{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T15:59:27Z","timestamp":1784217567107,"version":"3.55.0"},"reference-count":109,"publisher":"Springer Science and Business Media LLC","issue":"7","license":[{"start":{"date-parts":[[2025,4,1]],"date-time":"2025-04-01T00:00:00Z","timestamp":1743465600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"},{"start":{"date-parts":[[2025,4,1]],"date-time":"2025-04-01T00:00:00Z","timestamp":1743465600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"}],"funder":[{"DOI":"10.13039\/501100004489","name":"Mitacs","doi-asserted-by":"publisher","award":["FR97683"],"award-info":[{"award-number":["FR97683"]}],"id":[{"id":"10.13039\/501100004489","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Appl Intell"],"published-print":{"date-parts":[[2025,5]]},"DOI":"10.1007\/s10489-025-06422-4","type":"journal-article","created":{"date-parts":[[2025,4,3]],"date-time":"2025-04-03T11:50:34Z","timestamp":1743681034000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":22,"title":["Advanced IDS: a comparative study of datasets and machine learning algorithms for network flow-based intrusion detection systems"],"prefix":"10.1007","volume":"55","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6203-5450","authenticated-orcid":false,"given":"Jose Carlos","family":"Mondragon","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Paula","family":"Branco","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Guy-Vincent","family":"Jourdan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Andres Eduardo","family":"Gutierrez-Rodriguez","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rajesh Roshan","family":"Biswal","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,4,1]]},"reference":[{"key":"6422_CR1","doi-asserted-by":"publisher","unstructured":"Dhanya KA, Vajipayajula S, Srinivasan K, Tibrewal A, Kumar TS, Kumar TG (2023) Detection of network attacks using machine learning and deep learning models. Procedia Comput Sci 218:57\u201366 https:\/\/doi.org\/10.1016\/j.procs.2022.12.401","DOI":"10.1016\/j.procs.2022.12.401"},{"issue":"4","key":"6422_CR2","doi-asserted-by":"publisher","first-page":"2451","DOI":"10.1109\/tnsm.2020.3016246","volume":"17","author":"B Molina-Coronado","year":"2020","unstructured":"Molina-Coronado B, Mori U, Mendiburu A, Miguel-Alonso J (2020) Survey of network intrusion detection methods from the perspective of the knowledge discovery in databases process. IEEE Trans Netw Serv Manage 17(4):2451\u20132479. https:\/\/doi.org\/10.1109\/tnsm.2020.3016246","journal-title":"IEEE Trans Netw Serv Manage"},{"key":"6422_CR3","doi-asserted-by":"publisher","unstructured":"Macas M, Wu C, Fuertes W (2022) A survey on deep learning for cybersecurity: Progress, challenges, and opportunities. Comput Netw 212:109032 https:\/\/doi.org\/10.1016\/j.comnet.2022.109032","DOI":"10.1016\/j.comnet.2022.109032"},{"key":"6422_CR4","doi-asserted-by":"publisher","unstructured":"Pawlicki M, Kozik R, Chora\u015b M (2022) A survey on neural networks for (cyber-) security and (cyber-) security of neural networks. Neurocomput 500:1075\u20131087. https:\/\/doi.org\/10.1016\/j.neucom.2022.06.002","DOI":"10.1016\/j.neucom.2022.06.002"},{"key":"6422_CR5","doi-asserted-by":"publisher","unstructured":"Fu J, Wang L, Ke J, Yang K, Yu R (2022) GANAD:a GAN-based method for network anomaly detection . https:\/\/doi.org\/10.21203\/rs.3.rs-2081269\/v1","DOI":"10.21203\/rs.3.rs-2081269\/v1"},{"key":"6422_CR6","doi-asserted-by":"publisher","unstructured":"Santos RR, Viegas EK, Santin AO, Cogo VV (2022) Reinforcement learning for intrusion detection: More model longness and fewer updates. IEEE Trans Netw Serv Manage, 1\u20131 . https:\/\/doi.org\/10.1109\/tnsm.2022.3207094","DOI":"10.1109\/tnsm.2022.3207094"},{"issue":"2","key":"6422_CR7","doi-asserted-by":"publisher","first-page":"567","DOI":"10.1016\/j.jnca.2012.12.020","volume":"36","author":"B Li","year":"2013","unstructured":"Li B, Springer J, Bebis G, Hadi Gunes M (2013) A survey of network flow applications. J Netw Comput Appl 36(2):567\u2013581","journal-title":"J Netw Comput Appl"},{"key":"6422_CR8","doi-asserted-by":"publisher","unstructured":"Yang L, Shami A (2022) IDS-ML: An open source code for intrusion detection system development using machine learning. Softw Impact 14:100446. https:\/\/doi.org\/10.1016\/j.simpa.2022.100446","DOI":"10.1016\/j.simpa.2022.100446"},{"key":"6422_CR9","doi-asserted-by":"crossref","unstructured":"Lo WW, Layeghy S, Sarhan M, Gallagher M, Portmann M (2022) E-graphsage: A graph