{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T16:36:42Z","timestamp":1783615002670,"version":"3.55.0"},"reference-count":68,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,11,25]],"date-time":"2025-11-25T00:00:00Z","timestamp":1764028800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,11,25]],"date-time":"2025-11-25T00:00:00Z","timestamp":1764028800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100003407","name":"Ministero dell\u2019Istruzione, dell\u2019Universit\u00e0 e della Ricerca","doi-asserted-by":"publisher","award":["20229BCXNW (CUP B53D23012910006)"],"award-info":[{"award-number":["20229BCXNW (CUP B53D23012910006)"]}],"id":[{"id":"10.13039\/501100003407","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Complex Intell. Syst."],"published-print":{"date-parts":[[2026,1]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>Adversarial attacks, wherein slight inputs are carefully crafted to mislead intelligent models, have attracted increasing attention. However, a critical gap persists between theoretical advancements and practical application, particularly in structured data like network traffic, where interdependent features complicate effective adversarial manipulations. Moreover, ambiguity in current approaches restricts reproducibility and limits progress in this field. Hence, existing defenses often fail to handle evolving adversarial attacks. This paper proposes a novel approach for black-box adversarial attacks that addresses these limitations. Unlike prior work, which often assumes system access or relies on repeated probing, our method strictly respects black-box constraints, reducing interaction to avoid detection and better reflect real-world scenarios. We present an adaptive feature selection strategy using change-point detection and causality analysis to identify and target sensitive features for perturbation. This lightweight design ensures low computational cost and high deployability. Our comprehensive experiments show the attack\u2019s effectiveness in evading detection with minimal interaction, enhancing its adaptability and applicability in real-world scenarios. By advancing the understanding of adversarial attacks in network traffic, this work lays a foundation for developing robust defenses.<\/jats:p>","DOI":"10.1007\/s40747-025-02115-0","type":"journal-article","created":{"date-parts":[[2025,11,25]],"date-time":"2025-11-25T05:47:39Z","timestamp":1764049659000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["Vulnerability disclosure through adaptive black-box adversarial attacks in network intrusion detection systems"],"prefix":"10.1007","volume":"12","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-5119-3467","authenticated-orcid":false,"given":"Sabrine","family":"Ennaji","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Elhadj","family":"Benkhelifa","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Luigi Vincenzo","family":"Mancini","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,11,25]]},"reference":[{"key":"2115_CR1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2025.104327","volume":"151","author":"JM Adeke","year":"2025","unstructured":"Adeke JM, Liu G, Amoah L, Nwali OJ (2025) Investigating the impact of feature selection on adversarial transferability in intrusion detection system. Comput Secur 151:104327","journal-title":"Comput Secur"},{"key":"2115_CR2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2021.115782","volume":"186","author":"E Alhajjar","year":"2021","unstructured":"Alhajjar E, Maxwell P, Bastian N (2021) Adversarial machine learning in network intrusion detection systems. Expert Syst Appl 186:115782","journal-title":"Expert Syst Appl"},{"issue":"3","key":"2115_CR3","doi-asserted-by":"publisher","first-page":"2751","DOI":"10.1109\/TNSM.2024.3357316","volume":"21","author":"N