{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T23:10:25Z","timestamp":1780441825333,"version":"3.54.1"},"reference-count":74,"publisher":"Oxford University Press (OUP)","issue":"6","license":[{"start":{"date-parts":[[2024,2,11]],"date-time":"2024-02-11T00:00:00Z","timestamp":1707609600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/academic.oup.com\/pages\/standard-publication-reuse-rights"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024,6,24]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>Ensuring the security of computer networks is of utmost importance, and intrusion detection plays a vital role in safeguarding these systems. Traditional intrusion detection systems (IDSs) often suffer from drawbacks like reliance on outdated rules and centralized architectures, limiting their performance in the face of evolving threats and large-scale data networks. To address these challenges, we present an advanced anomaly detection-based IDS that utilizes a decentralized communicative multi-agent reinforcement learning (MARL). In our approach, multiple reinforcement learning agents collaborate in intrusion detection, effectively mitigating the non-stationarity problem and introducing a specialized secure communication method. We further enhance the learning process by incorporating external knowledge. Our approach is evaluated through extensive experiments conducted on the benchmark NSL Knowledge Discovery and Data Mining dataset. These experiments encompass diverse scenarios, involving varying numbers of agents to prove scalability feature. The results underscore the effectiveness of our method, which surpasses the performance of existing state-of-the-art solutions based on MARL, achieving a high accuracy rate of 97.80%.<\/jats:p>","DOI":"10.1093\/comjnl\/bxae008","type":"journal-article","created":{"date-parts":[[2024,2,12]],"date-time":"2024-02-12T09:49:25Z","timestamp":1707731365000},"page":"2317-2330","source":"Crossref","is-referenced-by-count":13,"title":["An Intelligent Security System Using Enhanced Anomaly-Based Detection Scheme"],"prefix":"10.1093","volume":"67","author":[{"given":"Faten","family":"Louati","sequence":"first","affiliation":[{"name":"FSEG , University of Sfax, Tunisia, MIRACL laboratory"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Farah","family":"Barika Ktata","sequence":"additional","affiliation":[{"name":"ISSATSo , University of Sousse, Tunisia, MIRACL laboratory"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ikram","family":"Amous","sequence":"additional","affiliation":[{"name":"Enet\u2019com , University of Sfax, Tunisia, MIRACL laboratory"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"286","published-online":{"date-parts":[[2024,2,11]]},"reference":[{"key":"2024062414161544200_ref1","doi-asserted-by":"crossref","first-page":"100449","DOI":"10.1016\/j.ijcip.2021.100449","article-title":"A homogeneous ensemble based dynamic artificial neural network for solving the intrusion detection problem","volume":"34","author":"Al-Daweri","year":"2021","journal-title":"Int. J. Crit. Infrastruct. Prot."},{"key":"2024062414161544200_ref2","doi-asserted-by":"crossref","first-page":"675","DOI":"10.1007\/s42452-020-2414-z","article-title":"A deep learning-based multi-agent system for intrusion detection","volume":"2","author":"Louati","year":"2020","journal-title":"SN Appl. Sci."},{"key":"2024062414161544200_ref3","doi-asserted-by":"crossref","first-page":"107810","DOI":"10.1016\/j.compeleceng.2022.107810","article-title":"Anomaly-based intrusion detection system for IoT networks through deep learning model","volume":"99","author":"Saba","year":"2022","journal-title":"Comput. Electr. Eng."},{"key":"2024062414161544200_ref4","first-page":"252","article-title":"A simulation framework for IoT networks intrusion and penetration testing","volume-title":"Digital Technologies and Applications","author":"Ben Kalboussi"},{"key":"2024062414161544200_ref5","first-page":"1004","article-title":"An efficient real time intrusion detection system for Big Data environment","volume-title":"Proceedings of the 15th International Conference on Agents and Artificial Intelligence, ICAART 2023","author":"Louati"},{"key":"2024062414161544200_ref6","doi-asserted-by":"crossref","first-page":"6081","DOI":"10.1007\/s13369-020-04476-9","article-title":"A modified multi-objective particle swarm optimizer-based L\u00e9vy flight: an approach toward intrusion detection in internet of things","volume":"45","author":"Habib","year":"2020","journal-title":"Arab. J. Sci. Eng."