{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,30]],"date-time":"2026-05-30T08:01:16Z","timestamp":1780128076782,"version":"3.54.0"},"reference-count":39,"publisher":"Springer Science and Business Media LLC","issue":"8","license":[{"start":{"date-parts":[[2026,5,30]],"date-time":"2026-05-30T00:00:00Z","timestamp":1780099200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,5,30]],"date-time":"2026-05-30T00:00:00Z","timestamp":1780099200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Front. Comput. Sci."],"published-print":{"date-parts":[[2026,8]]},"DOI":"10.1007\/s11704-026-51877-4","type":"journal-article","created":{"date-parts":[[2026,5,30]],"date-time":"2026-05-30T07:09:48Z","timestamp":1780124988000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Robustness on deep learning based DDoS detection: an adversarial study"],"prefix":"10.1007","volume":"20","author":[{"given":"Hui","family":"Shao","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jianjun","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wei","family":"Ruan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jing","family":"Lai","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,5,30]]},"reference":[{"key":"51877_CR1","doi-asserted-by":"publisher","first-page":"103212","DOI":"10.1016\/j.jisa.2022.103212","volume":"68","author":"A Ahalawat","year":"2022","unstructured":"Ahalawat A, Babu K S, Turuk A K, Patel S. A low-rate DDoS detection and mitigation for SDN using Renyi entropy with packet drop. Journal of Information Security and Applications, 2022, 68: 103212","journal-title":"Journal of Information Security and Applications"},{"key":"51877_CR2","doi-asserted-by":"publisher","first-page":"143985","DOI":"10.1109\/ACCESS.2020.3013998","volume":"8","author":"M A Aladaileh","year":"2020","unstructured":"Aladaileh M A, Anbar M, Hasbullah I H, Chong Y W, Sanjalawe Y K. Detection techniques of distributed denial of service attacks on software-defined networking controller\u2013a review. IEEE Access, 2020, 8: 143985\u2013143995","journal-title":"IEEE Access"},{"issue":"2","key":"51877_CR3","doi-asserted-by":"publisher","first-page":"876","DOI":"10.1109\/TNSM.2020.2971776","volume":"17","author":"R Doriguzzi-Corin","year":"2020","unstructured":"Doriguzzi-Corin R, Millar S, Scott-Hayward S, Mart\u00ednez-Del-Rinc\u00f3n J, Siracusa, D. Lucid: a practical, lightweight deep learning solution for DDoS attack detection. IEEE Transactions on Network and Service Management, 2020, 17(2): 876\u2013889","journal-title":"IEEE Transactions on Network and Service Management"},{"issue":"1","key":"51877_CR4","doi-asserted-by":"publisher","first-page":"89","DOI":"10.32604\/cmes.2022.020724","volume":"134","author":"G Kumar","year":"2022","unstructured":"Kumar G, Alqahtani H. Machine learning techniques for intrusion detection systems in SDN-recent advances, challenges and future directions. CMES - Computer Modeling in Engineering and Sciences, 2022, 134(1): 89\u2013119","journal-title":"CMES - Computer Modeling in Engineering and Sciences"},{"key":"51877_CR5","doi-asserted-by":"publisher","first-page":"239","DOI":"10.1016\/j.procs.2021.05.025","volume":"185","author":"L Ashiku","year":"2021","unstructured":"Ashiku L, Dagli C. Network intrusion detection system using deep learning. Procedia Computer Science, 2021, 185: 239\u2013247","journal-title":"Procedia Computer Science"},{"key":"51877_CR6","first-page":"207","volume-title":"Proceedings of the 5th Southern African Conference on Artificial Intelligence Research","author":"L L Mutembei","year":"2024","unstructured":"Mutembei L L, Senekane M C, Van Zyl T. Deep learning-based network intrusion detection systems: a systematic literature review. In: Proceedings of the 5th Southern African Conference on Artificial Intelligence Research. 2024, 207\u2013234"},{"key":"51877_CR7","doi-asserted-by":"publisher","first-page":"205","DOI":"10.1016\/j.procs.2022.03.029","volume":"201","author":"E E Abdallah","year":"2022","unstructured":"Abdallah E E, Eleisah W, Otoom A F. Intrusion detection systems using supervised machine learning techniques: a survey. Procedia Computer Science, 2022, 201: 205\u2013212","journal-title":"Procedia Computer Science"},{"key":"51877_CR8","doi-asserted-by":"publisher","first-page":"24808","DOI":"10.1109\/ACCESS.2023.3254915","volume":"11","author":"J Du","year":"2023","unstructured":"Du J, Yang K, Hu Y, Jiang L. NIDS-CNNLSTM: network intrusion detection classification model based on deep learning. IEEE Access, 2023, 11: 24808\u201324821","journal-title":"IEEE Access"},{"key":"51877_CR9","first-page":"1","volume-title":"Proceeding of the 8th International Conference on Wireless and Telematics","author":"A H Halbouni","year":"2022","unstructured":"Halbouni A H, Gunawan T S, Halbouni M, Assaig F A A, Effendi M R, Ismail N. CNN-IDS: convolutional neural network for network intrusion detection system. In: Proceeding of the 8th International Conference on Wireless and Telematics. 