{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,28]],"date-time":"2026-05-28T20:05:22Z","timestamp":1779998722639,"version":"3.53.1"},"reference-count":60,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/100007911","name":"University of California San Diego","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100007911","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Computer Networks"],"published-print":{"date-parts":[[2026,7]]},"DOI":"10.1016\/j.comnet.2026.112398","type":"journal-article","created":{"date-parts":[[2026,5,22]],"date-time":"2026-05-22T23:38:48Z","timestamp":1779493128000},"page":"112398","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["CITADEL: Continual Anomaly Detection for Enhanced Learning in intrusion detection systems"],"prefix":"10.1016","volume":"285","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-0274-7666","authenticated-orcid":false,"given":"Elvin","family":"Li","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Onat","family":"Gungor","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhengli","family":"Shang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jing","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tajana","family":"Rosing","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"issue":"16","key":"10.1016\/j.comnet.2026.112398_b1","doi-asserted-by":"crossref","first-page":"7194","DOI":"10.3390\/s23167194","article-title":"Unleashing the power of IoT: A comprehensive review of IoT applications and future prospects in healthcare, agriculture, smart homes, smart cities, and industry 4.0","volume":"23","author":"Chataut","year":"2023","journal-title":"Sensors"},{"key":"10.1016\/j.comnet.2026.112398_b2","article-title":"A survey on intelligent internet of things: Applications, security, privacy, and future directions","author":"Aouedi","year":"2024","journal-title":"IEEE Commun. Surv. & Tutorials"},{"key":"10.1016\/j.comnet.2026.112398_b3","series-title":"2024 Design, Automation & Test in Europe Conference & Exhibition","first-page":"1","article-title":"ROLDEF: Robust layered defense for intrusion detection against adversarial attacks","author":"Gungor","year":"2024"},{"key":"10.1016\/j.comnet.2026.112398_b4","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2022.109032","article-title":"A survey on deep learning for cybersecurity: Progress, challenges, and opportunities","volume":"212","author":"Macas","year":"2022","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112398_b5","doi-asserted-by":"crossref","DOI":"10.1109\/TIFS.2024.3402148","article-title":"Online self-supervised deep learning for intrusion detection systems","author":"Nak\u0131p","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112398_b6","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2022.110030","article-title":"Anomal-E: A self-supervised network intrusion detection system based on graph neural networks","volume":"258","author":"Caville","year":"2022","journal-title":"Knowl.-Based Syst."},{"issue":"4","key":"10.1016\/j.comnet.2026.112398_b7","doi-asserted-by":"crossref","first-page":"4232","DOI":"10.1109\/TNSM.2022.3218843","article-title":"Contrastive learning enhanced intrusion detection","volume":"19","author":"Yue","year":"2022","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"10.1016\/j.comnet.2026.112398_b8","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2023.110966","article-title":"TS-IDS: Traffic-aware self-supervised learning for IoT network intrusion detection","volume":"279","author":"Nguyen","year":"2023","journal-title":"Knowl.-Based Syst."},{"issue":"20","key":"10.1016\/j.comnet.2026.112398_b9","doi-asserted-by":"crossref","first-page":"19706","DOI":"10.1109\/JIOT.2022.3167005","article-title":"Intrusion detection in the iot under data and concept drifts: Online deep learning approach","volume":"9","author":"Wahab","year":"2022","journal-title":"IEEE Internet Things J."},{"key":"10.1016\/j.comnet.2026.112398_b10","series-title":"Continual learning: Applications and the road forward","author":"Verwimp","year":"2023"},{"issue":"7","key":"10.1016\/j.comnet.2026.112398_b11","first-page":"3366","article-title":"A continual learning survey: Defying forgetting in classification tasks","volume":"44","author":"De Lange","year":"2021","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"10.1016\/j.comnet.2026.112398_b12","article-title":"A comprehensive survey of continual learning: theory, method and application","author":"Wang","year":"2024","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"10.1016\/j.comnet.2026.112398_b13","doi-asserted-by":"crossref","unstructured":"S.K. Amalapuram, T.T. Reddy, S.S. Channappayya, B.R. Tamma, On