{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,13]],"date-time":"2026-07-13T18:08:12Z","timestamp":1783966092846,"version":"3.55.0"},"reference-count":150,"publisher":"Springer Science and Business Media LLC","issue":"9","license":[{"start":{"date-parts":[[2025,6,23]],"date-time":"2025-06-23T00:00:00Z","timestamp":1750636800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"},{"start":{"date-parts":[[2025,6,23]],"date-time":"2025-06-23T00:00:00Z","timestamp":1750636800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"}],"funder":[{"DOI":"10.13039\/100006228","name":"Oak Ridge National Laboratory","doi-asserted-by":"publisher","award":["LDRD"],"award-info":[{"award-number":["LDRD"]}],"id":[{"id":"10.13039\/100006228","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100006228","name":"Oak Ridge National Laboratory","doi-asserted-by":"publisher","award":["LDRD"],"award-info":[{"award-number":["LDRD"]}],"id":[{"id":"10.13039\/100006228","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100006228","name":"Oak Ridge National Laboratory","doi-asserted-by":"publisher","award":["LDRD"],"award-info":[{"award-number":["LDRD"]}],"id":[{"id":"10.13039\/100006228","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100006228","name":"Oak Ridge National Laboratory","doi-asserted-by":"publisher","award":["LDRD"],"award-info":[{"award-number":["LDRD"]}],"id":[{"id":"10.13039\/100006228","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Artif Intell Rev"],"DOI":"10.1007\/s10462-025-11292-w","type":"journal-article","created":{"date-parts":[[2025,6,23]],"date-time":"2025-06-23T02:25:40Z","timestamp":1750645540000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":42,"title":["Adaptive anomaly detection for identifying attacks in cyber-physical systems: A systematic literature review"],"prefix":"10.1007","volume":"58","author":[{"given":"Pablo","family":"Moriano","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Steven C.","family":"Hespeler","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mingyan","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Maria","family":"Mahbub","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,6,23]]},"reference":[{"key":"11292_CR1","doi-asserted-by":"crossref","unstructured":"Abie H (2019) Cognitive cybersecurity for CPS-IoT enabled healthcare ecosystems. In: 2019 13th International Symposium on Medical Information and Communication Technology (ISMICT). IEEE, pp 1\u20136","DOI":"10.1109\/ISMICT.2019.8743670"},{"key":"11292_CR2","doi-asserted-by":"publisher","first-page":"19921","DOI":"10.1109\/ACCESS.2020.2968934","volume":"8","author":"MRC Acosta","year":"2020","unstructured":"Acosta MRC, Ahmed S, Garcia CE, Koo I (2020) Extremely randomized trees-based scheme for stealthy cyber-attack detection in smart grid networks. IEEE Access 8:19921\u201319933","journal-title":"IEEE Access"},{"issue":"5","key":"11292_CR3","doi-asserted-by":"publisher","first-page":"4049","DOI":"10.1109\/TSG.2017.2647778","volume":"9","author":"U Adhikari","year":"2017","unstructured":"Adhikari U, Morris TH, Pan S (2017) Applying hoeffding adaptive trees for real-time cyber-power event and intrusion classification. IEEE Trans Smart Grid 9(5):4049\u20134060","journal-title":"IEEE Trans Smart Grid"},{"key":"11292_CR4","doi-asserted-by":"publisher","first-page":"134","DOI":"10.1016\/j.neucom.2017.04.070","volume":"262","author":"S Ahmad","year":"2017","unstructured":"Ahmad S, Lavin A, Purdy S, Agha Z (2017) Unsupervised real-time anomaly detection for streaming data. Neurocomputing 262:134\u2013147","journal-title":"Neurocomputing"},{"key":"11292_CR5","doi-asserted-by":"crossref","unstructured":"Akowuah F, Kong F (2021) Real-time adaptive sensor attack detection in autonomous cyber-physical systems. In: 2021 IEEE 27th real-time and embedded technology and applications symposium (RTAS). IEEE, pp 237\u2013250","DOI":"10.1109\/RTAS52030.2021.00027"},{"issue":"1","key":"11292_CR6","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1186\/s13677-022-00338-x","volume":"11","author":"KA Alaghbari","year":"2022","unstructured":"Alaghbari KA, Saad MHM, Hussain A, Alam MR (2022) Complex event processing for physical and cyber security in datacentres-recent progress, challenges and recommendations. J Cloud Comput 11(1):65","journal-title":"J Cloud Comput"},{"key":"11292_CR7","doi-asserted-by":"crossref","unstructured":"Al-E\u2019mari S, Anbar M, Sanjalawe Y, Manickam S (2020) A labeled transactions-based dataset on the ethereum network. In: International conference on advances in cyber security, Penang, Malaysia. Springer, Singapore, pp 61\u201379","DOI":"10.1007\/978-981-33-6835-4_5"},{"issue":"5","key":"11292_CR8","doi-asserted-by":"publisher","first-page":"1045","DOI":"10.1007\/s11571-022-09780-8","volume":"16","author":"MA Alohali","year":"2022","unstructured":"Alohali MA, Al-Wesabi FN, Hilal AM, Goel S, Gupta D, Khanna A (2022) Artificial intelligence enabled intrusion detection systems for cognitive cyber-physical systems in industry 4.0 environment. Cogn Neurodyn 16(5):1045\u20131057","journal-title":"Cogn Neurodyn"},{"key":"11292_CR9","doi-asserted-by":"crossref","unstructured":"Aloraini F, Javed A (2024) Adversarial attacks in intrusion detection systems: triggering false alarms in connected and autonomous vehicles. In: 2024 IEEE international conference on cyber security and resilience (CSR). IEEE, pp 714\u2013719","DOI":"10.1109\/CSR61664.2024.10679419"},{"issue":"1","key":"11292_CR10","doi-asserted-by":"publisher","first-page":"59","DOI":"10.1007\/s11761-022-00354-4","volume":"17","author":"FH Alshammari","year":"2023","unstructured":"Alshammari FH (2023) Design of capability maturity model integration with cybersecurity risk severity complex prediction using Bayesian-based machine learning models. SOCA 17(1):59\u201372","journal-title":"SOCA"},{"issue":"1","key":"11292_CR11","doi-asserted-by":"publisher","first-page":"181","DOI":"10.1186\/s13677-023-00564-x","volume":"12","author":"AA Alsulami","year":"2023","unstructured":"Alsulami AA, Al-Haija QA, Alturki B, Alqahtani A, Alsini R (2023) Security strategy for autonomous vehicle cyber-physical systems using transfer learning. J Cloud Comput 12(1):181\u2013199","journal-title":"J Cloud Comput"},{"key":"11292_CR12","doi-asserted-by":"publisher","DOI":"10.1016\/j.measurement.2021.110145","volume":"186","author":"MM Althobaiti","year":"2021","unstructured":"Althobaiti MM, Kumar KPM, Gupta D, Kumar S, Mansour RF (2021) An intelligent cognitive computing based intrusion detection for industrial cyber-physical systems. Measurement 186:110145","journal-title":"Measurement"},{"key":"11292_CR13","volume":"48","author":"RO Andrade","year":"2019","unstructured":"Andrade RO, Yoo SG (2019) Cognitive security: a comprehensive study of cognitive science in cybersecurity. J Inf Secur Appl 48:102352","journal-title":"J Inf Secur Appl"},{"key":"11292_CR14","doi-asserted-by":"crossref","unstructured":"Arrington B, Barnett L, Rufus