{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T08:54:14Z","timestamp":1780044854577,"version":"3.53.1"},"reference-count":90,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2025,9,6]],"date-time":"2025-09-06T00:00:00Z","timestamp":1757116800000},"content-version":"vor","delay-in-days":248,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100000780","name":"European Commission","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100000780","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100024370","name":"Governo Italiano Ministero dell'Istruzione dell'Universita e della Ricerca","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100024370","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["International Journal of Intelligent Networks"],"published-print":{"date-parts":[[2025]]},"DOI":"10.1016\/j.ijin.2025.09.001","type":"journal-article","created":{"date-parts":[[2025,9,17]],"date-time":"2025-09-17T04:01:39Z","timestamp":1758081699000},"page":"204-223","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":2,"special_numbering":"C","title":["MIDES: A multi-layer Intrusion Detection System using ensemble machine learning"],"prefix":"10.1016","volume":"6","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3326-8500","authenticated-orcid":false,"given":"Vincenzo","family":"Agate","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7340-1847","authenticated-orcid":false,"given":"Alessandra","family":"De Paola","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1574-1111","authenticated-orcid":false,"given":"Pierluca","family":"Ferraro","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8217-2230","authenticated-orcid":false,"given":"Giuseppe","family":"Lo Re","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.ijin.2025.09.001_b1","doi-asserted-by":"crossref","first-page":"26","DOI":"10.58496\/BJML\/2023\/005","article-title":"Reviews research on applying machine learning techniques to reduce false positives for network intrusion detection systems","volume":"2023","author":"Rajora","year":"2023","journal-title":"Babylon. J. Mach. Learn."},{"key":"10.1016\/j.ijin.2025.09.001_b2","first-page":"1","article-title":"Designing a novel network anomaly detection framework using multi-serial stacked network with optimal feature selection procedures over DDOS attacks","volume":"6","author":"Pradeep","year":"2025","journal-title":"Int. J. Intell. Netw."},{"key":"10.1016\/j.ijin.2025.09.001_b3","unstructured":"P. Rieger, M. Chilese, R. Mohamed, M. Miettinen, H. Fereidooni, A.-R. Sadeghi, ARGUS: Context-Based detection of stealthy IoT infiltration attacks, in: 32nd USENIX Security Symposium, USENIX Security 23, 2023, pp. 4301\u20134318."},{"issue":"8","key":"10.1016\/j.ijin.2025.09.001_b4","first-page":"5099","article-title":"Ensemble adaptive online machine learning in data stream: a case study in cyber intrusion detection system","volume":"16","author":"Roshan","year":"2024","journal-title":"Int. J. Inf. Technol."},{"issue":"1","key":"10.1016\/j.ijin.2025.09.001_b5","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1186\/s42400-019-0038-7","article-title":"Survey of intrusion detection systems: techniques, datasets and challenges","volume":"2","author":"Khraisat","year":"2019","journal-title":"Cybersecurity"},{"issue":"2","key":"10.1016\/j.ijin.2025.09.001_b6","doi-asserted-by":"crossref","first-page":"1153","DOI":"10.1109\/COMST.2015.2494502","article-title":"A survey of data mining and machine learning methods for cyber security intrusion detection","volume":"18","author":"Buczak","year":"2016","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"10.1016\/j.ijin.2025.09.001_b7","first-page":"38","article-title":"ARTP: Anomaly based real time prevention of distributed denial of service attacks on the web using machine learning approach","volume":"4","author":"Krishna Kishore","year":"2023","journal-title":"Int. J. Intell. Netw."},{"issue":"3","key":"10.1016\/j.ijin.2025.09.001_b8","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s10922-021-09589-6","article-title":"As-ids: Anomaly and signature based ids for the internet of things","volume":"29","author":"Otoum","year":"2021","journal-title":"J. Netw. Syst. Manage."