},{"key":"2024062414161544200_ref7","doi-asserted-by":"crossref","first-page":"101964","DOI":"10.1016\/j.artmed.2020.101964","article-title":"Reinforcement learning for intelligent healthcare applications: a survey","volume":"109","author":"Coronato","year":"2020","journal-title":"Artif. Intell. Med."},{"key":"2024062414161544200_ref8","first-page":"2978","article-title":"Optimal medication dosing from suboptimal clinical examples: a deep reinforcement learning approach","volume-title":"2016 38th Annual International Conference of the IEEE Engineering in Medicine and Biology Society (EMBC)","author":"Nemati"},{"key":"2024062414161544200_ref9","first-page":"1","article-title":"A deep reinforcement learning process based on robotic training to assist mental health patients","volume":"34","author":"Altameem","journal-title":"Neural Comput. Appl."},{"key":"2024062414161544200_ref10","article-title":"Virtual to real reinforcement learning for autonomous driving","author":"You"},{"key":"2024062414161544200_ref11","first-page":"356","article-title":"Deep reinforcement learning with visual attention for vehicle classification","volume-title":"IEEE Trans. Cogn. Develop. Syst.","author":"Zhao"},{"key":"2024062414161544200_ref12","first-page":"1","article-title":"Classification of thermal image of clinical burn based on incremental reinforcement learning","author":"Wu","journal-title":"Neural Comput. Appl."},{"key":"2024062414161544200_ref13","first-page":"2488","article-title":"Active object localization with deep reinforcement learning","volume-title":"2015 IEEE International Conference on Computer Vision (ICCV)","author":"Caicedo"},{"key":"2024062414161544200_ref14","article-title":"QT-Opt: scalable deep reinforcement learning for vision-based robotic manipulation","volume-title":"Conference on Robot Learning","author":"Kalashnikov"},{"key":"2024062414161544200_ref15","doi-asserted-by":"crossref","article-title":"Asymmetric actor critic for image-based robot learning","author":"Pinto","DOI":"10.15607\/RSS.2018.XIV.008"},{"key":"2024062414161544200_ref16","doi-asserted-by":"crossref","DOI":"10.1109\/IROS.2017.8206247","article-title":"Learning to fly by crashing","volume-title":"IEEE\/RSJ International Conference on Intelligent Robots and Systems (IROS)","author":"Gandhi"},{"key":"2024062414161544200_ref17","doi-asserted-by":"crossref","first-page":"653","DOI":"10.1109\/TNNLS.2016.2522401","article-title":"Deep direct reinforcement learning for financial signal representation and trading","volume":"28","author":"Deng","year":"2017","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"2024062414161544200_ref18","first-page":"1","article-title":"Language understanding for text-based games using deep reinforcement learning","volume-title":"Proceedings of the 2015 Conference on Empirical Methods in Natural Language Processing, Lisbon, Portugal, Sep","author":"Narasimhan"},{"key":"2024062414161544200_ref19","first-page":"1621","article-title":"Deep reinforcement learning with a natural language action space","volume-title":"Proceedings of the 54th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers), Berlin, Germany, aug","author":"He"},{"key":"2024062414161544200_ref20","doi-asserted-by":"crossref","first-page":"529","DOI":"10.1038\/nature14236","article-title":"Human-level control through deep reinforcement learning","volume":"518","author":"Mnih","year":"2015","journal-title":"Nature"},{"key":"2024062414161544200_ref21","article-title":"Multi-agent reinforcement learning in Bayesian Stackelberg Markov games for adaptive moving target defense","author":"Sengupta"},{"key":"2024062414161544200_ref22","article-title":"Adversarial deep reinforcement learning based adaptive moving target defense","volume":"12513","author":"Eghtesad","journal-title":"GameSec"},{"key":"2024062414161544200_ref23","article-title":"Discover the hidden attack path in multi-domain cyberspace based on reinforcement learning","volume-title":"Sci. Program.","author":"Zhang"},{"key":"2024062414161544200_ref24","doi-asserted-by":"crossref","first-page":"102204","DOI":"10.1016\/j.cose.2021.102204","article-title":"Discovering reflected cross-site scripting vulnerabilities using a multiobjective reinforcement learning environment","volume":"103","author":"Caturano","year":"2021","journal-title":"Comput. Secur."