{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T14:13:25Z","timestamp":1785420805008,"version":"3.56.0"},"reference-count":36,"publisher":"Emerald","issue":"1","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,1,2]]},"abstract":"<jats:sec>\n                  <jats:title>Purpose<\/jats:title>\n                  <jats:p>The primary purpose of this paper is to introduce the drift detection method-online random forest (DDM-ORF) model for intrusion detection, combining DDM for detecting concept drift and ORF for incremental learning. The paper addresses the challenges of dynamic and nonstationary data, offering a solution that continuously adapts to changes in the data distribution. The goal is to provide effective intrusion detection in real-world scenarios, demonstrated through comprehensive experiments and evaluations using Apache Spark.<\/jats:p>\n               <\/jats:sec>\n               <jats:sec>\n                  <jats:title>Design\/methodology\/approach<\/jats:title>\n                  <jats:p>The paper uses an experimental approach to evaluate the DDM-ORF model. The design involves assessing classification performance metrics, including accuracy, precision, recall and F-measure. The methodology integrates Apache Spark for distributed computing, using metrics such as processed records per second and input rows per second. The evaluation extends to the analysis of IP addresses, ports and taxonomies in the MAWILab data set. This comprehensive design and methodology showcase the model\u2019s effectiveness in detecting intrusions through concept drift detection and online incremental learning on large-scale, heterogeneous data.<\/jats:p>\n               <\/jats:sec>\n               <jats:sec>\n                  <jats:title>Findings<\/jats:title>\n                  <jats:p>The paper\u2019s findings reveal that the DDM-ORF model achieves outstanding classification results with 99.96% accuracy, demonstrating its efficacy in intrusion detection. Comparative analysis against a convolutional neural network-based model indicates superior performance in anomalous and suspicious detection rates. The exploration of IP addresses, ports and taxonomies uncovers valuable insights into attack patterns. Apache Spark evaluation attests to the system\u2019s high processing rates. The study emphasizes the scalability, availability and fault tolerance of DDM-ORF, making it suitable for real-world scenarios. Overall, the paper establishes the model\u2019s proficiency in handling dynamic, nonstationary data for intrusion detection.<\/jats:p>\n               <\/jats:sec>\n               <jats:sec>\n                  <jats:title>Research limitations\/implications<\/jats:title>\n                  <jats:p>The research acknowledges certain limitations, including the potential challenge of DDM detecting only frequency changes in class labels and not complex concept drifts. The incremental random forest\u2019s reliance on memory may pose constraints as the forest size increases, potentially leading to overfitting. Addressing these limitations could involve exploring alternative concept drift detection algorithms and implementing ensemble pruning techniques for memory efficiency. Further research avenues may investigate algorithms balancing accuracy and memory usage, such as compressed random forests, to enhance the model\u2019s effectiveness in evolving data environments.<\/jats:p>\n               <\/jats:sec>\n               <jats:sec>\n                  <jats:title>Practical implications<\/jats:title>\n                  <jats:p>The study\u2019s practical implications are noteworthy. The proposed DDM-ORF model, designed for intrusion detection through concept drift detection and online incremental learning, offers a scalable, available and fault-tolerant solution. Leveraging Apache Spark and Microsoft Azure Cloud enhances processing capabilities for large data sets in dynamic, nonstationary scenarios. The model\u2019s applicability to heterogeneous data sets and its achievement of high-accuracy multi-class classification make it suitable for real-world intrusion detection. Moreover, the auto-scaling features of Microsoft Azure Cloud contribute to adaptability, ensuring efficient resource utilization without downtime. These practical implications underscore the model\u2019s relevance and effectiveness in diverse operational contexts.<\/jats:p>\n               <\/jats:sec>\n               <jats:sec>\n                  <jats:title>Social implications<\/jats:title>\n                  <jats:p>The DDM-ORF model\u2019s social implications are significant, contributing to enhanced cybersecurity measures. By providing an effective intrusion detection system, it helps safeguard digital ecosystems, preserving user privacy and securing sensitive information. The model\u2019s accuracy in identifying and classifying various intrusion attempts aids in mitigating potential cyber threats, thereby fostering a safer online environment for individuals and organizations. As cybersecurity is paramount in the digital age, the social impact lies in fortifying the resilience of networks, systems and data against malicious activities, ultimately promoting trust and reliability in online interactions.