserted-by":"crossref","unstructured":"Ganame, K., Allaire, M.\u00a0A.,\u00a0Zagdene, G.,\u00a0Boudar, O.: Network behavioral analysis for zero-day malware detection\u2013a case study. In: International Conference on Intelligent, Secure, and Dependable Systems in Distributed and Cloud Environments, pp.\u00a0169\u2013181, Springer (2017)","DOI":"10.1007\/978-3-319-69155-8_13"},{"key":"676_CR17","unstructured":"Sinclair, C.,\u00a0Pierce, L.,\u00a0Matzner, S.: An application of machine learning to network intrusion detection. In: Proceedings 15th Annual Computer Security Applications Conference (ACSAC\u201999), pp.\u00a0371\u2013377, IEEE (1999)"},{"key":"676_CR18","doi-asserted-by":"crossref","unstructured":"S.\u00a0Sahu and B.\u00a0M. Mehtre, Network intrusion detection system using j48 decision tree. In: 2015 International Conference on Advances in Computing, Communications and Informatics (ICACCI), pp.\u00a02023\u20132026, IEEE (2015)","DOI":"10.1109\/ICACCI.2015.7275914"},{"key":"676_CR19","doi-asserted-by":"crossref","unstructured":"Xian, Y.,\u00a0Schiele, B., Akata, Z.: Zero-shot learning-the good, the bad and the ugly. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp.\u00a04582\u20134591 (2017)","DOI":"10.1109\/CVPR.2017.328"},{"issue":"2","key":"676_CR20","first-page":"1","volume":"10","author":"W Wang","year":"2019","unstructured":"Wang, W., Zheng, V.W., Yu, H., Miao, C.: A survey of zero-shot learning: settings, methods, and applications. ACM Trans. Intell. Syst. Technol. (TIST) 10(2), 1\u201337 (2019)","journal-title":"ACM Trans. Intell. Syst. Technol. (TIST)"},{"key":"676_CR21","doi-asserted-by":"publisher","first-page":"193981","DOI":"10.1109\/ACCESS.2020.3033494","volume":"8","author":"Z Zhang","year":"2020","unstructured":"Zhang, Z., Liu, Q., Qiu, S., Zhou, S., Zhang, C.: Unknown attack detection based on zero-shot learning. IEEE Access 8, 193981\u2013193991 (2020)","journal-title":"IEEE Access"},{"key":"676_CR22","doi-asserted-by":"crossref","unstructured":"Sommer, R.,\u00a0Paxson, V.: Outside the closed world: on using machine learning for network intrusion detection. In: 2010 IEEE Symposium on Security and Privacy, pp.\u00a0305\u2013316, IEEE (2010)","DOI":"10.1109\/SP.2010.25"},{"issue":"7","key":"676_CR23","doi-asserted-by":"publisher","first-page":"772","DOI":"10.1016\/j.comcom.2012.01.016","volume":"35","author":"P Casas","year":"2012","unstructured":"Casas, P., Mazel, J., Owezarski, P.: Unsupervised network intrusion detection systems: detecting the unknown without knowledge. Comput. Commun. 35(7), 772\u2013783 (2012)","journal-title":"Comput. Commun."},{"key":"676_CR24","doi-asserted-by":"crossref","unstructured":"Holm, H.: Signature based intrusion detection for zero-day attacks:(not) a closed chapter?. In: 2014 47th Hawaii International Conference on System Sciences, pp.\u00a04895\u20134904, IEEE (2014)","DOI":"10.1109\/HICSS.2014.600"},{"issue":"10","key":"676_CR25","doi-asserted-by":"publisher","first-page":"1684","DOI":"10.3390\/electronics9101684","volume":"9","author":"H Hindy","year":"2020","unstructured":"Hindy, H., Atkinson, R., Tachtatzis, C., Colin, J.-N., Bayne, E., Bellekens, X.: Utilising deep learning techniques for effective zero-day attack detection. Electronics 9(10), 1684 (2020)","journal-title":"Electronics"},{"key":"676_CR26","doi-asserted-by":"crossref","unstructured":"Li, Z.,\u00a0Qin, Z.,\u00a0Shen, P.,\u00a0Jiang, L.: Zero-shot learning for intrusion detection via attribute representation. In: International Conference on Neural Information Processing, pp.\u00a0352\u2013364, Springer (2019)","DOI":"10.1007\/978-3-030-36708-4_29"},{"issue":"5","key":"676_CR27","doi-asserted-by":"publisher","first-page":"2211","DOI":"10.1007\/s40747-021-00396-9","volume":"7","author":"V Kumar","year":"2021","unstructured":"Kumar, V., Sinha, D.: A robust intelligent zero-day cyber-attack detection technique. Complex Intell. Syst. 7(5), 2211\u20132234 (2021)","journal-title":"Complex Intell. Syst."