2022, 1\u20134"},{"key":"51877_CR10","doi-asserted-by":"publisher","first-page":"119862","DOI":"10.1109\/ACCESS.2023.3327620","volume":"11","author":"A Ahmim","year":"2023","unstructured":"Ahmim A, Maazouzi F, Ahmim M, Namane S, Dhaou I B. Distributed denial of service attack detection for the internet of things using hybrid deep learning model. IEEE Access, 2023, 11: 119862\u2013119875","journal-title":"IEEE Access"},{"key":"51877_CR11","doi-asserted-by":"publisher","first-page":"103251","DOI":"10.1016\/j.cose.2023.103251","volume":"129","author":"S Aktar","year":"2023","unstructured":"Aktar S, Nur A Y. Towards DDoS attack detection using deep learning approach. Computers & Security, 2023, 129: 103251","journal-title":"Computers & Security"},{"issue":"12","key":"51877_CR12","doi-asserted-by":"publisher","first-page":"2404","DOI":"10.3390\/electronics13122404","volume":"13","author":"H D Le","year":"2024","unstructured":"Le H D, Park M. Enhancing multi-class attack detection in graph neural network through feature rearrangement. Electronics, 2024, 13(12): 2404","journal-title":"Electronics"},{"key":"51877_CR13","first-page":"1275","volume-title":"Proceedings of the 25th IEEE International Conference on Computer Supported Cooperative Work in Design","author":"Y Li","year":"2022","unstructured":"Li Y, Li R, Zhou Z, Guo J, Yang W, Du M, Liu Q. GraphDDoS: effective DDoS attack detection using graph neural networks. In: Proceedings of the 25th IEEE International Conference on Computer Supported Cooperative Work in Design. 2022, 1275\u20131280"},{"key":"51877_CR14","doi-asserted-by":"publisher","first-page":"110508","DOI":"10.1016\/j.comnet.2024.110508","volume":"250","author":"R A Bakar","year":"2024","unstructured":"Bakar R A, De Marinis L, Cugini F, Paolucci F. FTG-Net-E: a hierarchical ensemble graph neural network for DDoS attack detection. Computer Networks, 2024, 250: 110508","journal-title":"Computer Networks"},{"issue":"6","key":"51877_CR15","doi-asserted-by":"publisher","first-page":"5103","DOI":"10.1109\/JIOT.2020.2975654","volume":"7","author":"J Li","year":"2020","unstructured":"Li J, Liu Y, Chen T, Xiao Z, Li Z, Wang J. Adversarial attacks and defenses on cyber\u2013physical systems: a survey. IEEE Internet of Things Journal, 2020, 7(6): 5103\u20135115","journal-title":"IEEE Internet of Things Journal"},{"issue":"5","key":"51877_CR16","doi-asserted-by":"publisher","first-page":"202","DOI":"10.3390\/technologies13050202","volume":"13","author":"A Abomakhelb","year":"2025","unstructured":"Abomakhelb A, Jalil K A, Buja A G, Alhammadi A, Alenezi A M. A comprehensive review of adversarial attacks and defense strategies in deep neural networks. Technologies, 2025, 13(5): 202","journal-title":"Technologies"},{"key":"51877_CR17","first-page":"372","volume-title":"Proceedings of the IEEE European Symposium on Security and Privacy","author":"N Papernot","year":"2016","unstructured":"Papernot N, McDaniel P, Jhay S, Fredriksonz M, Celik Z B, Swami, A. The limitations of deep learning in adversarial settings. In: Proceedings of the IEEE European Symposium on Security and Privacy. 2016, 372\u2013387"},{"key":"51877_CR18","unstructured":"Saini S, Chennamaneni A, Sawyerr B. A review of the duality of adversarial learning in network intrusion: attacks and countermeasures. 2024, arXiv preprint arXiv: 2412.13880"},{"key":"51877_CR19","unstructured":"Venturi A, Stabili D, Marchetti M. Problem space structural adversarial attacks for network intrusion detection systems based on graph neural networks. 