{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,11]],"date-time":"2026-06-11T16:09:11Z","timestamp":1781194151626,"version":"3.54.1"},"reference-count":33,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100007129","name":"Shandong Province Natural Science Foundation","doi-asserted-by":"publisher","award":["ZR2021QF056"],"award-info":[{"award-number":["ZR2021QF056"]}],"id":[{"id":"10.13039\/501100007129","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100007129","name":"Shandong Province Natural Science Foundation","doi-asserted-by":"publisher","award":["ZR2024MF120"],"award-info":[{"award-number":["ZR2024MF120"]}],"id":[{"id":"10.13039\/501100007129","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62202206"],"award-info":[{"award-number":["62202206"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004543","name":"China Scholarship Council","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100004543","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012154","name":"Graduate Research and Innovation Projects of Jiangsu Province","doi-asserted-by":"publisher","award":["KYCX25_4240"],"award-info":[{"award-number":["KYCX25_4240"]}],"id":[{"id":"10.13039\/501100012154","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004608","name":"Jiangsu Province Natural Science Foundation","doi-asserted-by":"publisher","award":["BK20220515"],"award-info":[{"award-number":["BK20220515"]}],"id":[{"id":"10.13039\/501100004608","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Expert Systems with Applications"],"published-print":{"date-parts":[[2026,7]]},"DOI":"10.1016\/j.eswa.2026.132177","type":"journal-article","created":{"date-parts":[[2026,3,25]],"date-time":"2026-03-25T07:55:51Z","timestamp":1774425351000},"page":"132177","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["MTD-CDA: A novel malicious traffic detection method based on concept drift adaptation"],"prefix":"10.1016","volume":"320","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0743-1156","authenticated-orcid":false,"given":"Saihua","family":"Cai","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-1561-2929","authenticated-orcid":false,"given":"Yige","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-7633-1803","authenticated-orcid":false,"given":"Han","family":"Tang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-1066-4340","authenticated-orcid":false,"given":"Shengran","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-6081-146X","authenticated-orcid":false,"given":"Xiheng","family":"Jia","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2064-3172","authenticated-orcid":false,"given":"Guofeng","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.eswa.2026.132177_bib0001","series-title":"Proceedings of the 14th ACM workshop on artificial intelligence and security","first-page":"111","article-title":"INSOMNIA: Towards concept-drift robustness in network intrusion detection","author":"Andresini","year":"2021"},{"key":"10.1016\/j.eswa.2026.132177_bib0002","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2020.107391","article-title":"Detection of zero-day attacks: An unsupervised port-based approach","volume":"180","author":"Blaise","year":"2020","journal-title":"Computer Networks"},{"key":"10.1016\/j.eswa.2026.132177_bib0003","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2021.102225","article-title":"Network anomaly detection in a controlled environment based on an enhanced PSOGSARFC","volume":"104","author":"Boahen","year":"2021","journal-title":"Computers & Security"},{"key":"10.1016\/j.eswa.2026.132177_bib0004","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.104121","article-title":"CDDA-MD: An efficient malicious traffic detection method based on concept drift detection and adaptation technique","volume":"148","author":"Cai","year":"2025","journal-title":"Computers & Security"},{"issue":"2","key":"10.1016\/j.eswa.2026.132177_bib0005","doi-asserted-by":"crossref","first-page":"2059","DOI":"10.1109\/TNSM.2025.3531885","article-title":"GSA-DT: A malicious traffic detection model based on graph self-attention network and decision tree","volume":"22","author":"Cai","year":"2025","journal-title":"IEEE Transactions on Network and Service Management"},{"key":"10.1016\/j.eswa.2026.132177_bib0006","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103580","article-title":"A malicious network traffic detection model based on bidirectional temporal convolutional network with multi-head self-attention mechanism","volume":"136","author":"Cai","year":"2024","journal-title":"Computers & Security"},{"key":"10.1016\/j.eswa.2026.132177_bib0007","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2024.111681","article-title":"CD-BTMSE: A Concept Drift detection model based on bidirectional temporal convolutional network and multi-stacking ensemble