},{"key":"2024062414161544200_ref25","first-page":"152","article-title":"A distributed intelligent intrusion detection system based on parallel machine learning and Big Data analysis","author":"Louati","journal-title":"SENSORNETS"},{"key":"2024062414161544200_ref26","first-page":"1","article-title":"Deep reinforcement learning based intrusion detection system for cloud infrastructure","volume-title":"2020 International Conference on COMmunication Systems NETworkS (COMSNETS)","author":"Sethi"},{"key":"2024062414161544200_ref27","doi-asserted-by":"crossref","first-page":"778","DOI":"10.1109\/TGCN.2021.3073714","article-title":"Intrusion detection in green internet of things: a deep deterministic policy gradient-based algorithm","volume":"5","author":"Nie","year":"2021","journal-title":"IEEE Trans. Green Commun. Netw."},{"key":"2024062414161544200_ref28","doi-asserted-by":"crossref","first-page":"2169","DOI":"10.1109\/TII.2020.3004232","article-title":"A reinforcement learning-based network traffic prediction mechanism in intelligent internet of things","volume":"17","author":"Nie","year":"2021","journal-title":"IEEE Trans. Industr. Inform."},{"key":"2024062414161544200_ref29","article-title":"Application of deep reinforcement learning to intrusion detection for supervised problems","volume":"141","author":"Mart\u00edn","year":"2020","journal-title":"Expert Syst. Appl."},{"key":"2024062414161544200_ref30","first-page":"1","article-title":"A deep reinforcement learning approach for anomaly network intrusion detection system","volume-title":"2020 IEEE 9th International Conference on Cloud Networking (CloudNet)","author":"Hsu"},{"key":"2024062414161544200_ref31","first-page":"1146","article-title":"Network intrusion detection using deep reinforcement learning","volume-title":"2023 7th International Conference on Computing Methodologies and Communication (ICCMC)","author":"Sujatha"},{"key":"2024062414161544200_ref32","first-page":"157","article-title":"Markov games as a framework for multi-agent reinforcement learning","volume-title":"Proceedings of the Eleventh International Conference on Machine Learning","author":"Littman"},{"key":"2024062414161544200_ref33","first-page":"1","article-title":"Collaborative training of heterogeneous reinforcement learning agents in environments with sparse rewards: what and when to share?","volume":"35","author":"Andres","journal-title":"Neural Comput. Appl."},{"key":"2024062414161544200_ref34","doi-asserted-by":"crossref","first-page":"96","DOI":"10.1016\/j.comnet.2019.05.013","article-title":"Adversarial environment reinforcement learning algorithm for intrusion detection","volume":"159","author":"Caminero Fern\u00e1ndez","year":"2019","journal-title":"Comput. Netw."},{"key":"2024062414161544200_ref35","article-title":"Multi-agent adversarial inverse reinforcement learning with latent variables","author":"Gruver","journal-title":"AAMAS"},{"key":"2024062414161544200_ref36","article-title":"Multi-agent adversarial inverse reinforcement learning","volume-title":"International Conference on Machine Learning","author":"Yu"},{"key":"2024062414161544200_ref37","article-title":"Multi-agent actor-critic for mixed cooperative-competitive environments","volume-title":"Advances in Neural Information Processing Systems","author":"Lowe"},{"key":"2024062414161544200_ref38","article-title":"Multi-agent reinforcement learning for networked system control","author":"Chu","journal-title":"International Conference on Learning Representations"},{"key":"2024062414161544200_ref39","first-page":"5872","article-title":"Fully decentralized multi-agent reinforcement learning with networked agents","volume-title":"Proceedings of the 35th International Conference on Machine Learning, 10\u201315 Jul, Proceedings of Machine Learning Research","author":"Zhang"},{"key":"2024062414161544200_ref40","article-title":"Learning attentional communication for multi-agent cooperation","author":"Jiang","journal-title":"NeurIPS"},{"key":"2024062414161544200_ref41","article-title":"Multiagent bidirectionally-coordinated nets: emergence of human-level coordination in learning to play starcraft combat games","author":"Peng"},{"key":"2024062414161544200_ref42","article-title":"Learning when to communicate at scale in multiagent cooperative and competitive tasks","author":"Singh"},{"key":"2024062414161544200_ref43","first-page":"1","article-title":"Multi-agent deep reinforcement learning: a survey","author":"Gronauer","journal-title":"Artif. Intell. Rev."