{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T17:06:29Z","timestamp":1784912789096,"version":"3.55.0"},"reference-count":67,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Computer Networks"],"published-print":{"date-parts":[[2026,10]]},"DOI":"10.1016\/j.comnet.2026.112581","type":"journal-article","created":{"date-parts":[[2026,7,23]],"date-time":"2026-07-23T16:05:22Z","timestamp":1784822722000},"page":"112581","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["SIGMA: An interpretable and efficient clean-label adversarial framework for evaluating the robustness of NIDS"],"prefix":"10.1016","volume":"288","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-2835-8992","authenticated-orcid":false,"given":"Zhonghang","family":"Sui","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2545-4079","authenticated-orcid":false,"given":"Fei","family":"Kang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2797-1355","authenticated-orcid":false,"given":"Hui","family":"Shu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.comnet.2026.112581_b1","series-title":"2017 International Conference on Information Networking","first-page":"712","article-title":"Malware traffic classification using convolutional neural network for representation learning","author":"Wang","year":"2017"},{"issue":"3","key":"10.1016\/j.comnet.2026.112581_b2","doi-asserted-by":"crossref","DOI":"10.3390\/app13031974","article-title":"A comprehensive review of tunnel detection on multilayer protocols: From traditional to machine learning approaches","volume":"13","author":"Sui","year":"2023","journal-title":"Appl. Sci."},{"key":"10.1016\/j.comnet.2026.112581_b3","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2021.108322","article-title":"A comprehensive survey on DNS tunnel detection","volume":"197","author":"Wang","year":"2021","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112581_b4","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103098","article-title":"Darknet traffic classification and adversarial attacks using machine learning","volume":"127","author":"Rust-Nguyen","year":"2023","journal-title":"Comput. Secur."},{"key":"10.1016\/j.comnet.2026.112581_b5","unstructured":"J. Qu, X. Ma, J. Li, X. Luo, L. Xue, J. Zhang, Z. Li, L. Feng, X. Guan, An Input-Agnostic Hierarchical Deep Learning Framework for Traffic Fingerprinting, in: USENIX Security Symposium."},{"key":"10.1016\/j.comnet.2026.112581_b6","doi-asserted-by":"crossref","unstructured":"M. Nasr, A. Bahramali, A. Houmansadr, DeepCorr: Strong Flow Correlation Attacks on Tor Using Deep Learning, in: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, 2018.","DOI":"10.1145\/3243734.3243824"},{"key":"10.1016\/j.comnet.2026.112581_b7","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2024.110598","article-title":"Encrypted malicious traffic detection based on natural language processing and deep learning","volume":"250","author":"Zang","year":"2024","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112581_b8","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2023.110120","article-title":"PETNet: Plaintext-aware encrypted traffic detection network for identifying cobalt strike HTTPS traffics","volume":"238","author":"Yang","year":"2024","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112581_b9","doi-asserted-by":"crossref","unstructured":"W. Wang, M. Zhu, J. Wang, X. Zeng, Z. Yang, End-to-end encrypted traffic classification with one-dimensional convolution neural networks, in: 2017 IEEE International Conference on Intelligence and Security Informatics, ISI, 2017, pp. 43\u201348.","DOI":"10.1109\/ISI.2017.8004872"},{"key":"10.1016\/j.comnet.2026.112581_b10","series-title":"When does machine learning FAIL? Generalized transferability for evasion and poisoning attacks","author":"Suciu","year":"2018"},{"key":"10.1016\/j.comnet.2026.112581_b11","doi-asserted-by":"crossref","unstructured":"G. Verma, E.N. Ciftcioglu, R. Sheatsley, K.S. Chan, L.M. Scott, Network Traffic Obfuscation: An Adversarial Machine Learning Approach, in: MILCOM 2018 - 2018 IEEE Military Communications Conference, MILCOM, 2018, pp. 1\u20136.","DOI":"10.1109\/MILCOM.2018.8599680"},{"key":"10.1016\/j.comnet.2026.112581_b12","unstructured":"B. Biggio, B. Nelson, P. Laskov, Poisoning Attacks against Support Vector Machines, in: International Conference on Machine Learning."