{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T17:04:51Z","timestamp":1782320691975,"version":"3.54.5"},"reference-count":49,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Knowledge-Based Systems"],"published-print":{"date-parts":[[2026,9]]},"DOI":"10.1016\/j.knosys.2026.116483","type":"journal-article","created":{"date-parts":[[2026,6,18]],"date-time":"2026-06-18T16:40:23Z","timestamp":1781800823000},"page":"116483","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["ProtoZero: An adaptive framework for unknown attack detection via macro\u2013micro graph learning"],"prefix":"10.1016","volume":"349","author":[{"given":"Congheng","family":"Hu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Huaxin","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Junwei","family":"Du","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Junjie","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jiapeng","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jun","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Minglai","family":"Shao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.knosys.2026.116483_b1","article-title":"Standard feature sets for network intrusion detection systems: A comparative study","volume":"198","author":"Sarhan","year":"2022","journal-title":"J. Netw. Comput. Appl."},{"issue":"2","key":"10.1016\/j.knosys.2026.116483_b2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3565973","article-title":"Graph neural networks in iot: A survey","volume":"19","author":"Dong","year":"2023","journal-title":"ACM Trans. Sens. Networks"},{"issue":"5","key":"10.1016\/j.knosys.2026.116483_b3","doi-asserted-by":"crossref","first-page":"6062","DOI":"10.1109\/JIOT.2025.3525494","article-title":"Transformer-based intrusion detection for iot networks","volume":"12","author":"Akuthota","year":"2025","journal-title":"IEEE Internet Things J."},{"key":"10.1016\/j.knosys.2026.116483_b4","article-title":"Low-and-slow DDoS attacks detection and mitigation: A survey","author":"Raza","year":"2019","journal-title":"IEEE Commun. Surv. Tuts."},{"key":"10.1016\/j.knosys.2026.116483_b5","unstructured":"J. Zhang, et al., Triage: A graph-based approach for fast and accurate network intrusion detection, in: Proc. IEEE ICDM, 2019."},{"key":"10.1016\/j.knosys.2026.116483_b6","unstructured":"M. Roesch, Snort: Lightweight intrusion detection for networks, in: Proc. 13th USENIX Conf. Syst. Admin., LISA, 1999, pp. 229\u2013238."},{"key":"10.1016\/j.knosys.2026.116483_b7","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.103821","article-title":"A survey on graph neural networks for intrusion detection systems: methods, trends and challenges","author":"Zhong","year":"2024","journal-title":"Comput. Secur."},{"key":"10.1016\/j.knosys.2026.116483_b8","unstructured":"Y. Li, et al., FlowGNN: A graph neural network-based approach for network traffic classification, in: Proc. IEEE GLOBECOM, 2020."},{"issue":"5","key":"10.1016\/j.knosys.2026.116483_b9","doi-asserted-by":"crossref","first-page":"2894","DOI":"10.1109\/TNSE.2022.3184975","article-title":"Intrusion detection of industrial internet-of-things based on reconstructed graph neural networks","volume":"10","author":"Zhang","year":"2023","journal-title":"IEEE Trans. Netw. Sci. Eng."},{"key":"10.1016\/j.knosys.2026.116483_b10","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.104210","article-title":"Pdgat-id: An intrusion detection method for industrial control systems based on periodic extraction and spatiotemporal graph attention","volume":"149","author":"Zhang","year":"2025","journal-title":"Comput. Secur."},{"issue":"1","key":"10.1016\/j.knosys.2026.116483_b11","doi-asserted-by":"crossref","first-page":"42","DOI":"10.1007\/s11227-024-06471-5","article-title":"E-gracl: an iot intrusion detection system based on graph neural networks","volume":"81","author":"Lin","year":"2025","journal-title":"J. Supercomput."},{"key":"10.1016\/j.knosys.2026.116483_b12","first-page":"573","article-title":"Gat-sffs: A novel feature selection method using graph attention networks and sequential forward approach for machine learning-based iot intrusion detection system","volume":"vol. 2","author":"Pham","year":"2024"},{"key":"10.1016\/j.knosys.2026.116483_b13","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2024.110495","article-title":"Applying self-supervised learning to network intrusion detection for network flows with graph neural network","volume":"248","author":"Xu","year":"2024","journal-title":"Comput. Netw."