{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T14:21:33Z","timestamp":1783088493362,"version":"3.54.6"},"reference-count":56,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100011757","name":"SNS Nordic Forest Research","doi-asserted-by":"publisher","award":["101095363"],"award-info":[{"award-number":["101095363"]}],"id":[{"id":"10.13039\/501100011757","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100023354","name":"Deputy Ministry of Research, Innovation and Digital Policy","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100023354","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100010661","name":"Horizon 2020 Framework Programme","doi-asserted-by":"publisher","award":["739578"],"award-info":[{"award-number":["739578"]}],"id":[{"id":"10.13039\/100010661","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Journal of Information Security and Applications"],"published-print":{"date-parts":[[2026,7]]},"DOI":"10.1016\/j.jisa.2026.104496","type":"journal-article","created":{"date-parts":[[2026,5,10]],"date-time":"2026-05-10T00:08:10Z","timestamp":1778371690000},"page":"104496","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["Adaptive active-defense hardening of ML-based NIDS against RL-driven adversaries: A comparative analysis with static defenses"],"prefix":"10.1016","volume":"100","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1562-5543","authenticated-orcid":false,"given":"Iacovos","family":"Ioannou","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christophoros","family":"Christophorou","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Andreas","family":"Andreou","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1513-6018","authenticated-orcid":false,"given":"Marios","family":"Raspopoulos","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Constandinos","family":"Mavromoustakis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Vasos","family":"Vassiliou","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2439-277X","authenticated-orcid":false,"given":"Fabrizio","family":"Granelli","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"issue":"1","key":"10.1016\/j.jisa.2026.104496_bib0001","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1016\/j.jnca.2012.09.004","article-title":"Intrusion detection system: a comprehensive review","volume":"36","author":"Liao","year":"2013","journal-title":"J Netw Comput Appl"},{"issue":"4","key":"10.1016\/j.jisa.2026.104496_bib0002","first-page":"3583","article-title":"A comprehensive survey on machine learning for network intrusion detection","volume":"21","author":"Garg","year":"2019","journal-title":"IEEE Commun Surv Tutor"},{"key":"10.1016\/j.jisa.2026.104496_bib0003","unstructured":"Goodfellow I.J., Shlens J., Szegedy C.. Explaining and harnessing adversarial examples. 2014;. arXiv preprint arXiv:arXiv: 14126572."},{"key":"10.1016\/j.jisa.2026.104496_bib0004","series-title":"Proceedings of the 2017 ACM on Asia conference on computer and communications security","first-page":"506","article-title":"Practical black-box attacks against machine learning","author":"Papernot","year":"2017"},{"key":"10.1016\/j.jisa.2026.104496_bib0005","series-title":"Moving Target Defense: Creating Asymmetric Uncertainty for Cyber Threats","author":"Jajodia","year":"2011"},{"key":"10.1016\/j.jisa.2026.104496_bib0006","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103546","article-title":"Apollon: a robust defense system against adversarial machine learning attacks in intrusion detection systems","volume":"136","author":"Paya","year":"2024","journal-title":"Comput Secur"},{"key":"10.1016\/j.jisa.2026.104496_bib0007","series-title":"Backdoor adversarial machine learning attack on graph convolutional networks for IoMT traffic misclassification","isbn-type":"print","doi-asserted-by":"crossref","first-page":"174","DOI":"10.1007\/978-3-031-95652-2_16","author":"Georgiades","year":"2025","ISBN":"https:\/\/id.crossref.org\/isbn\/9783031956515"},{"issue":"1","key":"10.1016\/j.jisa.2026.104496_bib0008","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1023\/A:1010933404324","article-title":"Random forests","volume":"45","author":"Breiman","year":"2001","journal-title":"Mach Learn"},{"key":"10.1016\/j.jisa.2026.104496_bib0009","series-title":"Proceedings of the 22nd ACM SIGKDD international conference on knowledge discovery and data mining","first-page":"785","article-title":"XGBoost: A scalable tree boosting system","author":"Chen","year":"2016"},{"key":"10.1016\/j.jisa.2026.104496_bib0010","doi-asserted-by":"crossref","first-page":"41525","DOI":"10.1109\/ACCESS.2019.2895334","article-title":"Deep learning approach for intelligent intrusion detection system","volume":"7","author":"Vinayakumar","year":"2019","journal-title":"IEEE