},{"key":"2024062414161544200_ref44","article-title":"Lenient multi-agent deep reinforcement learning","author":"Palmer"},{"key":"2024062414161544200_ref45","article-title":"Likelihood quantile networks for coordinating multi-agent reinforcement learning","author":"Lyu"},{"key":"2024062414161544200_ref46","article-title":"Value-decomposition networks for cooperative multi-agent learning","author":"Sunehag"},{"key":"2024062414161544200_ref47","first-page":"7234","article-title":"Monotonic value function factorisation for deep multi-agent reinforcement learning","volume":"21","author":"Rashid","year":"2020","journal-title":"J. Mach. Learn. Res."},{"key":"2024062414161544200_ref48","first-page":"5887","article-title":"Qtran: Learning to factorize with transformation for cooperative multi-agent reinforcement learning","volume-title":"International Conference on Machine Learning","author":"Son"},{"key":"2024062414161544200_ref49","first-page":"159","article-title":"Multi-agent reinforcement learning for intrusion detection: a case study and evaluation","volume-title":"Multiagent System Technologies: 6th German Conference, MATES 2008, Kaiserslautern, Germany, September 23\u201326, 2008. Proceedings 6","author":"Servin"},{"key":"2024062414161544200_ref50","doi-asserted-by":"crossref","first-page":"1432","DOI":"10.1109\/TIFS.2018.2790382","article-title":"A game theory based collaborative security detection method for internet of things systems","volume":"13","author":"Wu","year":"2018","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"2024062414161544200_ref51","first-page":"1","article-title":"Intrusion detection system for internet of things based on a machine learning approach","volume-title":"2019 International Conference on Vision Towards Emerging Trends in Communication and Networking (ViTECoN)","author":"Liang"},{"key":"2024062414161544200_ref52","first-page":"1","article-title":"Network intrusion detection systems using adversarial reinforcement learning with deep q-network","volume-title":"2020 18th International Conference on ICT and Knowledge Engineering (ICT KE)","author":"Suwannalai"},{"key":"2024062414161544200_ref53","doi-asserted-by":"crossref","first-page":"943","DOI":"10.1109\/TNSE.2020.3004312","article-title":"AESMOTE: Adversarial Reinforcement Learning with SMOTE for anomaly detection","volume":"8","author":"Ma","year":"2021","journal-title":"IEEE Trans. Netw. Sci. Eng."},{"key":"2024062414161544200_ref54","first-page":"245","article-title":"Collaborative multi-agent reinforcement learning for intrusion detection","volume-title":"2021 7th IEEE International Conference on Network Intelligence and Digital Content (IC-NIDC)","author":"Shi"},{"key":"2024062414161544200_ref55","first-page":"102923","article-title":"Attention based multi-agent intrusion detection systems using reinforcement learning","volume":"61","author":"Sethi","year":"2021","journal-title":"J. Inf. Secur. Appl."},{"key":"2024062414161544200_ref56","doi-asserted-by":"crossref","first-page":"11089","DOI":"10.1109\/TVT.2022.3186834","article-title":"Robust enhancement of intrusion detection systems using deep reinforcement learning and stochastic game","volume":"71","author":"Benaddi","year":"2022","journal-title":"IEEE Trans. Veh. Technol."},{"key":"2024062414161544200_ref57","first-page":"772","article-title":"Improving intrusion detection systems with multi-agent deep reinforcement learning: Enhanced centralized and decentralized approaches","volume-title":"Proceedings of the 20th International Conference on Security and Cryptography - SECRYPT","author":"Bacha"},{"key":"2024062414161544200_ref58","article-title":"Learning multiagent communication with backpropagation","author":"Sukhbaatar"},{"key":"2024062414161544200_ref59","article-title":"Learning to communicate with deep multi-agent reinforcement learning","author":"Foerster","journal-title":"NIPS"},{"key":"2024062414161544200_ref60","doi-asserted-by":"crossref","first-page":"3143","DOI":"10.1007\/s00521-022-07880-4","article-title":"Mix-attention approximation for homogeneous large-scale multi-agent reinforcement learning","volume":"35","author":"Shike","year":"2023","journal-title":"Neural Comput. Appl."