{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T12:46:45Z","timestamp":1780318005716,"version":"3.54.1"},"reference-count":36,"publisher":"Springer Science and Business Media LLC","issue":"6","license":[{"start":{"date-parts":[[2021,1,24]],"date-time":"2021-01-24T00:00:00Z","timestamp":1611446400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,1,24]],"date-time":"2021-01-24T00:00:00Z","timestamp":1611446400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"funder":[{"DOI":"10.13039\/100000185","name":"MoE-CMCC \u201cArtifical Intelligence\u201d Project","doi-asserted-by":"publisher","award":["No. MCM20190701"],"award-info":[{"award-number":["No. MCM20190701"]}],"id":[{"id":"10.13039\/100000185","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Mach. Learn. &amp; Cyber."],"published-print":{"date-parts":[[2021,6]]},"DOI":"10.1007\/s13042-020-01264-7","type":"journal-article","created":{"date-parts":[[2021,1,24]],"date-time":"2021-01-24T09:04:38Z","timestamp":1611479078000},"page":"1649-1665","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":32,"title":["A scalable network intrusion detection system towards detecting, discovering, and learning unknown attacks"],"prefix":"10.1007","volume":"12","author":[{"given":"Zhao","family":"Zhang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4997-698X","authenticated-orcid":false,"given":"Yong","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Da","family":"Guo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mei","family":"Song","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2021,1,24]]},"reference":[{"key":"1264_CR1","doi-asserted-by":"crossref","unstructured":"Karatas G, Demir O, Sahingoz OK (2018) Deep learning in intrusion detection systems. In: 2018 International congress on big data, deep learning and fighting cyber terrorism (IBIGDELFT), IEEE, pp 113\u2013116","DOI":"10.1109\/IBIGDELFT.2018.8625278"},{"issue":"2","key":"1264_CR2","doi-asserted-by":"publisher","first-page":"1153","DOI":"10.1109\/COMST.2015.2494502","volume":"18","author":"AL Buczak","year":"2016","unstructured":"Buczak AL, Guven E (2016) A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Commun Surv Tutor 18(2):1153\u20131176","journal-title":"IEEE Commun Surv Tutor"},{"key":"1264_CR3","doi-asserted-by":"publisher","first-page":"1145","DOI":"10.1109\/COMST.2016.2636078","volume":"19","author":"EM Rudd","year":"2017","unstructured":"Rudd EM, Rozsa A, G\u00fcnther M et al (2017) A survey of stealth malware: attacks, mitigation measures, and steps toward autonomous open world solutions. IEEE Commun Surv Tutor 19(2):1145\u20131172","journal-title":"IEEE Commun Surv Tutor"},{"issue":"7","key":"1264_CR4","doi-asserted-by":"publisher","first-page":"1757","DOI":"10.1109\/TPAMI.2012.256","volume":"35","author":"WJ Scheirer","year":"2013","unstructured":"Scheirer WJ, de Rezende Rocha A, Sapkota A, Boult TE (2013) Toward open set recognition. IEEE Trans Pattern Anal Mach Intell 35(7):1757\u20131772","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"1264_CR5","doi-asserted-by":"crossref","unstructured":"Bendale A, Boult T (2015) Towards open world recognition. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 1893\u20131902","DOI":"10.1109\/CVPR.2015.7298799"},{"key":"1264_CR6","unstructured":"Miller D, S\u00fcnderhauf N, Milford M et al (2020) Class anchor clustering: a distance-based loss for training open set classifiers. arXiv preprint arXiv:2004.02434"},{"key":"1264_CR7","doi-asserted-by":"publisher","unstructured":"Geng C, Huang S, Chen S (2020) Recent advances in open set recognition: a survey. IEEE Trans Pattern Anal Mach Intell, early access. https:\/\/doi.org\/10.1109\/TPAMI.2020.2981604","DOI":"10.1109\/TPAMI.2020.2981604"},{"issue":"3","key":"1264_CR8","doi-asserted-by":"publisher","first-page":"762","DOI":"10.1109\/TPAMI.2017.2707495","volume":"40","author":"EM Rudd","year":"2017","unstructured":"Rudd EM, Jain LP, Scheirer WJ et al (2017) The extreme value machine. IEEE Trans Pattern Anal Mach Intell 40(3):762\u2013768","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"1264_CR9","doi-asserted-by":"crossref","unstructured":"Jain LP, Scheirer WJ, Boult TE (2014) Multi-class open set recognition using probability of inclusion. In: European conference on computer vision, Springer, Cham, pp 393\u2013409","DOI":"10.1007\/978-3-319-10578-9_26"},{"key":"1264_CR10","doi-asserted-by":"crossref","unstructured":"Henrydoss J, Cruz S, Rudd EM et al (2017) Incremental open set intrusion recognition using extreme value machine. In: 2017 