handling class imbalance in continual learning based network intrusion detection systems, in: Proceedings of the First International Conference on AI-ML Systems, 2021, pp. 1\u20137.","DOI":"10.1145\/3486001.3486231"},{"key":"10.1016\/j.comnet.2026.112398_b14","doi-asserted-by":"crossref","first-page":"41364","DOI":"10.1109\/ACCESS.2024.3377690","article-title":"Lifelong continual learning for anomaly detection: New challenges, perspectives, and insights","volume":"12","author":"Faber","year":"2024","journal-title":"IEEE Access"},{"key":"10.1016\/j.comnet.2026.112398_b15","doi-asserted-by":"crossref","first-page":"137042","DOI":"10.1109\/ACCESS.2021.3115946","article-title":"Learning without forgetting: A new framework for network cyber security threat detection","volume":"9","author":"Karn","year":"2021","journal-title":"IEEE Access"},{"key":"10.1016\/j.comnet.2026.112398_b16","series-title":"Continual learning with strategic selection and forgetting for network intrusion detection","author":"Zhang","year":"2024"},{"key":"10.1016\/j.comnet.2026.112398_b17","doi-asserted-by":"crossref","first-page":"121444","DOI":"10.1109\/ACCESS.2022.3222715","article-title":"Analysis of continual learning models for intrusion detection system","volume":"10","author":"Prasath","year":"2022","journal-title":"IEEE Access"},{"key":"10.1016\/j.comnet.2026.112398_b18","first-page":"17156","article-title":"Augmented memory replay-based continual learning approaches for network intrusion detection","volume":"36","author":"Channappayya","year":"2023","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.comnet.2026.112398_b19","series-title":"2025 62nd ACM\/IEEE Design Automation Conference","first-page":"1","article-title":"CND-IDS: Continual novelty detection for intrusion detection systems","author":"Fuhrman","year":"2025"},{"key":"10.1016\/j.comnet.2026.112398_b20","doi-asserted-by":"crossref","first-page":"248","DOI":"10.1016\/j.neunet.2023.05.032","article-title":"Vlad: Task-agnostic vae-based lifelong anomaly detection","volume":"165","author":"Faber","year":"2023","journal-title":"Neural Netw."},{"issue":"17","key":"10.1016\/j.comnet.2026.112398_b21","doi-asserted-by":"crossref","DOI":"10.3390\/s23177391","article-title":"A holistic review of cyber\u2013physical\u2013social systems: New directions and opportunities","volume":"23","author":"Sobb","year":"2023","journal-title":"Sensors"},{"key":"10.1016\/j.comnet.2026.112398_b22","doi-asserted-by":"crossref","DOI":"10.1016\/j.iot.2024.101398","article-title":"Securing constrained IoT systems: A lightweight machine learning approach for anomaly detection and prevention","volume":"28","author":"Alwaisi","year":"2024","journal-title":"Internet Things"},{"issue":"4","key":"10.1016\/j.comnet.2026.112398_b23","doi-asserted-by":"crossref","first-page":"2753","DOI":"10.1007\/s11277-022-10069-6","article-title":"Intrusion detection systems for the internet of thing: a survey study","volume":"128","author":"Hassan","year":"2023","journal-title":"Wirel. Pers. Commun."},{"issue":"1","key":"10.1016\/j.comnet.2026.112398_b24","article-title":"Deep learning for intrusion detection and security of internet of things (IoT): current analysis, challenges, and possible solutions","volume":"2022","author":"Khan","year":"2022","journal-title":"Secur. Commun. Networks"},{"issue":"1","key":"10.1016\/j.comnet.2026.112398_b25","doi-asserted-by":"crossref","DOI":"10.1155\/2023\/8981988","article-title":"A comprehensive survey on machine learning-based intrusion detection systems for secure communication in internet of things","volume":"2023","author":"Santhosh Kumar","year":"2023","journal-title":"Comput. Intell. Neurosci."},{"key":"10.1016\/j.comnet.2026.112398_b26","series-title":"Testing the performance of multi-class IDS public dataset using supervised machine learning algorithms","author":"Malele","year":"2023"},{"key":"10.1016\/j.comnet.2026.112398_b27","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s10922-021-09615-7","article-title":"Towards model generalization for intrusion detection: Unsupervised machine learning techniques","volume":"30","author":"Verkerken","year":"2022","journal-title":"J. Netw. Syst. Manage."