Alhussien","year":"2024","unstructured":"Alhussien N, Aleroud A, Melhem A, Khamaiseh SY (2024) Constraining adversarial attacks on network intrusion detection systems: transferability and defense analysis. IEEE Trans Netw Serv Manag 21(3):2751\u20132772","journal-title":"IEEE Trans Netw Serv Manag"},{"key":"2115_CR4","doi-asserted-by":"publisher","first-page":"34872","DOI":"10.1109\/ACCESS.2022.3162874","volume":"10","author":"ZTM Ali","year":"2022","unstructured":"Ali ZTM, Mohammed A, Ahmad I (2022) Evaluating adversarial robustness of secret key-based defenses. IEEE Access 10:34872\u201334882","journal-title":"IEEE Access"},{"issue":"2","key":"2115_CR5","doi-asserted-by":"publisher","first-page":"62","DOI":"10.3390\/fi15020062","volume":"15","author":"A Alotaibi","year":"2023","unstructured":"Alotaibi A, Rassam MA (2023) Adversarial machine learning attacks against intrusion detection systems: a survey on strategies and defense. Future Internet 15(2):62","journal-title":"Future Internet"},{"key":"2115_CR6","doi-asserted-by":"crossref","unstructured":"Alzantot M, Sharma Y, Chakraborty S, Zhang H, Hsieh CJ, Srivastava MB (2019) GenAttack: practical black-box attacks with gradient-free optimization. In: Proceedings of the genetic and evolutionary computation conference, pp 1111\u20131119","DOI":"10.1145\/3321707.3321749"},{"key":"2115_CR7","volume":"58","author":"E Anthi","year":"2021","unstructured":"Anthi E, Williams L, Rhode M, Burnap P, Wedgbury A (2021) Adversarial attacks on machine learning cybersecurity defences in industrial control systems. J Inf Secur Appl 58:102717","journal-title":"J Inf Secur Appl"},{"issue":"3","key":"2115_CR8","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3469659","volume":"3","author":"G Apruzzese","year":"2022","unstructured":"Apruzzese G, Andreolini M, Ferretti L, Marchetti M, Colajanni M (2022) Modeling realistic adversarial attacks against network intrusion detection systems. Digit Threats Res Pract (DTRAP) 3(3):1\u201319","journal-title":"Digit Threats Res Pract (DTRAP)"},{"key":"2115_CR9","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2022.109037","volume":"133","author":"Y Bai","year":"2023","unstructured":"Bai Y, Wang Y, Zeng Y, Jiang Y, Xia ST (2023) Query efficient black-box adversarial attack on deep neural networks. Pattern Recognit 133:109037","journal-title":"Pattern Recognit"},{"issue":"3","key":"2115_CR10","doi-asserted-by":"publisher","first-page":"178","DOI":"10.1002\/widm.1124","volume":"4","author":"T Bartz-Beielstein","year":"2014","unstructured":"Bartz-Beielstein T, Branke J, Mehnen J, Mersmann O (2014) Evolutionary algorithms. Wiley Interdiscip Rev Data Min Knowl Discov 4(3):178\u2013195","journal-title":"Wiley Interdiscip Rev Data Min Knowl Discov"},{"key":"2115_CR11","unstructured":"Carlini N (2019) A complete list of all (arxiv) adversarial example papers. https:\/\/nicholascarlini.com\/writing\/2019\/all-adversarial-example-papers.html (26.05.2023)"},{"key":"2115_CR12","doi-asserted-by":"crossref","unstructured":"Chen J, Jordan MI, Wainwright MJ (2020) HopSkipJumpAttack: a query-efficient decision-based attack. In: 2020 IEEE symposium on security and privacy (SP). IEEE, pp 1277\u20131294","DOI":"10.1109\/SP40000.2020.00045"},{"key":"2115_CR13","doi-asserted-by":"crossref","unstructured":"Chen PY, Zhang H, Sharma Y, Yi, J, Hsieh CJ (2017) Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models. In: Proceedings of the 10th ACM workshop on artificial intelligence and security, pp 15\u201326","DOI":"10.1145\/3128572.3140448"},{"key":"2115_CR14","doi-asserted-by":"crossref","unstructured":"Chen Y, Zhang M, Li J, Kuang X (2022) Adversarial attacks and defenses in image classification: a practical perspective. In: 2022 7th International conference on image, vision and computing (ICIVC). IEEE, pp 