},{"key":"10.1016\/j.comnet.2026.112581_b13","doi-asserted-by":"crossref","first-page":"155","DOI":"10.3390\/a17040155","article-title":"Impacting robustness in deep learning-based NIDS through poisoning attacks","volume":"17","author":"Alahmed","year":"2024","journal-title":"Algorithms"},{"key":"10.1016\/j.comnet.2026.112581_b14","series-title":"Proceedings of the 20th European Conference on Artificial Intelligence","first-page":"870","article-title":"Adversarial label flips attack on support vector machines","author":"Xiao","year":"2012"},{"issue":"11","key":"10.1016\/j.comnet.2026.112581_b15","first-page":"69","article-title":"Targeted poisoning attacks against multimodal contrastive learning","volume":"23","author":"Liu Gaoyang","year":"2023","journal-title":"Netinfo Secur."},{"key":"10.1016\/j.comnet.2026.112581_b16","article-title":"The robustness of popular multiclass machine learning models against poisoning attacks: Lessons and insights","volume":"18","author":"Maabreh","year":"2022","journal-title":"Int. J. Distrib. Sens. Networks"},{"key":"10.1016\/j.comnet.2026.112581_b17","series-title":"BadNets: Identifying vulnerabilities in the machine learning model supply chain","author":"Gu","year":"2017"},{"key":"10.1016\/j.comnet.2026.112581_b18","doi-asserted-by":"crossref","first-page":"303","DOI":"10.1109\/TIFS.2021.3139777","article-title":"Gradient leakage attack resilient deep learning","volume":"17","author":"Wei","year":"2022","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112581_b19","article-title":"Defending against adversarial machine learning attacks using hierarchical learning: A case study on network traffic attack classification","volume":"72","author":"McCarthy","year":"2023","journal-title":"J. Inf. Secur. Appl."},{"key":"10.1016\/j.comnet.2026.112581_b20","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103433","article-title":"SoK: Realistic adversarial attacks and defenses for intelligent network intrusion detection","volume":"134","author":"Vitorino","year":"2023","journal-title":"Comput. Secur."},{"issue":"5","key":"10.1016\/j.comnet.2026.112581_b21","doi-asserted-by":"crossref","first-page":"4744","DOI":"10.1109\/TNSE.2024.3397719","article-title":"Poison-resilient anomaly detection: Mitigating poisoning attacks in semi-supervised encrypted traffic anomaly detection","volume":"11","author":"Wu","year":"2024","journal-title":"IEEE Trans. Netw. Sci. Eng."},{"key":"10.1016\/j.comnet.2026.112581_b22","series-title":"Diffusion denoising as a certified defense against clean-label poisoning","author":"Hong","year":"2024"},{"key":"10.1016\/j.comnet.2026.112581_b23","series-title":"2021 IEEE European Symposium on Security and Privacy","first-page":"159","article-title":"Bullseye polytope: A scalable clean-label poisoning attack with improved transferability","author":"Aghakhani","year":"2020"},{"key":"10.1016\/j.comnet.2026.112581_b24","doi-asserted-by":"crossref","unstructured":"S. Zhao, X. Ma, X. Zheng, J. Bailey, J. Chen, Y.G. Jiang, Clean-Label Backdoor Attacks on Video Recognition Models, in: 2020 IEEE\/CVF Conference on Computer Vision and Pattern Recognition, CVPR, 2020, pp. 14431\u201314440.","DOI":"10.1109\/CVPR42600.2020.01445"},{"issue":"8","key":"10.1016\/j.comnet.2026.112581_b25","doi-asserted-by":"crossref","DOI":"10.1145\/3551636","article-title":"A comprehensive survey on poisoning attacks and countermeasures in machine learning","volume":"55","author":"Tian","year":"2022","journal-title":"ACM Comput. Surv."