},{"issue":"21","key":"10.1016\/j.comnet.2026.112398_b28","doi-asserted-by":"crossref","first-page":"8701","DOI":"10.3390\/s23218701","article-title":"Enhancing IoT network security: Unveiling the power of self-supervised learning against DDoS attacks","volume":"23","author":"Almaraz-Rivera","year":"2023","journal-title":"Sensors"},{"key":"10.1016\/j.comnet.2026.112398_b29","series-title":"SAFE: Self-supervised anomaly detection framework for intrusion detection","author":"Li","year":"2025"},{"key":"10.1016\/j.comnet.2026.112398_b30","series-title":"A cookbook of self-supervised learning","author":"Balestriero","year":"2023"},{"key":"10.1016\/j.comnet.2026.112398_b31","series-title":"2025 3rd International Conference on Advancement in Computation & Computer Technologies","first-page":"644","article-title":"Self-supervised learning for anomaly detection in IoT networks","author":"Kour","year":"2025"},{"issue":"16","key":"10.1016\/j.comnet.2026.112398_b32","doi-asserted-by":"crossref","first-page":"7215","DOI":"10.3390\/s23167215","article-title":"Malicious traffic identification with self-supervised contrastive learning","volume":"23","author":"Yang","year":"2023","journal-title":"Sensors"},{"key":"10.1016\/j.comnet.2026.112398_b33","series-title":"2025 IEEE International Conference on Cyber Security and Resilience","first-page":"206","article-title":"Contrastive self-supervised network intrusion detection using augmented negative pairs","author":"Wilkie","year":"2025"},{"key":"10.1016\/j.comnet.2026.112398_b34","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103131","article-title":"Robust unsupervised network intrusion detection with self-supervised masked context reconstruction","volume":"128","author":"Wang","year":"2023","journal-title":"Comput. Secur."},{"issue":"1","key":"10.1016\/j.comnet.2026.112398_b35","doi-asserted-by":"crossref","first-page":"1","DOI":"10.3390\/bdcc5010001","article-title":"A review of local outlier factor algorithms for outlier detection in big data streams","volume":"5","author":"Alghushairy","year":"2020","journal-title":"Big Data Cogn. Comput."},{"key":"10.1016\/j.comnet.2026.112398_b36","series-title":"2021 8th International Conference on Information Technology, Computer and Electrical Engineering","first-page":"118","article-title":"Isolation forest based anomaly detection: A systematic literature review","author":"Al Farizi","year":"2021"},{"issue":"12","key":"10.1016\/j.comnet.2026.112398_b37","doi-asserted-by":"crossref","first-page":"12591","DOI":"10.1109\/TKDE.2023.3270293","article-title":"Deep isolation forest for anomaly detection","volume":"35","author":"Xu","year":"2023","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"10.1016\/j.comnet.2026.112398_b38","unstructured":"Y. Wu, H. Wang, P. Zhao, Y. Zheng, Y. Wei, L.-K. Huang, Mitigating catastrophic forgetting in online continual learning by modeling previous task interrelations via pareto optimization, in: Forty-First International Conference on Machine Learning, 2024."},{"key":"10.1016\/j.comnet.2026.112398_b39","series-title":"2023 IEEE International Conference on Cyber Security and Resilience","first-page":"86","article-title":"A multi-class intrusion detection system based on continual learning","author":"Oikonomou","year":"2023"},{"key":"10.1016\/j.comnet.2026.112398_b40","doi-asserted-by":"crossref","unstructured":"S. kumar Amalapuram, S.S. Channappayya, B. Tamma, Augmented Memory Replay-based Continual Learning Approaches for Network Intrusion Detection, in: Thirty-Seventh Conference on Neural Information Processing Systems, 2023.","DOI":"10.52202\/075280-0750"},{"issue":"12","key":"10.1016\/j.comnet.2026.112398_b41","doi-asserted-by":"crossref","first-page":"9992","DOI":"10.1109\/TNNLS.2022.3163362","article-title":"Unsupervised continual learning in streaming environments","volume":"34","author":"Ashfahani","year":"2022","journal-title":"IEEE Trans. Neural Networks Learn. Syst."},{"key":"10.1016\/j.comnet.2026.112398_b42","doi-asserted-by":"crossref","unstructured":"Q. Han, G. Zhang, J. Huang, P. Gao, Z. Wei, S. Lu, Efficient MAE towards Large-Scale Vision Transformers, in: Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision, 2024, pp. 606\u2013615.","DOI":"10.1109\/WACV57701.2024.00066"},{"key":"10.1016\/j.comnet.2026.112398_b43","first-page":"27","article-title":"Feature selection using principal component analysis","volume":"vol. 1","author":"Song","year":"2010"},{"key":"10.1016\/j.comnet.2026.112398_b44","series-title":"2021 8th NAFOSTED Conference on Information and Computer Science","first-page":"120","article-title":"DeepInsight-convolutional neural network for intrusion detection systems","author":"Tran","year":"2021"},{"issue":"11","key":"10.1016\/j.comnet.2026.112398_b45","article-title":"Visualizing data using t-SNE","volume":"9","author":"Van der Maaten","year":"2008","journal-title":"J. Mach. Learn. Res."