424\u2013430","DOI":"10.1109\/ICIVC55077.2022.9886997"},{"issue":"9","key":"2115_CR15","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3472753","volume":"54","author":"D Chou","year":"2021","unstructured":"Chou D, Jiang M (2021) A survey on data-driven network intrusion detection. ACM Comput Surv (CSUR) 54(9):1\u201336","journal-title":"ACM Comput Surv (CSUR)"},{"key":"2115_CR16","doi-asserted-by":"crossref","unstructured":"Costa J, Apolin\u00e1rio F, Ribeiro C (2024) ARGAN-IDS: adversarial resistant intrusion detection systems using generative adversarial networks. In: Proceedings of the 19th international conference on availability, reliability and security, pp 1\u201310","DOI":"10.1145\/3664476.3669928"},{"key":"2115_CR17","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103176","volume":"129","author":"I Debicha","year":"2023","unstructured":"Debicha I, Cochez B, Kenaza T, Debatty T, Dricot JM, Mees W (2023) Adv-Bot: realistic adversarial botnet attacks against network intrusion detection systems. Comput Secur 129:103176","journal-title":"Comput Secur"},{"key":"2115_CR18","doi-asserted-by":"crossref","unstructured":"Ennaji S, Benkhelifa E, Mancini LV (2025) Vulnerability disclosure through adaptive black-box adversarial attacks on NIDS. arXiv preprint arXiv:2506.20576","DOI":"10.1007\/s40747-025-02115-0"},{"key":"2115_CR19","doi-asserted-by":"crossref","unstructured":"Ennaji S, De\u00a0Gaspari F, Hitaj D, Mancini LV et\u00a0al (2024) Adversarial challenges in network intrusion detection systems: research insights and future prospects. arXiv preprint arXiv:2409.18736","DOI":"10.1109\/ACCESS.2025.3600984"},{"key":"2115_CR20","doi-asserted-by":"crossref","unstructured":"Finlay C, Pooladian AA, Oberman A (2019) The logbarrier adversarial attack: making effective use of decision boundary information. In: Proceedings of the IEEE\/CVF international conference on computer vision, pp 4862\u20134870","DOI":"10.1109\/ICCV.2019.00496"},{"key":"2115_CR21","unstructured":"Goodfellow IJ, Shlens J, Szegedy C (2014) Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572"},{"key":"2115_CR22","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.104028","volume":"145","author":"K He","year":"2024","unstructured":"He K, Kim DD, Asghar MR (2024) NIDS-VIS: improving the generalized adversarial robustness of network intrusion detection system. Comput Secur 145:104028","journal-title":"Comput Secur"},{"issue":"1","key":"2115_CR23","doi-asserted-by":"publisher","first-page":"249","DOI":"10.1093\/biomet\/asac052","volume":"110","author":"S Kov\u00e1cs","year":"2023","unstructured":"Kov\u00e1cs S, B\u00fchlmann P, Li H, Munk A (2023) Seeded binary segmentation: a general methodology for fast and optimal changepoint detection. Biometrika 110(1):249\u2013256","journal-title":"Biometrika"},{"key":"2115_CR24","doi-asserted-by":"crossref","unstructured":"Kumar RSS, Nystr\u00f6m M, Lambert J, Marshall A, Goertzel M, Comissoneru A, Swann M, Xia S (2020) Adversarial machine learning-industry perspectives. In: 2020 IEEE security and privacy workshops (SPW). IEEE, pp 69\u201375","DOI":"10.1109\/SPW50608.2020.00028"},{"key":"2115_CR25","doi-asserted-by":"crossref","unstructured":"Le CC, Phan T, Luong NH (2025) Gradient-free sparse adversarial attack on object detection models. In: Proceedings of the genetic and evolutionary computation conference, pp 800\u2013808","DOI":"10.1145\/3712256.3726305"},{"key":"2115_CR26","doi-asserted-by":"crossref","unstructured":"Lin Z, Shi Y, Xue Z (2022) IDSGAN: generative adversarial networks for attack generation against intrusion detection. In: Pacific-Asia conference on knowledge discovery and data mining. Springer, pp 79\u201391","DOI":"10.1007\/978-3-031-05981-0_7"},{"key":"2115_CR27","unstructured":"Ma X, Li B, Wang Y, Erfani SM, Wijewickrema S, Schoenebeck