neural network based intrusion detection system for iot. In: NOMS 2022-2022 IEEE\/IFIP Network Operations and Management Symposium, pp 1\u20139. IEEE","DOI":"10.1109\/NOMS54207.2022.9789878"},{"key":"6422_CR10","doi-asserted-by":"publisher","unstructured":"Sharafaldin I, Lashkari AH, Ghorbani AA (2018) Toward generating a new intrusion detection dataset and intrusion traffic characterization, 108\u2013116. https:\/\/doi.org\/10.5220\/0006639801080116","DOI":"10.5220\/0006639801080116"},{"key":"6422_CR11","doi-asserted-by":"publisher","unstructured":"Moustafa N, Slay J (2015) UNSW-NB15: a comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set) . https:\/\/doi.org\/10.1109\/milcis.2015.7348942","DOI":"10.1109\/milcis.2015.7348942"},{"key":"6422_CR12","doi-asserted-by":"publisher","unstructured":"Damasevicius R, Venckauskas A, Grigaliunas S, Toldinas J, Morkevicius N, Aleliunas T, Smuikys P (2020) Litnet-2020: An annotated real-world network flow dataset for network intrusion detection. Electron 9(5). https:\/\/doi.org\/10.3390\/electronics9050800","DOI":"10.3390\/electronics9050800"},{"key":"6422_CR13","doi-asserted-by":"crossref","unstructured":"Apruzzese G, Pajola L, Conti M (2022) The Cross-evaluation of Machine Learning-based Network Intrusion Detection Systems. IEEE Trans Netw Serv Manage (IEEE TNSM) . IEEE","DOI":"10.1109\/TNSM.2022.3157344"},{"key":"6422_CR14","doi-asserted-by":"publisher","unstructured":"Tavallaee M, Bagheri E, Lu W, Ghorbani AA (2009) A detailed analysis of the KDD CUP 99 data set https:\/\/doi.org\/10.1109\/cisda.2009.5356528","DOI":"10.1109\/cisda.2009.5356528"},{"key":"6422_CR15","unstructured":"California I. KDD Cup 1999 Data. University of California, Irvine. https:\/\/kdd.ics.uci.edu\/databases\/kddcup99\/kddcup99.html"},{"key":"6422_CR16","doi-asserted-by":"publisher","unstructured":"Engelen G, Rimmer V, Joosen W (2021) Troubleshooting an intrusion detection dataset: the CICIDS2017 case study. https:\/\/doi.org\/10.1109\/spw53761.2021.00009","DOI":"10.1109\/spw53761.2021.00009"},{"key":"6422_CR17","doi-asserted-by":"publisher","unstructured":"Ferriyan A, Thamrin AH, Takeda K, Murai J (2021) Generating network intrusion detection dataset based on real and encrypted synthetic attack traffic. Appl Sci 11(17). https:\/\/doi.org\/10.3390\/app11177868","DOI":"10.3390\/app11177868"},{"key":"6422_CR18","doi-asserted-by":"publisher","unstructured":"Ahmetoglu H, Das R (2022) A comprehensive review on detection of cyber-attacks: Data sets, methods, challenges, and future research directions. Internet of Things 20:100615. https:\/\/doi.org\/10.1016\/j.iot.2022.100615","DOI":"10.1016\/j.iot.2022.100615"},{"key":"6422_CR19","doi-asserted-by":"publisher","unstructured":"Jmila H, Khedher MI (2022) Adversarial machine learning for network intrusion detection: A comparative study. Comput Netw 214:109073. https:\/\/doi.org\/10.1016\/j.comnet.2022.109073","DOI":"10.1016\/j.comnet.2022.109073"},{"key":"6422_CR20","doi-asserted-by":"publisher","DOI":"10.1007\/s10796-022-10333-x","author":"M Sewak","year":"2022","unstructured":"Sewak M, Sahay SK, Rathore H (2022) Deep reinforcement learning in the advanced cybersecurity threat detection and protection. Inf Syst Frontier. https:\/\/doi.org\/10.1007\/s10796-022-10333-x","journal-title":"Inf Syst Frontier"},{"key":"6422_CR21","doi-asserted-by":"publisher","unstructured":"Ahmad Z, Khan AS, Shiang CW, Abdullah J, Ahmad F (2020) Network intrusion detection system: A systematic study of machine learning and deep learning approaches. Trans Emerg Telecommun Technol 32(1). https:\/\/doi.org\/10.1002\/ett.4150","DOI":"10.1002\/ett.4150"},{"issue":"1","key":"6422_CR22","doi-asserted-by":"publisher","first-page":"29","DOI":"10.3390\/informatics9010029","volume":"9","author":"M Antunes","year":"2022","unstructured":"Antunes M, Oliveira L, Seguro A, Ver\u00edssimo J, Salgado R, Murteira T (2022) Benchmarking deep learning methods for behaviour-based network intrusion detection. Inf 9(1):29. https:\/\/doi.org\/10.3390\/informatics9010029","journal-title":"Inf"},{"key":"6422_CR23","doi-asserted-by":"publisher","first-page":"147","DOI":"10.1016\/j.cose.2019.06.005","volume":"86","author":"M Ring","year":"2019","unstructured":"Ring M, Wunderlich S, Scheuring D, Landes D, Hotho A (2019) A survey of network-based intrusion detection data sets. Comput Secur 86:147\u2013167","journal-title":"Comput Secur"},{"key":"6422_CR24","doi-asserted-by":"publisher","DOI":"10.1007\/s40745-022-00444-2","author":"IH Sarker","year":"2022","unstructured":"Sarker IH (2022) Machine learning for intelligent data analysis and automation in cybersecurity: Current and future prospects. Annals of Data Sci. https:\/\/doi.org\/10.1007\/s40745-022-00444-2","journal-title":"Annals of Data Sci"},{"issue":"1","key":"6422_CR25","doi-asserted-by":"publisher","first-page":"453","DOI":"10.1007\/s10462-021-10037-9","volume":"55","author":"A Thakkar","year":"2021","unstructured":"Thakkar A, Lohiya R (2021) A survey on intrusion detection system: feature selection, model, performance measures, application perspective, challenges, and future research directions. Artif Intell Rev 55(1):453\u2013563. https:\/\/doi.org\/10.1007\/s10462-021-10037-9","journal-title":"Artif Intell Rev"},{"key":"6422_CR26","doi-asserted-by":"publisher","unstructured":"Gharib A, Sharafaldin I, Lashkari AH, Ghorbani AA (2016) An evaluation framework for intrusion detection dataset. In: 2016 International Conference on Information Science and Security (ICISS), pp 1\u20136 . https:\/\/doi.org\/10.1109\/ICISSEC.2016.7885840","DOI":"10.1109\/ICISSEC.2016.7885840"},{"key":"6422_CR27","doi-asserted-by":"publisher","unstructured":"Aldweesh A, Derhab A, Emam AZ (2020) Deep learning approaches for anomaly-based intrusion detection systems: A survey, taxonomy, and open issues. Knowl-Based Syst 189:105124. https:\/\/doi.org\/10.1016\/j.knosys.2019.105124","DOI":"10.1016\/j.knosys.2019.105124"},{"key":"6422_CR28","doi-asserted-by":"publisher","unstructured":"Adawadkar AMK, Kulkarni N (2022) Cyber-security and reinforcement learning \u2014 a brief survey. Eng Appl Artif Intell 114:105116. https:\/\/doi.org\/10.1016\/j.engappai.2022.105116","DOI":"10.1016\/j.engappai.2022.105116"},{"key":"6422_CR29","unstructured":"Oracle (2017) 7 securing ports. Oracle. https:\/\/docs.oracle.com\/cd\/E89228_03\/otn\/pdf\/install\/html_edmsc\/output\/chapter_6.htm"},{"key":"6422_CR30","doi-asserted-by":"publisher","unstructured":"Ortigosa-Hern\u00e1ndez J, Inza I, Lozano JA (2017) Measuring the class-imbalance extent of multi-class problems. Pattern Recognn Lett 98:32\u201338. https:\/\/doi.org\/10.1016\/j.patrec.2017.08.002","DOI":"10.1016\/j.patrec.2017.08.002"},{"key":"6422_CR31","doi-asserted-by":"publisher","unstructured":"Pinto R (2020) M2M using OPC UA. IEEE Dataport. https:\/\/doi.org\/10.21227\/ychv-6c68 . https:\/\/dx.doi.org\/10.21227\/ychv-6c68","DOI":"10.21227\/ychv-6c68"},{"key":"6422_CR32","doi-asserted-by":"publisher","unstructured":"Elsayed MS, Le-Khac N-A, Jurcut AD (2020) Insdn: A novel sdn intrusion dataset. IEEE Access 8:165263\u2013165284. https:\/\/doi.org\/10.1109\/ACCESS.2020.3022633","DOI":"10.1109\/ACCESS.2020.3022633"},{"issue":"1","key":"6422_CR33","doi-asserted-by":"publisher","first-page":"357","DOI":"10.1007\/s11036-021-01843-0","volume":"27","author":"M Sarhan","year":"2021","unstructured":"Sarhan M, Layeghy S, Portmann M (2021) Towards a standard feature set for network intrusion detection system datasets. Mobile Netw Appl 27(1):357\u2013370. https:\/\/doi.org\/10.1007\/s11036-021-01843-0","journal-title":"Mobile Netw Appl"},{"key":"6422_CR34","unstructured":"Ring M, Wunderlich S, Gr\u00fcdl D, Landes D, Hotho A (2017) Flow-based benchmark data sets for intrusion detection. In: Proceedings of the 16th European Conference on Cyber Warfare and Security (ECCWS), pp 361\u2013369. ACPI, ???"},{"key":"6422_CR35","unstructured":"Beer F, Hofer T, Karimi D, B\u00fchler U (2017) A new attack composition for network security. In: M\u00fcller P, Neumair B, Raiser H, Dreo\u00a0Rodosek G (eds) 10. DFN-Forum Kommunikationstechnologien, pp 11\u201320. Gesellschaft f\u00fcr Informatik e.V., Bonn"},{"issue":"3","key":"6422_CR36","doi-asserted-by":"publisher","first-page":"357","DOI":"10.1016\/j.cose.2011.12.012","volume":"31","author":"A Shiravi","year":"2012","unstructured":"Shiravi A, Shiravi H, Tavallaee M, Ghorbani AA (2012) Toward developing a systematic approach to generate benchmark datasets for intrusion detection. Comput Secur 31(3):357\u2013374. https:\/\/doi.org\/10.1016\/j.cose.2011.12.012","journal-title":"Comput Secur"},{"key":"6422_CR37","doi-asserted-by":"publisher","unstructured":"Catillo M, Del\u00a0Vecchio A, Ocone L, Pecchia A, Villano U (2021) Usb-ids-1: a public multilayer dataset of labeled network flows for ids evaluation. In: 2021 51st Annual IEEE\/IFIP International Conference on Dependable Systems and Networks Workshops (DSN-W), pp 1\u20136. https:\/\/doi.org\/10.1109\/DSN-W52860.2021.00012","DOI":"10.1109\/DSN-W52860.2021.00012"},{"key":"6422_CR38","doi-asserted-by":"publisher","unstructured":"Sharafaldin