<\/jats:p>\n               <\/jats:sec>\n               <jats:sec>\n                  <jats:title>Originality\/value<\/jats:title>\n                  <jats:p>The DDM-ORF model introduces a novel approach to intrusion detection by combining drift detection and online incremental learning. This originality lies in its utilization of the DDM-ORF algorithm, offering a dynamic and adaptive system for evolving data. The model\u2019s contribution extends to its scalability, fault-tolerance and suitability for heterogeneous data sets, addressing challenges in dynamic, nonstationary environments. Its application on a large-scale data set and multi-class classification, along with integration with Apache Spark and Microsoft Azure Cloud, enhances the field\u2019s understanding and application of intrusion detection, providing valuable insights for securing digital infrastructures.<\/jats:p>\n               <\/jats:sec>","DOI":"10.1108\/ijpcc-12-2023-0358","type":"journal-article","created":{"date-parts":[[2024,10,21]],"date-time":"2024-10-21T23:58:41Z","timestamp":1729555121000},"page":"81-115","source":"Crossref","is-referenced-by-count":21,"title":["Intrusion detection based on concept drift detection and online incremental learning"],"prefix":"10.1108","volume":"21","author":[{"given":"Farah","family":"Jemili","sequence":"first","affiliation":[{"name":"LR17ES05, University of Sousse ISITCom, Mars Research Laboratory, , Sousse,","place":["Tunisia"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Khaled","family":"Jouini","sequence":"additional","affiliation":[{"name":"LR17ES05, University of Sousse ISITCom, Mars Research Laboratory, , Sousse,","place":["Tunisia"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ouajdi","family":"Korbaa","sequence":"additional","affiliation":[{"name":"LR17ES05, University of Sousse ISITCom, Mars Research Laboratory, , Sousse,","place":["Tunisia"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"140","published-online":{"date-parts":[[2024,10,23]]},"reference":[{"issue":"20","key":"2025091209084290800_ref001","doi-asserted-by":"publisher","first-page":"19706","DOI":"10.1109\/JIOT.2022.3167005","article-title":"Intrusion detection in the IoT under data and concept drifts: online deep learning approach","volume":"9","author":"Abdel Wahab","year":"2022","journal-title":"IEEE Internet of Things Journal"},{"key":"2025091209084290800_ref002","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-031-16210-7_39","article-title":"Distributed architecture of an intrusion detection system in industrial control systems","volume-title":"ICCCI 2022 14th International Conference on Computational Collective Intelligence","author":"Abid","year":"2022"},{"key":"2025091209084290800_ref003","doi-asserted-by":"publisher","first-page":"448","DOI":"10.1016\/j.procs.2020.08.059","article-title":"Intrusion detection based on graph oriented big data analytics","volume-title":"KES-2020 24th International Conference on Knowledge-Based and Intelligent Information and Engineering Systems","author":"Abid","year":"2020"},{"issue":"23","key":"2025091209084290800_ref004","doi-asserted-by":"publisher","first-page":"7803","DOI":"10.3390\/s21237803","article-title":"Scientific developments and new technological trajectories in sensor research","volume":"21","author":"Coccia","year":"2021","journal-title":"Sensors"},{"key":"2025091209084290800_ref005","first-page":"171","article-title":"Effectiveness of video-classification in android malware detection through API-Streams and CNN-LSTM autoencoders","author":"D\u2019Angelo","year":"2021"},{"key":"2025091209084290800_ref006","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/HPCC-SmartCity-DSS51687.2021.00033","article-title":"A deep learning approach for intrusion detection","author":"Dhahbi","year":"2021"},{"key":"2025091209084290800_ref007","doi-asserted-by":"crossref","DOI":"10.1109\/ISI49825.2020.9280519","article-title":"A comparative study on contemporary intrusion detection datasets for machine learning research","volume-title":"2020 IEEE International Conference on Intelligence and Security Informatics (ISI)","author":"Dwibedi","year":"2020"},{"issue":"23","key":"2025091209084290800_ref008","doi-asserted-by":"crossref","DOI":"10.1007\/s00500-020-05200-3","article-title":"A GP-based ensemble classification framework for time-changing streams of intrusion detection data","volume":"24","author":"Folino","year":"2020","journal-title":"Soft