{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,14]],"date-time":"2026-05-14T18:19:15Z","timestamp":1778782755630,"version":"3.51.4"},"reference-count":41,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100012245","name":"Science and Technology Planning Project of Guangdong Province","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100012245","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100010877","name":"Shenzhen Science and Technology Innovation Committee","doi-asserted-by":"publisher","award":["KJZD20240903103811016"],"award-info":[{"award-number":["KJZD20240903103811016"]}],"id":[{"id":"10.13039\/501100010877","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100017610","name":"Shenzhen Science and Technology Innovation Program","doi-asserted-by":"publisher","award":["PCL2024A05"],"award-info":[{"award-number":["PCL2024A05"]}],"id":[{"id":"10.13039\/501100017610","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Expert Systems with Applications"],"published-print":{"date-parts":[[2026,8]]},"DOI":"10.1016\/j.eswa.2026.132353","type":"journal-article","created":{"date-parts":[[2026,4,6]],"date-time":"2026-04-06T16:50:41Z","timestamp":1775494241000},"page":"132353","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["An interpretable intrusion detection framework based on ensemble neural networks for dynamic network environments"],"prefix":"10.1016","volume":"323","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7125-8584","authenticated-orcid":false,"given":"Zhiqiang","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5702-9897","authenticated-orcid":false,"given":"Haiyan","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-1627-5811","authenticated-orcid":false,"given":"Liyi","family":"Zeng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-9074-3739","authenticated-orcid":false,"given":"Dong","family":"Zhu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0024-0165","authenticated-orcid":false,"given":"Zhaohua","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-3121-9308","authenticated-orcid":false,"given":"Rongxin","family":"Hu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7546-852X","authenticated-orcid":false,"given":"Zhaoquan","family":"Gu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/j.eswa.2026.132353_bib0001","unstructured":"Ahuja, N., Singal, G., & Mukhopadhyay, D. (2020). DDOS attack SDN Dataset. Mendeley Data, V1. 10.17632\/jxpfjc64kr.1."},{"key":"10.1016\/j.eswa.2026.132353_bib0002","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2022.108912","article-title":"Wrapper feature selection method based differential evolution and extreme learning machine for intrusion detection system","volume":"132","author":"Al-Yaseen","year":"2022","journal-title":"Pattern Recognition"},{"key":"10.1016\/j.eswa.2026.132353_bib0003","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2020.113249","article-title":"A feature selection algorithm for intrusion detection system based on pigeon inspired optimizer","volume":"148","author":"Alazzam","year":"2020","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.132353_bib0004","doi-asserted-by":"crossref","first-page":"415","DOI":"10.1016\/j.aej.2023.11.078","article-title":"Golden jackal optimization algorithm with deep learning assisted intrusion detection system for network security","volume":"86","author":"Aljehane","year":"2024","journal-title":"Alexandria Engineering Journal"},{"key":"10.1016\/j.eswa.2026.132353_bib0005","series-title":"Ieee infocom 2024 - ieee conference on computer communications","first-page":"571","article-title":"Spider: A semi-supervised continual learning-based network intrusion detection system","author":"Amalapuram","year":"2024"},{"key":"10.1016\/j.eswa.2026.132353_bib0006","doi-asserted-by":"crossref","first-page":"1156","DOI":"10.1109\/TIFS.2023.3331240","article-title":"Tmg-gan: Generative adversarial networks-based imbalanced learning for network intrusion detection","volume":"19","author":"Ding","year":"2024","journal-title":"IEEE Transactions on Information Forensics and Security"},{"issue":"4","key":"10.1016\/j.eswa.2026.132353_bib0007","doi-asserted-by":"crossref","first-page":"1862","DOI":"10.1109\/TCCN.2022.3186331","article-title":"A flow-based anomaly detection approach with feature selection method against ddos attacks in sdns","volume":"8","author":"El Sayed","year":"2022","journal-title":"IEEE Transactions on Cognitive Communications and Networking"},{"key":"10.1016\/j.eswa.2026.132353_bib0008","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103675","article-title":"A feature selection based on genetic algorithm for intrusion detection of industrial control systems","volume":"139","author":"Fang","year":"2024","journal-title":"Computers & Security"},{"key":"10.1016\/j.eswa.2026.132353_bib0009","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2023.121000","article-title":"Fed-ANIDS: Federated learning for anomaly-based network intrusion detection systems","volume":"234","author":"Idrissi","year":"2023","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.132353_bib0010","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2021.115524","article-title":"A bidirectional LSTM deep learning approach for intrusion