},{"key":"10.1016\/j.ijin.2025.09.001_b9","article-title":"A signature-based intrusion detection system for the internet of things","author":"Ioulianou","year":"2018","journal-title":"Inf. Commun. Technol. Form"},{"key":"10.1016\/j.ijin.2025.09.001_b10","doi-asserted-by":"crossref","DOI":"10.1016\/j.asoc.2020.106301","article-title":"A survey and taxonomy of the fuzzy signature-based intrusion detection systems","volume":"92","author":"Masdari","year":"2020","journal-title":"Appl. Soft Comput."},{"issue":"5","key":"10.1016\/j.ijin.2025.09.001_b11","doi-asserted-by":"crossref","first-page":"973","DOI":"10.1016\/j.jcss.2014.02.005","article-title":"A survey of emerging threats in cybersecurity","volume":"80","author":"Jang-Jaccard","year":"2014","journal-title":"J. Comput. System Sci."},{"issue":"1","key":"10.1016\/j.ijin.2025.09.001_b12","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1016\/j.cose.2008.08.003","article-title":"Anomaly-based network intrusion detection: Techniques, systems and challenges","volume":"28","author":"Garc\u00eda-Teodoro","year":"2009","journal-title":"Comput. Secur."},{"issue":"2","key":"10.1016\/j.ijin.2025.09.001_b13","doi-asserted-by":"crossref","first-page":"314","DOI":"10.1109\/TETC.2016.2633228","article-title":"A two-layer dimension reduction and two-tier classification model for anomaly-based intrusion detection in IoT backbone networks","volume":"7","author":"Pajouh","year":"2019","journal-title":"IEEE Trans. Emerg. Top. Comput."},{"issue":"1","key":"10.1016\/j.ijin.2025.09.001_b14","doi-asserted-by":"crossref","first-page":"276","DOI":"10.1109\/TAES.2019.2914519","article-title":"MAIDENS: MIL-STD-1553 anomaly-based intrusion detection system using time-based histogram comparison","volume":"56","author":"G\u00e9n\u00e9reux","year":"2020","journal-title":"IEEE Trans. Aerosp. Electron. Syst."},{"issue":"4","key":"10.1016\/j.ijin.2025.09.001_b15","doi-asserted-by":"crossref","first-page":"1643","DOI":"10.1109\/TSG.2013.2294473","article-title":"Integrated anomaly detection for cyber security of the substations","volume":"5","author":"Hong","year":"2014","journal-title":"IEEE Trans. Smart Grid"},{"key":"10.1016\/j.ijin.2025.09.001_b16","doi-asserted-by":"crossref","first-page":"108346","DOI":"10.1109\/ACCESS.2020.3001350","article-title":"Anomaly-based intrusion detection from network flow features using variational autoencoder","volume":"8","author":"Zavrak","year":"2020","journal-title":"IEEE Access"},{"issue":"8","key":"10.1016\/j.ijin.2025.09.001_b17","doi-asserted-by":"crossref","first-page":"6882","DOI":"10.1109\/JIOT.2020.2970501","article-title":"Passban IDS: An intelligent anomaly-based intrusion detection system for IoT edge devices","volume":"7","author":"Eskandari","year":"2020","journal-title":"IEEE Internet Things J."},{"issue":"1","key":"10.1016\/j.ijin.2025.09.001_b18","doi-asserted-by":"crossref","first-page":"303","DOI":"10.1109\/SURV.2013.052213.00046","article-title":"Network anomaly detection: Methods, systems and tools","volume":"16","author":"Bhuyan","year":"2014","journal-title":"IEEE Commun. Surv. Tutor."},{"issue":"4","key":"10.1016\/j.ijin.2025.09.001_b19","doi-asserted-by":"crossref","first-page":"865","DOI":"10.1109\/TSG.2011.2159406","article-title":"Anomaly detection for cybersecurity of the substations","volume":"2","author":"Ten","year":"2011","journal-title":"IEEE Trans. Smart Grid"},{"issue":"5","key":"10.1016\/j.ijin.2025.09.001_b20","doi-asserted-by":"crossref","first-page":"516","DOI":"10.1109\/TSMCC.2010.2048428","article-title":"Toward credible evaluation of anomaly-based intrusion-detection methods","volume":"40","author":"Tavallaee","year":"2010","journal-title":"IEEE Trans. Syst. Man Cybern. Part C (Applications Reviews)"},{"key":"10.1016\/j.ijin.2025.09.001_b21","doi-asserted-by":"crossref","first-page":"303","DOI":"10.1016\/j.future.2017.01.029","article-title":"A novel statistical technique for intrusion detection systems","volume":"79","author":"Kabir","year":"2018","journal-title":"Future Gener. Comput. Syst."