},{"key":"676_CR28","doi-asserted-by":"crossref","unstructured":"Siddique, K.,\u00a0Akhtar, Z.,\u00a0Aslam Khan, F.,\u00a0Kim, Y.: Kdd cup 99 data sets: A perspective on the role of data sets in network intrusion detection research. Computer 52(2), 41\u201351 (2019)","DOI":"10.1109\/MC.2018.2888764"},{"key":"676_CR29","doi-asserted-by":"crossref","unstructured":"Felix, R.,\u00a0Harwood, B.,\u00a0Sasdelli, M.,\u00a0Carneiro, G.: Generalised zero-shot learning with domain classification in a joint semantic and visual space. In: 2019 Digital Image Computing: Techniques and Applications (DICTA), pp.\u00a01\u20138, IEEE (2019)","DOI":"10.1109\/DICTA47822.2019.8945949"},{"issue":"1","key":"676_CR30","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1023\/A:1010933404324","volume":"45","author":"L Breiman","year":"2001","unstructured":"Breiman, L.: Random forests. Mach. Learn. 45(1), 5\u201332 (2001)","journal-title":"Mach. Learn."},{"key":"676_CR31","unstructured":"Hinton, G.\u00a0E.: Connectionist learning procedures. Mach. learn., pp.\u00a0555\u2013610, Elsevier (1990)"},{"issue":"1","key":"676_CR32","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1007\/BF00117831","volume":"24","author":"L Breiman","year":"1996","unstructured":"Breiman, L.: Some properties of splitting criteria. Mach. Learn. 24(1), 41\u201347 (1996)","journal-title":"Mach. Learn."},{"key":"676_CR33","unstructured":"Agarap, A.\u00a0F.: Deep learning using rectified linear units (relu). arXiv preprint arXiv:1803.08375 (2018)"},{"key":"676_CR34","doi-asserted-by":"crossref","unstructured":"Moustafa, N.,\u00a0Slay, J.: Unsw-nb15: a comprehensive data set for network intrusion detection systems (unsw-nb15 network data set). In: 2015 Military Communications and Information Systems Conference (MilCIS), pp.\u00a01\u20136, IEEE (2015)","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"676_CR35","unstructured":"Sarhan, M.,\u00a0Layeghy, S.,\u00a0Moustafa, N.,\u00a0Portmann, M.: Towards a Standard Feature Set of NIDS Datasets. arXiv preprint arXiv:2101.11315 (2021)"},{"issue":"2","key":"676_CR36","doi-asserted-by":"publisher","first-page":"2042","DOI":"10.1016\/j.asoc.2010.07.002","volume":"11","author":"E Corchado","year":"2011","unstructured":"Corchado, E., Herrero, \u00c1.: Neural visualization of network traffic data for intrusion detection. Appl. Soft Comput. 11(2), 2042\u20132056 (2011)","journal-title":"Appl. Soft Comput."},{"key":"676_CR37","unstructured":"Layeghy, S.,\u00a0Gallagher, M.,\u00a0Portmann, M.: Benchmarking the Benchmark - Analysis of Synthetic NIDS Datasets. arXiv preprint arXiv:2104.09029 (2021)"},{"issue":"2","key":"676_CR38","doi-asserted-by":"publisher","first-page":"47","DOI":"10.3390\/e19020047","volume":"19","author":"A Ramdas","year":"2017","unstructured":"Ramdas, A., Trillos, N.G., Cuturi, M.: On wasserstein two-sample testing and related families of nonparametric tests. Entropy 19(2), 47 (2017)","journal-title":"Entropy"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-023-00676-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10207-023-00676-0\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-023-00676-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,7,25]],"date-time":"2023-07-25T21:07:59Z","timestamp":1690319279000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10207-023-00676-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,3,15]]},"references-count":38,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2023,8]]}},"alternative-id":["676"],"URL":"https:\/\/doi.org\/10.1007\/s10207-023-00676-0","relation":{"has-preprint":[{"id-type":"doi","id":"10.21203\/rs.3.rs-2097775\/v1","asserted-by":"object"}]},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,3,15]]},"assertion":[{"value":"15 March 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have no competing interests to declare relevant to this article\u2019s content.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"This article does not contain any studies with human participants or animals performed by any authors.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Human and animal participants"}}]}}