Access"},{"key":"10.1016\/j.jisa.2026.104496_bib0011","series-title":"Advances in neural information processing systems 27","article-title":"Generative adversarial nets","author":"Goodfellow","year":"2014"},{"key":"10.1016\/j.jisa.2026.104496_bib0012","series-title":"Information processing in medical imaging","first-page":"146","article-title":"Unsupervised anomaly detection with generative adversarial networks to guide marker discovery","volume":"Vol. 10265","author":"Schlegl","year":"2017"},{"key":"10.1016\/j.jisa.2026.104496_bib0013","doi-asserted-by":"crossref","first-page":"279","DOI":"10.1109\/TIFS.2024.3516548","article-title":"Global or local adaptation? Client-sampled federated meta-learning for personalized IoT intrusion detection","volume":"20","author":"Yan","year":"2025","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"10.1016\/j.jisa.2026.104496_bib0014","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.103928","article-title":"A sequential deep learning framework for a robust and resilient network intrusion detection system","volume":"144","author":"Hore","year":"2024","journal-title":"Comput Secur"},{"key":"10.1016\/j.jisa.2026.104496_bib0015","doi-asserted-by":"crossref","DOI":"10.1109\/ACCESS.2025.3585445","article-title":"Adaptive defense: zero-day attack detection in NIDS with deep reinforcement learning","author":"Alam","year":"2025","journal-title":"IEEE Access"},{"key":"10.1016\/j.jisa.2026.104496_bib0016","unstructured":"Szegedy C., Zaremba W., Sutskever I., Bruna J., Erhan D., Goodfellow I., et al. Intriguing properties of neural networks, 2013. arXiv preprint arXiv:arXiv: 13126199."},{"key":"10.1016\/j.jisa.2026.104496_bib0017","unstructured":"Madry A., Makelov A., Schmidt L., Tsipras D., Vladu A.. Towards deep learning models resistant to adversarial attacks, 2017. arXiv preprint arXiv:arXiv: 170606083."},{"key":"10.1016\/j.jisa.2026.104496_bib0018","series-title":"2018 IEEE Military communications conference (MILCOM)","first-page":"1","article-title":"Towards deep-learning-based malware-traffic-detection that is resilient to adversarial attacks","author":"Anderson","year":"2018"},{"key":"10.1016\/j.jisa.2026.104496_bib0019","series-title":"Proceedings of the AAAI conference on artificial intelligence","article-title":"Deep reinforcement learning with double Q-learning","volume":"Vol. 30","author":"Van Hasselt","year":"2016"},{"key":"10.1016\/j.jisa.2026.104496_bib0020","series-title":"Proceedings of the 35th international conference on machine learning","first-page":"1861","article-title":"Soft actor-critic: off-policy maximum entropy deep reinforcement learning with a stochastic actor","author":"Haarnoja","year":"2018"},{"key":"10.1016\/j.jisa.2026.104496_bib0021","unstructured":"Schulman J., Wolski F., Dhariwal P., Radford A., Klimov O.. Proximal policy optimization algorithms, 2017. arXiv preprint arXiv:arXiv: 170706347."},{"key":"10.1016\/j.jisa.2026.104496_bib0022","series-title":"Proceedings of the 33rd international conference on machine learning","first-page":"1928","article-title":"Asynchronous methods for deep reinforcement learning","author":"Mnih","year":"2016"},{"key":"10.1016\/j.jisa.2026.104496_bib0023","doi-asserted-by":"crossref","first-page":"5476","DOI":"10.1109\/TIFS.2024.3402155","article-title":"ProGen: projection-based adversarial attack generation against network intrusion detection","volume":"19","author":"Wang","year":"2024","journal-title":"IEEE Trans Inf Forensics Secur"},{"issue":"13","key":"10.1016\/j.jisa.2026.104496_bib0024","doi-asserted-by":"crossref","first-page":"10327","DOI":"10.1109\/JIOT.2020.3048038","article-title":"Adversarial attacks against network intrusion detection in IoT systems","volume":"8","author":"Qiu","year":"2021","journal-title":"IEEE Internet Things J"},{"issue":"3","key":"10.1016\/j.jisa.2026.104496_bib0025","doi-asserted-by":"crossref","first-page":"2295","DOI":"10.1109\/TNSM.2022.3173933","article-title":"Sneaking through security: mutating live network traffic to evade learning-based NIDS","volume":"19","author":"Tan","year":"2022","journal-title":"IEEE Trans Netw Serv Manag"},{"key":"10.1016\/j.jisa.2026.104496_bib0026","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103176","article-title":"Adv-Bot: realistic adversarial botnet attacks against network intrusion detection systems","volume":"129","author":"Debicha","year":"2023","journal-title":"Comput Secur"},{"key":"10.1016\/j.jisa.2026.104496_bib0027","doi-asserted-by":"crossref","first-page":"148613","DOI":"10.1109\/ACCESS.2025.3600984","article-title":"Adversarial challenges in network intrusion detection systems: research insights and future prospects","volume":"13","author":"Ennaji","year":"2025","journal-title":"IEEE