},{"issue":"4","key":"10.1016\/j.ijin.2025.09.001_b22","doi-asserted-by":"crossref","first-page":"312","DOI":"10.1016\/j.inffus.2009.01.003","article-title":"Processing intrusion detection alert aggregates with time series modeling","volume":"10","author":"Viinikka","year":"2009","journal-title":"Inf. Fusion"},{"key":"10.1016\/j.ijin.2025.09.001_b23","doi-asserted-by":"crossref","DOI":"10.1016\/j.chaos.2021.111143","article-title":"A new approach to combine multiplex networks and time series attributes: Building intrusion detection systems (IDS) in cybersecurity","volume":"150","author":"Iglesias P\u00e9rez","year":"2021","journal-title":"Chaos Solitons Fractals"},{"key":"10.1016\/j.ijin.2025.09.001_b24","series-title":"Proceedings of the 1st ACM Workshop on Security of Ad Hoc and Sensor Networks","first-page":"125","article-title":"A specification-based intrusion detection system for AODV","author":"Tseng","year":"2003"},{"key":"10.1016\/j.ijin.2025.09.001_b25","doi-asserted-by":"crossref","DOI":"10.1016\/j.compeleceng.2021.107094","article-title":"Deep learning-based feature extraction and optimizing pattern matching for intrusion detection using finite state machine","volume":"92","author":"Abbasi","year":"2021","journal-title":"Comput. Electr. Eng."},{"key":"10.1016\/j.ijin.2025.09.001_b26","doi-asserted-by":"crossref","first-page":"94","DOI":"10.58496\/BJIoT\/2024\/012","article-title":"Evaluating the effectiveness of machine learning-based intrusion detection in multi-cloud environments","volume":"2024","author":"Masoodi","year":"2024","journal-title":"Babylon. J. Internet Things"},{"key":"10.1016\/j.ijin.2025.09.001_b27","series-title":"2011 7th International Conference on Information Assurance and Security","first-page":"192","article-title":"Intrusion detection based on k-means clustering and oner classification","author":"Muda","year":"2011"},{"key":"10.1016\/j.ijin.2025.09.001_b28","series-title":"2011 7th International Conference on Information Technology in Asia","first-page":"1","article-title":"Intrusion detection based on K-means clustering and na\u00efve Bayes classification","author":"Muda","year":"2011"},{"key":"10.1016\/j.ijin.2025.09.001_b29","series-title":"2018 IEEE\/ACIS 17th International Conference on Computer and Information Science","first-page":"34","article-title":"Hybrid intrusion detection system using K-means and K-nearest neighbors algorithms","author":"Aung","year":"2018"},{"key":"10.1016\/j.ijin.2025.09.001_b30","doi-asserted-by":"crossref","first-page":"42210","DOI":"10.1109\/ACCESS.2019.2904620","article-title":"An intrusion detection model based on feature reduction and convolutional neural networks","volume":"7","author":"Xiao","year":"2019","journal-title":"IEEE Access"},{"key":"10.1016\/j.ijin.2025.09.001_b31","series-title":"2020 IEEE International IOT, Electronics and Mechatronics Conference","first-page":"1","article-title":"PCA, random-forest and pearson correlation for dimensionality reduction in IoT IDS","author":"Alhowaide","year":"2020"},{"key":"10.1016\/j.ijin.2025.09.001_b32","doi-asserted-by":"crossref","first-page":"139","DOI":"10.1016\/j.comcom.2020.05.048","article-title":"An effective feature engineering for DNN using hybrid PCA-GWO for intrusion detection in IoMT architecture","volume":"160","author":"R.M.","year":"2020","journal-title":"Comput. Commun."},{"issue":"8","key":"10.1016\/j.ijin.2025.09.001_b33","doi-asserted-by":"crossref","first-page":"1143","DOI":"10.1109\/TPDS.2009.142","article-title":"Impact of feature reduction on the efficiency of wireless intrusion detection systems","volume":"21","author":"El-Khatib","year":"2009","journal-title":"IEEE Transactions Parallel Distrib. Syst."