Computing"},{"key":"2025091209084290800_ref009","doi-asserted-by":"crossref","DOI":"10.1109\/MN55117.2022.9887775","article-title":"On the use of machine learning approaches for the early classification in network intrusion detection","volume-title":"2022 IEEE International Symposium on Measurements and Networking (M&N)","author":"Guarino","year":"2022"},{"issue":"1","key":"2025091209084290800_ref010","doi-asserted-by":"publisher","first-page":"1","DOI":"10.3390\/bdcc3010001","article-title":"Comparative study between big data analysis techniques in intrusion detection","volume":"3","author":"Hafsa","year":"2018","journal-title":"Big Data and Cognitive Computing"},{"key":"2025091209084290800_ref012","doi-asserted-by":"crossref","DOI":"10.1145\/3185768.3186360","article-title":"Exploratory analysis of spark structured streaming","volume-title":"International Conference on Performance Engineering, Berlin","author":"Ivanov","year":"2018"},{"issue":"6","key":"2025091209084290800_ref013","doi-asserted-by":"publisher","DOI":"10.1007\/s10586-022-03769-y","article-title":"Intelligent intrusion detection based on fuzzy big data classification","volume":"26","author":"Jemili","year":"2022","journal-title":"Cluster Computing"},{"key":"2025091209084290800_ref014","doi-asserted-by":"publisher","first-page":"108239","DOI":"10.1016\/j.compeleceng.2022.108239","article-title":"Learn to adapt: robust drift detection in security domain","volume":"102","author":"KuppaLe-Khac","year":"2022","journal-title":"Computers and Electrical Engineering"},{"issue":"2","key":"2025091209084290800_ref015","first-page":"169","article-title":"Adaptive class incremental learning-based IoT intrusion detection system","volume":"49","author":"Liu","year":"2023","journal-title":"Computer Engineering"},{"key":"2025091209084290800_ref016","doi-asserted-by":"publisher","first-page":"109542","DOI":"10.1016\/j.knosys.2022.109542","article-title":"ITL-IDS: incremental transfer learning for intrusion detection systems","volume":"253","author":"Mahdavi","year":"2022","journal-title":"Knowledge-Based Systems"},{"issue":"14","key":"2025091209084290800_ref017","doi-asserted-by":"publisher","DOI":"10.1007\/s00500-023-08324-4","article-title":"A deep learning based intrusion detection approach for mobile ad-hoc network","volume":"27","author":"Meddeb","year":"2023","journal-title":"Soft Computing"},{"key":"2025091209084290800_ref018","doi-asserted-by":"crossref","DOI":"10.1109\/ICSITech49800.2020.9392075","article-title":"A review of intrusion detection system in IoT with machine learning approach: current and future research","volume-title":"6th International Conference on Science in Information Technology (ICSITech)","author":"Nugroho","year":"2020"},{"issue":"4","key":"2025091209084290800_ref019","doi-asserted-by":"crossref","first-page":"482","DOI":"10.1108\/IJIUS-05-2021-0028","article-title":"Literature review on network security in wireless mobile Ad-hoc network for IoT applications: network attacks and detection mechanisms","volume":"10","author":"Pamarthi","year":"2022","journal-title":"International Journal of Intelligent Unmanned Systems"},{"issue":"3.24","key":"2025091209084290800_ref020","first-page":"479","article-title":"A detailed analysis of CICIDS2017 dataset for designing intrusion detection systems","volume":"7","author":"Panigrahi","year":"2018","journal-title":"International Journal of Engineering and Technology"},{"key":"2025091209084290800_ref021","first-page":"29","article-title":"Augmentation-based ensemble learning for stance and fake news detection","volume-title":"in Advances in Computational Collective Intelligence \u2013 14th International Conference, ICCCI 2022, Hammamet, Tunisia, September 28-30, 2022, Proceedings, vol. 1653 of Communications in Computer and Information Science, Springer","author":"Salah","year":"2022"},{"issue":"2","key":"2025091209084290800_ref022","doi-asserted-by":"crossref","first-page":"565","DOI":"10.1007\/s41870-020-00583-w","article-title":"Attack and intrusion detection in cloud computing using an ensemble learning approach","volume":"13","author":"Singh","year":"2021","journal-title":"International Journal of Information Technology"},{"issue":"2","key":"2025091209084290800_ref023","doi-asserted-by":"crossref","first-page":"99","DOI":"10.32604\/jiot.2022.037416","article-title":"Intrusion detection method based on active incremental learning in industrial internet of things environment","volume":"4","author":"Sun","year":"2022","journal-title":"Journal on Internet of Things"},{"issue":"4","key":"2025091209084290800_ref024","doi-asserted-by":"crossref","first-page":"3211","DOI":"10.1007\/s11831-020-09496-0","article-title":"A review on machine learning and deep learning perspectives of IDS for IoT: recent updates, security issues, and challenges","volume":"28","author":"ThakkarLohiya","year":"2021","journal-title":"Archives of Computational Methods in