I, Lashkari AH, Hakak S, Ghorbani AA (2019) Developing realistic distributed denial of service (ddos) attack dataset and taxonomy. In: 2019 International Carnahan Conference on Security Technology (ICCST), pp 1\u20138. https:\/\/doi.org\/10.1109\/CCST.2019.8888419","DOI":"10.1109\/CCST.2019.8888419"},{"key":"6422_CR39","unstructured":"New\u00a0Brunswick U. CSE-CIC-IDS2018 on AWS. Canadian Institute of CyberSecurity. https:\/\/www.unb.ca\/cic\/datasets\/ids-2018.html"},{"key":"6422_CR40","doi-asserted-by":"publisher","unstructured":"Farhady H, Lee H, Nakao A (2015) Software-defined networking: A survey. Comput Netw 81:79\u201395. https:\/\/doi.org\/10.1016\/j.comnet.2015.02.014","DOI":"10.1016\/j.comnet.2015.02.014"},{"key":"6422_CR41","unstructured":"Lashkari AH. CICFlowMeter (formerly ISCXFlowMeter). Canadian Institute for Cybersecurity. https:\/\/www.unb.ca\/cic\/research\/applications.html"},{"key":"6422_CR42","doi-asserted-by":"publisher","unstructured":"Maci\u00e1-Fern\u00e1ndez G, Camacho J, Mag\u00e1n-Carri\u00f3n R, Garc\u00eda-Teodoro P, Ther\u00f3n R (2018) Ugr 16: A new dataset for the evaluation of cyclostationarity-based network idss. Comput Secur 73:411\u2013424. https:\/\/doi.org\/10.1016\/j.cose.2017.11.004","DOI":"10.1016\/j.cose.2017.11.004"},{"key":"6422_CR43","unstructured":"Applied Internet\u00a0Analysis C (2020) Caida data - completed datasets. UC San Diego. https:\/\/www.caida.org\/catalog\/datasets\/completed-datasets\/"},{"key":"6422_CR44","doi-asserted-by":"publisher","unstructured":"Fontugne R, Borgnat P, Abry P, Fukuda K (2010) Mawilab: Combining diverse anomaly detectors for automated anomaly labeling and performance benchmarking. In: Proceedings of the 6th International COnference. Co-NEXT \u201910. Association for Computing Machinery, New York, NY, USA. https:\/\/doi.org\/10.1145\/1921168.1921179","DOI":"10.1145\/1921168.1921179"},{"key":"6422_CR45","unstructured":"Weisberg J. Argus - The all seeing System and Network Monitoring Software. http:\/\/argus.tcp4me.com\/"},{"key":"6422_CR46","unstructured":"Project Z. Bro Ids. Zeek. https:\/\/old.zeek.org\/manual\/2.5.5\/broids\/index.html"},{"key":"6422_CR47","doi-asserted-by":"crossref","unstructured":"Claise EB (2004) Cisco Systems NetFlow Services Export Version 9. Internet Engineering Task Force. https:\/\/www.ietf.org\/rfc\/rfc3954.txt","DOI":"10.17487\/rfc3954"},{"key":"6422_CR48","doi-asserted-by":"publisher","unstructured":"Creech G, Hu J (2013) Generation of a new ids test dataset: Time to retire the kdd collection. In: 2013 IEEE Wireless Commun Netw Conf (WCNC), pp 4487\u20134492. https:\/\/doi.org\/10.1109\/WCNC.2013.6555301","DOI":"10.1109\/WCNC.2013.6555301"},{"issue":"9","key":"6422_CR49","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3472753","volume":"54","author":"D Chou","year":"2021","unstructured":"Chou D, Jiang M (2021) A survey on data-driven network intrusion detection. ACM Comput Surv 54(9):1\u201336. https:\/\/doi.org\/10.1145\/3472753","journal-title":"ACM Comput Surv"},{"key":"6422_CR50","unstructured":"Google: Iman Sharafaldin from Google Scholar. Google Scholar. https:\/\/scholar.google.com\/citations?user=NGOL_BwAAAAJ"},{"key":"6422_CR51","doi-asserted-by":"publisher","unstructured":"ROSAY A, CARLIER F, CHEVAL E, LEROUX P (2022) From cic-ids2017 to lycos-ids2017: A corrected dataset for better performance. In: IEEE\/WIC\/ACM International Conference on Web Intelligence and Intelligent Agent Technology. WI-IAT \u201921, pp 570\u2013575. Association for Computing Machinery, New York, NY, USA . https:\/\/doi.org\/10.1145\/3486622.3493973","DOI":"10.1145\/3486622.3493973"},{"key":"6422_CR52","doi-asserted-by":"publisher","unstructured":"Liu L, Engelen G, Lynar T, Essam D, Joosen W (2022) Error prevalence in nids datasets: A case study on cic-ids-2017 and cse-cic-ids-2018. In: 2022 IEEE Conference on Communications and Network Security (CNS), pp 254\u2013262. https:\/\/doi.org\/10.1109\/CNS56114.2022.9947235","DOI":"10.1109\/CNS56114.2022.9947235"},{"key":"6422_CR53","doi-asserted-by":"crossref","unstructured":"Lanvin M, Gimenez P-F, Han Y, Majorczyk F, M\u00e9 L, Totel E (2022) Errors in the CICIDS2017 Dataset and the Significant Differences in Detection Performances It Makes, pp 1\u201316. HAL. https:\/\/hal.science\/hal-03775466","DOI":"10.1007\/978-3-031-31108-6_2"},{"key":"6422_CR54","unstructured":"New\u00a0Brunswick U (2017) IDS 2017 | Datasets | Research | Canadian Institute for Cybersecurity | UNB \u2014 unb.ca. https:\/\/www.unb.ca\/cic\/datasets\/ids-2017.html. [Accessed 24-10-2023]"},{"key":"6422_CR55","unstructured":"Ring M, Wunderlich S, Gr\u00fcdl D, Landes D, Hotho A (2017) Flow-based benchmark data sets for intrusion detection. In: Proceedings of the 16th European Conference on Cyber Warfare and Security (ECCWS), pp 361\u2013369. ACPI, ???"