},{"key":"10.1016\/j.comnet.2026.112581_b26","unstructured":"C. Zhu, W.R. Huang, A. Shafahi, H. Li, G. Taylor, C. Studer, T. Goldstein, R. Huang, Transferable Clean-Label Poisoning Attacks on Deep Neural Nets, in: International Conference on Machine Learning."},{"key":"10.1016\/j.comnet.2026.112581_b27","series-title":"Neural Information Processing Systems","article-title":"Poison frogs! targeted clean-label poisoning attacks on neural networks","author":"Shafahi","year":"2018"},{"key":"10.1016\/j.comnet.2026.112581_b28","series-title":"Proceedings of the 39th Annual Computer Security Applications Conference","first-page":"337","article-title":"Poisoning network flow classifiers","author":"Severi","year":"2023"},{"key":"10.1016\/j.comnet.2026.112581_b29","series-title":"IEEE INFOCOM 2022 - IEEE Conference on Computer Communications","first-page":"1429","article-title":"TrojanFlow: A neural backdoor attack to deep learning-based network traffic classifiers","author":"Ning","year":"2022"},{"key":"10.1016\/j.comnet.2026.112581_b30","series-title":"MetaPoison: Practical general-purpose clean-label data poisoning","author":"Huang","year":"2020"},{"key":"10.1016\/j.comnet.2026.112581_b31","series-title":"Witches\u2019 brew: Industrial scale data poisoning via gradient matching","author":"Geiping","year":"2020"},{"key":"10.1016\/j.comnet.2026.112581_b32","series-title":"Generating potent poisons and backdoors from scratch with guided diffusion","author":"Souri","year":"2024"},{"key":"10.1016\/j.comnet.2026.112581_b33","series-title":"2022 IEEE International Conference on Data Mining Workshops","first-page":"577","article-title":"Backdoor poisoning of encrypted traffic classifiers","author":"Holodnak","year":"2022"},{"key":"10.1016\/j.comnet.2026.112581_b34","series-title":"2018 IEEE International Conference on Communications","first-page":"1","article-title":"Chronic poisoning against machine learning based IDSs using edge pattern detection","author":"Li","year":"2018"},{"key":"10.1016\/j.comnet.2026.112581_b35","series-title":"Model-agnostic clean-label backdoor mitigation in cybersecurity environments","author":"Severi","year":"2024"},{"issue":"C","key":"10.1016\/j.comnet.2026.112581_b36","doi-asserted-by":"crossref","first-page":"154","DOI":"10.1016\/j.future.2022.04.010","article-title":"SecFedNIDS: Robust defense for poisoning attack against federated learning-based network intrusion detection system","volume":"134","author":"Zhang","year":"2022","journal-title":"Future Gener. Comput. Syst."},{"key":"10.1016\/j.comnet.2026.112581_b37","series-title":"UltraClean: A simple framework to train robust neural networks against backdoor attacks","author":"Zhao","year":"2023"},{"issue":"13","key":"10.1016\/j.comnet.2026.112581_b38","doi-asserted-by":"crossref","first-page":"10327","DOI":"10.1109\/JIOT.2020.3048038","article-title":"Adversarial attacks against network intrusion detection in IoT systems","volume":"8","author":"Qiu","year":"2021","journal-title":"IEEE Internet Things J."},{"key":"10.1016\/j.comnet.2026.112581_b39","first-page":"1","article-title":"Addressing adversarial attacks against security systems based on machine learning","volume":"vol. 900","author":"Apruzzese","year":"2019"},{"key":"10.1016\/j.comnet.2026.112581_b40","doi-asserted-by":"crossref","unstructured":"R. Babaria, S.C. Madanapalli, H. Kumar, V. Sivaraman, FlowFormers: Transformer-based Models for Real-time Network Flow Classification, in: 2021 17th International Conference on Mobility, Sensing and Networking, MSN, pp. 231\u2013238, http:\/\/dx.doi.org\/10.1109\/MSN53354.2021.00046.","DOI":"10.1109\/MSN53354.2021.00046"},{"key":"10.1016\/j.comnet.2026.112581_b41","series-title":"Detecting