16th IEEE international conference on machine learning and applications (ICMLA), IEEE, pp 1089\u20131093","DOI":"10.1109\/ICMLA.2017.000-3"},{"key":"1264_CR11","doi-asserted-by":"crossref","unstructured":"Cruz S, Coleman C, Rudd EM et al (2017) Open set intrusion recognition for fine-grained attack categorization. In: 2017 IEEE international symposium on technologies for homeland security (HST), IEEE, pp 1\u20136","DOI":"10.1109\/THS.2017.7943467"},{"key":"1264_CR12","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.comcom.2014.04.012","volume":"49","author":"N Hubballi","year":"2014","unstructured":"Hubballi N, Suryanarayanan V (2014) False alarm minimization techniques in signature-based intrusion detection systems: a survey. Comput Commun 49:1\u201317","journal-title":"Comput Commun"},{"issue":"6","key":"1264_CR13","doi-asserted-by":"publisher","first-page":"1035","DOI":"10.1007\/s13042-014-0309-2","volume":"7","author":"M Agarwal","year":"2016","unstructured":"Agarwal M, Pasumarthi D, Biswas S et al (2016) Machine learning approach for detection of flooding DoS attacks in 802.11 networks and attacker localization. Int J Mach Learn Cybern 7(6):1035\u20131051","journal-title":"Int J Mach Learn Cybern"},{"issue":"6","key":"1264_CR14","doi-asserted-by":"publisher","first-page":"1767","DOI":"10.1007\/s13042-016-0557-4","volume":"8","author":"RAR Ashfaq","year":"2017","unstructured":"Ashfaq RAR, He Y, Chen D (2017) Toward an efficient fuzziness based instance selection methodology for intrusion detection system. Int J Mach Learn Cybern 8(6):1767\u20131776","journal-title":"Int J Mach Learn Cybern"},{"issue":"12","key":"1264_CR15","doi-asserted-by":"publisher","first-page":"3387","DOI":"10.1007\/s13042-019-00925-6","volume":"10","author":"Q Yan","year":"2019","unstructured":"Yan Q, Wang M, Huang W et al (2019) Automatically synthesizing DoS attack traces using generative adversarial networks. Int J Mach Learn Cybern 10(12):3387\u20133396","journal-title":"Int J Mach Learn Cybern"},{"key":"1264_CR16","doi-asserted-by":"crossref","unstructured":"Roopak M, Tian GY, Chambers J (2019) Deep learning models for cyber security in IoT networks. In: 2019 IEEE 9th annual computing and communication workshop and conference (CCWC), IEEE, pp 0452\u20130457","DOI":"10.1109\/CCWC.2019.8666588"},{"key":"1264_CR17","doi-asserted-by":"publisher","first-page":"37004","DOI":"10.1109\/ACCESS.2019.2905041","volume":"7","author":"Y Zhang","year":"2019","unstructured":"Zhang Y, Chen X, Jin L et al (2019) Network intrusion detection: based on deep hierarchical network and original flow data. IEEE Access 7:37004\u201337016","journal-title":"IEEE Access"},{"issue":"4","key":"1264_CR18","doi-asserted-by":"publisher","first-page":"583","DOI":"10.3390\/sym11040583","volume":"11","author":"MA Khan","year":"2019","unstructured":"Khan MA, Karim M, Kim Y (2019) A scalable and hybrid intrusion detection system based on the convolutional-LSTM network. Symmetry 11(4):583","journal-title":"Symmetry"},{"key":"1264_CR19","doi-asserted-by":"crossref","unstructured":"Lin P, Ye K, Xu CZ (2019) Dynamic network anomaly detection system by using deep learning techniques. In: International conference on cloud computing, Springer, Cham, pp 161\u2013176","DOI":"10.1007\/978-3-030-23502-4_12"},{"key":"1264_CR20","unstructured":"Hendrycks D, Gimpel K (2016) A baseline for detecting misclassified and out-of-distribution examples in neural networks. arXiv preprint arXiv:1610.02136"},{"key":"1264_CR21","unstructured":"Liang S, Li Y, Srikant R (2017) Enhancing the reliability of out-of-distribution image detection in neural networks. arXiv preprint arXiv:1706.02690"},{"key":"1264_CR22","unstructured":"Shu L, Xu H, Liu B (2018) Unseen class discovery in open-world classification. arXiv preprint arXiv:1801.05609"},{"key":"1264_CR23","unstructured":"Hsu YC, Lv Z, Schlosser J et al (2018) A probabilistic constrained clustering for transfer learning and image category discovery. arXiv preprint arXiv:1806.11078"},{"key":"1264_CR24","doi-asserted-by":"crossref","unstructured":"Shmelkov K, Schmid C, Alahari K (2017) Incremental learning of object detectors without catastrophic forgetting. In: Proceedings of the IEEE international conference on computer vision, pp 3400\u20133409","DOI":"10.1109\/ICCV.2017.368"},{"key":"1264_CR25","doi-asserted-by":"crossref","unstructured":"Rebuffi SA, Kolesnikov A, Sperl G et al (2017) icarl: Incremental classifier and representation learning. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 2001\u20132010","DOI":"10.1109\/CVPR.2017.587"},{"key":"1264_CR26","unstructured":"Goodfellow IJ, Shlens J, Szegedy C (2015) Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572"},{"key":"1264_CR27","first-page":"1750","volume":"22","author":"K Sriperumbudur Bharath","year":"2009","unstructured":"Sriperumbudur Bharath K, Kenji F, Arthur G, Lanckriet Gert RG, Scholkopf B (2009) Kernel choice and classifiability for RKHS embeddings of probability distributions. Adv Neural Inf Process Syst 22:1750\u20131758","journal-title":"Adv Neural Inf Process Syst"},{"key":"1264_CR28","unstructured":"Long M, Wang J (2015) Learning transferable features with deep adaptation networks. In: Proceedings of the 32nd international conference on machine learning (ICML), pp 97\u2013105"},{"key":"1264_CR29","doi-asserted-by":"crossref","unstructured":"Changpinyo S, Chao WL, Sha F (2017) Predicting visual exemplars of unseen classes for zero-shot learning. In: Proceedings of the IEEE international conference on computer vision, pp 3476\u20133485","DOI":"10.1109\/ICCV.2017.376"},{"key":"1264_CR30","unstructured":"Ester M, Kriegel, Hans-Peter, Sander J et al (1996) A density-based algorithm for discovering clusters a density-based algorithm for discovering clusters in large spatial databases with noise. In: Proceedings of the 2nd international conference on knowledge discovery & data mining (KDD'96), pp 226\u2013231"},{"issue":"3","key":"1264_CR31","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3068335","volume":"42","author":"E Schubert","year":"2017","unstructured":"Schubert E, Sander J\u00f6rg, Ester M et al (2017) DBSCAN revisited, revisited: why and how you should (still) use DBSCAN. ACM Trans Database Syst 42(3):1\u201321","journal-title":"ACM Trans Database Syst"},{"issue":"11","key":"1264_CR32","doi-asserted-by":"publisher","first-page":"2624","DOI":"10.1109\/TPAMI.2013.83","volume":"35","author":"T Mensink","year":"2013","unstructured":"Mensink T, Verbeek J, Perronnin F et al (2013) Distance-based image classification: generalizing to new classes at near-zero cost. IEEE Trans Pattern Anal Mach Intell 35(11):2624\u20132637","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"1264_CR33","doi-asserted-by":"publisher","first-page":"119904","DOI":"10.1109\/ACCESS.2019.2933165","volume":"7","author":"Y Zhang","year":"2019","unstructured":"Zhang Y, Chen X, Guo D et al (2019) PCCN: parallel cross convolutional neural network for abnormal network traffic flows detection in multi-class imbalanced network traffic flows. IEEE Access 7:119904\u2013119916","journal-title":"IEEE Access"},{"key":"1264_CR34","unstructured":"Long M, Zhu H, Wang J et al (2016) Deep transfer learning with joint adaptation networks. arXiv preprint arXiv:1605.06636"},{"issue":"10","key":"1264_CR35","doi-asserted-by":"publisher","first-page":"2761","DOI":"10.1109\/TIP.2010.2049235","volume":"19","author":"Y Yang","year":"2010","unstructured":"Yang Y, Xu D, Nie F et al (2010) Image clustering using local discriminant models and global integration. IEEE Trans Image Process 19(10):2761\u20132773","journal-title":"IEEE Trans Image Process"},{"issue":"1\u20132","key":"1264_CR36","doi-asserted-by":"publisher","first-page":"83","DOI":"10.1002\/nav.3800020109","volume":"2","author":"HW Kuhn","year":"1955","unstructured":"Kuhn HW (1955) The Hungarian method for the assignment problem. Nav Res Logist Q 2(1\u20132):83\u201397","journal-title":"Nav Res Logist Q"}],"container-title":["International Journal of Machine Learning and Cybernetics"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13042-020-01264-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s13042-020-01264-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13042-020-01264-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,5,20]],"date-time":"2021-05-20T09:07:07Z","timestamp":1621501627000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s13042-020-01264-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,1,24]]},"references-count":36,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2021,6]]}},"alternative-id":["1264"],"URL":"https:\/\/doi.org\/10.1007\/s13042-020-01264-7","relation":{},"ISSN":["1868-8071","1868-808X"],"issn-type":[{"value":"1868-8071","type":"print"},{"value":"1868-808X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,1,24]]},"assertion":[{"value":"14 December 2019","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"16 December 2020","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"24 January 2021","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}