},{"key":"6422_CR56","doi-asserted-by":"publisher","unstructured":"Moustafa N (2019) The Bot-IoT dataset. IEEE Dataport . https:\/\/doi.org\/10.21227\/fesz-dm97 . https:\/\/dx.doi.org\/10.21227\/fesz-dm97","DOI":"10.21227\/fesz-dm97"},{"key":"6422_CR57","unstructured":"Project Z . The Zeek Network Security Monitor. Zeek Project. https:\/\/zeek.org\/"},{"key":"6422_CR58","doi-asserted-by":"publisher","unstructured":"Moustafa N (2019) The Bot-IoT dataset. IEEE Dataport. https:\/\/doi.org\/10.21227\/r7v2-x988 . https:\/\/dx.doi.org\/10.21227\/r7v2-x988","DOI":"10.21227\/r7v2-x988"},{"key":"6422_CR59","doi-asserted-by":"publisher","unstructured":"Akgun D, Hizal S, Cavusoglu U (2022) A new DDoS attacks intrusion detection model based on deep learning for cybersecurity. Comput Secur 118:102748. https:\/\/doi.org\/10.1016\/j.cose.2022.102748","DOI":"10.1016\/j.cose.2022.102748"},{"key":"6422_CR60","doi-asserted-by":"publisher","unstructured":"Garcia S, Parmisano A, Erquiaga MJ (2020) IoT-23: A labeled dataset with malicious and benign IoT network traffic. Zenodo. More details here https:\/\/www.stratosphereips.org \/datasets-iot23. https:\/\/doi.org\/10.5281\/zenodo.4743746","DOI":"10.5281\/zenodo.4743746"},{"key":"6422_CR61","doi-asserted-by":"publisher","unstructured":"Chatzoglou E, Kouliaridis V, Kambourakis G, Karopoulos G, Gritzalis S (2023) A hands-on gaze on http\/3 security through the lens of http\/2 and a public dataset. Comput Secur 125:103051. https:\/\/doi.org\/10.1016\/j.cose.2022.103051","DOI":"10.1016\/j.cose.2022.103051"},{"key":"6422_CR62","doi-asserted-by":"publisher","unstructured":"Neto ECP, Taslimasa H, Dadkhah S, Iqbal S, Xiong P, Rahman T, Ghorbani AA (2024) Ciciov2024: Advancing realistic ids approaches against dos and spoofing attack in iov can bus. Internet of Things 26:101209. https:\/\/doi.org\/10.1016\/j.iot.2024.101209","DOI":"10.1016\/j.iot.2024.101209"},{"key":"6422_CR63","unstructured":"Haider W (2023) Next-Generation Intrusion Detection System-Dataset (NGIDS-DS). UNSW Sydney"},{"key":"6422_CR64","doi-asserted-by":"publisher","first-page":"100","DOI":"10.1016\/j.cose.2014.05.011","volume":"45","author":"S Garcia","year":"2014","unstructured":"Garcia S, Grill M, Stiborek J, Zunino A (2014) An empirical comparison of botnet detection methods. Comput Secur 45:100\u2013123","journal-title":"Comput Secur"},{"key":"6422_CR65","doi-asserted-by":"publisher","unstructured":"Rojas JS, Pekar A, Rendon A, Corrales JC (2020) Smart user consumption profiling: Incremental learning-based ott service degradation. IEEE Access 8:207426\u2013207442. https:\/\/doi.org\/10.1109\/ACCESS.2020.3037971","DOI":"10.1109\/ACCESS.2020.3037971"},{"key":"6422_CR66","doi-asserted-by":"publisher","unstructured":"Szumelda P, Orzechowski N, Rawski M, Janicki A (2022) Vhs-22 \u2013 a very heterogeneous set of network traffic data for threat detection. In: Proceedings of the 2022 European Interdisciplinary Cybersecurity Conference. EICC \u201922, pp 72\u201378. Association for Computing Machinery, New York, NY, USA. https:\/\/doi.org\/10.1145\/3528580.3532843","DOI":"10.1145\/3528580.3532843"},{"issue":"5","key":"6422_CR67","doi-asserted-by":"publisher","first-page":"1125","DOI":"10.1007\/s10207-023-00682-2","volume":"22","author":"OH Abdulganiyu","year":"2023","unstructured":"Abdulganiyu OH, Ait Tchakoucht T, Saheed YK (2023) A systematic literature review for network intrusion detection system (ids). Int J Inf Secur 22(5):1125\u20131162","journal-title":"Int J Inf Secur"},{"key":"6422_CR68","doi-asserted-by":"publisher","unstructured":"Jain N, Jana PK (2023) A logically randomized forest algorithm for classification and regression problems. Expert Syst Appl 213:119225. https:\/\/doi.org\/10.1016\/j.eswa.2022.119225","DOI":"10.1016\/j.eswa.2022.119225"},{"issue":"12","key":"6422_CR69","doi-asserted-by":"publisher","first-page":"453","DOI":"10.3390\/a15120453","volume":"15","author":"B Yang","year":"2022","unstructured":"Yang B, Arshad MH, Zhao Q (2022) Packet-level and flow-level network intrusion detection based on reinforcement learning and adversarial training. Algorithms 15(12):453. https:\/\/doi.org\/10.3390\/a15120453","journal-title":"Algorithms"},{"key":"6422_CR70","doi-asserted-by":"publisher","unstructured":"Lopez-Martin