{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,12]],"date-time":"2026-05-12T16:44:25Z","timestamp":1778604265576,"version":"3.51.4"},"reference-count":39,"publisher":"Oxford University Press (OUP)","issue":"6","license":[{"start":{"date-parts":[[2022,2,24]],"date-time":"2022-02-24T00:00:00Z","timestamp":1645660800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/academic.oup.com\/journals\/pages\/open_access\/funder_policies\/chorus\/standard_publication_model"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022,11,23]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>Contemporary Artificial Intelligence methods, especially their subset-deep learning, are finding their way to successful implementations in the detection and classification of intrusions at the network level. This paper presents an intrusion detection mechanism that leverages Deep AutoEncoder and several Deep Decoders for unsupervised classification. This work incorporates multiple network topology setups for comparative studies. The efficiency of the proposed topologies is validated on two established benchmark datasets: UNSW-NB15 and NetML-2020. The results of their analysis are discussed in terms of classification accuracy, detection rate, false-positive rate, negative predictive value, Matthews correlation coefficient and F1-score. Furthermore, comparing against the state-of-the-art methods used for network intrusion detection is also disclosed.<\/jats:p>","DOI":"10.1093\/jigpal\/jzac002","type":"journal-article","created":{"date-parts":[[2022,2,11]],"date-time":"2022-02-11T20:11:26Z","timestamp":1644610286000},"page":"912-925","source":"Crossref","is-referenced-by-count":20,"title":["Unsupervised network traffic anomaly detection with deep autoencoders"],"prefix":"10.1093","volume":"30","author":[{"given":"Vibekananda","family":"Dutta","sequence":"first","affiliation":[{"name":"Institute of Telecommunications and Computer Science , Bydgoszcz University of Science and Technology, al. Profesora Sylwestra Kaliskiego 7, 85-976 Bydgoszcz, Poland and Institute of Micromechanics and Photonics, Warsaw University of Technology, \u015bw. Andrzeja Boboli 8\/507, 02-525 Warsaw, Poland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Marek","family":"Pawlicki","sequence":"additional","affiliation":[{"name":"Institute of Telecommunications and Computer Science , Bydgoszcz University of Science and Technology, al. Profesora Sylwestra Kaliskiego 7, 85-976 Bydgoszcz, Poland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rafa\u0142","family":"Kozik","sequence":"additional","affiliation":[{"name":"Institute of Telecommunications and Computer Science , Bydgoszcz University of Science and Technology, al. Profesora Sylwestra Kaliskiego 7, 85-976 Bydgoszcz, Poland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Micha\u0142","family":"Chora\u015b","sequence":"additional","affiliation":[{"name":"Institute of Telecommunications and Computer Science , Bydgoszcz University of Science and Technology, al. Profesora Sylwestra Kaliskiego 7, 85-976 Bydgoszcz, Poland"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"286","published-online":{"date-parts":[[2022,2,24]]},"reference":[{"key":"2022112012285629100_ref1","doi-asserted-by":"crossref","first-page":"135","DOI":"10.1016\/j.cose.2016.11.004","article-title":"A survey of intrusion detection systems based on ensemble and hybrid classifiers","volume":"65","author":"Aburomman","year":"2017","journal-title":"Computers & Security"},{"key":"2022112012285629100_ref2","doi-asserted-by":"crossref","first-page":"152","DOI":"10.1016\/j.jocs.2017.03.006","article-title":"Anomaly-based intrusion detection system through feature selection analysis and building hybrid efficient model","volume":"25","author":"Aljawarneh","year":"2018","journal-title":"Journal of Computational Science"},{"key":"2022112012285629100_ref3","first-page":"1","article-title":"Unsupervised deep learning approach for network intrusion detection combining convolutional autoencoder and one-class