detection","volume":"185","author":"Imrana","year":"2021","journal-title":"Expert Systems with Applications"},{"issue":"2","key":"10.1016\/j.eswa.2026.132353_bib0011","doi-asserted-by":"crossref","first-page":"1919","DOI":"10.1007\/s10462-023-10567-4","article-title":"Crayfish optimization algorithm","volume":"56","author":"Jia","year":"2023","journal-title":"Artificial Intelligence Review"},{"key":"10.1016\/j.eswa.2026.132353_bib0012","article-title":"Deep residual convolutional neural network: an efficient technique for intrusion detection system","volume":"238","author":"Kumar","year":"2024","journal-title":"Expert Systems with Applications"},{"issue":"1","key":"10.1016\/j.eswa.2026.132353_bib0013","doi-asserted-by":"crossref","first-page":"65","DOI":"10.1186\/s40537-021-00448-4","article-title":"Intrusion detection systems using long short-term memory (LSTM)","volume":"8","author":"Laghrissi","year":"2021","journal-title":"Journal of Big Data"},{"key":"10.1016\/j.eswa.2026.132353_bib0014","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2023.122198","article-title":"Hda-Ids: A hybrid dos attacks intrusion detection system for iot by using semi-supervised cl-gan","volume":"238","author":"Li","year":"2024","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.132353_bib0015","unstructured":"Liu, Z., Wang, Y., Vaidya, S., Ruehle, F., Halverson, J., Solja\u010di\u0107, M., Hou, T. Y., & Tegmark, M. (2024). Kan: Kolmogorov-Arnold Networks. arxiv preprint arxiv: 2404.19756."},{"key":"10.1016\/j.eswa.2026.132353_bib0016","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2022.119030","article-title":"Dual-IDS: A bagging-based gradient boosting decision tree model for network anomaly intrusion detection system","volume":"213","author":"Louk","year":"2023","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.132353_bib0017","unstructured":"Luo, X., Liu, C., Xiong, G., Yang, C., Gou, G., Ren, Y., & Li, Z. (2025). MalRAG: A retrieval-augmented LLM framework for open-set malicious traffic identification. arXiv preprint arXiv: 2511.14129."},{"key":"10.1016\/j.eswa.2026.132353_bib0018","unstructured":"Meng, X., Lin, C., Wang, Y., & Zhang, Y. (2023). NetGpt: Generative pretrained transformer for network traffic. arXiv preprint arXiv: 2304.09513."},{"key":"10.1016\/j.eswa.2026.132353_bib0019","first-page":"1","article-title":"Unsw-nb15: a comprehensive data set for network intrusion detection systems (unsw-nb15 network data set)","author":"Moustafa","year":"2015","journal-title":"2015 Military Communications and Information Systems Conference (MilCIS)"},{"key":"10.1016\/j.eswa.2026.132353_bib0020","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2024.123808","article-title":"Deep learning enabled intrusion detection system for industrial IOT environment","volume":"249","author":"Nandanwar","year":"2024","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.132353_bib0021","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2020.102164","article-title":"A novel combinatorial optimization based feature selection method for network intrusion detection","volume":"102","author":"Nazir","year":"2021","journal-title":"Computers & Security"},{"key":"10.1016\/j.eswa.2026.132353_bib0022","doi-asserted-by":"crossref","first-page":"418","DOI":"10.1016\/j.future.2020.07.042","article-title":"Genetic convolutional neural network for intrusion detection systems","volume":"113","author":"Nguyen","year":"2020","journal-title":"Future Generation Computer Systems"},{"key":"10.1016\/j.eswa.2026.132353_bib0023","doi-asserted-by":"crossref","first-page":"1794","DOI":"10.1109\/TIFS.2025.3529316","article-title":"Bottom aggregating, top separating: An aggregator and separator network for encrypted traffic understanding","volume":"20","author":"Peng","year":"2025","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"10.1016\/j.eswa.2026.132353_bib0024","doi-asserted-by":"crossref","DOI":"10.1016\/j.asoc.2019.105980","article-title":"An efficient feature selection based bayesian and rough set approach for intrusion detection","volume":"87","author":"Prasad","year":"2020","journal-title":"Applied Soft Computing"},{"key":"10.1016\/j.eswa.2026.132353_bib0025","doi-asserted-by":"crossref","DOI":"10.1016\/j.inffus.2024.102807","article-title":"FedKD-IDS: A robust intrusion detection system using knowledge distillation-based semi-supervised federated learning and anti-poisoning attack mechanism","volume":"117","author":"Quyen","year":"2025","journal-title":"Information Fusion"},{"key":"10.1016\/j.eswa.2026.132353_bib0026","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.103751","article-title":"Archimedes fire hawk optimization enabled feature selection with deep maxout for network intrusion detection","volume":"140","author":"Rani","year":"2024","journal-title":"Computers & Security"},{"key":"10.1016\/j.eswa.2026.132353_bib0027","doi-asserted-by":"crossref","DOI":"10.1016\/j.asoc.2024.111434","article-title":"Modified genetic algorithm and fine-tuned long short-term memory network for intrusion detection in the internet of things networks with edge capabilities","volume":"155","author":"Saheed","year":"2024","journal-title":"Applied Soft Computing"},{"key":"10.1016\/j.eswa.2026.132353_bib0028","doi-asserted-by":"crossref","first-page":"108","DOI":"10.5220\/0006639801080116","article-title":"Toward