{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,26]],"date-time":"2025-11-26T19:11:46Z","timestamp":1764184306935,"version":"3.46.0"},"reference-count":44,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"Project Panacea: A Model-Based Framework for Self-Protecting Systems through the Progetti di Ricerca di Rilevante Interesse Nazionale (PRIN) 2022 Program","award":["2022Y45XE3"],"award-info":[{"award-number":["2022Y45XE3"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/access.2025.3633419","type":"journal-article","created":{"date-parts":[[2025,11,17]],"date-time":"2025-11-17T18:42:17Z","timestamp":1763404937000},"page":"197899-197911","source":"Crossref","is-referenced-by-count":0,"title":["NOCTOWL: Adaptive Tree-Based Model for Network Anomaly Detection Under Delayed and Sampled Label Availability"],"prefix":"10.1109","volume":"13","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-7659-662X","authenticated-orcid":false,"given":"Sara","family":"Pederzoli","sequence":"first","affiliation":[{"name":"DIEF, University of Modena and Reggio Emilia, Modena, Italy"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8119-895X","authenticated-orcid":false,"given":"Matteo","family":"Paganelli","sequence":"additional","affiliation":[{"name":"DIEF, University of Modena and Reggio Emilia, Modena, Italy"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-7526-8534","authenticated-orcid":false,"given":"Michele","family":"Luca Contalbo","sequence":"additional","affiliation":[{"name":"DIEF, University of Modena and Reggio Emilia, Modena, Italy"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-4819-259X","authenticated-orcid":false,"given":"Riccardo","family":"Benassi","sequence":"additional","affiliation":[{"name":"DIEF, University of Modena and Reggio Emilia, Modena, Italy"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0605-4184","authenticated-orcid":false,"given":"Donato","family":"Tiano","sequence":"additional","affiliation":[{"name":"Vita-Salute San Raffaele University (UniSR), Milano, Italy"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7485-9772","authenticated-orcid":false,"given":"Stefano","family":"Iannucci","sequence":"additional","affiliation":[{"name":"Department of Civil, Computer Science and Aeronautical Technologies Engineering, Roma Tre University, Rome, Italy"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6864-568X","authenticated-orcid":false,"given":"Francesco","family":"Guerra","sequence":"additional","affiliation":[{"name":"DIEF, University of Modena and Reggio Emilia, Modena, Italy"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2023.122564"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3182333"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103171"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/3474369.3486864"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3678890.3678901"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2018.2876857"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE53745.2022.00237"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23204"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-024-00296-8"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3564625.3567992"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3580305.3599238"},{"key":"ref12","first-page":"2327","article-title":"CADE: Detecting and explaining concept drift samples for security applications","volume-title":"Proc. USENIX Secur. Symp.","author":"Yang"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3511808.3557549"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2025.3541890"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103131"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2022.110030"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2025.3557741"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2024.110423"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.24830"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/3472753"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-019-0038-7"},{"issue":"1","key":"ref22","doi-asserted-by":"crossref","first-page":"181","DOI":"10.1016\/j.icte.2025.01.005","article-title":"Deep learning-driven methods for network-based intrusion detection systems: A systematic review","volume":"11","author":"Chinnasamy","year":"2025","journal-title":"ICT Exp."},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102600"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3176317"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2022.3167005"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539297"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3060878"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1002\/dac.3002"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2020.113577"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3077014"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2021.04.112"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4899-7488-4_304"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/5326.983933"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.14778\/3467861.3467863"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539348"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833659"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/3689932.3694757"},{"key":"ref38","first-page":"625","article-title":"Transcend: Detecting concept drift in malware classification models","volume-title":"Proc. USENIX","author":"Jordaney"},{"key":"ref39","doi-asserted-by":"crossref","DOI":"10.17487\/rfc3954","volume-title":"Cisco Systems Netflow Services Export Version 9","author":"Claise","year":"2004"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1007\/s10586-024-04444-0"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.5220\/0006639801080116"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/SPW53761.2021.00009"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/CNS56114.2022.9947235"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1145\/3359786"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/6287639\/10820123\/11250580.pdf?arnumber=11250580","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,26]],"date-time":"2025-11-26T19:05:25Z","timestamp":1764183925000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11250580\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":44,"URL":"https:\/\/doi.org\/10.1109\/access.2025.3633419","relation":{},"ISSN":["2169-3536"],"issn-type":[{"type":"electronic","value":"2169-3536"}],"subject":[],"published":{"date-parts":[[2025]]}}}