svm","author":"Binbusayyis","year":"2021","journal-title":"Applied Intelligence"},{"key":"2022112012285629100_ref4","first-page":"5371","article-title":"Tight arms race: overview of current malware threats and trends in their detection","volume-title":"IEEE Access","author":"Caviglione","year":"2021"},{"key":"2022112012285629100_ref5","doi-asserted-by":"crossref","first-page":"45","DOI":"10.1093\/jigpal\/jzu038","article-title":"Machine learning techniques applied to detect cyber attacks on web applications","volume":"23","author":"Chora\u015b","year":"2015","journal-title":"Logic Journal of the IGPL"},{"key":"2022112012285629100_ref6","doi-asserted-by":"crossref","first-page":"705","DOI":"10.1016\/j.neucom.2020.07.138","article-title":"Intrusion detection approach based on optimised artificial neural network","volume":"452","author":"Chora\u015b","year":"2021","journal-title":"Neurocomputing"},{"key":"2022112012285629100_ref7","doi-asserted-by":"crossref","first-page":"10015","DOI":"10.1109\/ACCESS.2019.2891933","article-title":"Adapted k-nearest neighbors for detecting anomalies on spatio\u2013temporal traffic flow","volume":"7","author":"Djenouri","year":"2019","journal-title":"IEEE Access"},{"key":"2022112012285629100_ref8","first-page":"405","article-title":"Hybrid model for improving the classification effectiveness of network intrusion detection","volume-title":"The 13th International Conference on Computational Intelligence in Security for Information Systems (CISIS 2020)","author":"Dutta","year":"2020"},{"key":"2022112012285629100_ref9","doi-asserted-by":"crossref","first-page":"1422","DOI":"10.3897\/jucs.2020.075","article-title":"Detection of cyber attacks traces in IoT data","volume":"26","author":"Dutta","year":"2020","journal-title":"Journal of Universal Computer Science"},{"key":"2022112012285629100_ref10","doi-asserted-by":"crossref","first-page":"4583","DOI":"10.3390\/s20164583","article-title":"A deep learning ensemble for network anomaly and cyber-attack detection","volume":"20","author":"Dutta","year":"2020","journal-title":"Sensors"},{"key":"2022112012285629100_ref11","first-page":"45","article-title":"Networking technologies for robotic applications","volume-title":"International Journal of Advanced Studies in Computer Science and Engineering","author":"Dutta","year":"2015"},{"key":"2022112012285629100_ref12","doi-asserted-by":"crossref","first-page":"178","DOI":"10.23919\/ICACT.2018.8323688","article-title":"A deep auto-encoder based approach for intrusion detection system","volume-title":"2018 20th International Conference on Advanced Communication Technology (ICACT)","author":"Farahnakian","year":"2018"},{"key":"2022112012285629100_ref13","doi-asserted-by":"crossref","first-page":"887","DOI":"10.1080\/0952813X.2018.1509379","article-title":"I-AHSDT: intrusion detection using adaptive dynamic directive operative fractional lion clustering and hyperbolic secant-based decision tree classifier","volume":"30","author":"Ganeshan","year":"2018","journal-title":"Journal of Experimental & Theoretical Artificial Intelligence"},{"key":"2022112012285629100_ref14","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1186\/1869-0238-4-5","article-title":"An analysis of security issues for cloud computing","volume":"4","author":"Hashizume","year":"2013","journal-title":"Journal of Internet Services and Applications"},{"key":"2022112012285629100_ref15","first-page":"1","article-title":"Artificial immune system based intrusion detection: innate immunity using an unsupervised learning approach","volume":"8","author":"Hosseinpour","year":"2014","journal-title":"International Journal of Digital Content Technology and its Applications"},{"key":"2022112012285629100_ref16","doi-asserted-by":"crossref","first-page":"51","DOI":"10.1016\/j.neucom.2019.11.016","article-title":"A novel statistical analysis and autoencoder driven intelligent intrusion detection approach","volume":"387","author":"Ieracitano","year":"2020","journal-title":"Neurocomputing"},{"key":"2022112012285629100_ref17","first-page":"1372","article-title":"Anomaly