2024, arXiv preprint arXiv: 2403.11830"},{"key":"51877_CR20","doi-asserted-by":"publisher","first-page":"148613","DOI":"10.1109\/ACCESS.2025.3600984","volume":"13","author":"S Ennaji","year":"2025","unstructured":"Ennaji S, De Gaspari F, Hitaj D, Kbidi A, Vincenzo Mancini L. Adversarial challenges in network intrusion detection systems: research insights and future prospects. IEEE Access, 2025, 13: 148613\u2013148645","journal-title":"IEEE Access"},{"key":"51877_CR21","first-page":"41","volume-title":"Proceedings of the 4th International Conference on Artificial Intelligence, Robotics, and Communication (ICAIRC)","author":"H Xi","year":"2024","unstructured":"Xi H, Ru L, Tian J, Lu B, Hu S, Wang W. Adversarial attacks: key challenges for security defense in the age of intelligence. In: Proceedings of the 4th International Conference on Artificial Intelligence, Robotics, and Communication (ICAIRC). 2024, 41\u201346"},{"issue":"10","key":"51877_CR22","doi-asserted-by":"publisher","first-page":"e0275971","DOI":"10.1371\/journal.pone.0275971","volume":"17","author":"E Alshahrani","year":"2022","unstructured":"Alshahrani E, Alghazzawi D, Alotaibi R, Rabie O. Adversarial attacks against supervised machine learning based network intrusion detection systems. PLoS One, 2022, 17(10): e0275971","journal-title":"PLoS One"},{"issue":"2","key":"51877_CR23","doi-asserted-by":"publisher","first-page":"728","DOI":"10.1093\/comjnl\/bxad014","volume":"67","author":"T J Liu","year":"2024","unstructured":"Liu T J. Adversarial attacks on network intrusion detection systems using flow containers. The Computer Journal, 2024, 67(2): 728\u2013745","journal-title":"The Computer Journal"},{"issue":"16","key":"51877_CR24","doi-asserted-by":"publisher","first-page":"6897","DOI":"10.3390\/app14166897","volume":"14","author":"S Wu","year":"2024","unstructured":"Wu S, Liu J, Huang Y, Guan H, Zhang S. An audio watermarking algorithm based on adversarial perturbation. Applied Sciences, 2024, 14(16): 6897","journal-title":"Applied Sciences"},{"key":"51877_CR25","unstructured":"Zhao M, Zhang L, Ye J, Lu H, Yin B, Wang X. Adversarial training: a survey. 2024, arXiv preprint arXiv: 2410.15042"},{"issue":"16","key":"51877_CR26","doi-asserted-by":"publisher","first-page":"3249","DOI":"10.3390\/electronics14163249","volume":"14","author":"V Heydari","year":"2025","unstructured":"Heydari V, Nyarko K. Enhancing adversarial robustness in network intrusion detection: a novel adversarially trained neural network approach. Electronics, 2025, 14(16): 3249","journal-title":"Electronics"},{"key":"51877_CR27","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1109\/NFV-SDN50289.2020.9289869","volume-title":"Proceedings of the IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)","author":"M J Hashemi","year":"2020","unstructured":"Hashemi M J, Keller E. Enhancing robustness against adversarial examples in network intrusion detection systems. In: Proceedings of the IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN). 2020, 37\u201343"},{"issue":"2","key":"51877_CR28","doi-asserted-by":"publisher","first-page":"15","DOI":"10.1145\/3712307","volume":"28","author":"S Hore","year":"2025","unstructured":"Hore S, Ghadermazi J, Paudel D, Shah D, Das T, Bastian N. Deep PackGen: a deep reinforcement learning framework for adversarial network packet generation. ACM Transactions on Privacy and Security, 2025, 28(2): 15","journal-title":"ACM Transactions on Privacy and Security"},{"key":"51877_CR29","first-page":"165","volume-title":"Proceedings of the 53rd Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN)","author":"X Chen","year":"2023","unstructured":"Chen X, Cui L, Wen H, Li Z, Zhu H, Hao Z, Sun L. MalAder: decision-based black-box attack against api sequence based malware detectors. In: Proceedings of the 53rd Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN). 2023, 165\u2013178"},{"issue":"1","key":"51877_CR30","doi-asserted-by":"publisher","first-page":"153","DOI":"10.1109\/TDSC.2023.3247585","volume":"21","author":"H Yan","year":"2024","unstructured":"Yan H, Li X, Zhang W, Wang R, Li H, Zhao X, Li F, Lin X. Automatic evasion of machine learning-based network intrusion detection systems. IEEE Transactions on Dependable and Secure Computing, 2024, 21(1): 153\u2013167","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"51877_CR31","doi-asserted-by":"publisher","first-page":"408","DOI":"10.1109\/SaTML59370.2024.00027","volume-title":"Proceedings of 2024 IEEE Conference on Secure and Trustworthy Machine Learning (SaTML)","author":"E Debenedetti","year":"2024","unstructured":"Debenedetti E, Carlini N, Tram\u00e8r F. Evading black-box classifiers without breaking eggs. In: Proceedings of 2024 IEEE Conference on Secure and Trustworthy Machine Learning (SaTML). 