},{"key":"2024062414161544200_ref61","doi-asserted-by":"crossref","first-page":"449","DOI":"10.1093\/jigpal\/jzz053","article-title":"Evolutionary reinforcement learning for adaptively detecting database intrusions","volume":"28","author":"Choi","year":"2020","journal-title":"Logic J. IGPL"},{"key":"2024062414161544200_ref62","article-title":"Multi-agent deep reinforcement learning-driven mitigation of adverse effects of cyber-attacks on electric vehicle charging station","author":"Basnet"},{"key":"2024062414161544200_ref63","doi-asserted-by":"crossref","first-page":"156","DOI":"10.1109\/TSMCC.2007.913919","article-title":"A comprehensive survey of multiagent reinforcement learning","volume":"38","author":"Busoniu","year":"2008","journal-title":"IEEE Trans. Syst. Man Cybern. C (Appl. Rev.)"},{"key":"2024062414161544200_ref64","article-title":"Reinforcement learning with external knowledge and two-stage q-functions for predicting popular reddit threads","author":"He"},{"key":"2024062414161544200_ref65","article-title":"Schwing asking for knowledge: training RL agents to query external knowledge using language","author":"Liu"},{"key":"2024062414161544200_ref66","volume-title":"Deep Reinforcement Learning Boosted by External Knowledge, New York, NY, USA SAC \u201818 331\u2013338","author":"Bougie"},{"key":"2024062414161544200_ref67","article-title":"Reinforcement learning with external knowledge by using logical neural networks","author":"Kimura"},{"key":"2024062414161544200_ref68","article-title":"Emergence of language with multi-agent games: learning to communicate with sequences of symbols","volume":"30","author":"Havrylov","year":"2008","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"2024062414161544200_ref69","article-title":"Learning attentional communication for multi-agent cooperation","volume":"31","author":"Jiang","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"2024062414161544200_ref70","article-title":"Parameter sharing deep deterministic policy gradient for cooperative multi-agent reinforcement learning","author":"Chu"},{"key":"2024062414161544200_ref71","article-title":"Recent advances on federated learning for cybersecurity and cybersecurity for federated learning for internet of things","volume":"9","author":"Ghimire","journal-title":"IEEE Internet of Things Journal"},{"key":"2024062414161544200_ref72","article-title":"Communication-efficient learning of deep networks from decentralized data","author":"Brendan McMahan"},{"key":"2024062414161544200_ref73","doi-asserted-by":"crossref","first-page":"657","DOI":"10.1007\/s10207-019-00482-7","article-title":"A context-aware robust intrusion detection system: a reinforcement learning-based approach","volume":"19","author":"Sethi","year":"2020","journal-title":"Int. J. Inf. Sec."},{"key":"2024062414161544200_ref74","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-030-52988-8_7","article-title":"A deep reinforcement learning based intrusion detection system (DRL-IDS) for securing wireless sensor networks and internet of things","volume-title":"Wireless Internet: 12th EAI International Conference, WiCON 2019, TaiChung, Taiwan, November 26\u201327, 2019, Proceedings","author":"Benaddi"}],"container-title":["The Computer Journal"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/67\/6\/2317\/58309298\/bxae008.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/67\/6\/2317\/58309298\/bxae008.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,6,24]],"date-time":"2024-06-24T14:56:26Z","timestamp":1719240986000},"score":1,"resource":{"primary":{"URL":"https:\/\/academic.oup.com\/comjnl\/article\/67\/6\/2317\/7606361"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,2,11]]},"references-count":74,"journal-issue":{"issue":"6","published-online":{"date-parts":[[2024,2,11]]},"published-print":{"date-parts":[[2024,6,24]]}},"URL":"https:\/\/doi.org\/10.1093\/comjnl\/bxae008","relation":{},"ISSN":["0010-4620","1460-2067"],"issn-type":[{"value":"0010-4620","type":"print"},{"value":"1460-2067","type":"electronic"}],"subject":[],"published-other":{"date-parts":[[2024,6]]},"published":{"date-parts":[[2024,2,11]]}}}