{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T04:07:12Z","timestamp":1784088432643,"version":"3.55.0"},"reference-count":54,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2027,1,1]],"date-time":"2027-01-01T00:00:00Z","timestamp":1798761600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2027,1,1]],"date-time":"2027-01-01T00:00:00Z","timestamp":1798761600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2027,1,1]],"date-time":"2027-01-01T00:00:00Z","timestamp":1798761600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2027,1,1]],"date-time":"2027-01-01T00:00:00Z","timestamp":1798761600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2027,1,1]],"date-time":"2027-01-01T00:00:00Z","timestamp":1798761600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2027,1,1]],"date-time":"2027-01-01T00:00:00Z","timestamp":1798761600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2027,1,1]],"date-time":"2027-01-01T00:00:00Z","timestamp":1798761600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Expert Systems with Applications"],"published-print":{"date-parts":[[2027,1]]},"DOI":"10.1016\/j.eswa.2026.133614","type":"journal-article","created":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T23:24:50Z","timestamp":1783725890000},"page":"133614","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"PC","title":["SCALA-NIDS: Safety-constrained LLM-Advised closed-loop adaptation for online open-world network intrusion detection"],"prefix":"10.1016","volume":"332","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-4749-2209","authenticated-orcid":false,"given":"Xiaojie","family":"Qin","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6598-8190","authenticated-orcid":false,"given":"Qingjun","family":"Yuan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8824-0468","authenticated-orcid":false,"given":"Haopeng","family":"Fan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1779-6290","authenticated-orcid":false,"given":"Jing","family":"Tao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5779-6108","authenticated-orcid":false,"given":"Pinghui","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-5683-3544","authenticated-orcid":false,"given":"Jihong","family":"Teng","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8593-9636","authenticated-orcid":false,"given":"Siqi","family":"Lu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9819-404X","authenticated-orcid":false,"given":"Yongjuan","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.eswa.2026.133614_bib0001","series-title":"Proceedings of the IEEE conference on computer vision and pattern recognition (CVPR)","first-page":"1563","article-title":"Towards open set deep networks","author":"Bendale","year":"2016"},{"issue":"1","key":"10.1016\/j.eswa.2026.133614_bib0002","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1023\/A:1010933404324","article-title":"Random forests","volume":"45","author":"Breiman","year":"2001","journal-title":"Machine Learning"},{"key":"10.1016\/j.eswa.2026.133614_bib0003","series-title":"Advances in neural information processing systems","first-page":"1877","article-title":"Language models are few-shot learners","volume":"vol. 33","author":"Brown","year":"2020"},{"key":"10.1016\/j.eswa.2026.133614_bib0004","series-title":"30th USENIX security symposium","first-page":"2633","article-title":"Extracting training data from large language models","author":"Carlini","year":"2021"},{"key":"10.1016\/j.eswa.2026.133614_bib0005","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2026.112129","article-title":"Robust intrusion detection in CPS: A pre-training-based multi-view feature collaboration and correlation analysis method","volume":"279","author":"Chen","year":"2026","journal-title":"Computer Networks"},{"key":"10.1016\/j.eswa.2026.133614_bib0006","series-title":"Proceedings of the 22nd ACM SIGKDD international conference on knowledge discovery and data mining","first-page":"785","article-title":"XGBoost: A scalable tree boosting system","author":"Chen","year":"2016"},{"issue":"7","key":"10.1016\/j.eswa.2026.133614_bib0007","first-page":"3366","article-title":"A continual learning survey: Defying forgetting in classification tasks","volume":"44","author":"De Lange","year":"2022","journal-title":"IEEE Transactions on Pattern Analysis and Machine Intelligence"},{"key":"10.1016\/j.eswa.2026.133614_bib0008","series-title":"Technical