R, Esterline A (2016) Behavioral modeling intrusion detection system (BMIDS) using internet of things (IoT) behavior-based anomaly detection via immunity-inspired algorithms. In: 2016 25th International conference on computer communication and networks (ICCCN). IEEE, pp 1\u20136","DOI":"10.1109\/ICCCN.2016.7568495"},{"key":"11292_CR15","doi-asserted-by":"publisher","first-page":"124017","DOI":"10.1109\/ACCESS.2022.3224023","volume":"10","author":"K Arshad","year":"2022","unstructured":"Arshad K, Ali RF, Muneer A, Aziz IA, Naseer S, Khan NS, Taib SM (2022) Deep reinforcement learning for anomaly detection: a systematic review. IEEE Access 10:124017\u2013124035","journal-title":"IEEE Access"},{"key":"11292_CR16","doi-asserted-by":"publisher","first-page":"73603","DOI":"10.1109\/ACCESS.2018.2878681","volume":"6","author":"R Atat","year":"2018","unstructured":"Atat R, Liu L, Wu J, Li G, Ye C, Yang Y (2018) Big data meet cyber-physical systems: a panoramic survey. IEEE Access 6:73603\u201373636","journal-title":"IEEE Access"},{"key":"11292_CR17","doi-asserted-by":"crossref","unstructured":"Bacher R, Chatelain F, Michel O (2016) An adaptive robust regression method: application to galaxy spectrum baseline estimation. In: 2016 IEEE international conference on acoustics, speech and signal processing (ICASSP). IEEE, pp 4423\u20134427","DOI":"10.1109\/ICASSP.2016.7472513"},{"issue":"2","key":"11292_CR18","doi-asserted-by":"publisher","first-page":"64","DOI":"10.26483\/ijarcs.v10i2.6395","volume":"10","author":"R Bala","year":"2019","unstructured":"Bala R, Nagpal R (2019) A review on KDD cup9 and NSL-KDD dataset. Int J Adv Res Comput Sci 10(2):64","journal-title":"Int J Adv Res Comput Sci"},{"issue":"7","key":"11292_CR19","doi-asserted-by":"publisher","first-page":"4813","DOI":"10.1007\/s00521-021-06011-9","volume":"35","author":"A Basati","year":"2023","unstructured":"Basati A, Faghih MM (2023) APAE: an iot intrusion detection system using asymmetric parallel auto-encoder. Neural Comput Appl 35(7):4813\u20134833","journal-title":"Neural Comput Appl"},{"key":"11292_CR20","unstructured":"Bezzina D, Sayer J (2014) Safety pilot model deployment: test conductor team report. Report No DOT HS 812(171):18"},{"issue":"9","key":"11292_CR21","doi-asserted-by":"publisher","first-page":"7749","DOI":"10.1109\/JIOT.2022.3229722","volume":"10","author":"I Bibi","year":"2022","unstructured":"Bibi I, Akhunzada A, Kumar N (2022) Deep ai-powered cyber threat analysis in IIoT. IEEE Internet Things J 10(9):7749\u20137760","journal-title":"IEEE Internet Things J"},{"issue":"11","key":"11292_CR22","doi-asserted-by":"publisher","first-page":"103","DOI":"10.1145\/3655635","volume":"67","author":"B Biggio","year":"2024","unstructured":"Biggio B (2024) Machine learning in computer security is difficult to fix. Commun ACM 67(11):103\u2013103","journal-title":"Commun ACM"},{"issue":"1","key":"11292_CR23","doi-asserted-by":"publisher","first-page":"485","DOI":"10.1109\/JIOT.2021.3085194","volume":"9","author":"TM Booij","year":"2021","unstructured":"Booij TM, Chiscop I, Meeuwissen E, Moustafa N, Den Hartog FT (2021) Ton\\_IoT: the role of heterogeneity and the need for standardization of features and attack types in IoT network intrusion data sets. IEEE Internet Things J 9(1):485\u2013496","journal-title":"IEEE Internet Things J"},{"issue":"2","key":"11292_CR24","doi-asserted-by":"publisher","first-page":"1153","DOI":"10.1109\/COMST.2015.2494502","volume":"18","author":"AL Buczak","year":"2015","unstructured":"Buczak AL, Guven E (2015) A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Commun Surv Tutor 18(2):1153\u20131176","journal-title":"IEEE Commun Surv Tutor"},{"issue":"6","key":"11292_CR25","doi-asserted-by":"publisher","first-page":"7802","DOI":"10.1109\/TII.2023.3240586","volume":"19","author":"T Cai","year":"2023","unstructured":"Cai T, Jia T, Adepu S, Li Y, Yang Z (2023) ADAM: an adaptive ddos attack mitigation scheme in software-defined cyber-physical system. IEEE Trans Industr Inf 19(6):7802\u20137813","journal-title":"IEEE Trans Industr Inf"},{"key":"11292_CR26","doi-asserted-by":"publisher","unstructured":"C\u00e1rdenas AA, Amin S, Sastry S (2008) Secure control: Towards survivable cyber-physical systems. In: 2008 The 28th international conference on distributed computing systems workshops. IEEE, Beijing, pp 495\u2013500. https:\/\/doi.org\/10.1109\/ICDCS.Workshops.2008.41","DOI":"10.1109\/ICDCS.Workshops.2008.41"},{"issue":"1","key":"11292_CR27","doi-asserted-by":"publisher","first-page":"25","DOI":"10.1049\/cit2.12028","volume":"6","author":"A Chakraborty","year":"2021","unstructured":"Chakraborty A, Alam M, Dey V, Chattopadhyay A, Mukhopadhyay D (2021) A survey on adversarial attacks and defences. CAAI Trans Intell Technol 6(1):25\u201345","journal-title":"CAAI Trans Intell Technol"},{"issue":"3","key":"11292_CR28","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/1541880.1541882","volume":"41","author":"V Chandola","year":"2009","unstructured":"Chandola V, Banerjee A, Kumar V (2009) Anomaly detection: a survey. ACM Comput Surv (CSUR) 41(3):1\u201358","journal-title":"ACM Comput Surv (CSUR)"},{"key":"11292_CR29","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1186\/s12864-019-6413-7","volume":"21","author":"D Chicco","year":"2020","unstructured":"Chicco D, Jurman G (2020) The advantages of the matthews correlation coefficient (MCC) over f1 score and accuracy in binary classification evaluation. BMC Genomics 21:1\u201313","journal-title":"BMC Genomics"},{"key":"11292_CR30","doi-asserted-by":"crossref","unstructured":"Clements AA, Almakhdhub NS, Saab KS, Srivastava P, Koo J, Bagchi S, Payer M (2017) Protecting bare-metal embedded systems with privilege overlays. In: 2017 IEEE symposium on security and privacy (SP), San Jose, CA. IEEE, pp 289\u2013303","DOI":"10.1109\/SP.2017.37"},{"issue":"18","key":"11292_CR31","doi-asserted-by":"publisher","first-page":"6678","DOI":"10.3390\/en16186678","volume":"16","author":"A Cooper","year":"2023","unstructured":"Cooper A, Bretas A, Meyn S (2023) Anomaly detection in power system state estimation: review and new directions. Energies 16(18):6678","journal-title":"Energies"},{"issue":"5","key":"11292_CR32","doi-asserted-by":"publisher","first-page":"4577","DOI":"10.1109\/TSG.2021.3089041","volume":"12","author":"Y Cui","year":"2021","unstructured":"Cui Y, Bai F, Yan R, Saha T, Ko RK, Liu Y (2021) Source authentication of distribution synchrophasors for cybersecurity of microgrids. IEEE Trans Smart Grid 12(5):4577\u20134580","journal-title":"IEEE Trans Smart Grid"},{"issue":"2","key":"11292_CR33","doi-asserted-by":"publisher","first-page":"1291","DOI":"10.1007\/s11831-021-09628-0","volume":"29","author":"D Dai","year":"2022","unstructured":"Dai D, Boroomand S (2022) A review of artificial intelligence to enhance the security of big data systems: state-of-art, methodologies, applications, and challenges. Arch Comput Methods Eng 29(2):1291\u20131309","journal-title":"Arch