intrusion detection techniques: a brief review","volume":"5","author":"Jain","year":"2014","journal-title":"International Journal of Scientific & Engineering Research"},{"key":"2022112012285629100_ref18","first-page":"1060","article-title":"Anomaly detection using machine learning with a case study","volume-title":"The 2014 IEEE International Conference on Advanced Communications, Control and Computing Technologies","author":"Jidiga","year":"2014"},{"key":"2022112012285629100_ref19","doi-asserted-by":"crossref","first-page":"36","DOI":"10.1016\/j.eswa.2018.04.038","article-title":"An anomaly-based intrusion detection system in presence of benign outliers with visualization capabilities","volume":"108","author":"Karami","year":"2018","journal-title":"Expert Systems with Applications"},{"key":"2022112012285629100_ref20","doi-asserted-by":"crossref","first-page":"149","DOI":"10.1093\/jigpal\/jzy029","article-title":"Protecting the application layer in the public domain with machine learning methods","volume":"27","author":"Kozik","year":"2019","journal-title":"Logic Journal of the IGPL"},{"key":"2022112012285629100_ref21","doi-asserted-by":"crossref","first-page":"783","DOI":"10.1007\/s12652-015-0283-x","article-title":"Advanced services for critical infrastructures protection","volume":"6","author":"Kozik","year":"2015","journal-title":"Journal of Ambient Intelligence and Humanized Computing"},{"key":"2022112012285629100_ref22","first-page":"1","article-title":"A new method of hybrid time window embedding with transformer-based traffic data classification in iot-networked environment","author":"Kozik","year":"2021","journal-title":"Pattern Analysis and Applications"},{"key":"2022112012285629100_ref23","doi-asserted-by":"crossref","first-page":"949","DOI":"10.1007\/s10586-017-1117-8","article-title":"A survey of deep learning-based network anomaly detection","volume":"22","author":"Kwon","year":"2019","journal-title":"Cluster Computing"},{"key":"2022112012285629100_ref24","doi-asserted-by":"crossref","first-page":"1967","DOI":"10.3390\/s17091967","article-title":"Conditional variational autoencoder for prediction and feature recovery applied to intrusion detection in IoT","volume":"17","author":"Lopez-Martin","year":"2017","journal-title":"Sensors"},{"key":"2022112012285629100_ref25","doi-asserted-by":"crossref","first-page":"180","DOI":"10.3390\/fi12110180","article-title":"Ensemble classifiers for network intrusion detection using a novel network attack dataset","volume":"12","author":"Mahfouz","year":"2020","journal-title":"Future Internet"},{"key":"2022112012285629100_ref26","article-title":"Winner-take-all autoencoders","author":"Makhzani","year":"2014"},{"key":"2022112012285629100_ref27","doi-asserted-by":"crossref","first-page":"12","DOI":"10.1109\/MPRV.2018.03367731","article-title":"N-baIoT\u2013network-based detection of IoT botnet attacks using deep autoencoders","volume":"17","author":"Meidan","year":"2018","journal-title":"IEEE Pervasive Computing"},{"key":"2022112012285629100_ref28","first-page":"18","article-title":"The evaluation of network anomaly detection systems: Statistical analysis of the UNSW-NB15 data set and the comparison with the KDD99 data set","volume":"25","author":"Moustafa","year":"2016","journal-title":"Information Security Journal: A Global Perspective"},{"key":"2022112012285629100_ref29","doi-asserted-by":"crossref","first-page":"259","DOI":"10.3390\/electronics9020259","article-title":"An enhanced design of sparse autoencoder for latent features extraction based on trigonometric simplexes for network intrusion detection systems","volume":"9","author":"Musafer","year":"2020","journal-title":"Electronics"},{"key":"2022112012285629100_ref30","doi-asserted-by":"crossref","first-page":"923","DOI":"10.3390\/electronics9060923","article-title":"Network anomaly detection inside consumer networks\u2013a hybrid