},{"issue":"3","key":"10.1016\/j.ijin.2025.09.001_b34","doi-asserted-by":"crossref","first-page":"345","DOI":"10.1109\/TKDE.2007.44","article-title":"K-Means+ ID3: A novel method for supervised anomaly detection by cascading K-means clustering and ID3 decision tree learning methods","volume":"19","author":"Gaddam","year":"2007","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"10.1016\/j.ijin.2025.09.001_b35","doi-asserted-by":"crossref","unstructured":"N.B. Amor, S. Benferhat, Z. Elouedi, Naive bayes vs decision trees in intrusion detection systems, in: Proceedings of the 2004 ACM Symposium on Applied Computing, 2004, pp. 420\u2013424.","DOI":"10.1145\/967900.967989"},{"issue":"18","key":"10.1016\/j.ijin.2025.09.001_b36","doi-asserted-by":"crossref","first-page":"13492","DOI":"10.1016\/j.eswa.2012.07.009","article-title":"A network intrusion detection system based on a hidden na\u00efve Bayes multiclass classifier","volume":"39","author":"Koc","year":"2012","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.ijin.2025.09.001_b37","doi-asserted-by":"crossref","first-page":"119","DOI":"10.1016\/j.protcy.2012.05.017","article-title":"Intrusion detection using naive Bayes classifier with feature reduction","volume":"4","author":"Mukherjee","year":"2012","journal-title":"Procedia Technol."},{"key":"10.1016\/j.ijin.2025.09.001_b38","series-title":"Research in Intelligent and Computing in Engineering","first-page":"171","article-title":"Improving extreme learning machine accuracy utilizing genetic algorithm for intrusion detection purposes","author":"Obaid","year":"2021"},{"key":"10.1016\/j.ijin.2025.09.001_b39","doi-asserted-by":"crossref","first-page":"15","DOI":"10.58496\/BJML\/2024\/002","article-title":"Intrusion detection system based on machine learning algorithms:(SVM and genetic algorithm)","volume":"2024","author":"Alsajri","year":"2024","journal-title":"Babylon. J. Mach. Learn."},{"key":"10.1016\/j.ijin.2025.09.001_b40","doi-asserted-by":"crossref","first-page":"705","DOI":"10.1016\/j.neucom.2020.07.138","article-title":"Intrusion detection approach based on optimised artificial neural network","volume":"452","author":"Chora\u015b","year":"2021","journal-title":"Neurocomputing"},{"key":"10.1016\/j.ijin.2025.09.001_b41","doi-asserted-by":"crossref","DOI":"10.1016\/j.ijcip.2021.100449","article-title":"A homogeneous ensemble based dynamic artificial neural network for solving the intrusion detection problem","volume":"34","author":"Al-Daweri","year":"2021","journal-title":"Int. J. Crit. Infrastruct. Prot."},{"key":"10.1016\/j.ijin.2025.09.001_b42","series-title":"2015 Fifth International Conference on Communication Systems and Network Technologies","first-page":"987","article-title":"Classification of attacks using support vector machine (svm) on kddcup\u201999 ids database","author":"Kotpalliwar","year":"2015"},{"key":"10.1016\/j.ijin.2025.09.001_b43","series-title":"Information and Communication Technology for Sustainable Development","first-page":"413","article-title":"HMM-based IDS for attack detection and prevention in MANET","author":"Pathak","year":"2018"},{"key":"10.1016\/j.ijin.2025.09.001_b44","series-title":"Soft Computing: Theories and Applications","first-page":"565","article-title":"Development of IDS using supervised machine learning","author":"Kumar","year":"2020"},{"key":"10.1016\/j.ijin.2025.09.001_b45","doi-asserted-by":"crossref","first-page":"135","DOI":"10.1016\/j.cose.2016.11.004","article-title":"A survey of intrusion detection systems based on ensemble and hybrid classifiers","volume":"65","author":"Aburomman","year":"2017","journal-title":"Comput. Secur."},{"key":"10.1016\/j.ijin.2025.09.001_b46","doi-asserted-by":"crossref","first-page":"94497","DOI":"10.1109\/ACCESS.2019.2928048","article-title":"TSE-IDS: A two-stage classifier ensemble for intelligent anomaly-based intrusion detection system","volume":"7","author":"Tama","year":"2019","journal-title":"IEEE Access"},{"key":"10.1016\/j.ijin.2025.09.001_b47","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2020.107247","article-title":"Building an efficient intrusion detection system based on feature selection and ensemble classifier","volume":"174","author":"Zhou","year":"2020","journal-title":"Comput. Netw."