Comput Methods Eng"},{"key":"11292_CR34","unstructured":"Das S, Islam MR, Jayakodi NK, Doppa JR (2018) Active anomaly detection via ensembles. arXiv preprint. arXiv:1809.06477"},{"key":"11292_CR35","doi-asserted-by":"publisher","first-page":"318","DOI":"10.1016\/j.procs.2023.01.014","volume":"218","author":"AK Dey","year":"2023","unstructured":"Dey AK, Gupta GP, Sahu SP (2023) Hybrid meta-heuristic based feature selection mechanism for cyber-attack detection in iot-enabled networks. Procedia Comput Sci 218:318\u2013327","journal-title":"Procedia Comput Sci"},{"issue":"11","key":"11292_CR36","doi-asserted-by":"publisher","first-page":"1159","DOI":"10.1007\/s11265-022-01741-y","volume":"94","author":"J Ding","year":"2022","unstructured":"Ding J, Lu C, Li B (2022) A data-driven based security situational awareness framework for power systems. J Signal Process Syst 94(11):1159\u20131168","journal-title":"J Signal Process Syst"},{"key":"11292_CR37","doi-asserted-by":"publisher","first-page":"435","DOI":"10.1016\/j.future.2018.06.042","volume":"90","author":"X Fei","year":"2019","unstructured":"Fei X, Shah N, Verba N, Chao K-M, Sanchez-Anguix V, Lewandowski J, James A, Usman Z (2019) CPS data streams analytics based on machine learning for cloud and fog computing: a survey. Futur Gener Comput Syst 90:435\u2013450","journal-title":"Futur Gener Comput Syst"},{"key":"11292_CR38","doi-asserted-by":"publisher","DOI":"10.1016\/j.sysarc.2019.101694","volume":"103","author":"Z Feng","year":"2020","unstructured":"Feng Z, Guan N, Lv M, Liu W, Deng Q, Liu X, Yi W (2020) Efficient drone hijacking detection using two-step GA-XGBOOST. J Syst Architect 103:101694","journal-title":"J Syst Architect"},{"issue":"4","key":"11292_CR39","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2523813","volume":"46","author":"J Gama","year":"2014","unstructured":"Gama J, \u017dliobait\u0117 I, Bifet A, Pechenizkiy M, Bouchachia A (2014) A survey on concept drift adaptation. ACM comput surv (CSUR) 46(4):1\u201337","journal-title":"ACM comput surv (CSUR)"},{"key":"11292_CR40","unstructured":"Giannoni F, Mancini M, Marinelli F (2018) Anomaly detection models for iot time series data. arXiv preprint. arXiv:1812.00890"},{"issue":"4","key":"11292_CR41","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3203245","volume":"51","author":"J Giraldo","year":"2018","unstructured":"Giraldo J, Urbina D, Cardenas A, Valente J, Faisal M, Ruths J, Tippenhauer NO, Sandberg H, Candell R (2018) A survey of physics-based attack detection in cyber-physical systems. ACM Comput Surv (CSUR) 51(4):1\u201336","journal-title":"ACM Comput Surv (CSUR)"},{"issue":"4","key":"11292_CR42","doi-asserted-by":"publisher","first-page":"0152173","DOI":"10.1371\/journal.pone.0152173","volume":"11","author":"M Goldstein","year":"2016","unstructured":"Goldstein M, Uchida S (2016) A comparative evaluation of unsupervised anomaly detection algorithms for multivariate data. PLoS ONE 11(4):0152173","journal-title":"PLoS ONE"},{"key":"11292_CR43","doi-asserted-by":"crossref","unstructured":"Goodge A, Hooi B, Ng SK, Ng WS (2021) Robustness of autoencoders for anomaly detection under adversarial impact. In: Proceedings of the twenty-ninth international conference on international joint conferences on artificial intelligence, pp 1244\u20131250","DOI":"10.24963\/ijcai.2020\/173"},{"key":"11292_CR44","doi-asserted-by":"publisher","first-page":"185938","DOI":"10.1109\/ACCESS.2020.3030726","volume":"8","author":"T Gopalakrishnan","year":"2020","unstructured":"Gopalakrishnan T, Ruby D, Al-Turjman F, Gupta D, Pustokhina IV, Pustokhin DA, Shankar K (2020) Deep learning enabled data offloading with cyber attack detection model in mobile edge computing systems. IEEE Access 8:185938\u2013185949","journal-title":"IEEE Access"},{"key":"11292_CR45","doi-asserted-by":"publisher","first-page":"101809","DOI":"10.1109\/ACCESS.2021.3097146","volume":"9","author":"D Grimm","year":"2021","unstructured":"Grimm D, Stang M, Sax E (2021) Context-aware security for vehicles and fleets: a survey. IEEE Access 9:101809\u2013101846","journal-title":"IEEE Access"},{"key":"11292_CR46","doi-asserted-by":"crossref","unstructured":"Gupta D, Moni SS, Tosun AS (2023) Integration of digital twin and federated learning for securing vehicular internet of things. In: Proceedings of the 2023 international conference on research in adaptive and convergent systems, Gdansk, Poland, pp 1\u20138","DOI":"10.1145\/3599957.3606250"},{"issue":"5","key":"11292_CR47","doi-asserted-by":"publisher","first-page":"3827","DOI":"10.1109\/JIOT.2022.3172393","volume":"10","author":"E Gyamfi","year":"2022","unstructured":"Gyamfi E, Jurcut AD (2022) Novel online network intrusion detection system for industrial iot based on OI-SVDD and AS-ELM. IEEE Internet Things J 10(5):3827\u20133839","journal-title":"IEEE Internet Things J"},{"issue":"2","key":"11292_CR48","doi-asserted-by":"publisher","first-page":"357","DOI":"10.1016\/j.ijforecast.2013.07.001","volume":"30","author":"T Hong","year":"2014","unstructured":"Hong T, Pinson P, Fan S (2014) Global energy forecasting competition 2012. Int J Forecast 30(2):357\u2013363","journal-title":"Int J Forecast"},{"issue":"4","key":"11292_CR49","doi-asserted-by":"publisher","first-page":"3150","DOI":"10.1109\/TSG.2022.3230730","volume":"14","author":"C Hu","year":"2022","unstructured":"Hu C, Yan J, Liu X (2022) Reinforcement learning-based adaptive feature boosting for smart grid intrusion detection. IEEE Trans Smart Grid 14(4):3150\u20133163","journal-title":"IEEE Trans Smart Grid"},{"key":"11292_CR50","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.101660","volume":"89","author":"L Huang","year":"2020","unstructured":"Huang L, Zhu Q (2020) A dynamic games approach to proactive defense strategies against advanced persistent threats in cyber-physical systems. Comput Secur 89:101660","journal-title":"Comput Secur"},{"key":"11292_CR51","doi-asserted-by":"publisher","first-page":"273","DOI":"10.1016\/j.arcontrol.2022.01.001","volume":"53","author":"Y Huang","year":"2022","unstructured":"Huang Y, Huang L, Zhu Q (2022) Reinforcement learning for feedback-enabled cyber resilience. Annu Rev Control 53:273\u2013295","journal-title":"Annu Rev Control"},{"key":"11292_CR52","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.comcom.2014.04.012","volume":"49","author":"N Hubballi","year":"2014","unstructured":"Hubballi N, Suryanarayanan V (2014) False alarm minimization techniques in signature-based intrusion detection systems: a survey. Comput Commun 49:1\u201317","journal-title":"Comput Commun"},{"key":"11292_CR53","doi-asserted-by":"crossref","unstructured":"Huber PJ (1992) Robust estimation of a location parameter. In: Breakthroughs in statistics: methodology and distribution. Springer, New York, pp 492\u2013518","DOI":"10.1007\/978-1-4612-4380-9_35"},{"issue":"6","key":"11292_CR54","doi-asserted-by":"publisher","first-page":"1802","DOI":"10.1109\/JIOT.2017.2703172","volume":"4","author":"A