Report","article-title":"ENISA threat landscape 2024","year":"2024"},{"issue":"59","key":"10.1016\/j.eswa.2026.133614_bib0009","first-page":"1","article-title":"Domain-adversarial training of neural networks","volume":"17","author":"Ganin","year":"2016","journal-title":"Journal of Machine Learning Research"},{"key":"10.1016\/j.eswa.2026.133614_bib0010","doi-asserted-by":"crossref","first-page":"7705","DOI":"10.1109\/TIFS.2024.3443596","article-title":"GraphTunnel: Robust DNS tunnel detection based on DNS recursive resolution graph","volume":"19","author":"Gao","year":"2024","journal-title":"IEEE Transactions on Information Forensics and Security"},{"issue":"10","key":"10.1016\/j.eswa.2026.133614_bib0011","doi-asserted-by":"crossref","first-page":"3614","DOI":"10.1109\/TPAMI.2020.2981604","article-title":"Recent advances in open set recognition: A survey","volume":"43","author":"Geng","year":"2021","journal-title":"IEEE Transactions on Pattern Analysis and Machine Intelligence"},{"key":"10.1016\/j.eswa.2026.133614_bib0012","series-title":"International conference on learning representations","article-title":"A baseline for detecting misclassified and out-of-distribution examples in neural networks","author":"Hendrycks","year":"2017"},{"issue":"2","key":"10.1016\/j.eswa.2026.133614_bib0013","doi-asserted-by":"crossref","first-page":"745","DOI":"10.26599\/TST.2024.9010165","article-title":"FlowCoPCL: Enhanced flow correlation attacks on Tor using patching and contrastive learning","volume":"31","author":"Huang","year":"2026","journal-title":"Tsinghua Science and Technology"},{"key":"10.1016\/j.eswa.2026.133614_bib0014","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2023.119946","article-title":"Concept drift handling: A domain adaptation perspective","volume":"224","author":"Karimian","year":"2023","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.133614_bib0015","series-title":"Advances in neural information processing systems","article-title":"A simple unified framework for detecting out-of-distribution samples and adversarial attacks","volume":"vol. 31","author":"Lee","year":"2018"},{"issue":"1","key":"10.1016\/j.eswa.2026.133614_bib0016","doi-asserted-by":"crossref","first-page":"31","DOI":"10.1007\/s11263-024-02181-w","article-title":"A comprehensive survey on test-time adaptation under distribution shifts","volume":"133","author":"Liang","year":"2025","journal-title":"International Journal of Computer Vision"},{"key":"10.1016\/j.eswa.2026.133614_bib0017","series-title":"Proceedings of the 37th international conference on machine learning","first-page":"6028","article-title":"Do we really need to access the source data? Source hypothesis transfer for unsupervised domain adaptation","volume":"vol. 119","author":"Liang","year":"2020"},{"key":"10.1016\/j.eswa.2026.133614_bib0018","series-title":"International conference on learning representations","article-title":"Enhancing the reliability of out-of-distribution image detection in neural networks","author":"Liang","year":"2018"},{"key":"10.1016\/j.eswa.2026.133614_bib0019","series-title":"Advances in neural information processing systems","first-page":"21464","article-title":"Energy-based out-of-distribution detection","volume":"vol. 33","author":"Liu","year":"2020"},{"key":"10.1016\/j.eswa.2026.133614_bib0020","series-title":"Proceedings of the 32nd international conference on machine learning","first-page":"97","article-title":"Learning transferable features with deep adaptation networks","volume":"vol. 37","author":"Long","year":"2015"},{"key":"10.1016\/j.eswa.2026.133614_bib0021","series-title":"Advances in neural information processing systems","article-title":"Conditional adversarial domain adaptation","volume":"vol. 31","author":"Long","year":"2018"},{"key":"10.1016\/j.eswa.2026.133614_bib0022","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2023.122564","article-title":"Flowtransformer: A transformer framework for flow-based network intrusion detection systems","volume":"241","author":"Manocchio","year":"2024","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.133614_bib0023","doi-asserted-by":"crossref","first-page":"10652","DOI":"10.1109\/TIFS.2025.3612141","article-title":"Detection of unknown attacks through encrypted traffic: A gaussian prototype-aided variational autoencoder