approach","volume":"9","author":"Patel","year":"2020","journal-title":"Electronics"},{"key":"2022112012285629100_ref31","doi-asserted-by":"crossref","first-page":"196","DOI":"10.1007\/978-3-030-50423-6_15","article-title":"On the impact of network data balancing in cybersecurity applications","volume-title":"Computational Science \u2013 ICCS 2020: 20th International Conference, Amsterdam","author":"Pawlicki","year":"2020"},{"key":"2022112012285629100_ref32","first-page":"218","article-title":"Research on industrial control anomaly detection based on FCM and SVM","volume-title":"The 2018 17th IEEE International Conference on Trust, Security and Privacy in Computing and Communications\/12th IEEE International Conference on Big Data Science and Engineering (TrustCom\/BigDataSE)","author":"Shang","year":"2018"},{"key":"2022112012285629100_ref33","doi-asserted-by":"crossref","first-page":"258","DOI":"10.1109\/WINCOM.2016.7777224","article-title":"Deep learning approach for network intrusion detection in software defined networking","volume-title":"The 2016 International Conference on Wireless Networks and Mobile Communications (WINCOM)","author":"Tang","year":"2016"},{"key":"2022112012285629100_ref34","doi-asserted-by":"crossref","first-page":"223","DOI":"10.1016\/j.neucom.2018.05.027","article-title":"Ramp loss one-class support vector machine; a robust and effective approach to anomaly detection problems","volume":"310","author":"Tian","year":"2018","journal-title":"Neurocomputing"},{"key":"2022112012285629100_ref35","doi-asserted-by":"crossref","DOI":"10.7717\/peerj-cs.327","article-title":"Application of deep autoencoder as an one-class classifier for unsupervised network intrusion detection: a comparative evaluation","volume":"6","author":"Vaiyapuri","year":"2020","journal-title":"PeerJ Computer Science"},{"key":"2022112012285629100_ref36","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/TVCG.2017.2744878","article-title":"Visualizing dataflow graphs of deep learning models in tensor flow","volume":"24","author":"Wongsuphasawat","year":"2017","journal-title":"IEEE Transactions on Visualization and Computer Graphics"},{"key":"2022112012285629100_ref37","doi-asserted-by":"crossref","first-page":"35365","DOI":"10.1109\/ACCESS.2018.2836950","article-title":"Machine learning and deep learning methods for cybersecurity","volume":"6","author":"Xin","year":"2018","journal-title":"IEEE Access"},{"key":"2022112012285629100_ref38","doi-asserted-by":"crossref","first-page":"2528","DOI":"10.3390\/s19112528","article-title":"Improving the classification effectiveness of intrusion detection by using improved conditional variational autoencoder and deep neural network","volume":"19","author":"Yang","year":"2019","journal-title":"Sensors"},{"key":"2022112012285629100_ref39","doi-asserted-by":"crossref","first-page":"130","DOI":"10.1016\/j.future.2021.03.024","article-title":"Multi-dimensional feature fusion and stacking ensemble mechanism for network intrusion detection","volume":"122","author":"Zhang","year":"2021","journal-title":"Future Generation Computer Systems"}],"container-title":["Logic Journal of the IGPL"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/academic.oup.com\/jigpal\/article-pdf\/30\/6\/912\/47058081\/jzac002.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/academic.oup.com\/jigpal\/article-pdf\/30\/6\/912\/47058081\/jzac002.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,11,20]],"date-time":"2022-11-20T12:29:25Z","timestamp":1668947365000},"score":1,"resource":{"primary":{"URL":"https:\/\/academic.oup.com\/jigpal\/article\/30\/6\/912\/6534146"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,2,24]]},"references-count":39,"journal-issue":{"issue":"6","published-online":{"date-parts":[[2022,2,24]]},"published-print":{"date-parts":[[2022,11,23]]}},"URL":"https:\/\/doi.org\/10.1093\/jigpal\/jzac002","relation":{},"ISSN":["1367-0751","1368-9894"],"issn-type":[{"value":"1367-0751","type":"print"},{"value":"1368-9894","type":"electronic"}],"subject":[],"published-other":{"date-parts":[[2022,12]]},"published":{"date-parts":[[2022,2,24]]}}}