M, Carro B, Sanchez-Esguevillas A (2020) Application of deep reinforcement learning to intrusion detection for supervised problems. Expert Syst Appl 141:112963. https:\/\/doi.org\/10.1016\/j.eswa.2019.112963","DOI":"10.1016\/j.eswa.2019.112963"},{"key":"6422_CR71","doi-asserted-by":"crossref","unstructured":"Alrashdi I, Alqazzaz A, Aloufi E, Alharthi R, Zohdy M, Ming H (2019) Ad-iot: Anomaly detection of iot cyberattacks in smart city using machine learning. In: 2019 IEEE 9th Annual Computing and Communication Workshop and Conference (CCWC), pp 0305\u20130310. IEEE","DOI":"10.1109\/CCWC.2019.8666450"},{"issue":"2","key":"6422_CR72","doi-asserted-by":"publisher","first-page":"1125","DOI":"10.1109\/TNSM.2021.3075503","volume":"18","author":"CF Pontes","year":"2021","unstructured":"Pontes CF, De Souza MM, Gondim JJ, Bishop M, Marotta MA (2021) A new method for flow-based network intrusion detection using the inverse potts model. IEEE Trans Netw Serv Manage 18(2):1125\u20131136","journal-title":"IEEE Trans Netw Serv Manage"},{"key":"6422_CR73","unstructured":"Souza M, Pontes C, Gondim J, Garcia LP, DaSilva L, Marotta MA (2021) A novel open set energy-based flow classifier for network intrusion detection. arXiv:2109.11224"},{"issue":"6","key":"6422_CR74","doi-asserted-by":"publisher","first-page":"1649","DOI":"10.1007\/s13042-020-01264-7","volume":"12","author":"Z Zhang","year":"2021","unstructured":"Zhang Z, Zhang Y, Guo D, Song M (2021) A scalable network intrusion detection system towards detecting, discovering, and learning unknown attacks. Int J Mach Learn Cybern 12(6):1649\u20131665. https:\/\/doi.org\/10.1007\/s13042-020-01264-7","journal-title":"Int J Mach Learn Cybern"},{"key":"6422_CR75","unstructured":"Liang S, Li Y, Srikant R (2018) Enhancing the reliability of out-of-distribution image detection in neural networks. In: International Conference on Learning Representations (2018). https:\/\/openreview.net\/forum?id=H1VGkIxRZ"},{"key":"6422_CR76","unstructured":"Armi L, Fekri-Ershad S (2019) Texture image analysis and texture classification methods-a review. arXiv:1904.06554"},{"key":"6422_CR77","doi-asserted-by":"publisher","unstructured":"Rogachev A, Melikhova E, Atamanov G (2021) Building artificial neural networks for NLP analysis and classification of target content. In: Proceedings of the Conference on Current Problems of Our Time: the Relationship of Man and Society (CPT 2020). Atlantis Press, ???. https:\/\/doi.org\/10.2991\/assehr.k.210225.058","DOI":"10.2991\/assehr.k.210225.058"},{"key":"6422_CR78","doi-asserted-by":"publisher","unstructured":"Bui V, Pham TL, Nguyen H, Jang YM (2021) Data augmentation using generative adversarial network for automatic machine fault detection based on vibration signals. Appl Sci 11(5). https:\/\/doi.org\/10.3390\/app11052166","DOI":"10.3390\/app11052166"},{"issue":"1","key":"6422_CR79","first-page":"9","volume":"17","author":"N Abedzadeh","year":"2023","unstructured":"Abedzadeh N, Jacobs M (2023) A survey in techniques for imbalanced intrusion detection system datasets. Int J Comput Syst Eng 17(1):9\u201318","journal-title":"Int J Comput Syst Eng"},{"key":"6422_CR80","first-page":"1","volume":"9","author":"RB Basnet","year":"2019","unstructured":"Basnet RB, Shash R, Johnson C, Walgren L, Doleck T (2019) Towards detecting and classifying network intrusion traffic using deep learning frameworks. J Internet Serv Inf Secur 9:1\u201317","journal-title":"J Internet Serv Inf Secur"},{"key":"6422_CR81","doi-asserted-by":"publisher","first-page":"377","DOI":"10.1007\/978-3-031-17551-0_25","volume-title":"Sci Cyber Secur","author":"O Belarbi","year":"2022","unstructured":"Belarbi O, Khan A, Carnelli P, Spyridopoulos T (2022) An intrusion detection system based on deep belief networks. In: Su C, Sakurai K, Liu F (eds) Sci Cyber Secur. Springer, Cham, pp 377\u2013392"},{"issue":"1","key":"6422_CR82","first-page":"321","volume":"16","author":"NV Chawla","year":"2002","unstructured":"Chawla NV, Bowyer KW, Hall LO, Kegelmeyer WP (2002) Smote: Synthetic minority over-sampling technique. J Artif Int Res 16(1):321\u2013357","journal-title":"J Artif Int Res"},{"key":"6422_CR83","unstructured":"Khosla P, Teterwak P, Wang C, Sarna A, Tian Y, Isola P, Maschinot A, Liu C, Krishnan D (2020) Supervised contrastive learning. In: Larochelle H, Ranzato M, Hadsell R, Balcan MF, Lin H (eds) Advances in Neural Information Processing Systems, vol 33, pp 18661\u201318673. Curran Associates, Inc., ???"