},{"key":"10.1016\/j.ijin.2025.09.001_b48","doi-asserted-by":"crossref","first-page":"138451","DOI":"10.1109\/ACCESS.2021.3116219","article-title":"A novel ensemble framework for an intelligent intrusion detection system","volume":"9","author":"Seth","year":"2021","journal-title":"IEEE Access"},{"key":"10.1016\/j.ijin.2025.09.001_b49","doi-asserted-by":"crossref","first-page":"3204","DOI":"10.1109\/TIFS.2025.3551643","article-title":"A-NIDS: Adaptive network intrusion detection system based on clustering and stacked CTGAN","volume":"20","author":"Zha","year":"2025","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"4","key":"10.1016\/j.ijin.2025.09.001_b50","first-page":"1591","article-title":"Sustainable ensemble learning driving intrusion detection model","volume":"18","author":"Li","year":"2021","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"10.1016\/j.ijin.2025.09.001_b51","article-title":"ENIDS: A deep learning-based ensemble framework for network intrusion detection systems","author":"Sayem","year":"2024","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"10.1016\/j.ijin.2025.09.001_b52","article-title":"Hybrid ensemble broad learning system for network intrusion detection","author":"Lin","year":"2023","journal-title":"IEEE Trans. Ind. Inform."},{"key":"10.1016\/j.ijin.2025.09.001_b53","first-page":"1","article-title":"TRACER: Attack-aware divide-and-conquer transformer for intrusion detection in industrial internet of things","author":"Wu","year":"2025","journal-title":"IEEE Trans. Ind. Inform."},{"key":"10.1016\/j.ijin.2025.09.001_b54","doi-asserted-by":"crossref","first-page":"4026","DOI":"10.1109\/TIFS.2025.3557741","article-title":"GTAE-IDS: Graph transformer-based autoencoder framework for real-time network intrusion detection","volume":"20","author":"Ghadermazi","year":"2025","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.ijin.2025.09.001_b55","doi-asserted-by":"crossref","DOI":"10.1016\/j.iot.2021.100435","article-title":"Ensemble detection model for IoT IDS","volume":"16","author":"Alhowaide","year":"2021","journal-title":"Internet Things"},{"key":"10.1016\/j.ijin.2025.09.001_b56","article-title":"Deep ensemble learning with pruning for ddos attack detection in IoT networks","author":"Saiyed","year":"2024","journal-title":"IEEE Trans. Mach. Learn. Commun. Netw."},{"key":"10.1016\/j.ijin.2025.09.001_b57","series-title":"GLOBECOM 2022-2022 IEEE Global Communications Conference","first-page":"3545","article-title":"LCCDE: a decision-based ensemble framework for intrusion detection in the internet of vehicles","author":"Yang","year":"2022"},{"issue":"1","key":"10.1016\/j.ijin.2025.09.001_b58","doi-asserted-by":"crossref","first-page":"187","DOI":"10.1109\/TNSM.2024.3444909","article-title":"A cross-domain intrusion detection method based on nonlinear augmented explicit features","volume":"22","author":"Yu","year":"2025","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"10.1016\/j.ijin.2025.09.001_b59","doi-asserted-by":"crossref","first-page":"2930","DOI":"10.1109\/TIFS.2025.3546849","article-title":"A lightweight and dynamic open-set intrusion detection for industrial internet of things","volume":"20","author":"Yang","year":"2025","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"2","key":"10.1016\/j.ijin.2025.09.001_b60","doi-asserted-by":"crossref","first-page":"2669","DOI":"10.1109\/TITS.2024.3510584","article-title":"AILL-IDS: An automatic incremental lifetime learning intrusion detection system for vehicular ad hoc networks","volume":"26","author":"Huang","year":"2025","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"key":"10.1016\/j.ijin.2025.09.001_b61","first-page":"1","article-title":"An ensemble-based hybrid model for the detection of attacks in the internet of vehicular things","author":"Ullah","year":"2025","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"key":"10.1016\/j.ijin.2025.09.001_b62","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/TITS.2025.3641708","article-title":"Sustainable learning-based intrusion detection system for VANETs","author":"Wei","year":"2025","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"key":"10.1016\/j.ijin.2025.09.001_b63","first-page":"1","article-title":"DATI-IDS: Domain adaptation and time-series imaging-based intrusion detection system for connected autonomous vehicles","author":"Tan","year":"2025","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"key":"10.1016\/j.ijin.2025.09.001_b64","doi-asserted-by":"crossref","DOI":"10.1109\/TCE.2025.3569886","article-title":"Lightweight fuzzy-driven intrusion detection for consumer life-tech applications","author":"Aljuhani","year":"2025","journal-title":"IEEE Trans. Consum. Electron."