unknown encrypted malicious traffic in real time via flow interaction graph analysis","author":"Fu","year":"2023"},{"issue":"1","key":"10.1016\/j.comnet.2026.112581_b42","doi-asserted-by":"crossref","first-page":"538","DOI":"10.1109\/COMST.2022.3233793","article-title":"Adversarial machine learning for network intrusion detection systems: A comprehensive survey","volume":"25","author":"He","year":"2023","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"10.1016\/j.comnet.2026.112581_b43","series-title":"Efficient black-box adversarial attacks via Bayesian optimization guided by a function prior","author":"Cheng","year":"2024"},{"key":"10.1016\/j.comnet.2026.112581_b44","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2024.110790","article-title":"Towards universal and transferable adversarial attacks against network traffic classification","volume":"254","author":"Ding","year":"2024","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112581_b45","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103257","article-title":"GPMT: Generating practical malicious traffic based on adversarial attacks with little prior knowledge","volume":"130","author":"Sun","year":"2023","journal-title":"Comput. Secur."},{"key":"10.1016\/j.comnet.2026.112581_b46","doi-asserted-by":"crossref","first-page":"153","DOI":"10.1109\/TDSC.2023.3247585","article-title":"Automatic evasion of machine learning-based network intrusion detection systems","volume":"21","author":"Yan","year":"2024","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"10.1016\/j.comnet.2026.112581_b47","doi-asserted-by":"crossref","unstructured":"M. Ribeiro, K. Grolinger, M.A.M. Capretz, MLaaS: Machine Learning as a Service, in: 2015 IEEE 14th International Conference on Machine Learning and Applications, ICMLA, pp. 896\u2013902, http:\/\/dx.doi.org\/10.1109\/ICMLA.2015.152.","DOI":"10.1109\/ICMLA.2015.152"},{"key":"10.1016\/j.comnet.2026.112581_b48","series-title":"Exploring backdoor poisoning attacks against malware classifiers","author":"Severi","year":"2020"},{"key":"10.1016\/j.comnet.2026.112581_b49","series-title":"Generalizable targeted data poisoning against varying physical objects","author":"Chen","year":"2024"},{"key":"10.1016\/j.comnet.2026.112581_b50","series-title":"International Conference on Information Systems Security and Privacy","article-title":"Characterization of tor traffic using time based features","author":"Lashkari","year":"2017"},{"key":"10.1016\/j.comnet.2026.112581_b51","series-title":"2022 9th International Conference on Internet of Things: Systems, Management and Security","first-page":"1","article-title":"Developing realistic Distributed Denial of Service (DDoS) dataset for machine learning-based intrusion detection system","author":"Hadi","year":"2022"},{"key":"10.1016\/j.comnet.2026.112581_b52","series-title":"Proceedings of the 2020 10th International Conference on Communication and Network Security","article-title":"DIDarknet: A contemporary approach to detect and characterize the darknet traffic using deep image learning","author":"Lashkari","year":"2020"},{"issue":"13","key":"10.1016\/j.comnet.2026.112581_b53","doi-asserted-by":"crossref","DOI":"10.3390\/s23135941","article-title":"CICIoT2023: A real-time dataset and benchmark for large-scale attacks in IoT environment","volume":"23","author":"Neto","year":"2023","journal-title":"Sensors"},{"key":"10.1016\/j.comnet.2026.112581_b54","article-title":"A comprehensive review study of cyber-attacks and cyber security","author":"Abhilash Maroju","year":"2023","journal-title":"Int. J. Recent. Innov. Trends Comput. Commun."