Humayed","year":"2017","unstructured":"Humayed A, Lin J, Li F, Luo B (2017) Cyber-physical systems security\u2014a survey. IEEE Internet Things J 4(6):1802\u20131831","journal-title":"IEEE Internet Things J"},{"issue":"1","key":"11292_CR55","doi-asserted-by":"publisher","first-page":"217","DOI":"10.1109\/TNSM.2017.2750906","volume":"15","author":"O Ibidunmoye","year":"2017","unstructured":"Ibidunmoye O, Rezaie A-R, Elmroth E (2017) Adaptive anomaly detection in performance metric streams. IEEE Trans Netw Serv Manage 15(1):217\u2013231","journal-title":"IEEE Trans Netw Serv Manage"},{"key":"11292_CR56","volume":"65","author":"AE Ibor","year":"2022","unstructured":"Ibor AE, Okunoye OB, Oladeji FA, Abdulsalam KA (2022) Novel hybrid model for intrusion prediction on cyber physical systems\u2019 communication networks based on bio-inspired deep neural network structure. J Inf Secur Appl 65:103107","journal-title":"J Inf Secur Appl"},{"key":"11292_CR57","doi-asserted-by":"publisher","first-page":"46765","DOI":"10.1109\/ACCESS.2023.3249666","volume":"11","author":"G Intriago","year":"2023","unstructured":"Intriago G, Zhang Y (2023) Real-time power system event detection: a novel instance selection approach. IEEE Access 11:46765\u201346781","journal-title":"IEEE Access"},{"key":"11292_CR58","unstructured":"Ioulianou P, Vasilakis V, Moscholios I, Logothetis M (2018) A signature-based intrusion detection system for the internet of things. In: Information and communication technology form, AUT"},{"issue":"1","key":"11292_CR59","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2847418","volume":"15","author":"R Ivanov","year":"2016","unstructured":"Ivanov R, Pajic M, Lee I (2016) Attack-resilient sensor fusion for safety-critical cyber-physical systems. ACM Trans Embedded Comput Syst (TECS) 15(1):1\u201324","journal-title":"ACM Trans Embedded Comput Syst (TECS)"},{"key":"11292_CR60","doi-asserted-by":"publisher","first-page":"2302","DOI":"10.1016\/j.matpr.2021.06.320","volume":"80","author":"AA Jamal","year":"2023","unstructured":"Jamal AA, Majid A-AM, Konev A, Kosachenko T, Shelupanov A (2023) A review on security analysis of cyber physical systems using machine learning. Mater Today proc 80:2302\u20132306","journal-title":"Mater Today proc"},{"issue":"3","key":"11292_CR61","doi-asserted-by":"publisher","first-page":"910","DOI":"10.1016\/j.ijforecast.2021.06.009","volume":"38","author":"J Jiao","year":"2022","unstructured":"Jiao J, Tang Z, Zhang P, Yue M, Yan J (2022) Cyberattack-resilient load forecasting with adaptive robust regression. Int J Forecast 38(3):910\u2013919","journal-title":"Int J Forecast"},{"issue":"2","key":"11292_CR62","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1007\/s10922-023-09722-7","volume":"31","author":"O Jullian","year":"2023","unstructured":"Jullian O, Otero B, Rodriguez E, Gutierrez N, Antona H, Canal R (2023) Deep-learning based detection for cyber-attacks in IoT networks: a distributed attack detection framework. J Netw Syst Manage 31(2):33","journal-title":"J Netw Syst Manage"},{"key":"11292_CR63","doi-asserted-by":"crossref","unstructured":"Junejo KN, Goh J (2016) Behaviour-based attack detection and classification in cyber physical systems using machine learning. In: Proceedings of the 2nd ACM International workshop on cyber-physical system security, Xi\u2019an, China, pp 34\u201343","DOI":"10.1145\/2899015.2899016"},{"key":"11292_CR64","doi-asserted-by":"crossref","unstructured":"Jung E, Le\u00a0Tilly M, Gehani A, Ge Y (2019) Data mining-based ethereum fraud detection. In: 2019 IEEE international conference on blockchain (blockchain), Atlanta, GA. IEEE, pp 266\u2013273","DOI":"10.1109\/Blockchain.2019.00042"},{"issue":"11s","key":"11292_CR65","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3510410","volume":"54","author":"H Kayan","year":"2022","unstructured":"Kayan H, Nunes M, Rana O, Burnap P, Perera C (2022) Cybersecurity of industrial cyber-physical systems: a review. ACM Comput Surv (CSUR) 54(11s):1\u201335","journal-title":"ACM Comput Surv (CSUR)"},{"key":"11292_CR66","doi-asserted-by":"publisher","first-page":"7306","DOI":"10.1007\/s10489-021-02222-8","volume":"51","author":"IA Khan","year":"2021","unstructured":"Khan IA, Pi D, Khan N, Khan ZU, Hussain Y, Nawaz A, Ali F (2021) A privacy-conserving framework based intrusion detection method for detecting and recognizing malicious behaviours in cyber-physical power networks. Appl Intell 51:7306\u20137321","journal-title":"Appl Intell"},{"issue":"3","key":"11292_CR67","doi-asserted-by":"publisher","first-page":"1534","DOI":"10.1109\/COMST.2022.3187531","volume":"24","author":"S Kim","year":"2022","unstructured":"Kim S, Park K-J, Lu C (2022) A survey on network security for cyber-physical systems: from threats to resilient design. IEEE Commun Surv Tutor 24(3):1534\u20131573","journal-title":"IEEE Commun Surv Tutor"},{"key":"11292_CR68","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1016\/j.patrec.2022.12.009","volume":"167","author":"M Kim","year":"2023","unstructured":"Kim M, Kim J, Yu J, Choi JK (2023) Active anomaly detection based on deep one-class classification. Pattern Recogn Lett 167:18\u201324","journal-title":"Pattern Recogn Lett"},{"issue":"2","key":"11292_CR69","doi-asserted-by":"publisher","first-page":"377","DOI":"10.1007\/s10844-022-00753-1","volume":"60","author":"AM Koay","year":"2023","unstructured":"Koay AM, Ko RKL, Hettema H, Radke K (2023) Machine learning in industrial control system (ICS) security: current landscape, opportunities and challenges. J Intell Inf Syst 60(2):377\u2013405","journal-title":"J Intell Inf Syst"},{"key":"11292_CR70","doi-asserted-by":"publisher","unstructured":"Kundur D, Liu X, Zourntos S, Butler-Purry KL (2011) Towards a framework for cyber attack impact analysis of the electric smart grid. In: 2011 IEEE international conference on smart grid communications (SmartGridComm). IEEE, Brussels, pp 244\u2013249. https:\/\/doi.org\/10.1109\/SmartGridComm.2011.6102312","DOI":"10.1109\/SmartGridComm.2011.6102312"},{"issue":"1","key":"11292_CR71","doi-asserted-by":"publisher","first-page":"493","DOI":"10.1007\/s00521-021-06400-0","volume":"34","author":"HI Kure","year":"2022","unstructured":"Kure HI, Islam S, Ghazanfar M, Raza A, Pasha M (2022) Asset criticality and risk prediction for an effective cybersecurity risk management of cyber-physical system. Neural Comput Appl 34(1):493\u2013514","journal-title":"Neural Comput Appl"},{"key":"11292_CR72","doi-asserted-by":"publisher","unstructured":"Lee EA (2008) Cyber physical systems: Design challenges. In: Proceedings of the 11th IEEE international symposium on object and component-oriented real-time distributed computing (ISORC). IEEE, Orlando, pp 363\u2013369. https:\/\/doi.org\/10.1109\/ISORC.2008.25","DOI":"10.1109\/ISORC.2008.25"},{"issue":"11","key":"11292_CR73","doi-asserted-by":"publisher","first-page":"2415","DOI":"10.1109\/TIFS.2016.2576898","volume":"11","author":"B Li","year":"2016","unstructured":"Li