},{"key":"10.1016\/j.knosys.2026.116483_b14","article-title":"Mr-did: Multi-relational graph neural network with adaptive structural entropy optimization for dynamic intrusion detection","author":"Gao","year":"2025","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.knosys.2026.116483_b15","unstructured":"J. Snell, et al., Prototypical networks for few-shot learning, in: Proc. NeurIPS, 2017."},{"key":"10.1016\/j.knosys.2026.116483_b16","unstructured":"Z. Li, et al., Global-local knowledge distillation for zero-shot learning, in: Proc. IEEE Conf. Comput. Vis. Pattern Recog., CVPR, 2020, pp. 1755\u20131764."},{"key":"10.1016\/j.knosys.2026.116483_b17","doi-asserted-by":"crossref","unstructured":"A. Bendale, T. Boult, Towards open set deep networks, in: Proc. IEEE CVPR, 2016, pp. 1563\u20131572.","DOI":"10.1109\/CVPR.2016.173"},{"key":"10.1016\/j.knosys.2026.116483_b18","doi-asserted-by":"crossref","DOI":"10.1016\/j.measurement.2019.107450","article-title":"Robust detection for network intrusion of industrial iot based on multi-CNN fusion","volume":"154","author":"Li","year":"2020","journal-title":"Measurement"},{"issue":"1","key":"10.1016\/j.knosys.2026.116483_b19","doi-asserted-by":"crossref","first-page":"15498","DOI":"10.1038\/s41598-022-18936-9","article-title":"Iot malware detection architecture using a novel channel boosted and squeezed cnn","volume":"12","author":"Asam","year":"2022","journal-title":"Sci. Rep."},{"key":"10.1016\/j.knosys.2026.116483_b20","article-title":"Deep recurrent neural network for iot intrusion detection system","volume":"101","author":"Almiani","year":"2020","journal-title":"Simul. Model. Pr. Theory"},{"issue":"3","key":"10.1016\/j.knosys.2026.116483_b21","doi-asserted-by":"crossref","first-page":"129","DOI":"10.1007\/s12083-025-01944-7","article-title":"Network security based combined cnn-rnn models for iot intrusion detection system","volume":"18","author":"Jablaoui","year":"2025","journal-title":"Peer-To-Peer Netw. Appl."},{"key":"10.1016\/j.knosys.2026.116483_b22","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2025.127547","article-title":"Resnet-swin transformer based intrusion detection system for in-vehicle network","volume":"279","author":"Wu","year":"2025","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.knosys.2026.116483_b23","article-title":"Federated learning based on two-stage knowledge distillation for intrusion detection in industrial iot","author":"Zhou","year":"2025","journal-title":"Expert Syst. Appl."},{"issue":"1","key":"10.1016\/j.knosys.2026.116483_b24","article-title":"A contrastive learning and knowledge distillation-based framework for efficient federated intrusion detection in iot","volume":"13","author":"Ma","year":"2025","journal-title":"Syst. Sci. Control. Eng."},{"key":"10.1016\/j.knosys.2026.116483_b25","unstructured":"F. Alshehri, et al., Deep Transfer Learning-Based Intrusion Detection System in 5G Networks, in: Proc. IEEE Conference Publication, 2023."},{"key":"10.1016\/j.knosys.2026.116483_b26","article-title":"Applying transfer learning approaches for intrusion detection in software-defined networking","author":"Chen","year":"2023","journal-title":"MDPI Sustain."},{"key":"10.1016\/j.knosys.2026.116483_b27","unstructured":"S. Wang, et al., A Study on Transfer Learning TinyML-Based Intrusion Detection Framework on IoT Devices, in: Proc. IEEE Xplore, 2025."},{"key":"10.1016\/j.knosys.2026.116483_b28","unstructured":"A. Gueriani, et al., A Transfer Learning Based Intrusion Detection System for Internet of Vehicles, in: Proc. IEEE Xplore, 2023."},{"key":"10.1016\/j.knosys.2026.116483_b29","article-title":"A federated deep transfer learning algorithm for intrusion detection","author":"Liu","year":"2024","journal-title":"IGI Glob."},{"key":"10.1016\/j.knosys.2026.116483_b30","unstructured":"Z. Li, et al., An Online Transfer Learning Model for Intrusion Detection using FT-Transformer and KSWIN-Driven Concept Drift Detection Mechanism, in: Proc. IEEE Xplore, 2024."},{"key":"10.1016\/j.knosys.2026.116483_b31","doi-asserted-by":"crossref","unstructured":"Y. Mirsky, et al., Kitsune: An ensemble of autoencoders for online network intrusion detection, in: Proc. NDSS, 2018.","DOI":"10.14722\/ndss.2018.23204"},{"key":"10.1016\/j.knosys.2026.116483_b32","article-title":"A lightweight iot intrusion detection model based on improved bert-of-theseus","volume":"238","author":"Wang","year":"2024","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.knosys.2026.116483_b33","unstructured":"M.S. Ahmad, Optimizing Large Language Models for Network Intrusion Detection Systems, (MSc Thesis), University of Windsor, p. 2025."