Access"},{"key":"10.1016\/j.jisa.2026.104496_bib0028","series-title":"Proceedings of the 2020 ACM SIGSAC conference on cloud computing security workshop","first-page":"27","article-title":"TIKI-TAKA: attacking and defending deep learning-based intrusion detection systems","author":"Zhang","year":"2020"},{"key":"10.1016\/j.jisa.2026.104496_bib0029","doi-asserted-by":"crossref","unstructured":"Rivas E., Saika S., Bakht A., Piplai A., Bastian N.D., Shah A.. Adapting under fire: Multi-agent reinforcement learning for adversarial drift in network security, 2025. arXiv preprint arXiv:arXiv: 250606565.","DOI":"10.5220\/0013640900003979"},{"issue":"1","key":"10.1016\/j.jisa.2026.104496_bib0030","doi-asserted-by":"crossref","first-page":"538","DOI":"10.1109\/COMST.2022.3233793","article-title":"Adversarial machine learning for network intrusion detection systems: a comprehensive survey","volume":"25","author":"He","year":"2023","journal-title":"IEEE Commun Surv Tutor"},{"key":"10.1016\/j.jisa.2026.104496_bib0031","unstructured":"Lin Z., Shi Y., Xue Z.. IDSGAN: Generative adversarial networks for attack generation against intrusion detection, 2018. arXiv preprint arXiv:arXiv: 180902077."},{"key":"10.1016\/j.jisa.2026.104496_bib0032","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2021.115782","article-title":"Adversarial machine learning in network intrusion detection systems","volume":"186","author":"Alhajjar","year":"2021","journal-title":"Expert Syst Appl"},{"issue":"3","key":"10.1016\/j.jisa.2026.104496_bib0033","first-page":"31:1","article-title":"Modeling realistic adversarial attacks against network intrusion detection systems","volume":"3","author":"Apruzzese","year":"2022","journal-title":"Digit Threats Res Pract"},{"key":"10.1016\/j.jisa.2026.104496_bib0034","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2022.109073","article-title":"Adversarial machine learning for network intrusion detection: a comparative study","volume":"214","author":"Jmila","year":"2022","journal-title":"Comput Netw"},{"key":"10.1016\/j.jisa.2026.104496_bib0035","series-title":"2016 IEEE Symposium on security and privacy (SP)","first-page":"582","article-title":"Distillation as a defense to adversarial perturbations against deep neural networks","author":"Papernot","year":"2016"},{"key":"10.1016\/j.jisa.2026.104496_bib0036","series-title":"2024 IEEE 23rd international conference on trust, security and privacy in computing and communications (trustcom)","first-page":"2436","article-title":"A defensive framework against adversarial attacks on machine learning-based network intrusion detection systems","author":"Tafreshian","year":"2024"},{"key":"10.1016\/j.jisa.2026.104496_bib0037","doi-asserted-by":"crossref","DOI":"10.1038\/s41598-025-94023-z","article-title":"An enhanced ensemble defense framework for boosting adversarial robustness of intrusion detection systems","volume":"15","author":"Awad","year":"2025","journal-title":"Sci Rep"},{"key":"10.1016\/j.jisa.2026.104496_bib0038","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2024.123567","article-title":"Boosting robustness of network intrusion detection systems: a novel two phase defense strategy against untargeted white-box optimization adversarial attack","volume":"249","author":"Roshan","year":"2024","journal-title":"Expert Syst Appl"},{"key":"10.1016\/j.jisa.2026.104496_bib0039","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2025.126513","article-title":"NIDS-DA: Detecting functionally preserved adversarial examples for network intrusion detection system using deep autoencoders","volume":"270","author":"Kumar","year":"2025","journal-title":"Expert Syst Appl"},{"issue":"1","key":"10.1016\/j.jisa.2026.104496_bib0040","doi-asserted-by":"crossref","first-page":"67","DOI":"10.1007\/s43926-025-00161-1","article-title":"Enhancing network slice security with deep reinforcement learning and moving target defense strategies","volume":"5","author":"Andreou","year":"2025","journal-title":"Discov Internet Things"},{"issue":"16","key":"10.1016\/j.jisa.2026.104496_bib0041","doi-asserted-by":"crossref","first-page":"3249","DOI":"10.3390\/electronics14163249","article-title":"Enhancing adversarial robustness in network intrusion detection: a novel adversarially trained neural network approach","volume":"14","author":"Heydari","year":"2025","journal-title":"Electronics"},{"issue":"3","key":"10.1016\/j.jisa.2026.104496_bib0042","doi-asserted-by":"crossref","first-page":"1294","DOI":"10.1109\/TNET.2021.3137084","article-title":"Adversarial attacks against deep learning-based network intrusion detection systems and defense mechanisms","volume":"30","author":"Zhang","year":"2022","journal-title":"IEEE\/ACM Trans Netw"},{"key":"10.1016\/j.jisa.2026.104496_bib0043","doi-asserted-by":"crossref","unstructured":"Pearson K.. LIII. on lines and planes of closest fit to systems of points in space. In: The London, Edinburgh, and Dublin Philosophical Magazine and Journal of Science1901; 2(11):559\u2013572. 