{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,19]],"date-time":"2026-05-19T07:17:49Z","timestamp":1779175069310,"version":"3.51.4"},"reference-count":50,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"1","license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key Research and Development Program of China","award":["2022YFB3103400"],"award-info":[{"award-number":["2022YFB3103400"]}]},{"name":"Shaanxi innovation team","award":["2018TD-007"],"award-info":[{"award-number":["2018TD-007"]}]},{"DOI":"10.13039\/501100013314","name":"Higher Education Discipline Innovation Project","doi-asserted-by":"publisher","award":["B16037"],"award-info":[{"award-number":["B16037"]}],"id":[{"id":"10.13039\/501100013314","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100008986","name":"University of Guelph","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100008986","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2024,1]]},"DOI":"10.1109\/tdsc.2023.3247585","type":"journal-article","created":{"date-parts":[[2023,2,22]],"date-time":"2023-02-22T18:37:05Z","timestamp":1677091025000},"page":"153-167","source":"Crossref","is-referenced-by-count":36,"title":["Automatic Evasion of Machine Learning-Based Network Intrusion Detection Systems"],"prefix":"10.1109","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1784-6091","authenticated-orcid":false,"given":"Haonan","family":"Yan","sequence":"first","affiliation":[{"name":"State Key Laboratory of Integrated Services Networks, School of Cyber Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1839-1607","authenticated-orcid":false,"given":"Xiaoguang","family":"Li","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Integrated Services Networks, School of Cyber Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3066-7186","authenticated-orcid":false,"given":"Wenjing","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Computer Science, University of Guelph, Guelph, ON, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rui","family":"Wang","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Integrated Services Networks, School of Cyber Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8310-7169","authenticated-orcid":false,"given":"Hui","family":"Li","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Integrated Services Networks, School of Cyber Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xingwen","family":"Zhao","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Integrated Services Networks, School of Cyber Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fenghua","family":"Li","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Information Security, Institute of Information Engineering, Chinese Academic of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8916-6645","authenticated-orcid":false,"given":"Xiaodong","family":"Lin","sequence":"additional","affiliation":[{"name":"School of Computer Science, University of Guelph, Guelph, ON, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Machine learning based intrusion detection approaches for industrial IoT control systems: A review","volume-title":"Proc. Int. Conf. Ind. Internet Things Smart Manuf.","author":"Flaus"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/2744769.2747942."},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-38040-3_76"},{"key":"ref4","doi-asserted-by":"crossref","DOI":"10.14722\/ndss.2018.23204","article-title":"Kitsune: An ensemble of autoencoders for online network intrusion detection","volume-title":"Proc. 25th Annu. Netw. Distrib. Syst. Secur. Symp.","author":"Mirsky","year":"2018"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1007\/s10922-018-9459-y"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/2046684.2046692"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/CISS48834.2020.1570617116"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3359992.3366642"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.20"},{"key":"ref11","doi-asserted-by":"crossref","DOI":"10.14722\/ndss.2016.23115","article-title":"Automatically evading classifiers: A case study on PDF malware classifiers","volume-title":"Proc. 23rd Annu. Netw. Distrib. Syst. Secur. Symp.","author":"Xu","year":"2016"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref13","doi-asserted-by":"crossref","DOI":"10.14722\/ndss.2019.23138","article-title":"Textbugger: Generating adversarial text against real-world applications","volume-title":"Proc. 26th Annu. Netw. Distrib. Syst. Secur. Symp.","author":"Li","year":"2019"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133978"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.4108\/eai.10-1-2019.156245"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2018.2847722"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/3385003.3410925"},{"key":"ref19","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.5220\/0006639801080116"},{"key":"ref21","first-page":"24","article-title":"Extracting tree-structured representations of trained networks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Craven"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274740"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-05318-5_6"},{"key":"ref24","article-title":"Delving into transferable adversarial examples and black-box attacks","author":"Liu","year":"2016"},{"key":"ref25","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","author":"Brendel","year":"2017"},{"key":"ref26","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/1544012.1544023"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2008.11.016"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/GLOBECOM38437.2019.9013941"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2018.2883147"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.5555\/3241094.3241142"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3069258"},{"key":"ref33","first-page":"1157","article-title":"An introduction to variable and feature selection","volume":"3","author":"Guyon","year":"Mar","journal-title":"J. Mach. Learn. Res."},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2021.3087242"},{"key":"ref35","article-title":"Adversarial examples in constrained domains","author":"Sheatsley","year":"2020"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2018.00159"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.3301742"},{"key":"ref38","first-page":"2137","article-title":"Black-box adversarial attacks with limited queries and information","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Ilyas"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2854599"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/ICTAI.2019.00179"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/NCA.2019.8935039"},{"key":"ref42","article-title":"Traffic morphing: An efficient defense against statistical traffic analysis","volume-title":"Proc. Netw. Distrib. Syst. Secur. Symp.","volume":"9","author":"Wright"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/SURV.2011.092311.00082"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2013.03.022"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/GLOBECOM38437.2019.9014337"},{"key":"ref46","first-page":"1","article-title":"Towards systematic evaluation of the evadability of bot\/botnet detection methods","volume-title":"Proc. 2nd Conf. USENIX Workshop Offensive Technol.","author":"Stinson"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/3147.3165"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00444"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8858\/10400751\/10049650.pdf?arnumber=10049650","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,6]],"date-time":"2024-09-06T18:44:58Z","timestamp":1725648298000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10049650\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,1]]},"references-count":50,"journal-issue":{"issue":"1"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2023.3247585","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,1]]}}}