},{"key":"10.1016\/j.knosys.2026.116483_b34","unstructured":"S. Chen, et al., Evaluating Large Language Models for Enhanced Intrusion Detection in Internet of Things Networks, in: 2024 IEEE Global Communications Conference, GLOBECOM, 2024, pp. 1\u20136."},{"key":"10.1016\/j.knosys.2026.116483_b35","article-title":"Reinforcement-learning-based intrusion detection in communication networks: A review","author":"Kheddar","year":"2024","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"10.1016\/j.knosys.2026.116483_b36","unstructured":"A. Guterman, et al., GNN-RL: Dynamic Reward Mechanism for Connected Vehicle Security using Graph Neural Networks and Reinforcement Learning, in: Proc. IEEE Xplore, 2023."},{"key":"10.1016\/j.knosys.2026.116483_b37","unstructured":"S. Roy, et al., A Hybrid Graph Neural Network-Based Reinforcement Learning Approach for Adaptive Cybersecurity Risk Management in FinTech, in: Proc. IEEE Conference Publication, 2025."},{"key":"10.1016\/j.knosys.2026.116483_b38","unstructured":"J. Kumar, et al., Methodology Review: Intrusion Detection in Cybersecurity - A Study on Explainable Graphical Reinforcement Learning, in: Proc. IEEE Xplore, 2026."},{"key":"10.1016\/j.knosys.2026.116483_b39","unstructured":"M. Alghamdi, et al., Explainable Al-Driven Intrusion Detection System for DoS Attack Classification Using Deep Learning and Optimization Techniques, in: Proc. IEEE Xplore, 2026."},{"key":"10.1016\/j.knosys.2026.116483_b40","article-title":"E-GraphSAGE: A graph neural network based intrusion detection system","author":"Zhou","year":"2023","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.knosys.2026.116483_b41","first-page":"245","article-title":"Adversarial robustness of graph neural networks for power system state estimation","volume":"18","author":"He","year":"2023","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"1","key":"10.1016\/j.knosys.2026.116483_b42","article-title":"Graph contrastive learning for anomaly detection","volume":"35","author":"Liu","year":"2023","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"10.1016\/j.knosys.2026.116483_b43","doi-asserted-by":"crossref","unstructured":"S. Vaze, K. Han, A. Vedaldi, A. Zisserman, Generalized category discovery, in: Proc. IEEE\/CVF Conf. Comput. Vis. Pattern Recog., CVPR, 2022, pp. 7492\u20137501.","DOI":"10.1109\/CVPR52688.2022.00734"},{"key":"10.1016\/j.knosys.2026.116483_b44","doi-asserted-by":"crossref","unstructured":"I. Sharafaldin, et al., Toward generating a new intrusion detection dataset and intrusion traffic characterization, in: Proc. 4th Int. Conf. Inf. Syst. Secur. Privacy, ICISSP, 2018.","DOI":"10.5220\/0006639801080116"},{"key":"10.1016\/j.knosys.2026.116483_b45","unstructured":"I. Sharafaldin, et al., Developing a comprehensive dataset for intrusion detection systems: CSE-CIC-IDS2018, in: Proc. IEEE Int. Conf. Commun., ICC, 2019."},{"key":"10.1016\/j.knosys.2026.116483_b46","unstructured":"P. Veli\u010dkovi\u0107, et al., Graph attention networks, in: Proc. ICLR, 2018."},{"key":"10.1016\/j.knosys.2026.116483_b47","unstructured":"W.L. Hamilton, et al., Inductive representation learning on large graphs, in: Proc. NeurIPS, 2017."},{"key":"10.1016\/j.knosys.2026.116483_b48","doi-asserted-by":"crossref","unstructured":"H. Wang, Y. Wang, Y. Zhou, Zero-shot recognition via semantic embeddings and knowledge graphs, in: Proc. IEEE Conf. Comput. Vis. Pattern Recog., CVPR, 2018, pp. 6857\u20136866.","DOI":"10.1109\/CVPR.2018.00717"},{"key":"10.1016\/j.knosys.2026.116483_b49","series-title":"ICT Express","article-title":"A robust cross-domain IDS using bigat-ID for medical and industrial IoT security","author":"Gueriani","year":"2025"}],"container-title":["Knowledge-Based Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0950705126012098?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0950705126012098?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T16:23:12Z","timestamp":1782318192000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0950705126012098"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,9]]},"references-count":49,"alternative-id":["S0950705126012098"],"URL":"https:\/\/doi.org\/10.1016\/j.knosys.2026.116483","relation":{},"ISSN":["0950-7051"],"issn-type":[{"value":"0950-7051","type":"print"}],"subject":[],"published":{"date-parts":[[2026,9]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"ProtoZero: An adaptive framework for unknown attack detection via macro\u2013micro graph learning","name":"articletitle","label":"Article Title"},{"value":"Knowledge-Based Systems","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.knosys.2026.116483","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"116483"}}