B, Lu R, Wang W, Choo K-KR (2016) DDOA: a Dirichlet-based detection scheme for opportunistic attacks in smart grid cyber-physical system. IEEE Trans Inf Forensics Secur 11(11):2415\u20132425","journal-title":"IEEE Trans Inf Forensics Secur"},{"issue":"4","key":"11292_CR74","doi-asserted-by":"publisher","first-page":"6396","DOI":"10.1109\/JIOT.2019.2897063","volume":"6","author":"F Li","year":"2019","unstructured":"Li F, Shinde A, Shi Y, Ye J, Li X-Y, Song W (2019) System statistics learning-based IoT security: feasibility and suitability. IEEE Internet Things J 6(4):6396\u20136403","journal-title":"IEEE Internet Things J"},{"key":"11292_CR75","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102856","volume":"121","author":"K Li","year":"2022","unstructured":"Li K, Ma W, Duan H, Xie H, Juanxiu Z (2022) Few-shot IoT attack detection based on RFP-CNN and adversarial unsupervised domain-adaptive regularization. Comput Secur 121:102856","journal-title":"Comput Secur"},{"issue":"1","key":"11292_CR76","first-page":"1","volume":"18","author":"Z Li","year":"2023","unstructured":"Li Z, Zhu Y, Van Leeuwen M (2023) A survey on explainable anomaly detection. ACM Trans Knowl Discov Data 18(1):1\u201354","journal-title":"ACM Trans Knowl Discov Data"},{"key":"11292_CR77","doi-asserted-by":"publisher","first-page":"68807","DOI":"10.1109\/ACCESS.2022.3186328","volume":"10","author":"P Liao","year":"2022","unstructured":"Liao P, Yan J, Sellier JM, Zhang Y (2022) Divergence-based transferability analysis for self-adaptive smart grid intrusion detection with transfer learning. IEEE Access 10:68807\u201368818","journal-title":"IEEE Access"},{"key":"11292_CR78","doi-asserted-by":"publisher","first-page":"1043","DOI":"10.1007\/s11036-023-02143-5","volume":"28","author":"C-C Lin","year":"2023","unstructured":"Lin C-C, Tsai C-T, Liu Y-L, Chang T-T, Chang Y-S (2023) Security and privacy in 5G-IIoT smart factories: novel approaches, trends, and challenges. Mobile Netw Appl 28:1043\u20131058","journal-title":"Mobile Netw Appl"},{"key":"11292_CR79","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2020.106527","volume":"211","author":"C Liu","year":"2021","unstructured":"Liu C, Lore KG, Jiang Z, Sarkar S (2021) Root-cause analysis for time-series anomalies via spatiotemporal graphical modeling in distributed complex systems. Knowl Based Syst 211:106527","journal-title":"Knowl Based Syst"},{"issue":"2","key":"11292_CR80","first-page":"2503","volume":"24","author":"W Liu","year":"2022","unstructured":"Liu W, Xu X, Wu L, Qi L, Jolfaei A, Ding W, Khosravi MR (2022) Intrusion detection for maritime transportation systems with batch federated aggregation. IEEE Trans Intell Transp Syst 24(2):2503\u20132514","journal-title":"IEEE Trans Intell Transp Syst"},{"issue":"4","key":"11292_CR81","first-page":"4167","volume":"45","author":"S-Y Lo","year":"2022","unstructured":"Lo S-Y, Oza P, Patel VM (2022) Adversarially robust one-class novelty detection. IEEE Trans Pattern Anal Mach Intell 45(4):4167\u20134179","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"11292_CR82","unstructured":"Loeffel P-X (2017) Adaptive machine learning algorithms for data streams subject to concept drifts. PhD thesis, Universit\u00e9 Pierre et Marie Curie-Paris VI"},{"issue":"5","key":"11292_CR83","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3453155","volume":"54","author":"Y Luo","year":"2021","unstructured":"Luo Y, Xiao Y, Cheng L, Peng G, Yao D (2021) Deep learning-based anomaly detection in cyber-physical systems: progress and opportunities. ACM Comput Surv (CSUR) 54(5):1\u201336","journal-title":"ACM Comput Surv (CSUR)"},{"key":"11292_CR84","doi-asserted-by":"crossref","unstructured":"Lu P, Zhang L, Park BB, Feng L (2018) Attack-resilient sensor fusion for cooperative adaptive cruise control. In: 2018 21st International conference on intelligent transportation systems (ITSC), Maui, HI. IEEE, pp 3955\u20133960","DOI":"10.1109\/ITSC.2018.8569578"},{"issue":"8","key":"11292_CR85","doi-asserted-by":"publisher","first-page":"6211","DOI":"10.1007\/s13369-020-04461-2","volume":"45","author":"SN Mahapatra","year":"2020","unstructured":"Mahapatra SN, Singh BK, Kumar V (2020) A survey on secure transmission in internet of things: taxonomy, recent techniques, research requirements, and challenges. Arab J Sci Eng 45(8):6211\u20136240","journal-title":"Arab J Sci Eng"},{"issue":"18","key":"11292_CR86","doi-asserted-by":"publisher","first-page":"14753","DOI":"10.1007\/s00521-020-04830-w","volume":"32","author":"S Mahdavifar","year":"2020","unstructured":"Mahdavifar S, Ghorbani AA (2020) DENNES: deep embedded neural network expert system for detecting cyber attacks. Neural Comput Appl 32(18):14753\u201314780","journal-title":"Neural Comput Appl"},{"issue":"11","key":"11292_CR87","doi-asserted-by":"publisher","first-page":"4477","DOI":"10.1007\/s12652-019-01417-9","volume":"11","author":"J Meira","year":"2020","unstructured":"Meira J, Andrade R, Pra\u00e7a I, Carneiro J, Bol\u00f3n-Canedo V, Alonso-Betanzos A, Marreiros G (2020) Performance evaluation of unsupervised techniques in cyber-attack anomaly detection. J Ambient Intell Humaniz Comput 11(11):4477\u20134489","journal-title":"J Ambient Intell Humaniz Comput"},{"key":"11292_CR88","unstructured":"Mikolov T, Chen K, Corrado G, Dean J (2013) Efficient estimation of word representations in vector space. arXiv preprint. arXiv:1301.3781"},{"key":"11292_CR89","doi-asserted-by":"crossref","unstructured":"Mirsky Y, Doitshman T, Elovici Y, Shabtai A (2018) Kitsune: an ensemble of autoencoders for online network intrusion detection. arXiv preprint. arXiv:1802.09089","DOI":"10.14722\/ndss.2018.23204"},{"key":"11292_CR90","doi-asserted-by":"publisher","first-page":"1377","DOI":"10.1007\/s11277-012-0528-3","volume":"68","author":"R Mitchell","year":"2013","unstructured":"Mitchell R, Chen I-R (2013) On survivability of mobile cyber physical systems with intrusion detection. Wirel Pers Commun 68:1377\u20131391","journal-title":"Wirel Pers Commun"},{"key":"11292_CR91","unstructured":"Mohus ML, Li J (2023) Adversarial robustness in unsupervised machine learning: A systematic review. arXiv preprint arXiv:2306.00687"},{"key":"11292_CR92","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2021.107835","volume":"188","author":"P Moriano","year":"2021","unstructured":"Moriano P, Hill R, Camp LJ (2021) Using bursty announcements for detecting bgp routing anomalies. Comput Netw 188:107835","journal-title":"Comput Netw"},{"key":"11292_CR93","doi-asserted-by":"publisher","unstructured":"Moriano P, Bridges RA, Iannacone MD (2022) Detecting can masquerade attacks with signal clustering similarity. In: Proceedings Fourth International Workshop on Automotive and Autonomous Vehicle Security. AutoSec 2022, pp. 1\u20138. Internet Society, San Diego, CA, USA. https:\/\/doi.org\/10.14722\/autosec.2022.23028","DOI":"10.14722\/autosec.2022.23028"},{"key":"11292_CR94","unstructured":"Moriano P, Hespeler SC, Li