generating a new intrusion detection dataset and intrusion traffic characterization","volume":"1","author":"Sharafaldin","year":"2018","journal-title":"4th International Conference on Information Systems Security and Privacy (ICISSP)"},{"key":"10.1016\/j.eswa.2026.132353_bib0029","doi-asserted-by":"crossref","DOI":"10.1016\/j.asoc.2023.111080","article-title":"Deep q-network-based heuristic intrusion detection against edge-based SIot zero-day attacks","volume":"150","author":"Shen","year":"2024","journal-title":"Applied Soft Computing"},{"key":"10.1016\/j.eswa.2026.132353_bib0030","series-title":"2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications","first-page":"1","article-title":"A detailed analysis of the KDD CUP 99 data set","author":"Tavallaee","year":"2009"},{"key":"10.1016\/j.eswa.2026.132353_bib0031","doi-asserted-by":"crossref","first-page":"353","DOI":"10.1016\/j.inffus.2022.09.026","article-title":"Fusion of statistical importance for feature selection in deep neural network-based intrusion detection system","volume":"90","author":"Thakkar","year":"2023","journal-title":"Information Fusion"},{"key":"10.1016\/j.eswa.2026.132353_bib0032","series-title":"Proceedings of the ACM SIGCOMM 2024 conference","first-page":"1","article-title":"NetMamba: Efficient network traffic classification via pre-training unidirectional mamba","author":"Wang","year":"2024"},{"key":"10.1016\/j.eswa.2026.132353_bib0033","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2021.102177","article-title":"Intrusion detection methods based on integrated deep learning model","volume":"103","author":"Wang","year":"2021","journal-title":"computers & security"},{"key":"10.1016\/j.eswa.2026.132353_bib0034","series-title":"Proceedings of the ACM SIGCOMM 2024 conference","first-page":"661","article-title":"Netllm: Adapting large language models for networking","author":"Wu","year":"2024"},{"issue":"1","key":"10.1016\/j.eswa.2026.132353_bib0035","doi-asserted-by":"crossref","first-page":"15","DOI":"10.1186\/s40537-023-00694-8","article-title":"Igrf-Rfe: A hybrid feature selection method for mlp-based network intrusion detection on unsw-nb15 dataset","volume":"10","author":"Yin","year":"2023","journal-title":"Journal of Big Data"},{"key":"10.1016\/j.eswa.2026.132353_bib0036","doi-asserted-by":"crossref","first-page":"3204","DOI":"10.1109\/TIFS.2025.3551643","article-title":"A-NIDS: Adaptive network intrusion detection system based on clustering and stacked CTGAN","volume":"20","author":"Zha","year":"2025","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"10.1016\/j.eswa.2026.132353_bib0037","series-title":"Ieee infocom 2024-ieee conference on computer communications","first-page":"581","article-title":"Aoc-Ids: Autonomous online framework with contrastive learning for intrusion detection","author":"Zhang","year":"2024"},{"issue":"4","key":"10.1016\/j.eswa.2026.132353_bib0038","doi-asserted-by":"crossref","first-page":"47","DOI":"10.1007\/s11280-024-01285-0","article-title":"Mim: A multiple integration model for intrusion detection on imbalanced samples","volume":"27","author":"Zhang","year":"2024","journal-title":"World Wide Web"},{"key":"10.1016\/j.eswa.2026.132353_bib0039","unstructured":"Zhao, D., Jiang, B., Liu, S., Cui, S., Shen, M., Han, D., Guan, X., & Lu, Z. (2025). Language of network: A generative pre-trained model for encrypted traffic comprehension. arXiv preprint arXiv: 2505.19482."},{"issue":"12","key":"10.1016\/j.eswa.2026.132353_bib0040","doi-asserted-by":"crossref","first-page":"9960","DOI":"10.1109\/JIOT.2021.3119055","article-title":"A novel intrusion detection method based on lightweight neural network for internet of things","volume":"9","author":"Zhao","year":"2022","journal-title":"IEEE Internet of Things Journal"},{"key":"10.1016\/j.eswa.2026.132353_bib0041","doi-asserted-by":"crossref","DOI":"10.1016\/j.engappai.2024.108162","article-title":"A fast intrusion detection system based on swift wrapper feature selection and speedy ensemble classifier","volume":"133","author":"Zorarpaci","year":"2024","journal-title":"Engineering Applications of Artificial Intelligence"}],"container-title":["Expert Systems with Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0957417426012662?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0957417426012662?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,5,14]],"date-time":"2026-05-14T17:58:31Z","timestamp":1778781511000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0957417426012662"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,8]]},"references-count":41,"alternative-id":["S0957417426012662"],"URL":"https:\/\/doi.org\/10.1016\/j.eswa.2026.132353","relation":{},"ISSN":["0957-4174"],"issn-type":[{"value":"0957-4174","type":"print"}],"subject":[],"published":{"date-parts":[[2026,8]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"An interpretable intrusion detection framework based on ensemble neural networks for dynamic network environments","name":"articletitle","label":"Article Title"},{"value":"Expert Systems with Applications","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.eswa.2026.132353","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"132353"}}