10.1080\/14786440109462720.","DOI":"10.1080\/14786440109462720"},{"key":"10.1016\/j.jisa.2026.104496_bib0044","unstructured":"Kingma D.P., Ba J.. Adam: a method for stochastic optimization, 2014. arXiv preprint arXiv:arXiv: 14126980."},{"key":"10.1016\/j.jisa.2026.104496_bib0045","series-title":"Proceedings of the IEEE international conference on computer vision (ICCV)","first-page":"1026","article-title":"Delving deep into rectifiers: surpassing human-level performance on imagenet classification","author":"He","year":"2015"},{"key":"10.1016\/j.jisa.2026.104496_bib0046","article-title":"DReLAB \u2013 deep REinforcement learning adversarial botnet: a benchmark dataset for adversarial attacks against botnet intrusion detection systems","volume":"34","author":"Venturi","year":"2021","journal-title":"Data Br"},{"key":"10.1016\/j.jisa.2026.104496_bib0047","series-title":"2020 IEEE international conference on big data (Big data)","first-page":"3173","article-title":"Explainable data drift detection","author":"Carletti","year":"2020"},{"key":"10.1016\/j.jisa.2026.104496_bib0048","series-title":"2022 IEEE Conference on communications and network security (CNS)","isbn-type":"print","doi-asserted-by":"crossref","first-page":"254","DOI":"10.1109\/CNS56114.2022.9947235","article-title":"Error prevalence in NIDS datasets: a case study on CIC-IDS-2017 and CSE-CIC-IDS-2018","author":"Liu","year":"2022","ISBN":"https:\/\/id.crossref.org\/isbn\/9781665462556"},{"key":"10.1016\/j.jisa.2026.104496_bib0049","doi-asserted-by":"crossref","first-page":"131","DOI":"10.1613\/jair.606","article-title":"Identifying mislabeled training data","volume":"11","author":"Brodley","year":"1999","journal-title":"J Artif Intell Res"},{"issue":"1","key":"10.1016\/j.jisa.2026.104496_bib0050","first-page":"119","article-title":"Statistical inference using extreme order statistics","volume":"3","author":"Pickands","year":"1975","journal-title":"Ann Stat"},{"key":"10.1016\/j.jisa.2026.104496_bib0051","series-title":"Advances in neural information processing systems 30","article-title":"Improved training of wasserstein GANs","author":"Gulrajani","year":"2017"},{"key":"10.1016\/j.jisa.2026.104496_bib0052","unstructured":"O\u2019Malley T., Bursztein E., Long J., Chollet F., Jin H., Invernizzi L., et al. KerasTuner. https:\/\/github.com\/keras-team\/keras-tuner; 2019. GitHub repository, accessed 2026-03-11."},{"key":"10.1016\/j.jisa.2026.104496_bib0053","series-title":"Advances in neural information processing systems 30","article-title":"A unified approach to interpreting model predictions","author":"Lundberg","year":"2017"},{"key":"10.1016\/j.jisa.2026.104496_bib0054","unstructured":"ONNX Community. ONNX: open neural network exchange. https:\/\/onnx.ai\/; 2019. Project website, accessed 2026-03-11."},{"issue":"4","key":"10.1016\/j.jisa.2026.104496_bib0055","doi-asserted-by":"crossref","first-page":"115","DOI":"10.1007\/BF02478259","article-title":"A logical calculus of the ideas immanent in nervous activity","volume":"5","author":"McCulloch","year":"1943","journal-title":"Bull Math Biophys"},{"issue":"2","key":"10.1016\/j.jisa.2026.104496_bib0056","doi-asserted-by":"crossref","first-page":"442","DOI":"10.1016\/0005-2795(75)90109-9","article-title":"Comparison of the predicted and observed secondary structure of T4 phage lysozyme","volume":"405","author":"Matthews","year":"1975","journal-title":"Biochim Biophys Acta \u2013 Protein Struct"}],"container-title":["Journal of Information Security and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2214212626001262?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2214212626001262?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T13:39:07Z","timestamp":1783085947000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S2214212626001262"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7]]},"references-count":56,"alternative-id":["S2214212626001262"],"URL":"https:\/\/doi.org\/10.1016\/j.jisa.2026.104496","relation":{},"ISSN":["2214-2126"],"issn-type":[{"value":"2214-2126","type":"print"}],"subject":[],"published":{"date-parts":[[2026,7]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Adaptive active-defense hardening of ML-based NIDS against RL-driven adversaries: A comparative analysis with static defenses","name":"articletitle","label":"Article Title"},{"value":"Journal of Information Security and Applications","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.jisa.2026.104496","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"104496"}}