},{"issue":"1","key":"10.1016\/j.ijin.2025.09.001_b65","doi-asserted-by":"crossref","first-page":"4249","DOI":"10.1109\/TCE.2024.3370193","article-title":"Threat detection and mitigation for tactile internet driven consumer IoT-healthcare system","volume":"70","author":"R","year":"2024","journal-title":"IEEE Trans. Consum. Electron."},{"issue":"3","key":"10.1016\/j.ijin.2025.09.001_b66","doi-asserted-by":"crossref","first-page":"2541","DOI":"10.1109\/TSG.2025.3535949","article-title":"Network intrusion detection for modern smart grids based on adaptive online incremental learning","volume":"16","author":"Lu","year":"2025","journal-title":"IEEE Trans. Smart Grid"},{"key":"10.1016\/j.ijin.2025.09.001_b67","doi-asserted-by":"crossref","first-page":"5895","DOI":"10.1109\/TIFS.2024.3402439","article-title":"RFG-HELAD: A robust fine-grained network traffic anomaly detection model based on heterogeneous ensemble learning","volume":"19","author":"Zhong","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.ijin.2025.09.001_b68","doi-asserted-by":"crossref","first-page":"605","DOI":"10.1109\/TMLCN.2025.3564587","article-title":"Evolving ML-based intrusion detection: Cyber threat intelligence for dynamic model updates","volume":"3","author":"Lin","year":"2025","journal-title":"IEEE Trans. Mach. Learn. Commun. Netw."},{"key":"10.1016\/j.ijin.2025.09.001_b69","doi-asserted-by":"crossref","first-page":"143","DOI":"10.1109\/TICPS.2024.3406505","article-title":"Real-time intrusion detection based on decision fusion in industrial control systems","volume":"2","author":"Xue","year":"2024","journal-title":"IEEE Trans. Ind. Cyber-Physical Syst."},{"key":"10.1016\/j.ijin.2025.09.001_b70","doi-asserted-by":"crossref","first-page":"62","DOI":"10.70470\/SHIFRA\/2025\/003","article-title":"Generative AI-enhanced intrusion detection framework for secure healthcare networks in MANETs","volume":"2025","author":"Addula","year":"2025","journal-title":"SHIFRA"},{"key":"10.1016\/j.ijin.2025.09.001_b71","first-page":"207","article-title":"A behavior-based intrusion detection system using ensemble learning techniques","volume":"vol. 3260","author":"Agate","year":"2022"},{"key":"10.1016\/j.ijin.2025.09.001_b72","article-title":"Adaptive ensemble learning for intrusion detection systems","volume":"vol. 3762","author":"Agate","year":"2024"},{"issue":"1","key":"10.1016\/j.ijin.2025.09.001_b73","doi-asserted-by":"crossref","first-page":"67","DOI":"10.1109\/4235.585893","article-title":"No free lunch theorems for optimization","volume":"1","author":"Wolpert","year":"1997","journal-title":"IEEE Trans. Evol. Comput."},{"key":"10.1016\/j.ijin.2025.09.001_b74","doi-asserted-by":"crossref","first-page":"154530","DOI":"10.1109\/ACCESS.2020.3017763","article-title":"HadIoT: A hierarchical anomaly detection framework for IoT","volume":"8","author":"Chang","year":"2020","journal-title":"IEEE Access"},{"issue":"2","key":"10.1016\/j.ijin.2025.09.001_b75","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3439950","article-title":"Deep learning for anomaly detection: A review","volume":"54","author":"Pang","year":"2021","journal-title":"ACM Comput. Surv."},{"key":"10.1016\/j.ijin.2025.09.001_b76","series-title":"Information retrieval. 2nd. newton, ma","author":"Van Rijsbergen","year":"1979"},{"key":"10.1016\/j.ijin.2025.09.001_b77","series-title":"Advances in Neural Information Processing Systems 30","first-page":"4765","article-title":"A unified approach to interpreting model predictions","author":"Lundberg","year":"2017"},{"issue":"2","key":"10.1016\/j.ijin.2025.09.001_b78","doi-asserted-by":"crossref","first-page":"241","DOI":"10.1016\/S0893-6080(05)80023-1","article-title":"Stacked generalization","volume":"5","author":"Wolpert","year":"1992","journal-title":"Neural Netw."},{"key":"10.1016\/j.ijin.2025.09.001_b79","doi-asserted-by":"crossref","first-page":"271","DOI":"10.1613\/jair.594","article-title":"Issues in stacked generalization","volume":"10","author":"Ting","year":"1999","journal-title":"J. Artificial Intelligence Res."},{"issue":"3","key":"10.1016\/j.ijin.2025.09.001_b80","doi-asserted-by":"crossref","first-page":"255","DOI":"10.1023\/B:MACH.0000015881.36452.6e","article-title":"Is combining classifiers with stacking better than selecting the best one?","volume":"54","author":"D\u017eeroski","year":"2004","journal-title":"Mach. Learn."