},{"key":"6422_CR84","doi-asserted-by":"crossref","unstructured":"Li T, Cao P, Yuan Y, Fan L, Yang Y, Feris RS, Indyk P, Katabi D (2021) Targeted supervised contrastive learning for long-tailed recognition. 2022 IEEE\/CVF Conf Comput Vis Pattern Recogn (CVPR), 6908\u20136918","DOI":"10.1109\/CVPR52688.2022.00679"},{"key":"6422_CR85","doi-asserted-by":"publisher","unstructured":"Gao T, Yao X, Chen D (2021) SimCSE: Simple contrastive learning of sentence embeddings. In: Proceedings of the 2021 Conference on Empirical Methods in Natural Language Processing, pp 6894\u20136910. Association for Computational Linguistics, Online and Punta Cana, Dominican Republic . https:\/\/doi.org\/10.18653\/v1\/2021.emnlp-main.552","DOI":"10.18653\/v1\/2021.emnlp-main.552"},{"key":"6422_CR86","doi-asserted-by":"publisher","unstructured":"Hinton GE, Salakhutdinov RR (2006) Reducing the dimensionality of data with neural networks. Science 313(5786):504\u2013507. https:\/\/doi.org\/10.1126\/science.1127647https:\/\/www.science.org\/doi\/pdf\/10.1126\/science.1127647","DOI":"10.1126\/science.1127647"},{"key":"6422_CR87","doi-asserted-by":"publisher","unstructured":"Liu L, Wang P, Ruan J, Lin J (2022) ConFlow: Contrast Network Flow Improving Class-Imbalanced Learning in Network Intrusion Detection. Research Square. https:\/\/doi.org\/10.21203\/rs.3.rs-1572776\/v1","DOI":"10.21203\/rs.3.rs-1572776\/v1"},{"key":"6422_CR88","doi-asserted-by":"crossref","unstructured":"Huang G, Liu Z, Weinberger, K.Q.: Densely connected convolutional networks. 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), 2261\u20132269","DOI":"10.1109\/CVPR.2017.243"},{"key":"6422_CR89","doi-asserted-by":"publisher","unstructured":"Shafiq M, Gu Z (2022) Deep residual learning for image recognition: A survey. Appl Sci 12(18). https:\/\/doi.org\/10.3390\/app12188972","DOI":"10.3390\/app12188972"},{"key":"6422_CR90","unstructured":"NFStream: A flexible network data analysis framework. NFStream Developers. https:\/\/www.nfstream.org\/"},{"issue":"1","key":"6422_CR91","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1109\/TNN.2008.2005605","volume":"20","author":"F Scarselli","year":"2009","unstructured":"Scarselli F, Gori M, Tsoi AC, Hagenbuchner M, Monfardini G (2009) The graph neural network model. IEEE Trans Neural Netw 20(1):61\u201380. https:\/\/doi.org\/10.1109\/TNN.2008.2005605","journal-title":"IEEE Trans Neural Netw"},{"key":"6422_CR92","unstructured":"Hamilton WL, Ying R, Leskovec J (2017) Inductive representation learning on large graphs. In: Proceedings of the 31st International Conference on Neural Information Processing Systems. NIPS\u201917, pp 1025\u20131035. Curran Associates Inc., Red Hook, NY, USA"},{"key":"6422_CR93","doi-asserted-by":"publisher","unstructured":"Kilincer IF, Ertam F, Sengur A (2021) Machine learning methods for cyber security intrusion detection: Datasets and comparative study. Comput Netw 188:107840. https:\/\/doi.org\/10.1016\/j.comnet.2021.107840","DOI":"10.1016\/j.comnet.2021.107840"},{"issue":"1","key":"6422_CR94","doi-asserted-by":"publisher","first-page":"538","DOI":"10.1109\/comst.2022.3233793","volume":"25","author":"K He","year":"2023","unstructured":"He K, Kim DD, Asghar MR (2023) Adversarial machine learning for network intrusion detection systems: A comprehensive survey. IEEE Commun Surv Tutor 25(1):538\u2013566. https:\/\/doi.org\/10.1109\/comst.2022.3233793","journal-title":"IEEE Commun Surv Tutor"},{"issue":"7","key":"6422_CR95","doi-asserted-by":"publisher","first-page":"314","DOI":"10.3390\/info13070314","volume":"13","author":"Y Zhang","year":"2022","unstructured":"Zhang Y, Zhang H, Zhang B (2022) An effective ensemble automatic feature selection method for network intrusion detection. Inf 13(7):314. https:\/\/doi.org\/10.3390\/info13070314","journal-title":"Inf"},{"key":"6422_CR96","doi-asserted-by":"publisher","unstructured":"Ansari MS, Barto\u0161 V, Lee B (2022) GRU-based deep learning approach for network intrusion alert prediction. Future Gener Comput Syst 128:235\u2013247. https:\/\/doi.org\/10.1016\/j.future.2021.09.040","DOI":"10.1016\/j.future.2021.09.040"},{"key":"6422_CR97","doi-asserted-by":"publisher","unstructured":"Bozinovski S (2020) Reminder of the first paper on transfer learning in neural networks, 1976. Inf 44(3) https:\/\/doi.org\/10.31449\/inf.v44i3.2828","DOI":"10.31449\/inf.v44i3.2828"},{"key":"6422_CR98","doi-asserted-by":"publisher","unstructured":"Lee J, Park K (2019) Ae-cgan model based high performance network intrusion detection system. Appl Sci 9(20). https:\/\/doi.org\/10.3390\/app9204221","DOI":"10.3390\/app9204221"},{"key":"6422_CR99","doi-asserted-by":"publisher","unstructured":"Mvula