{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,24]],"date-time":"2026-03-24T13:27:34Z","timestamp":1774358854203,"version":"3.50.1"},"reference-count":62,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U1433116"],"award-info":[{"award-number":["U1433116"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"crossref","award":["NP2017208"],"award-info":[{"award-number":["NP2017208"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2019]]},"DOI":"10.1109\/access.2019.2925838","type":"journal-article","created":{"date-parts":[[2019,7,11]],"date-time":"2019-07-11T19:04:36Z","timestamp":1562871876000},"page":"89507-89521","source":"Crossref","is-referenced-by-count":137,"title":["HML-IDS: A Hybrid-Multilevel Anomaly Prediction Approach for Intrusion Detection in SCADA Systems"],"prefix":"10.1109","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7180-8179","authenticated-orcid":false,"given":"Izhar Ahmed","family":"Khan","sequence":"first","affiliation":[]},{"given":"Dechang","family":"Pi","sequence":"additional","affiliation":[]},{"given":"Zaheer Ullah","family":"Khan","sequence":"additional","affiliation":[]},{"given":"Yasir","family":"Hussain","sequence":"additional","affiliation":[]},{"given":"Asif","family":"Nawaz","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2019.2893549"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/TETCI.2017.2772792"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA.2016.0040"},{"key":"ref32","first-page":"1","article-title":"On SCADA control system command and response injection and intrusion detection","author":"gao","year":"2010","journal-title":"Proc IEEE eCrime Res Summit"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2009.5178592"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CCECE.2012.6334816"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2017.2762418"},{"key":"ref36","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1016\/j.cose.2017.04.012","article-title":"An enhanced optimization based algorithm for intrusion detection in SCADA network","volume":"70","author":"shitharth","year":"2017","journal-title":"Comput Secur"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/NAECON.2015.7443094"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2017.34"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1006\/jcss.1997.1504"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/ICDAR.1995.598994"},{"key":"ref61","author":"trevor","year":"2009","journal-title":"The Elements of Statistical Learning Data Mining Inference and Prediction"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2014.2330796"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2010.2099234"},{"key":"ref29","first-page":"171","article-title":"Safeguarding SCADA systems with anomaly detection","author":"bigham","year":"2003","journal-title":"Proc Int Workshop Math Methods Models Archit Comput Netw Secur"},{"key":"ref2","author":"groover","year":"2016","journal-title":"Automation Production Systems and Computer-Integrated Manufacturing"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/HASE.2016.14"},{"key":"ref20","author":"poulsen","year":"2003","journal-title":"Slammer Worm Crashed Ohio Nuke Plant Network"},{"key":"ref22","article-title":"Cyber-attack against ukrainian critical infrastructure","author":"alert","year":"2016"},{"key":"ref21","first-page":"22","article-title":"German steel mill cyber attack","volume":"30","author":"lee","year":"2014","journal-title":"Ind Control Syst"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/2542049"},{"key":"ref23","first-page":"7","article-title":"SCADA-specific intrusion detection\/prevention systems: A survey and taxonomy","volume":"11","author":"zhu","year":"2010","journal-title":"Proc Workshop Secure Control Systems (SCS)"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/2732198.2732200"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/ISGT.2014.6816388"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1613\/jair.953"},{"key":"ref51","doi-asserted-by":"crossref","first-page":"769","DOI":"10.1109\/TSMC.1976.4309452","article-title":"Two modifications of CNN","volume":"smc 6","author":"tomek","year":"1976","journal-title":"IEEE Trans Syst Man Cybern"},{"key":"ref59","article-title":"Learning internal representations by error propagation","volume":"1","author":"rumelhart","year":"1986","journal-title":"Parallel Distributed Processing"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1967.1053964"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1016\/j.patrec.2005.10.010"},{"key":"ref56","first-page":"1015","article-title":"Beyond accuracy, F-score and ROC: A family of discriminant measures for performance