M, Bridges RA (2024) Benchmarking Unsupervised Online IDS for Masquerade Attacks in CAN. arXiv:2406.13778"},{"key":"11292_CR95","doi-asserted-by":"crossref","unstructured":"Morris T (2013) Industrial control system (ICS) cyber attack datasets. https:\/\/sites.google.com\/a\/uah.edu\/tommy-morris-uah\/ics-data-sets","DOI":"10.14236\/ewic\/ICSCSR2013.3"},{"key":"11292_CR96","doi-asserted-by":"crossref","unstructured":"Moustafa N, Slay J (2015) Unsw-nb15: a comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). In: 2015 Military communications and information systems conference (MilCIS), Canberra. IEEE, pp. 1\u20136","DOI":"10.1109\/MilCIS.2015.7348942"},{"issue":"3","key":"11292_CR97","doi-asserted-by":"publisher","first-page":"244","DOI":"10.1109\/JCN.2020.000015","volume":"22","author":"NI Mowla","year":"2020","unstructured":"Mowla NI, Tran NH, Doh I, Chae K (2020) AFRL: adaptive federated reinforcement learning for intelligent jamming defense in FANET. J Commun Netw 22(3):244\u2013258","journal-title":"J Commun Netw"},{"key":"11292_CR98","doi-asserted-by":"publisher","first-page":"1991","DOI":"10.1109\/ACCESS.2018.2886457","volume":"7","author":"M Munir","year":"2018","unstructured":"Munir M, Siddiqui SA, Dengel A, Ahmed S (2018) DEEPANT: a deep learning approach for unsupervised anomaly detection in time series. IEEE Access 7:1991\u20132005","journal-title":"IEEE Access"},{"key":"11292_CR99","doi-asserted-by":"publisher","first-page":"747","DOI":"10.1016\/j.egyr.2019.06.005","volume":"5","author":"A Muzhikyan","year":"2019","unstructured":"Muzhikyan A, Muhanji SO, Moynihan GD, Thompson DJ, Berzolla ZM, Farid AM (2019) The 2017 ISO new england system operational analysis and renewable energy integration study (SOARES). Energy Rep 5:747\u2013792","journal-title":"Energy Rep"},{"key":"11292_CR100","doi-asserted-by":"crossref","unstructured":"Nakayama K, Muralidhar N, Jin C, Sharma R (2019) Detection of false data injection attacks in cyber-physical systems using dynamic invariants. In: 2019 18th IEEE international conference on machine learning and applications (ICMLA), Boca Raton, FL. IEEE, pp 1023\u20131030","DOI":"10.1109\/ICMLA.2019.00173"},{"issue":"8","key":"11292_CR101","doi-asserted-by":"publisher","first-page":"3779","DOI":"10.1109\/TNNLS.2021.3121870","volume":"34","author":"TT Nguyen","year":"2021","unstructured":"Nguyen TT, Reddi VJ (2021) Deep reinforcement learning for cyber security. IEEE Trans Neural Netw Learn Syst 34(8):3779\u20133795","journal-title":"IEEE Trans Neural Netw Learn Syst"},{"key":"11292_CR102","doi-asserted-by":"crossref","unstructured":"Odiathevar M, Seah WK, Frean M (2019) A hybrid online offline system for network anomaly detection. In: 2019 28th International conference on computer communication and networks (ICCCN), Valencia, ES. IEEE, pp 1\u20139","DOI":"10.1109\/ICCCN.2019.8847011"},{"key":"11292_CR103","first-page":"879","volume":"37","author":"C Okoli","year":"2015","unstructured":"Okoli C (2015) A guide to conducting a standalone systematic literature review. Commun Assoc Inf Syst 37:879\u2013910","journal-title":"Commun Assoc Inf Syst"},{"issue":"1","key":"11292_CR104","doi-asserted-by":"publisher","first-page":"524","DOI":"10.1109\/COMST.2020.3036778","volume":"23","author":"FO Olowononi","year":"2020","unstructured":"Olowononi FO, Rawat DB, Liu C (2020) Resilient machine learning for networked cyber physical systems: a survey for machine learning security to securing machine learning for cps. IEEE Commun Surv Tutor 23(1):524\u2013552","journal-title":"IEEE Commun Surv Tutor"},{"issue":"10","key":"11292_CR105","doi-asserted-by":"publisher","first-page":"1345","DOI":"10.1109\/TKDE.2009.191","volume":"22","author":"SJ Pan","year":"2009","unstructured":"Pan SJ, Yang Q (2009) A survey on transfer learning. IEEE Trans Knowl Data Eng 22(10):1345\u20131359","journal-title":"IEEE Trans Knowl Data Eng"},{"issue":"12","key":"11292_CR106","doi-asserted-by":"publisher","first-page":"6481","DOI":"10.1109\/TII.2019.2925418","volume":"15","author":"F Pan","year":"2019","unstructured":"Pan F, Pang Z, Wen H, Luvisotto M, Xiao M, Liao R-F, Chen J (2019) Threshold-free physical layer authentication based on machine learning for industrial wireless CPS. IEEE Trans Industr Inf 15(12):6481\u20136491","journal-title":"IEEE Trans Industr Inf"},{"issue":"11","key":"11292_CR107","doi-asserted-by":"publisher","first-page":"2715","DOI":"10.1109\/TAC.2013.2266831","volume":"58","author":"F Pasqualetti","year":"2013","unstructured":"Pasqualetti F, D\u00f6rfler F, Bullo F (2013) Attack detection and identification in cyber-physical systems. IEEE Trans Autom Control 58(11):2715\u20132729. https:\/\/doi.org\/10.1109\/TAC.2013.2266831","journal-title":"IEEE Trans Autom Control"},{"key":"11292_CR108","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.jss.2023.111716","volume":"203","author":"I Pekaric","year":"2023","unstructured":"Pekaric I, Groner R, Witte T, Adigun JG, Raschke A, Felderer M, Tichy M (2023) A systematic review on security and safety of self-adaptive systems. J Syst Softw 203:1\u201325","journal-title":"J Syst Softw"},{"issue":"2015","key":"11292_CR109","first-page":"995","volume":"11","author":"J Petit","year":"2015","unstructured":"Petit J, Stottelaar B, Feiri M, Kargl F (2015) Remote attacks on automated vehicles sensors: experiments on camera and lidar. Black Hat Europe 11(2015):995\u20131008","journal-title":"Black Hat Europe"},{"key":"11292_CR110","doi-asserted-by":"crossref","unstructured":"Pike L, Hickey P, Elliott T, Mertens E, Tomb A (2016) Trackos: a security-aware real-time operating system. In: Runtime verification: 16th international conference, RV 2016, Madrid, Spain, 23\u201330 September 2016, proceedings 7. Springer, pp 302\u2013317","DOI":"10.1007\/978-3-319-46982-9_19"},{"key":"11292_CR111","unstructured":"Preece A, Harborne D, Braines D, Tomsett R, Chakraborty S (2018) Stakeholders in explainable ai. arXiv preprint. arXiv:1810.00184"},{"issue":"1","key":"11292_CR112","doi-asserted-by":"publisher","first-page":"614","DOI":"10.1109\/TNSM.2021.3088763","volume":"19","author":"SE Quincozes","year":"2021","unstructured":"Quincozes SE, Moss\u00e9 D, Passos D, Albuquerque C, Ochi LS, Santos VF (2021) On the performance of grasp-based feature selection for CPS intrusion detection. IEEE Trans Netw Serv Manage 19(1):614\u2013626","journal-title":"IEEE Trans Netw Serv Manage"},{"key":"11292_CR113","unstructured":"Quinonez R, Giraldo J, Salazar L, Bauman E, Cardenas A, Lin Z (2020) SAVIOR: Securing autonomous vehicles with robust physical invariants. In: 29th USENIX security symposium (USENIX security 20), pp 895\u2013912"},{"key":"11292_CR114","unstructured":"Raciti M (2013) Anomaly detection and its adaptation: Studies on cyber-physical systems. PhD thesis, Link\u00f6ping University Electronic Press, Sweden"},{"key":"11292_CR115","doi-asserted-by":"publisher","first-page":"517","DOI":"10.1007\/s00170-019-03854-4","volume":"104","author":"RA