2024, 408\u2013424"},{"key":"51877_CR32","doi-asserted-by":"publisher","first-page":"987","DOI":"10.1109\/TIFS.2019.2932228","volume":"15","author":"X Chen","year":"2020","unstructured":"Chen X, Li C, Wang D, Wen S, Zhang J, Nepal S, Xiang Y, Ren K. Android HIV: a study of repackaging malware for evading machine-learning detection. IEEE Transactions on Information Forensics and Security, 2020, 15: 987\u20131001","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"51877_CR33","first-page":"1208","volume-title":"Proceedings of the 2nd International Conference on Intelligent Computing, Instrumentation and Control Technologies (ICICICT)","author":"P Sinha","year":"2019","unstructured":"Sinha P, Rai A K, Bhushan B. Information security threats and attacks with conceivable counteraction. In: Proceedings of the 2nd International Conference on Intelligent Computing, Instrumentation and Control Technologies (ICICICT). 2019, 1208\u20131213"},{"issue":"6","key":"51877_CR34","doi-asserted-by":"publisher","first-page":"2471","DOI":"10.1109\/TNET.2018.2869798","volume":"26","author":"P Sermpezis","year":"2018","unstructured":"Sermpezis P, Kotronis V, Gigis P, Dimitropoulos X, Cicalese D, King A, Dainotti A. ARTEMIS: neutralizing BGP hijacking within a minute. IEEE\/ACM Transactions on Networking, 2018, 26(6): 2471\u20132486","journal-title":"IEEE\/ACM Transactions on Networking"},{"issue":"2","key":"51877_CR35","doi-asserted-by":"publisher","first-page":"239","DOI":"10.1504\/IJMOR.2016.074859","volume":"8","author":"A M Haghighi","year":"2016","unstructured":"Haghighi A M, Mishev D P. Busy period of a single-server Poisson queueing system with splitting and batch delayed-feedback. International Journal of Mathematics in Operational Research, 2016, 8(2): 239\u2013257","journal-title":"International Journal of Mathematics in Operational Research"},{"key":"51877_CR36","doi-asserted-by":"publisher","first-page":"39","DOI":"10.1109\/SECPRI.1995.398921","volume-title":"Proceedings of 1995 IEEE Symposium on Security and Privacy","author":"S Staniford-Chen","year":"1995","unstructured":"Staniford-Chen S, Heberlein L T. Holding intruders accountable on the internet. In: Proceedings of 1995 IEEE Symposium on Security and Privacy. 1995, 39\u201349."},{"key":"51877_CR37","unstructured":"\u201cInternet2\u2019s network topology,\u201d https:\/\/www.internet2.edu\/media\/medialibrary\/2013\/07\/31\/Internet2-NetworkInfrastructure-Topology.pdf"},{"key":"51877_CR38","first-page":"108","volume-title":"Proceedings of the 4th International Conference on Information Systems Security and Privacy (ICISSP)","author":"I Sharafaldin","year":"2018","unstructured":"Sharafaldin I, Lashkari A H, Ghorbani A A. Toward generating a new intrusion detection dataset and intrusion traffic characterization. In: Proceedings of the 4th International Conference on Information Systems Security and Privacy (ICISSP). 2018, 108\u2013116"},{"key":"51877_CR39","first-page":"253","volume-title":"Proceedings of the 15th International Conference on Systems, Signals and Image Processing","author":"M Fras","year":"2008","unstructured":"Fras M, Mohorko J, Cucej Z. Packet size process modeling of measured self-similar network traffic with defragmentation method. In: Proceedings of the 15th International Conference on Systems, Signals and Image Processing. 2008, 253\u2013256"}],"container-title":["Frontiers of Computer Science"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11704-026-51877-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11704-026-51877-4","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11704-026-51877-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,30]],"date-time":"2026-05-30T07:09:51Z","timestamp":1780124991000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11704-026-51877-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,30]]},"references-count":39,"journal-issue":{"issue":"8","published-print":{"date-parts":[[2026,8]]}},"alternative-id":["51877"],"URL":"https:\/\/doi.org\/10.1007\/s11704-026-51877-4","relation":{},"ISSN":["2095-2228","2095-2236"],"issn-type":[{"value":"2095-2228","type":"print"},{"value":"2095-2236","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,30]]},"assertion":[{"value":"12 November 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"28 December 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"30 May 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"The authors declare that they have no competing interests or financial conflicts to disclose.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"2008817"}}