G, Song D, Houle ME, Bailey J (2018) Characterizing adversarial subspaces using local intrinsic dimensionality. arXiv preprint arXiv:1801.02613"},{"key":"2115_CR28","unstructured":"Madry A (2017) Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083"},{"key":"2115_CR29","doi-asserted-by":"publisher","first-page":"35403","DOI":"10.1109\/ACCESS.2020.2974752","volume":"8","author":"N Martins","year":"2020","unstructured":"Martins N, Cruz JM, Cruz T, Abreu PH (2020) Adversarial machine learning applied to intrusion and malware scenarios: a systematic review. IEEE Access 8:35403\u201335419","journal-title":"IEEE Access"},{"key":"2115_CR30","unstructured":"Metzen JH, Genewein T, Fischer V, Bischoff B (2017) On detecting adversarial perturbations. arXiv preprint arXiv:1702.04267"},{"issue":"2","key":"2115_CR31","doi-asserted-by":"publisher","first-page":"131","DOI":"10.1007\/s13748-021-00269-9","volume":"11","author":"A Michel","year":"2022","unstructured":"Michel A, Jha SK, Ewetz R (2022) A survey on the vulnerability of deep neural networks against adversarial attacks. Prog Artif Intell 11(2):131\u2013141","journal-title":"Prog Artif Intell"},{"key":"2115_CR32","doi-asserted-by":"publisher","DOI":"10.1016\/j.asoc.2023.110173","volume":"137","author":"H Mohammadian","year":"2023","unstructured":"Mohammadian H, Ghorbani AA, Lashkari AH (2023) A gradient-based approach for adversarial attack on deep learning-based network intrusion detection systems. Appl Soft Comput 137:110173","journal-title":"Appl Soft Comput"},{"key":"2115_CR33","doi-asserted-by":"crossref","unstructured":"Nesmachnow S, Toutouh J (2025) Adversarial attacks to image classification systems using evolutionary algorithms. In: Proceedings of the genetic and evolutionary computation conference, pp 434\u2013442","DOI":"10.1145\/3712256.3726429"},{"key":"2115_CR34","doi-asserted-by":"publisher","first-page":"611","DOI":"10.1214\/16-STS587","volume":"31","author":"YS Niu","year":"2016","unstructured":"Niu YS, Hao N, Zhang H (2016) Multiple change-point detection: a selective overview. Stat Sci 31:611\u2013623","journal-title":"Stat Sci"},{"issue":"3","key":"2115_CR35","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s10207-025-01016-0","volume":"24","author":"S Okada","year":"2025","unstructured":"Okada S, Jmila H, Akashi K, Mitsunaga T, Sekiya Y, Takase H, Blanc G, Nakamura H (2025) XAI-driven black-box adversarial attacks on network intrusion detectors. Int J Inf Secur 24(3):1\u201315","journal-title":"Int J Inf Secur"},{"key":"2115_CR36","doi-asserted-by":"publisher","first-page":"157727","DOI":"10.1109\/ACCESS.2021.3129336","volume":"9","author":"M Ozkan-Okay","year":"2021","unstructured":"Ozkan-Okay M, Samet R, Aslan \u00d6, Gupta D (2021) A comprehensive systematic literature review on intrusion detection systems. IEEE Access 9:157727\u2013157760","journal-title":"IEEE Access"},{"key":"2115_CR37","unstructured":"Pang T, Xu K, Du C, Chen N, Zhu J (2019) Improving adversarial robustness via promoting ensemble diversity. In: International conference on machine learning. PMLR, pp 4970\u20134979"},{"key":"2115_CR38","doi-asserted-by":"crossref","unstructured":"Papernot N, McDaniel P, Jha S, Fredrikson M, Celik ZB, Swami A (2016) The limitations of deep learning in adversarial settings. In: 2016 IEEE European symposium on security and privacy (EuroS &P). IEEE, pp 372\u2013387","DOI":"10.1109\/EuroSP.2016.36"},{"key":"2115_CR39","doi-asserted-by":"publisher","first-page":"148","DOI":"10.1016\/j.future.2020.04.013","volume":"110","author":"M Pawlicki","year":"2020","unstructured":"Pawlicki M, Chora\u015b M, Kozik R (2020) Defending network intrusion detection systems against adversarial evasion attacks. Futur Gener Comput Syst 110:148\u2013154","journal-title":"Futur Gener Comput