},{"key":"10.1016\/j.comnet.2026.112398_b46","doi-asserted-by":"crossref","unstructured":"Z. Cheng, C. Zou, J. Dong, Outlier detection using isolation forest and local outlier factor, in: Proceedings of the Conference on Research in Adaptive and Convergent Systems, 2019, pp. 161\u2013168.","DOI":"10.1145\/3338840.3355641"},{"key":"10.1016\/j.comnet.2026.112398_b47","doi-asserted-by":"crossref","first-page":"41364","DOI":"10.1109\/ACCESS.2024.3377690","article-title":"Lifelong continual learning for anomaly detection: New challenges, perspectives, and insights","volume":"12","author":"Faber","year":"2024","journal-title":"IEEE Access"},{"key":"10.1016\/j.comnet.2026.112398_b48","doi-asserted-by":"crossref","DOI":"10.1002\/9781118445112.stat06558","article-title":"Kolmogorov\u2013smirnov test: Overview","author":"Berger","year":"2014","journal-title":"Wiley Statsref: Stat. Ref. Online"},{"issue":"22","key":"10.1016\/j.comnet.2026.112398_b49","doi-asserted-by":"crossref","first-page":"6578","DOI":"10.3390\/s20226578","article-title":"MQTTset, a new dataset for machine learning techniques on MQTT","volume":"20","author":"Vaccari","year":"2020","journal-title":"Sensors"},{"key":"10.1016\/j.comnet.2026.112398_b50","series-title":"WUSTL-IIOT-2021 dataset for iIoT cybersecurity research","author":"Zolanvari","year":"2021"},{"issue":"5","key":"10.1016\/j.comnet.2026.112398_b51","doi-asserted-by":"crossref","first-page":"3962","DOI":"10.1109\/JIOT.2021.3102056","article-title":"X-IIoTID: A connectivity-agnostic and device-agnostic intrusion data set for industrial internet of things","volume":"9","author":"Al-Hawawreh","year":"2021","journal-title":"IEEE Internet Things J."},{"key":"10.1016\/j.comnet.2026.112398_b52","series-title":"2015 Military Communications and Information Systems Conference","first-page":"1","article-title":"UNSW-NB15: a comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set)","author":"Moustafa","year":"2015"},{"key":"10.1016\/j.comnet.2026.112398_b53","series-title":"CICIDS2017","author":"Panigrahi","year":"2025"},{"key":"10.1016\/j.comnet.2026.112398_b54","series-title":"Toward generating a new intrusion detection dataset and intrusion traffic characterization: The CSE-CIC-IDS2018 dataset","author":"Sharafaldin","year":"2018"},{"key":"10.1016\/j.comnet.2026.112398_b55","series-title":"2008 Eighth Ieee International Conference on Data Mining","first-page":"413","article-title":"Isolation forest","author":"Liu","year":"2008"},{"key":"10.1016\/j.comnet.2026.112398_b56","series-title":"Machine Learning and Knowledge Discovery in Databases: European Conference, ECML PKDD 2018, Dublin, Ireland, September 10\u201314, 2018, Proceedings, Part I 18","first-page":"157","article-title":"Scalable and interpretable one-class svms with deep learning and random fourier features","author":"Nguyen","year":"2019"},{"key":"10.1016\/j.comnet.2026.112398_b57","series-title":"International Conference on Machine Learning","first-page":"38655","article-title":"Fascinating supervisory signals and where to find them: Deep anomaly detection with scale learning","author":"Xu","year":"2023"},{"key":"10.1016\/j.comnet.2026.112398_b58","unstructured":"T. Shenkar, L. Wolf, Anomaly Detection for Tabular Data with Internal Contrastive Learning, in: International Conference on Learning Representations, 2022."},{"key":"10.1016\/j.comnet.2026.112398_b59","first-page":"1505","article-title":"Rca: A deep collaborative autoencoder approach for anomaly detection","volume":"vol. 2021","author":"Liu","year":"2021"},{"key":"10.1016\/j.comnet.2026.112398_b60","series-title":"Unsupervised representation learning by predicting random distances","author":"Wang","year":"2019"}],"container-title":["Computer Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S138912862600410X?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S138912862600410X?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,5,28]],"date-time":"2026-05-28T19:44:17Z","timestamp":1779997457000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S138912862600410X"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7]]},"references-count":60,"alternative-id":["S138912862600410X"],"URL":"https:\/\/doi.org\/10.1016\/j.comnet.2026.112398","relation":{},"ISSN":["1389-1286"],"issn-type":[{"value":"1389-1286","type":"print"}],"subject":[],"published":{"date-parts":[[2026,7]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"CITADEL: Continual Anomaly Detection for Enhanced Learning in intrusion detection systems","name":"articletitle","label":"Article Title"},{"value":"Computer Networks","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.comnet.2026.112398","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"112398"}}