framework","volume":"20","author":"Meng","year":"2025","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"10.1016\/j.eswa.2026.133614_bib0024","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/TDSC.2026.3697849","article-title":"Fine-grained detection and analysis of unknown encrypted malicious traffic from mixed noisy labels","author":"Meng","year":"2026","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"10.1016\/j.eswa.2026.133614_bib0025","series-title":"2015 military communications and information systems conference (milCIS)","first-page":"1","article-title":"UNSW-NB15: A comprehensive data set for network intrusion detection systems","author":"Moustafa","year":"2015"},{"key":"10.1016\/j.eswa.2026.133614_bib0026","series-title":"Proceedings of the 39th international conference on machine learning","first-page":"16888","article-title":"Efficient test-time model adaptation without forgetting","volume":"vol. 162","author":"Niu","year":"2022"},{"key":"10.1016\/j.eswa.2026.133614_bib0027","series-title":"International conference on learning representations","article-title":"Towards stable test-time adaptation in dynamic wild world","author":"Niu","year":"2023"},{"key":"10.1016\/j.eswa.2026.133614_bib0028","series-title":"Advances in neural information processing systems","first-page":"27730","article-title":"Training language models to follow instructions with human feedback","volume":"vol. 35","author":"Ouyang","year":"2022"},{"key":"10.1016\/j.eswa.2026.133614_bib0029","unstructured":"OWASP Foundation (2025). OWASP Top 10 for large language model applications 2025. https:\/\/owasp.org\/www-project-top-10-for-large-language-model-applications\/."},{"key":"10.1016\/j.eswa.2026.133614_bib0030","series-title":"C4.5: Programs for machine learning","author":"Quinlan","year":"1993"},{"issue":"7","key":"10.1016\/j.eswa.2026.133614_bib0031","doi-asserted-by":"crossref","first-page":"1757","DOI":"10.1109\/TPAMI.2012.256","article-title":"Toward open set recognition","volume":"35","author":"Scheirer","year":"2013","journal-title":"IEEE Transactions on Pattern Analysis and Machine Intelligence"},{"key":"10.1016\/j.eswa.2026.133614_bib0032","series-title":"Advances in neural information processing systems","article-title":"Toolformer: Language models can teach themselves to use tools","volume":"vol. 36","author":"Schick","year":"2023"},{"key":"10.1016\/j.eswa.2026.133614_bib0033","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2024.125509","article-title":"Evaluation of LLM-based chatbots for OSINT-based cyber threat awareness","volume":"261","author":"Shafee","year":"2025","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.133614_bib0034","series-title":"2024 IEEE symposium on security and privacy (SP)","first-page":"3238","article-title":"Real-time website fingerprinting defense via traffic cluster anonymization","author":"Shen","year":"2024"},{"key":"10.1016\/j.eswa.2026.133614_bib0035","series-title":"Proceedings of the 2025 ACM SIGSAC conference on computer and communications security","first-page":"1574","article-title":"Swallow: A transfer-robust website fingerprinting attack via consistent feature learning","author":"Shen","year":"2025"},{"key":"10.1016\/j.eswa.2026.133614_bib0036","doi-asserted-by":"crossref","DOI":"10.1109\/TIFS.2025.3560560","article-title":"Robust detection of malicious encrypted traffic via contrastive learning","author":"Shen","year":"2025","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"10.1016\/j.eswa.2026.133614_bib0037","series-title":"Technical Report","article-title":"Artificial intelligence risk management framework (AI RMF 1.0)","author":"Standards","year":"2023"},{"key":"10.1016\/j.eswa.2026.133614_bib0038","series-title":"European conference on computer vision workshops","first-page":"443","article-title":"Deep CORAL: Correlation alignment for deep domain adaptation","author":"Sun","year":"2016"},{"key":"10.1016\/j.eswa.2026.133614_bib0039","series-title":"Proceedings of the 2009 IEEE symposium on computational intelligence for security and defense applications","first-page":"1","article-title":"A detailed analysis of the KDD CUP 99 data set","author":"Tavallaee","year":"2009"},{"key":"10.1016\/j.eswa.2026.133614_bib0040","unstructured":"UCI Machine Learning Repository(1999). KDD Cup 1999 data. http:\/\/kdd.ics.uci.edu\/databases\/kddcup99\/kddcup99.HTML. Accessed: 2024-12-01."