Rojas","year":"2019","unstructured":"Rojas RA, Rauch E (2019) From a literature review to a conceptual framework of enablers for smart manufacturing control. Int J Adv Manuf Technol 104:517\u2013533","journal-title":"Int J Adv Manuf Technol"},{"issue":"5","key":"11292_CR116","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3453158","volume":"54","author":"I Rosenberg","year":"2021","unstructured":"Rosenberg I, Shabtai A, Elovici Y, Rokach L (2021) Adversarial machine learning attacks and defense methods in the cyber security domain. ACM Comput Surv (CSUR) 54(5):1\u201336","journal-title":"ACM Comput Surv (CSUR)"},{"key":"11292_CR117","unstructured":"Rutkin AH (2013) Spoofers use fake GPS signals to knock a yacht off course. MIT Technology Review. Accessed 30 Apr 2025. https:\/\/www.technologyreview.com\/2013\/08\/14\/177015\/spoofers-use-fake-gps-signals-to-knock-a-yacht-off-course\/"},{"key":"11292_CR118","doi-asserted-by":"crossref","unstructured":"Saad M, Bukhari SBA, Kim CH (2019) A review of various modern strategies for mitigation of cyber attacks in smart grids. In: 2019 IEEE transportation electrification conference and expo, Asia-Pacific (ITEC Asia-Pacific), Seogwipo-si, KR. IEEE, pp 1\u20137","DOI":"10.1109\/ITEC-AP.2019.8903798"},{"issue":"1","key":"11292_CR119","doi-asserted-by":"publisher","first-page":"29","DOI":"10.1109\/TASE.2019.2918562","volume":"17","author":"MA Saez","year":"2019","unstructured":"Saez MA, Maturana FP, Barton K, Tilbury DM (2019) Context-sensitive modeling and analysis of cyber-physical manufacturing systems for anomaly detection and diagnosis. IEEE Trans Autom Sci Eng 17(1):29\u201340","journal-title":"IEEE Trans Autom Sci Eng"},{"key":"11292_CR120","doi-asserted-by":"crossref","unstructured":"Schneider P, B\u00f6ttinger K (2018) High-performance unsupervised anomaly detection for cyber-physical system networks. In: Proceedings of the 2018 workshop on cyber-physical systems security and privacy, Toronto, CA, pp 1\u201312","DOI":"10.1145\/3264888.3264890"},{"key":"11292_CR121","doi-asserted-by":"crossref","unstructured":"Settanni G, Skopik F, Karaj A, Wurzenberger M, Fiedler R (2018) Protecting cyber physical production systems using anomaly detection to enable self-adaptation. In: 2018 IEEE industrial cyber-physical systems (ICPS), Saint Petersburg, RU. IEEE, pp 173\u2013180","DOI":"10.1109\/ICPHYS.2018.8387655"},{"key":"11292_CR122","doi-asserted-by":"crossref","unstructured":"Shacham H, Page M, Pfaff B, Goh E-J, Modadugu N, Boneh D (2004) On the effectiveness of address-space randomization. In: Proceedings of the 11th ACM conference on computer and communications security, Washington, DC, pp 298\u2013307","DOI":"10.1145\/1030083.1030124"},{"key":"11292_CR123","doi-asserted-by":"publisher","first-page":"22111","DOI":"10.1109\/JIOT.2023.3303271","volume":"10","author":"MH Shahriar","year":"2023","unstructured":"Shahriar MH, Xiao Y, Moriano P, Lou W, Hou YT (2023) Canshield: deep learning-based intrusion detection framework for controller area networks at the signal-level. IEEE Internet Things J 10:22111\u201322127","journal-title":"IEEE Internet Things J"},{"key":"11292_CR124","doi-asserted-by":"publisher","first-page":"1815","DOI":"10.1007\/s10845-021-01879-9","volume":"34","author":"Z Shi","year":"2023","unstructured":"Shi Z, Mamun AA, Kan C, Tian W, Liu C (2023) An lstm-autoencoder based online side channel monitoring approach for cyber-physical attack detection in additive manufacturing. J Intell Manuf 34:1815\u20131831","journal-title":"J Intell Manuf"},{"key":"11292_CR125","doi-asserted-by":"crossref","unstructured":"Shin J, Baek Y, Eun Y, Son SH (2017) Intelligent sensor attack detection and identification for automotive cyber-physical systems. In: 2017 IEEE symposium series on computational intelligence (SSCI), Honolulu, HI. IEEE, pp 1\u20138","DOI":"10.1109\/SSCI.2017.8280915"},{"key":"11292_CR126","doi-asserted-by":"crossref","unstructured":"Shoukry Y, Martin P, Tabuada P, Srivastava M (2013) Non-invasive spoofing attacks for anti-lock braking systems. In: Cryptographic hardware and embedded systems\u2014CHES 2013: 15th international workshop, Santa Barbara, CA, USA, 20\u201323 August 2013. Springer, pp 55\u201372","DOI":"10.1007\/978-3-642-40349-1_4"},{"issue":"2","key":"11292_CR127","doi-asserted-by":"publisher","first-page":"1191","DOI":"10.1109\/COMST.2019.2962586","volume":"22","author":"M Stoyanova","year":"2020","unstructured":"Stoyanova M, Nikoloudakis Y, Panagiotakis S, Pallis E, Markakis EK (2020) A survey on the internet of things (IoT) forensics: challenges, approaches, and open issues. IEEE Commun Surv Tutor 22(2):1191\u20131221","journal-title":"IEEE Commun Surv Tutor"},{"issue":"2","key":"11292_CR128","doi-asserted-by":"publisher","first-page":"1350","DOI":"10.1109\/TIV.2022.3188340","volume":"8","author":"K Strandberg","year":"2022","unstructured":"Strandberg K, Nowdehi N, Olovsson T (2022) A systematic literature review on automotive digital forensics: challenges, technical solutions and data collection. IEEE Trans Intell Veh 8(2):1350\u20131367","journal-title":"IEEE Trans Intell Veh"},{"issue":"5","key":"11292_CR129","doi-asserted-by":"publisher","first-page":"1189","DOI":"10.1007\/s10207-022-00594-7","volume":"21","author":"AD Syrmakesis","year":"2022","unstructured":"Syrmakesis AD, Alcaraz C, Hatziargyriou ND (2022) Classifying resilience approaches for protecting smart grids against cyber threats. Int J Inf Secur 21(5):1189\u20131210","journal-title":"Int J Inf Secur"},{"key":"11292_CR130","doi-asserted-by":"publisher","unstructured":"Urbina DI, Giraldo JA, C\u00e1rdenas AA, Tippenhauer NO, Valente J, Faisal M, Ruths J, Candell R, Sandberg H (2016) Limiting the impact of stealthy attacks on industrial control systems. In: Proceedings of the 2016 ACM SIGSAC conference on computer and communications security (CCS), pp 1092\u20131105. https:\/\/doi.org\/10.1145\/2976749.2978388","DOI":"10.1145\/2976749.2978388"},{"issue":"3","key":"11292_CR131","doi-asserted-by":"crossref","first-page":"1264","DOI":"10.1109\/TITS.2019.2906038","volume":"21","author":"F Van Wyk","year":"2019","unstructured":"Van Wyk F, Wang Y, Khojandi A, Masoud N (2019) Real-time sensor anomaly detection and identification in automated vehicles. IEEE Trans Intell Transp Syst 21(3):1264\u20131276","journal-title":"IEEE Trans Intell Transp Syst"},{"key":"11292_CR132","first-page":"1","volume":"30","author":"A Vaswani","year":"2017","unstructured":"Vaswani A, Shazeer N, Parmar N, Uszkoreit J, Jones L, Gomez AN, Kaiser \u0141, Polosukhin I (2017) Attention is all you need. Adv Neural Inf Process Syst 30:1\u201311","journal-title":"Adv Neural Inf Process Syst"},{"key":"11292_CR133","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.ijcip.2021.100446","volume":"34","author":"J V\u00e1vra","year":"2021","unstructured":"V\u00e1vra J, Hromada M, Luk\u00e1\u0161 L, Dworzecki J (2021) Adaptive anomaly detection system based on machine learning algorithms in an industrial