evaluation","author":"sokolova","year":"2006","journal-title":"Artifi Intell J"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1145\/1099435.1099439"},{"key":"ref54","article-title":"Metaheuristic neural networks for anomaly recognition in industrial sensor networks with packet latency and jitter for smart infrastructures","author":"mansouri","year":"0","journal-title":"Int J Comput Appl"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/INISTA.2018.8466306"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/RWEEK.2016.7573322"},{"key":"ref10","first-page":"1","article-title":"Towards a stateful analysis framework for smart grid network intrusion detection","author":"kang","year":"2016","journal-title":"Proc 4th Int Symp ICS SCADA Cyber Secur Res"},{"key":"ref11","first-page":"3","article-title":"Industrial control system simulation and data logging for intrusion detection system research","author":"morris","year":"2015","journal-title":"7th Annual Southeastern Cyber Security Summit"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1007\/s11760-016-0935-0"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2016.49"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813654"},{"key":"ref14","first-page":"139","article-title":"BotMiner: Clustering analysis of network traffic for protocol- and structure-independent botnet detection","author":"gu","year":"2008","journal-title":"Proc 17th Conf Security Symp"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1016\/j.adhoc.2013.04.014"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-45477-1_15"},{"key":"ref17","first-page":"123","article-title":"Effective defence against zero-day exploits using Bayesian networks","author":"li","year":"2016","journal-title":"Proc 7th Int Conf Critical Inf Infrastruct Sec"},{"key":"ref18","first-page":"29","article-title":"W32. Stuxnet dossier","volume":"5","author":"falliere","year":"2011","journal-title":"Symantec Security Response"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-75462-8_6"},{"key":"ref4","author":"wood","year":"2012","journal-title":"Power Generation Operation and Control"},{"key":"ref3","first-page":"326","article-title":"Safety and security interactions modeling using the BDMP formalism: Case study of a pipeline","author":"kriaa","year":"2014","journal-title":"Proc Int Conf Comput Saf Rel Secur"},{"key":"ref6","first-page":"1","article-title":"Using model-based intrusion detection for SCADA networks","volume":"46","author":"cheung","year":"2007","journal-title":"Proc SCADA Security Sci Symp"},{"key":"ref5","year":"2016","journal-title":"ICS-CERT Annual Vulnerability Coordination Report"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/AINA.2010.86"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30115-8_7"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2014.09.006"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/PESMG.2013.6672100"},{"key":"ref46","doi-asserted-by":"crossref","first-page":"88","DOI":"10.1016\/j.cviu.2018.02.006","article-title":"Deep-anomaly: Fully convolutional neural network for fast anomaly detection in crowded scenes","volume":"172","author":"sabokrou","year":"2018","journal-title":"Comput Vis Image Understand"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2017.2670780"},{"key":"ref48","first-page":"331","article-title":"Impact of outlier removal and normalization approach in modified k-means clustering algorithm","volume":"8","author":"patel","year":"2011","journal-title":"Int J Comput Sci Issues"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.3844\/jcssp.2006.735.739"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00356"},{"key":"ref41","article-title":"End-to-end adversarial learning for intrusion detection in computer networks","author":"mohammadi","year":"2019","journal-title":"arXiv 1904 11577"},{"key":"ref44","article-title":"AVID: Adversarial visual irregularity detection","author":"sabokrou","year":"2018","journal-title":"arXiv 1805 09521"},{"key":"ref43","first-page":"146","article-title":"Unsupervised anomaly detection with generative adversarial networks to guide marker discovery","author":"schlegl","year":"2017","journal-title":"Proc Int Conf Inf Process Med Imag"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/8600701\/08751972.pdf?arnumber=8751972","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,1,27]],"date-time":"2022-01-27T00:30:56Z","timestamp":1643243456000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8751972\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"references-count":62,"URL":"https:\/\/doi.org\/10.1109\/access.2019.2925838","relation":{},"ISSN":["2169-3536"],"issn-type":[{"value":"2169-3536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019]]}}}