Syst"},{"key":"2115_CR40","doi-asserted-by":"crossref","unstructured":"Peng X, Huang W, Shi Z (2019) Adversarial attack against dos intrusion detection: an improved boundary-based method. In: 2019 IEEE 31st international conference on tools with artificial intelligence (ICTAI). IEEE, pp 1288\u20131295","DOI":"10.1109\/ICTAI.2019.00179"},{"key":"2115_CR41","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2025.113604","volume":"319","author":"J Pi","year":"2025","unstructured":"Pi J, Wen F, Xia F, Jiang N, Wu H, Liu Q (2025) Efficient black-box adversarial attacks via alternate query and boundary augmentation. Knowl-Based Syst 319:113604","journal-title":"Knowl-Based Syst"},{"issue":"6","key":"2115_CR42","doi-asserted-by":"publisher","first-page":"4863","DOI":"10.1007\/s40747-022-00739-0","volume":"8","author":"C Pimsarn","year":"2022","unstructured":"Pimsarn C, Boongoen T, Iam-On N, Naik N, Yang L (2022) Strengthening intrusion detection system for adversarial attacks: improved handling of imbalance classification problem. Complex Intell Syst 8(6):4863\u20134880","journal-title":"Complex Intell Syst"},{"issue":"5","key":"2115_CR43","doi-asserted-by":"publisher","first-page":"2415","DOI":"10.3390\/s23052415","volume":"23","author":"A Pinto","year":"2023","unstructured":"Pinto A, Herrera LC, Donoso Y, Gutierrez JA (2023) Survey on intrusion detection systems based on machine learning techniques for the protection of critical infrastructure. Sensors 23(5):2415","journal-title":"Sensors"},{"key":"2115_CR44","doi-asserted-by":"crossref","unstructured":"Rigaki M, Garcia S (2018) Bringing a GAN to a knife-fight: adapting malware communication to avoid detection. In: 2018 IEEE security and privacy workshops (SPW). IEEE, pp 70\u201375","DOI":"10.1109\/SPW.2018.00019"},{"key":"2115_CR45","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.103853","volume":"141","author":"K Roshan","year":"2024","unstructured":"Roshan K, Zafar A (2024) Black-box adversarial transferability: an empirical study in cybersecurity perspective. Comput Secur 141:103853","journal-title":"Comput Secur"},{"key":"2115_CR46","doi-asserted-by":"publisher","first-page":"97","DOI":"10.1016\/j.comcom.2023.09.030","volume":"218","author":"K Roshan","year":"2024","unstructured":"Roshan K, Zafar A, Haque SBU (2024) Untargeted white-box adversarial attack with heuristic defence methods in real-time deep learning based network intrusion detection system. Comput Commun 218:97\u2013113","journal-title":"Comput Commun"},{"key":"2115_CR47","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2024.123567","volume":"249","author":"MK Roshan","year":"2024","unstructured":"Roshan MK, Zafar A (2024) Boosting robustness of network intrusion detection systems: a novel two phase defense strategy against untargeted white-box optimization adversarial attack. Expert Syst Appl 249:123567","journal-title":"Expert Syst Appl"},{"issue":"7","key":"2115_CR48","doi-asserted-by":"publisher","first-page":"487","DOI":"10.1038\/s43017-023-00431-y","volume":"4","author":"J Runge","year":"2023","unstructured":"Runge J, Gerhardus A, Varando G, Eyring V, Camps-Valls G (2023) Causal inference for time series. Nat Rev Earth Environ 4(7):487\u2013505","journal-title":"Nat Rev Earth Environ"},{"issue":"24","key":"2115_CR49","doi-asserted-by":"publisher","first-page":"5030","DOI":"10.3390\/electronics13245030","volume":"13","author":"S Sharma","year":"2024","unstructured":"Sharma S, Chen Z (2024) A systematic study of adversarial attacks against network intrusion detection systems. Electronics 13(24):5030","journal-title":"Electronics"},{"key":"2115_CR50","doi-asserted-by":"publisher","first-page":"3225","DOI":"10.1109\/TIFS.2022.3201377","volume":"17","author":"Y Sharon","year":"2022","unstructured":"Sharon Y, Berend D, Liu Y, Shabtai A, Elovici Y (2022) Tantra: timing-based