},{"key":"10.1016\/j.ijin.2025.09.001_b81","doi-asserted-by":"crossref","first-page":"147","DOI":"10.1016\/j.cose.2019.06.005","article-title":"A survey of network-based intrusion detection data sets","volume":"86","author":"Ring","year":"2019","journal-title":"Comput. Secur."},{"key":"10.1016\/j.ijin.2025.09.001_b82","first-page":"202","article-title":"Three-stage data generation algorithm for multiclass network intrusion detection with highly imbalanced dataset","volume":"4","author":"Chui","year":"2023","journal-title":"Int. J. Intell. Netw."},{"issue":"4","key":"10.1016\/j.ijin.2025.09.001_b83","doi-asserted-by":"crossref","first-page":"807","DOI":"10.1109\/TC.2013.13","article-title":"A semantic approach to host-based intrusion detection systems using contiguousand discontiguous system call patterns","volume":"63","author":"Creech","year":"2014","journal-title":"IEEE Trans. Comput."},{"issue":"4","key":"10.1016\/j.ijin.2025.09.001_b84","doi-asserted-by":"crossref","first-page":"262","DOI":"10.1145\/382912.382923","article-title":"Testing intrusion detection systems: A critique of the 1998 and 1999 DARPA intrusion detection system evaluations as performed by Lincoln laboratory","volume":"3","author":"McHugh","year":"2000","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"10.1016\/j.ijin.2025.09.001_b85","series-title":"2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications","first-page":"1","article-title":"A detailed analysis of the KDD cup 99 data set","author":"Tavallaee","year":"2009"},{"issue":"3","key":"10.1016\/j.ijin.2025.09.001_b86","doi-asserted-by":"crossref","first-page":"357","DOI":"10.1016\/j.cose.2011.12.012","article-title":"Toward developing a systematic approach to generate benchmark datasets for intrusion detection","volume":"31","author":"Shiravi","year":"2012","journal-title":"Comput. Secur."},{"key":"10.1016\/j.ijin.2025.09.001_b87","first-page":"108","article-title":"Toward generating a new intrusion detection dataset and intrusion traffic characterization","volume":"1","author":"Sharafaldin","year":"2018","journal-title":"ICISSp"},{"key":"10.1016\/j.ijin.2025.09.001_b88","series-title":"2022 IEEE Conference on Communications and Network Security","first-page":"254","article-title":"Error prevalence in NIDS datasets: A case study on CIC-IDS-2017 and CSE-CIC-IDS-2018","author":"Liu","year":"2022"},{"key":"10.1016\/j.ijin.2025.09.001_b89","series-title":"2020 International Conference on Computing and Information Technology","first-page":"1","article-title":"SMOTE: Class imbalance problem in intrusion detection system","author":"Alfrhan","year":"2020"},{"issue":"1","key":"10.1016\/j.ijin.2025.09.001_b90","doi-asserted-by":"crossref","first-page":"616","DOI":"10.1109\/JIOT.2021.3084796","article-title":"MTH-IDS: A multitiered hybrid intrusion detection system for internet of vehicles","volume":"9","author":"Yang","year":"2021","journal-title":"IEEE Internet Things J."}],"container-title":["International Journal of Intelligent Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2666603025000156?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2666603025000156?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,2,16]],"date-time":"2026-02-16T12:37:31Z","timestamp":1771245451000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S2666603025000156"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":90,"alternative-id":["S2666603025000156"],"URL":"https:\/\/doi.org\/10.1016\/j.ijin.2025.09.001","relation":{},"ISSN":["2666-6030"],"issn-type":[{"value":"2666-6030","type":"print"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"MIDES: A multi-layer Intrusion Detection System using ensemble machine learning","name":"articletitle","label":"Article Title"},{"value":"International Journal of Intelligent Networks","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.ijin.2025.09.001","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2025 The Authors. Publishing services by Elsevier B.V. on behalf of KeAi Communications Co. Ltd.","name":"copyright","label":"Copyright"}]}}