control environment. Int J Crit Infrastruct Prot 34:1\u201311","journal-title":"Int J Crit Infrastruct Prot"},{"issue":"1","key":"11292_CR134","doi-asserted-by":"publisher","first-page":"0296879","DOI":"10.1371\/journal.pone.0296879","volume":"19","author":"ME Verma","year":"2024","unstructured":"Verma ME, Bridges RA, Iannacone MD, Hollifield SC, Moriano P, Hespeler SC, Kay B, Combs FL (2024) A comprehensive guide to can ids data and introduction of the road dataset. PLoS ONE 19(1):0296879","journal-title":"PLoS ONE"},{"key":"11292_CR135","unstructured":"Vinyals O, Blundell C, Lillicrap T, Wierstra D et al (2016) Matching networks for one shot learning. In: 30th Conference on neural information processing Systems (NIPS 2016), vol 29, Barcelona, ES, pp 1\u20139"},{"issue":"4","key":"11292_CR136","doi-asserted-by":"publisher","first-page":"3447","DOI":"10.1109\/TSG.2020.2970755","volume":"11","author":"P Wang","year":"2020","unstructured":"Wang P, Govindarasu M (2020) Multi-agent based attack-resilient system integrity protection for smart grid. IEEE Trans Smart Grid 11(4):3447\u20133456","journal-title":"IEEE Trans Smart Grid"},{"issue":"2","key":"11292_CR137","first-page":"1","volume":"20","author":"D Wang","year":"2023","unstructured":"Wang D, Li F, Liu K, Zhang X (2023) Real-time cyber-physical security solution leveraging an integrated learning-based approach: an integrated learning-based cyber-physical security solution. ACM Trans Sensor Netw 20(2):1\u201322","journal-title":"ACM Trans Sensor Netw"},{"key":"11292_CR138","doi-asserted-by":"crossref","unstructured":"Wohlin C (2014) Guidelines for snowballing in systematic literature studies and a replication in software engineering. In: Proceedings of the 18th international conference on evaluation and assessment in software engineering, London England, UK, pp 1\u201310","DOI":"10.1145\/2601248.2601268"},{"issue":"3","key":"11292_CR139","doi-asserted-by":"publisher","first-page":"919","DOI":"10.1109\/TITS.2019.2908074","volume":"21","author":"W Wu","year":"2019","unstructured":"Wu W, Li R, Xie G, An J, Bai Y, Zhou J, Li K (2019) A survey of intrusion detection for in-vehicle networks. IEEE Trans Intell Transp Syst 21(3):919\u2013933","journal-title":"IEEE Trans Intell Transp Syst"},{"issue":"22","key":"11292_CR140","doi-asserted-by":"publisher","first-page":"22410","DOI":"10.1109\/JIOT.2022.3150048","volume":"9","author":"L Xi","year":"2022","unstructured":"Xi L, Wang R, Haas ZJ (2022) Data-correlation-aware unsupervised deep-learning model for anomaly detection in cyber-physical systems. IEEE Internet Things J 9(22):22410\u201322421","journal-title":"IEEE Internet Things J"},{"issue":"4","key":"11292_CR141","doi-asserted-by":"publisher","first-page":"2888","DOI":"10.1109\/TDSC.2023.3319701","volume":"21","author":"L Xi","year":"2023","unstructured":"Xi L, Miao D, Li M, Wang R, Liu H, Huang X (2023) Adaptive-correlation-aware unsupervised deep learning for anomaly detection in cyber-physical systems. IEEE Trans Dependable Secure Comput 21(4):2888\u20132899","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"11292_CR142","doi-asserted-by":"crossref","unstructured":"Xian Y, Schiele B, Akata Z (2017) Zero-shot learning-the good, the bad and the ugly. In: Proceedings of the IEEE conference on computer vision and pattern recognition, San Francisco, CA, pp 4582\u20134591","DOI":"10.1109\/CVPR.2017.328"},{"key":"11292_CR143","doi-asserted-by":"crossref","unstructured":"Yampolskiy M, Horvath P, Koutsoukos XD, Xue Y, Sztipanovits J (2013) Taxonomy for description of cross-domain attacks on cps. In: Proceedings of the 2nd ACM international conference on high confidence networked systems, Philadelphia, PA, pp 135\u2013142","DOI":"10.1145\/2461446.2461465"},{"key":"11292_CR144","doi-asserted-by":"crossref","unstructured":"Yasaei R, Hernandez F, Faruque MAA (2020) Iot-cad: Context-aware adaptive anomaly detection in IoT systems through sensor association. In: Proceedings of the 39th international conference on computer-aided design, Virtual Event, USA, pp 1\u20139","DOI":"10.1145\/3400302.3415672"},{"key":"11292_CR145","doi-asserted-by":"publisher","DOI":"10.1016\/j.compind.2022.103801","volume":"144","author":"A Yazdinejad","year":"2023","unstructured":"Yazdinejad A, Dehghantanha A, Parizi RM, Srivastava G, Karimipour H (2023) Secure intelligent fuzzy blockchain framework: effective threat detection in IoT networks. Comput Ind 144:103801","journal-title":"Comput Ind"},{"issue":"1","key":"11292_CR146","doi-asserted-by":"publisher","first-page":"101","DOI":"10.1016\/j.dcan.2022.09.008","volume":"9","author":"A Yazdinejad","year":"2023","unstructured":"Yazdinejad A, Kazemi M, Parizi RM, Dehghantanha A, Karimipour H (2023) An ensemble deep learning model for cyber threat hunting in industrial Internet of Things. Digital Commun Netw 9(1):101\u2013110","journal-title":"Digital Commun Netw"},{"key":"11292_CR148","unstructured":"Yu F, Koltun V (2015) Multi-scale context aggregation by dilated convolutions. arXiv preprint. arXiv:1511.07122"},{"key":"11292_CR147","unstructured":"Yuan S, Wu X (2022) Trustworthy anomaly detection: a survey. arXiv preprint. arXiv:2202.07787"},{"key":"11292_CR149","doi-asserted-by":"publisher","first-page":"171126","DOI":"10.1109\/ACCESS.2019.2956124","volume":"7","author":"S Zeadally","year":"2019","unstructured":"Zeadally S, Sanislav T, Mois GD (2019) Self-adaptation techniques in cyber-physical systems (CPSS). IEEE Access 7:171126\u2013171139","journal-title":"IEEE Access"},{"issue":"12","key":"11292_CR150","doi-asserted-by":"publisher","first-page":"2077","DOI":"10.1007\/s11431-019-9544-7","volume":"62","author":"M Zhang","year":"2019","unstructured":"Zhang M, Shen C, He N, Han S, Li Q, Wang Q, Guan X (2019) False data injection attacks against smart gird state estimation: construction, detection and defense. Sci China Technol Sci 62(12):2077\u20132087","journal-title":"Sci China Technol Sci"}],"container-title":["Artificial Intelligence Review"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10462-025-11292-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10462-025-11292-w\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10462-025-11292-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,6]],"date-time":"2025-09-06T21:39:08Z","timestamp":1757194748000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10462-025-11292-w"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,23]]},"references-count":150,"journal-issue":{"issue":"9","published-online":{"date-parts":[[2025,9]]}},"alternative-id":["11292"],"URL":"https:\/\/doi.org\/10.1007\/s10462-025-11292-w","relation":{},"ISSN":["1573-7462"],"issn-type":[{"value":"1573-7462","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,6,23]]},"assertion":[{"value":"5 June 2025","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"23 June 2025","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no Conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"283"}}