adversarial network traffic reshaping attack. IEEE Trans Inf Forensics Secur 17:3225\u20133237","journal-title":"IEEE Trans Inf Forensics Secur"},{"issue":"5","key":"2115_CR51","doi-asserted-by":"publisher","first-page":"727","DOI":"10.3233\/JCS-210094","volume":"30","author":"R Sheatsley","year":"2022","unstructured":"Sheatsley R, Papernot N, Weisman MJ, Verma G, McDaniel P (2022) Adversarial examples for network intrusion detection systems. J Comput Secur 30(5):727\u2013752","journal-title":"J Comput Secur"},{"key":"2115_CR52","doi-asserted-by":"crossref","unstructured":"Shu D, Leslie NO, Kamhoua CA, Tucker CS (2020) Generative adversarial attacks against intrusion detection systems using active learning. In: Proceedings of the 2nd ACM workshop on wireless security and machine learning, pp 1\u20136","DOI":"10.1145\/3395352.3402618"},{"key":"2115_CR53","doi-asserted-by":"crossref","unstructured":"Tavallaee M, Bagheri E, Lu W, Ghorbani AA (2009) A detailed analysis of the KDD cup 99 data set. In: 2009 IEEE symposium on computational intelligence for security and defense applications. IEEE, pp 1\u20136","DOI":"10.1109\/CISDA.2009.5356528"},{"key":"2115_CR54","doi-asserted-by":"crossref","unstructured":"Thockchom N, Singh MM, Nandi U (2023) A novel ensemble learning-based model for network intrusion detection. Complex Intell Syst 9(5):5693\u20135714","DOI":"10.1007\/s40747-023-01013-7"},{"issue":"2","key":"2115_CR55","doi-asserted-by":"publisher","first-page":"81","DOI":"10.1080\/01973533.2016.1277529","volume":"39","author":"CG Thompson","year":"2017","unstructured":"Thompson CG, Kim RS, Aloe AM, Becker BJ (2017) Extracting the variance inflation factor and other multicollinearity diagnostics from typical regression results. Basic Appl Soc Psychol 39(2):81\u201390","journal-title":"Basic Appl Soc Psychol"},{"issue":"4","key":"2115_CR56","doi-asserted-by":"publisher","first-page":"108","DOI":"10.3390\/fi14040108","volume":"14","author":"J Vitorino","year":"2022","unstructured":"Vitorino J, Oliveira N, Pra\u00e7a I (2022) Adaptative perturbation patterns: realistic adversarial learning for robust intrusion detection. Future Internet 14(4):108","journal-title":"Future Internet"},{"key":"2115_CR57","doi-asserted-by":"crossref","unstructured":"Wang, F., Zuo, X., Huang, H., Chen, G.: ADBA: approximation decision boundary approach for black-box adversarial attacks. In: Proceedings of the AAAI conference on artificial intelligence, vol\u00a039, pp 7628\u20137636 (2025)","DOI":"10.1609\/aaai.v39i7.32821"},{"key":"2115_CR58","doi-asserted-by":"crossref","unstructured":"Wang Z, Yang H, Feng Y, Sun P, Guo H, Zhang Z, Ren K (2023) Towards transferable targeted adversarial examples. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition, pp 20534\u201320543","DOI":"10.1109\/CVPR52729.2023.01967"},{"key":"2115_CR59","doi-asserted-by":"crossref","unstructured":"Wu D, Fang B, Wang J, Liu Q, Cui X (2019) Evading machine learning botnet detection models via deep reinforcement learning. In: ICC 2019-2019 IEEE international conference on communications (ICC). IEEE, pp 1\u20136","DOI":"10.1109\/ICC.2019.8761337"},{"key":"2115_CR60","doi-asserted-by":"publisher","DOI":"10.1016\/j.cviu.2023.103647","volume":"229","author":"W Xiang","year":"2023","unstructured":"Xiang W, Su H, Liu C, Guo Y, Zheng S (2023) Improving the robustness of adversarial attacks using an affine-invariant gradient estimator. Comput Vis Image Underst 229:103647","journal-title":"Comput Vis Image Underst"},{"issue":"12","key":"2115_CR61","doi-asserted-by":"publisher","first-page":"12591","DOI":"10.1109\/TKDE.2023.3270293","volume":"35","author":"H Xu","year":"2023","unstructured":"Xu H, Pang G, Wang Y, Wang Y (2023) Deep isolation forest for anomaly detection. IEEE Trans Knowl Data Eng 35(12):12591\u201312604","journal-title":"IEEE