learning","volume":"294","author":"Cai","year":"2024","journal-title":"Knowledge-Based Systems"},{"key":"10.1016\/j.eswa.2026.132177_bib0008","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2022.110030","article-title":"Anomal-E: A self-supervised network intrusion detection system based on graph neural networks","volume":"258","author":"Caville","year":"2022","journal-title":"Knowledge-Based Systems"},{"key":"10.1016\/j.eswa.2026.132177_bib0009","doi-asserted-by":"crossref","DOI":"10.1016\/j.infsof.2023.107166","article-title":"A novel detection model for abnormal network traffic based on bidirectional temporal convolutional network","volume":"157","author":"Chen","year":"2023","journal-title":"Information and Software Technology"},{"key":"10.1016\/j.eswa.2026.132177_bib0010","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.104083","article-title":"GCN-MHSA: A novel malicious traffic detection method based on graph convolutional neural network and multi-head self-attention mechanism","volume":"147","author":"Chen","year":"2024","journal-title":"Computers & Security"},{"key":"10.1016\/j.eswa.2026.132177_bib0011","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2024.110576","article-title":"Machine learning-enabled hybrid intrusion detection system with host data transformation and an advanced two-stage classifier","volume":"250","author":"Chen","year":"2024","journal-title":"Computer Networks"},{"issue":"3","key":"10.1016\/j.eswa.2026.132177_bib0012","doi-asserted-by":"crossref","first-page":"2700","DOI":"10.1109\/TNSM.2023.3342716","article-title":"Cluster and Conquer: Malicious Traffic Classification at the Edge","volume":"21","author":"Diallo","year":"2024","journal-title":"IEEE Transactions on Network and Service Management"},{"key":"10.1016\/j.eswa.2026.132177_bib0013","doi-asserted-by":"crossref","first-page":"2401","DOI":"10.1007\/s10462-022-10232-2","article-title":"Unsupervised concept drift detection for multi-label data streams","volume":"56","author":"Gulcan","year":"2023","journal-title":"Artificial Intelligence Review"},{"key":"10.1016\/j.eswa.2026.132177_bib0014","series-title":"2025 28th international conference on computer supported cooperative work in design (CSCWD)","first-page":"2551","article-title":"DeepBytes: Hierarchical Features Fusion with Deep Byte Feature for Malicious Traffic Detection","author":"Han","year":"2025"},{"issue":"7","key":"10.1016\/j.eswa.2026.132177_bib0015","doi-asserted-by":"crossref","first-page":"7708","DOI":"10.1109\/JIOT.2024.3519633","article-title":"DroneGuard: An explainable and efficient machine learning framework for intrusion detection in drone networks","volume":"12","author":"Ihekoronye","year":"2025","journal-title":"IEEE Internet of Things Journal"},{"key":"10.1016\/j.eswa.2026.132177_bib0016","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2022.116510","article-title":"A K-means clustering and SVM based hybrid concept drift detection technique for network anomaly detection","volume":"193","author":"Jain","year":"2022","journal-title":"Expert Systems with Applications"},{"issue":"6","key":"10.1016\/j.eswa.2026.132177_bib0017","first-page":"5865","article-title":"GATrust: A multi-aspect graph attention network model for trust assessment in OSNs","volume":"35","author":"Jiang","year":"2023","journal-title":"IEEE Transactions on Knowledge and Data Engineering"},{"issue":"2","key":"10.1016\/j.eswa.2026.132177_bib0018","doi-asserted-by":"crossref","first-page":"1929","DOI":"10.1109\/TNSM.2025.3540753","article-title":"Adapting to the evolution: Enhancing intrusion detection through machine learning in the QUIC protocol era","volume":"22","author":"Kadi","year":"2025","journal-title":"IEEE Transactions on Network and Service Management"},{"key":"10.1016\/j.eswa.2026.132177_bib0019","doi-asserted-by":"crossref","DOI":"10.1155\/2022\/5363764","article-title":"E-minBatch GraphSAGE: An industrial internet attack detection Model","volume":"2022","author":"Lan","year":"2022","journal-title":"Security and Communication Networks"},{"issue":"11","key":"10.1016\/j.eswa.2026.132177_bib0020","doi-asserted-by":"crossref","first-page":"6911","DOI":"10.1109\/TSMC.2024.3446635","article-title":"A hypergraph-based machine learning ensemble network intrusion detection system","volume":"54","author":"Lin","year":"2024","journal-title":"EEE Transactions on Systems, Man, and Cybernetics: Systems"},{"key":"10.1016\/j.eswa.2026.132177_bib0021","doi-asserted-by":"crossref","DOI":"10.1007\/s11432-023-4010-4","article-title":"Identifying malicious traffic under concept drift based on intraclass consistency enhanced variational autoencoder","volume":"67","author":"Luo","year":"2024","journal-title":"Science China-Information Sciences"},{"key":"10.1016\/j.eswa.2026.132177_bib0022","article-title":"Class imbalance and concept drift invariant