Engineering"},{"issue":"1","key":"2025091209084290800_ref025","doi-asserted-by":"crossref","first-page":"149","DOI":"10.1007\/s10994-017-5686-9","article-title":"The online performance estimation framework: heterogeneous ensemble learning for data streams","volume":"107","author":"van Rijn","year":"2018","journal-title":"Machine Learning"},{"issue":"1","key":"2025091209084290800_ref026","first-page":"24","article-title":"Big data analytics for network intrusion detection: a survey","volume":"7","author":"WangJones","year":"2017","journal-title":"International Journal of Networks and Communications"},{"issue":"1","key":"2025091209084290800_ref027","doi-asserted-by":"crossref","first-page":"671","DOI":"10.1109\/TNSM.2021.3102388","article-title":"An incremental learning method based on dynamic ensemble RVM for intrusion detection","volume":"19","author":"Wu","year":"2022","journal-title":"IEEE Transactions on Network and Service Management"},{"key":"2025091209084290800_ref028","doi-asserted-by":"publisher","first-page":"350","DOI":"10.1109\/Cybermatics_2018.2018.00087","article-title":"A concept drift based ensemble incremental learning approach for intrusion detection","volume-title":"2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)","author":"Yuan","year":"2018"},{"key":"2025091209084290800_ref029","doi-asserted-by":"crossref","first-page":"107247","DOI":"10.1016\/j.comnet.2020.107247","article-title":"Building an efficient intrusion detection system based on feature selection and ensemble classifier","volume":"174","author":"Zhou","year":"2020","journal-title":"Computer Networks"},{"issue":"23","key":"2025091209084290800_ref030","doi-asserted-by":"publisher","first-page":"9419","DOI":"10.3390\/s22239419","article-title":"Evolution of sensor research for clarifying the dynamics and properties of future directions","volume":"22","author":"Coccia","year":"2022","journal-title":"Sensors"},{"key":"2025091209084290800_ref031","doi-asserted-by":"publisher","DOI":"10.1080\/24751839.2023.2214976","article-title":"Towards data fusion-based big data analytics for intrusion detection","author":"Jemili","year":"2023","journal-title":"Journal of Information and Telecommunication"},{"key":"2025091209084290800_ref032","first-page":"1","article-title":"Ensemble learning based big data classification for intrusion detection","author":"Kamel","year":"2022"},{"key":"2025091209084290800_ref033","article-title":"A hybrid machine learning based feature selection technique for attack detection in NIDS","author":"Karthika","year":"2024"},{"issue":"1","key":"2025091209084290800_ref034","doi-asserted-by":"crossref","first-page":"31","DOI":"10.30880\/jscdm.2021.02.01.004","article-title":"Evaluation of classification algorithms for intrusion detection system: a review","volume":"2","author":"Salih","year":"2021","journal-title":"Journal of Soft Computing and Data Mining"},{"issue":"10","key":"2025091209084290800_ref035","doi-asserted-by":"crossref","first-page":"2509","DOI":"10.3390\/en13102509","article-title":"Performance comparison and current challenges of using machine learning techniques in cybersecurity","volume":"13","author":"Shaukat","year":"2020","journal-title":"Energies"},{"key":"2025091209084290800_ref036","doi-asserted-by":"crossref","first-page":"108346","DOI":"10.1109\/ACCESS.2020.3001350","article-title":"Anomaly-based intrusion detection from network flow features using variational autoencoder","volume":"8","author":"Sultan","year":"2020","journal-title":"IEEE Access"},{"key":"2025091209084290800_ref037","doi-asserted-by":"crossref","first-page":"94497","DOI":"10.1109\/ACCESS.2019.2928048","article-title":"Tse-ids: a two-stage classifier ensemble for intelligent anomaly-based intrusion detection system","volume":"7","author":"Tama","year":"2019","journal-title":"IEEE Access"}],"container-title":["International Journal of Pervasive Computing and Communications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/IJPCC-12-2023-0358\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/ijpcc\/article-pdf\/21\/1\/81\/10282927\/ijpcc-12-2023-0358en.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/www.emerald.com\/ijpcc\/article-pdf\/21\/1\/81\/10282927\/ijpcc-12-2023-0358en.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,12]],"date-time":"2025-09-12T13:08:50Z","timestamp":1757682530000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.emerald.com\/ijpcc\/article\/21\/1\/81\/1239745\/Intrusion-detection-based-on-concept-drift"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,10,23]]},"references-count":36,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2025,1,2]]}},"URL":"https:\/\/doi.org\/10.1108\/ijpcc-12-2023-0358","relation":{},"ISSN":["1742-7371","1742-738X"],"issn-type":[{"value":"1742-7371","type":"print"},{"value":"1742-738X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,10,23]]}}}