Trans Knowl Data Eng"},{"key":"2115_CR62","doi-asserted-by":"crossref","unstructured":"Zdaniuk B (2024) Ordinary least-squares (OLS) model. In: Encyclopedia of quality of life and well-being research. Springer, pp 4867\u20134869","DOI":"10.1007\/978-3-031-17299-1_2008"},{"issue":"3","key":"2115_CR63","doi-asserted-by":"publisher","first-page":"1294","DOI":"10.1109\/TNET.2021.3137084","volume":"30","author":"C Zhang","year":"2022","unstructured":"Zhang C, Costa-Perez X, Patras P (2022) Adversarial attacks against deep learning-based network intrusion detection systems and defense mechanisms. IEEE\/ACM Trans Netw 30(3):1294\u20131311","journal-title":"IEEE\/ACM Trans Netw"},{"key":"2115_CR64","doi-asserted-by":"publisher","first-page":"5090","DOI":"10.1109\/TDSC.2025.3560486","volume":"22","author":"H Zhang","year":"2025","unstructured":"Zhang H, Han D, Zhuang S, Wang Z, Sun J, Liu Y, Liu J, Dong J (2025) Explainable and transferable adversarial attack for ML-based network intrusion detectors. IEEE Trans Depend Secure Comput 22:5090\u20135107","journal-title":"IEEE Trans Depend Secure Comput"},{"issue":"7","key":"2115_CR65","first-page":"2578","volume":"31","author":"J Zhang","year":"2019","unstructured":"Zhang J, Li C (2019) Adversarial examples: opportunities and challenges. IEEE Trans Neural Netw Learn Syst 31(7):2578\u20132593","journal-title":"IEEE Trans Neural Netw Learn Syst"},{"key":"2115_CR66","doi-asserted-by":"publisher","first-page":"13863","DOI":"10.1109\/TII.2024.3435532","volume":"20","author":"Y Zhang","year":"2024","unstructured":"Zhang Y, Wu Y, Huang X (2024) Toward transferable adversarial attacks against autoencoder-based network intrusion detectors. IEEE Trans Ind Inform 20:13863\u201313872","journal-title":"IEEE Trans Ind Inform"},{"key":"2115_CR67","doi-asserted-by":"publisher","first-page":"7867","DOI":"10.1109\/TPAMI.2025.3574432","volume":"47","author":"M Zheng","year":"2025","unstructured":"Zheng M, Yan X, Zhu Z, Chen H, Wu B (2025) BlackboxBench: a comprehensive benchmark of black-box adversarial attacks. IEEE Trans Pattern Anal Mach Intell 47:7867\u20137885","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"2115_CR68","unstructured":"Zolbayar BE, Sheatsley R, McDaniel P, Weisman MJ, Zhu S, Zhu S, Krishnamurthy S (2022) Generating practical adversarial network traffic flows using NIDSGAN. arXiv preprint arXiv:2203.06694"}],"container-title":["Complex &amp; Intelligent Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s40747-025-02115-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s40747-025-02115-0","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s40747-025-02115-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,30]],"date-time":"2026-01-30T11:49:00Z","timestamp":1769773740000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s40747-025-02115-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,25]]},"references-count":68,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2026,1]]}},"alternative-id":["2115"],"URL":"https:\/\/doi.org\/10.1007\/s40747-025-02115-0","relation":{},"ISSN":["2199-4536","2198-6053"],"issn-type":[{"value":"2199-4536","type":"print"},{"value":"2198-6053","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,11,25]]},"assertion":[{"value":"11 July 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"13 September 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"25 November 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no Conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"Not applicable.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval"}},{"value":"Not applicable.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent to participate"}},{"value":"Not applicable.","order":5,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent for publication"}}],"article-number":"18"}}