online botnet threat detection framework for heterogeneous IoT edge","volume":"141","author":"Nitish","year":"2024","journal-title":"Computers & Security"},{"issue":"2","key":"10.1016\/j.eswa.2026.132177_bib0023","doi-asserted-by":"crossref","first-page":"1129","DOI":"10.1109\/TNSM.2024.3490181","article-title":"Unsupervised machine learning for cybersecurity anomaly detection in traditional and software-defined networking environments","volume":"22","author":"Rookard","year":"2025","journal-title":"IEEE Transactions on Network and Service Management"},{"issue":"7","key":"10.1016\/j.eswa.2026.132177_bib0024","doi-asserted-by":"crossref","first-page":"2529","DOI":"10.1093\/comjnl\/bxae023","article-title":"Concept drift-based intrusion detection for evolving data stream classification in IDS: Approaches and comparative study","volume":"67","author":"Seth","year":"2024","journal-title":"The Computer Journal"},{"key":"10.1016\/j.eswa.2026.132177_bib0025","series-title":"4th international conference on information systems security and privacy (ICISSP)","first-page":"108","article-title":"Toward generating a new intrusion detection dataset and intrusion traffic characterization","author":"Sharafaldin","year":"2018"},{"key":"10.1016\/j.eswa.2026.132177_bib0026","doi-asserted-by":"crossref","first-page":"2139","DOI":"10.1007\/s10207-024-00833-z","article-title":"MLSTL-WSN: Machine learning-based intrusion detection using SMOTETomek in WSNs","volume":"23","author":"Talukder","year":"2024","journal-title":"International Journal of Information Security"},{"key":"10.1016\/j.eswa.2026.132177_bib0027","doi-asserted-by":"crossref","first-page":"238","DOI":"10.1016\/j.cose.2017.05.009","article-title":"Flow-based intrusion detection: Techniques and challenges","volume":"70","author":"Umer","year":"2017","journal-title":"Computers & Security"},{"key":"10.1016\/j.eswa.2026.132177_bib0028","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2023.122114","article-title":"QuadCDD: A quadruple-based approach for understanding concept drift in data streams","volume":"238","author":"Wang","year":"2024","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.132177_bib0029","series-title":"2017 international conference on information networking (ICOIN)","first-page":"712","article-title":"Malware traffic classification using convolutional neural network for representation learning","author":"Wang","year":"2017"},{"issue":"2","key":"10.1016\/j.eswa.2026.132177_bib0030","doi-asserted-by":"crossref","first-page":"2402","DOI":"10.1109\/TNSM.2023.3334028","article-title":"An autoencoder-based hybrid detection model for intrusion detection with small-sample problem","volume":"21","author":"Wei","year":"2024","journal-title":"IEEE Transactions on Network and Service Management"},{"issue":"6","key":"10.1016\/j.eswa.2026.132177_bib0031","doi-asserted-by":"crossref","first-page":"913","DOI":"10.1109\/TSUSC.2024.3386667","article-title":"Addressing concept drift in IoT anomaly detection: Drift detection, interpretation, and adaptation","volume":"9","author":"Xu","year":"2024","journal-title":"IEEE Transactions on Sustainable Computing"},{"key":"10.1016\/j.eswa.2026.132177_bib0032","series-title":"Proceedings of the 30th ACM SIGKDD conference on knowledge discovery and data mining (KDD 24)","first-page":"3818","article-title":"ReCDA: Concept drift adaptation with representation enhancement for network intrusion detection","author":"Yang","year":"2024"},{"key":"10.1016\/j.eswa.2026.132177_bib0033","doi-asserted-by":"crossref","DOI":"10.1016\/j.inffus.2025.103125","article-title":"METC: A hybrid deep learning framework for cross-network encrypted DNS over HTTPS traffic detection and tunnel identification","volume":"121","author":"Zuo","year":"2025","journal-title":"Information Fusion"}],"container-title":["Expert Systems with Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0957417426010900?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0957417426010900?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,11]],"date-time":"2026-06-11T15:53:54Z","timestamp":1781193234000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0957417426010900"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7]]},"references-count":33,"alternative-id":["S0957417426010900"],"URL":"https:\/\/doi.org\/10.1016\/j.eswa.2026.132177","relation":{},"ISSN":["0957-4174"],"issn-type":[{"value":"0957-4174","type":"print"}],"subject":[],"published":{"date-parts":[[2026,7]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"MTD-CDA: A novel malicious traffic detection method based on concept drift adaptation","name":"articletitle","label":"Article Title"},{"value":"Expert Systems with Applications","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.eswa.2026.132177","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"132177"}}