PK, Branco P, Jourdan G-V, Viktor HL (2023) A systematic literature review of cyber-security data repositories and performance assessment metrics for semi-supervised learning. Discover Data 1(1) https:\/\/doi.org\/10.1007\/s44248-023-00003-x","DOI":"10.1007\/s44248-023-00003-x"},{"issue":"1","key":"6422_CR100","first-page":"1","volume":"7","author":"J Dem\u0161ar","year":"2006","unstructured":"Dem\u0161ar J (2006) Statistical comparisons of classifiers over multiple data sets. J Mach Learn Res 7(1):1\u201330","journal-title":"J Mach Learn Res"},{"key":"6422_CR101","doi-asserted-by":"crossref","unstructured":"Abdulganiyu OH, Tchakoucht TA, Saheed YK (2024) Towards an efficient model for network intrusion detection system (IDS): systematic literature review. Wirel Netw 30(1):453\u2013482","DOI":"10.1007\/s11276-023-03495-2"},{"key":"6422_CR102","doi-asserted-by":"crossref","unstructured":"Vitorino J, Pra\u00e7a I, Maia E (2023) SoK: Realistic adversarial attacks and defenses for intelligent network intrusion detection. Comput Secur 134(103433):103433","DOI":"10.1016\/j.cose.2023.103433"},{"key":"6422_CR103","doi-asserted-by":"crossref","unstructured":"Verma J, Bhandari A, Singh G (2022) INIDS: SWOT analysis and TOWS inferences of state-of-the-art NIDS solutions for the development of intelligent network intrusion detection system. Comput Commun 195:227\u2013247","DOI":"10.1016\/j.comcom.2022.08.022"},{"key":"6422_CR104","doi-asserted-by":"crossref","unstructured":"Garc\u00eda S, Grill M, Stiborek J, Zunino A (2014) An empirical comparison of botnet detection methods. Comput Secur 45:100\u2013123","DOI":"10.1016\/j.cose.2014.05.011"},{"key":"6422_CR105","doi-asserted-by":"publisher","first-page":"227","DOI":"10.1016\/j.comcom.2022.08.022","volume":"195","author":"J Verma","year":"2022","unstructured":"Verma J, Bhandari A, Singh G (2022) inids: Swot analysis and tows inferences of state-of-the-art nids solutions for the development of intelligent network intrusion detection system. Comput Commun 195:227\u2013247","journal-title":"Comput Commun"},{"key":"6422_CR106","doi-asserted-by":"crossref","unstructured":"Verma J, Bhandari A, Singh G (2020) Review of existing data sets for network intrusion detection system. Adv Math, Sci J 9(6):3849\u20133854","DOI":"10.37418\/amsj.9.6.64"},{"issue":"1","key":"6422_CR107","doi-asserted-by":"publisher","first-page":"453","DOI":"10.1007\/s11276-023-03495-2","volume":"30","author":"OH Abdulganiyu","year":"2024","unstructured":"Abdulganiyu OH, Tchakoucht TA, Saheed YK (2024) Towards an efficient model for network intrusion detection system (ids): systematic literature review. Wirel Netw 30(1):453\u2013482","journal-title":"Wirel Netw"},{"issue":"10","key":"6422_CR108","first-page":"405","volume":"12","author":"M Nkongolo","year":"2021","unstructured":"Nkongolo M, Deventer JP, Kasongo SM (2021) UGRansome1819: A novel dataset for anomaly detection and zero-day threats. Inf (Basel) 12(10):405","journal-title":"Inf (Basel)"},{"key":"6422_CR109","doi-asserted-by":"crossref","unstructured":"Gaudreault J-G, Branco P (2024) Empirical analysis of performance assessment for imbalanced classification. Mach Learn, 1\u201343","DOI":"10.1007\/s10994-023-06497-5"}],"container-title":["Applied Intelligence"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10489-025-06422-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10489-025-06422-4\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10489-025-06422-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,19]],"date-time":"2025-09-19T19:38:23Z","timestamp":1758310703000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10489-025-06422-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,1]]},"references-count":109,"journal-issue":{"issue":"7","published-print":{"date-parts":[[2025,5]]}},"alternative-id":["6422"],"URL":"https:\/\/doi.org\/10.1007\/s10489-025-06422-4","relation":{},"ISSN":["0924-669X","1573-7497"],"issn-type":[{"value":"0924-669X","type":"print"},{"value":"1573-7497","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,4,1]]},"assertion":[{"value":"1 March 2025","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"1 April 2025","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing Interest"}},{"value":"This article does not contain any studies with human participants or animals performed by any of the authors.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical and Informed Consent for Data Used"}}],"article-number":"608"}}