},{"key":"10.1016\/j.comnet.2026.112581_b55","series-title":"Var-CNN and DynaFlow: Improved attacks and defenses for website fingerprinting","author":"Bhat","year":"2018"},{"key":"10.1016\/j.comnet.2026.112581_b56","doi-asserted-by":"crossref","unstructured":"P. Wu, H. Guo, LuNet: A Deep Neural Network for Network Intrusion Detection, in: 2019 IEEE Symposium Series on Computational Intelligence, SSCI, pp. 617\u2013624, http:\/\/dx.doi.org\/10.1109\/SSCI44817.2019.9003126.","DOI":"10.1109\/SSCI44817.2019.9003126"},{"key":"10.1016\/j.comnet.2026.112581_b57","series-title":"Proceedings of the 39th Annual Computer Security Applications Conference","first-page":"337","article-title":"Poisoning network flow classifiers","author":"Severi","year":"2023"},{"key":"10.1016\/j.comnet.2026.112581_b58","series-title":"PCAP-backdoor: Backdoor poisoning generator for network traffic in CPS\/IoT environments","author":"Chathoth","year":"2025"},{"issue":"12","key":"10.1016\/j.comnet.2026.112581_b59","doi-asserted-by":"crossref","first-page":"12181","DOI":"10.1109\/TKDE.2022.3159580","article-title":"ECOD: Unsupervised outlier detection using empirical cumulative distribution functions","volume":"35","author":"Li","year":"2023","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"10.1016\/j.comnet.2026.112581_b60","series-title":"2020 IEEE International Conference on Data Mining","first-page":"1118","article-title":"COPOD: Copula-based outlier detection","author":"Li","year":"2020"},{"key":"10.1016\/j.comnet.2026.112581_b61","series-title":"Neural Information Processing Systems","article-title":"Spectral signatures in backdoor attacks","author":"Tran","year":"2018"},{"issue":"4","key":"10.1016\/j.comnet.2026.112581_b62","doi-asserted-by":"crossref","first-page":"2922","DOI":"10.1109\/TNSE.2022.3173591","article-title":"Automatic detection of DGA-enabled malware using SDN and traffic behavioral modeling","volume":"9","author":"Ahmed","year":"2022","journal-title":"IEEE Trans. Netw. Sci. Eng."},{"key":"10.1016\/j.comnet.2026.112581_b63","series-title":"Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security","article-title":"Deep learning with differential privacy","author":"Abadi","year":"2016"},{"key":"10.1016\/j.comnet.2026.112581_b64","series-title":"Noise or signal: The role of image backgrounds in object recognition","author":"Xiao","year":"2020"},{"key":"10.1016\/j.comnet.2026.112581_b65","series-title":"LSCP: Locally selective combination in parallel outlier ensembles","author":"Zhao","year":"2018"},{"key":"10.1016\/j.comnet.2026.112581_b66","series-title":"2014 IEEE International Conference on Data Mining Workshop","first-page":"698","article-title":"Efficient anomaly detection by isolation using nearest neighbour ensemble","author":"Bandaragoda","year":"2014"},{"key":"10.1016\/j.comnet.2026.112581_b67","series-title":"SUOD: Accelerating large-scale unsupervised heterogeneous outlier detection","author":"Zhao","year":"2021"}],"container-title":["Computer Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1389128626005931?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1389128626005931?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T16:30:59Z","timestamp":1784910659000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S1389128626005931"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,10]]},"references-count":67,"alternative-id":["S1389128626005931"],"URL":"https:\/\/doi.org\/10.1016\/j.comnet.2026.112581","relation":{},"ISSN":["1389-1286"],"issn-type":[{"value":"1389-1286","type":"print"}],"subject":[],"published":{"date-parts":[[2026,10]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"SIGMA: An interpretable and efficient clean-label adversarial framework for evaluating the robustness of NIDS","name":"articletitle","label":"Article Title"},{"value":"Computer Networks","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.comnet.2026.112581","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"112581"}}