},{"key":"10.1016\/j.eswa.2026.133614_bib0041","series-title":"International conference on learning representations","article-title":"Tent: Fully test-time adaptation by entropy minimization","author":"Wang","year":"2021"},{"key":"10.1016\/j.eswa.2026.133614_bib0042","article-title":"Voyager: An open-ended embodied agent with large language models","author":"Wang","year":"2024","journal-title":"Transactions on Machine Learning Research"},{"key":"10.1016\/j.eswa.2026.133614_bib0043","series-title":"Ieee infocom 2022","first-page":"1409","article-title":"FeCo: Boosting intrusion detection capability in IoT networks via contrastive learning","author":"Wang","year":"2022"},{"key":"10.1016\/j.eswa.2026.133614_bib0044","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (CVPR)","first-page":"7201","article-title":"Continual test-time domain adaptation","author":"Wang","year":"2022"},{"key":"10.1016\/j.eswa.2026.133614_bib0045","article-title":"Entropy-regulated cross-modal generative fusion for multimodal network intrusion detection","volume":"126","author":"Wang","year":"2025","journal-title":"Information Fusion"},{"key":"10.1016\/j.eswa.2026.133614_bib0046","series-title":"Advances in neural information processing systems","first-page":"24824","article-title":"Chain-of-thought prompting elicits reasoning in large language models","volume":"vol. 35","author":"Wei","year":"2022"},{"key":"10.1016\/j.eswa.2026.133614_bib0047","unstructured":"Wu, Q., Bansal, G., Zhang, J., Wu, Y., Li, B., Zhu, E. et al. (2023). AutoGen: Enabling next-gen LLM applications via multi-agent conversation. arXiv: 2308.08155."},{"key":"10.1016\/j.eswa.2026.133614_bib0048","doi-asserted-by":"crossref","DOI":"10.1145\/3769676","article-title":"Large language models for cyber security: A systematic literature review","author":"Xu","year":"2025","journal-title":"ACM Transactions on Software Engineering and Methodology"},{"issue":"12","key":"10.1016\/j.eswa.2026.133614_bib0049","doi-asserted-by":"crossref","first-page":"5635","DOI":"10.1007\/s11263-024-02117-4","article-title":"Generalized out-of-distribution detection: A survey","volume":"132","author":"Yang","year":"2024","journal-title":"International Journal of Computer Vision"},{"key":"10.1016\/j.eswa.2026.133614_bib0050","series-title":"International conference on learning representations","article-title":"ReAct: Synergizing reasoning and acting in language models","author":"Yao","year":"2023"},{"key":"10.1016\/j.eswa.2026.133614_bib0051","doi-asserted-by":"crossref","first-page":"114","DOI":"10.1109\/MNET.2025.3579001","article-title":"Multi-agent for network security monitoring and warning: A generative AI solution","volume":"39","author":"Yuan","year":"2025","journal-title":"IEEE Network"},{"issue":"4","key":"10.1016\/j.eswa.2026.133614_bib0052","doi-asserted-by":"crossref","first-page":"4232","DOI":"10.1109\/TNSM.2022.3218843","article-title":"Contrastive learning enhanced intrusion detection","volume":"19","author":"Yue","year":"2022","journal-title":"IEEE Transactions on Network and Service Management"},{"key":"10.1016\/j.eswa.2026.133614_bib0053","series-title":"Ieee infocom 2025","first-page":"1","article-title":"Continual learning with strategic selection and forgetting for network intrusion detection","author":"Zhang","year":"2025"},{"key":"10.1016\/j.eswa.2026.133614_bib0054","series-title":"Ieee infocom 2024","first-page":"581","article-title":"AOC-IDS: Autonomous online framework with contrastive learning for intrusion detection","author":"Zhang","year":"2024"}],"container-title":["Expert Systems with Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0957417426025224?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0957417426025224?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T03:32:09Z","timestamp":1784086329000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0957417426025224"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2027,1]]},"references-count":54,"alternative-id":["S0957417426025224"],"URL":"https:\/\/doi.org\/10.1016\/j.eswa.2026.133614","relation":{},"ISSN":["0957-4174"],"issn-type":[{"value":"0957-4174","type":"print"}],"subject":[],"published":{"date-parts":[[2027,1]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"SCALA-NIDS: Safety-constrained LLM-Advised closed-loop adaptation for online open-world network intrusion detection","name":"articletitle","label":"Article Title"},{"value":"Expert Systems with Applications","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.eswa.2026.133614","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"133614"}}