{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T13:44:49Z","timestamp":1784295889414,"version":"3.55.0"},"reference-count":73,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"5","license":[{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2025,9]]},"DOI":"10.1109\/tdsc.2025.3560486","type":"journal-article","created":{"date-parts":[[2025,4,15]],"date-time":"2025-04-15T13:40:06Z","timestamp":1744724406000},"page":"5090-5107","source":"Crossref","is-referenced-by-count":13,"title":["Explainable and Transferable Adversarial Attack for ML-Based Network Intrusion Detectors"],"prefix":"10.1109","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6501-840X","authenticated-orcid":false,"given":"Hangsheng","family":"Zhang","sequence":"first","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0807-5934","authenticated-orcid":false,"given":"Dongqi","family":"Han","sequence":"additional","affiliation":[{"name":"Faculty of Beijing University of Posts and Telecommunications, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4978-9172","authenticated-orcid":false,"given":"Shangyuan","family":"Zhuang","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6587-820X","authenticated-orcid":false,"given":"Zhiliang","family":"Wang","sequence":"additional","affiliation":[{"name":"Department of Network Sciences and Cyberspace, Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jiyan","family":"Sun","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5984-1299","authenticated-orcid":false,"given":"Yinlong","family":"Liu","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1147-4327","authenticated-orcid":false,"given":"Jiqiang","family":"Liu","sequence":"additional","affiliation":[{"name":"Faculty of Beijing Jiaotong University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6512-8326","authenticated-orcid":false,"given":"Jinsong","family":"Dong","sequence":"additional","affiliation":[{"name":"Department of Computing, National University of Singapore (NUS), Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23204"},{"key":"ref2","first-page":"608","article-title":"ADSIM: Network anomaly detection via similarity-aware heterogeneous ensemble learning","volume-title":"Proc. 2021 IFIP\/IEEE Int. Symp. Integr. Netw. Manage.","author":"Chen"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484585"},{"key":"ref4","article-title":"Adversarial deep learning against intrusion detection classifiers","author":"Rigaki","year":"2017"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2854599"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/ICTAI50040.2020.00110"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/ssci50451.2021.9660011"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ICTAI.2019.00179"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3048038"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2021.115782"},{"key":"ref11","article-title":"Ensemble adversarial training: Attacks and defenses","volume-title":"Proc. 6th Int. Conf. Learn. Representations","author":"Tram\u00e8r"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref13","article-title":"Skip connections matter: On the transferability of adversarial examples generated with ResNets","author":"Wu","year":"2020"},{"key":"ref14","article-title":"A unified approach to interpreting and boosting adversarial transferability","author":"Wang","year":"2020"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.5220\/0006639801080116"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.05.016"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/ICACS47775.2020.9055946"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1016\/j.procs.2017.12.091"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/MILCOM.2018.8599759"},{"key":"ref20","first-page":"321","article-title":"Why do adversarial attacks transfer? Explaining transferability of evasion and poisoning attacks","volume-title":"Proc. 28th USENIX Secur. Symp.","author":"Demontis"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP57164.2023.00042"},{"key":"ref22","first-page":"3971","article-title":"Dos and don\u2019ts of machine learning in computer security","volume-title":"Proc. 31st USENIX Secur. Symp.","author":"Arp"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/SPW53761.2021.00009"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CNS56114.2022.9947235"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2020.107247"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3050605"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.23919\/CYCON.2019.8756865"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3357384.3357993"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2895334"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.3390\/s20051452"},{"key":"ref31","article-title":"Generating practical adversarial network traffic flows using NIDSGAN","author":"Zolbayar","year":"2022"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/IWQoS.2018.8624124"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2019.8737507"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-33338-5_18"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2014.600"},{"key":"ref36","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2024.110476","article-title":"A framework for detecting zero-day exploits in network flows","volume":"248","author":"Tour\u00e9","year":"2024","journal-title":"Comput. Netw."},{"key":"ref37","first-page":"4337","article-title":"xNIDS: Explaining deep learning-based network intrusion detection systems for active intrusion responses","volume-title":"Proc. 32nd USENIX Secur. Symp.","author":"Wei"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2013.03.022"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-05981-0_7"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2019.8761337"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/NCA.2018.8548327"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2021.3087242"},{"key":"ref43","first-page":"2705","article-title":"Defeating DNN-based traffic analysis systems in real-time with blind adversarial perturbations","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Nasr"},{"key":"ref44","article-title":"Transferability in machine learning: From phenomena to black-box attacks using adversarial samples","author":"Papernot","year":"2016"},{"key":"ref45","article-title":"Practical black-box attacks against deep learning systems using adversarial examples","author":"Papernot","year":"2016"},{"key":"ref46","article-title":"Understanding and enhancing the transferability of adversarial examples","author":"Wu","year":"2018"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3082327"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/TNSE.2023.3240687"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2020.2972320"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2019.2922398"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3229595"},{"key":"ref52","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2016.7727230"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref55","article-title":"Delving into transferable adversarial examples and black-box attacks","author":"Liu","year":"2016"},{"key":"ref56","article-title":"Adversarial examples are not bugs, they are features","author":"Ilyas","year":"2019"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1007\/s10489-024-05728-z"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3003571"},{"key":"ref59","first-page":"3745","article-title":"The space of adversarial strategies","volume-title":"Proc. 32nd USENIX Secur. Symp.","author":"Sheatsley"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-32430-8_28"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01456"},{"key":"ref62","article-title":"Towards a unified min-max framework for adversarial exploration and robustness","author":"Wang","year":"2019"},{"key":"ref63","article-title":"Explaining image classifiers by counterfactual generation","author":"Chang","year":"2018"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00304"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.371"},{"key":"ref66","first-page":"4768","article-title":"A unified approach to interpreting model predictions","volume-title":"Proc. 31st Int. Conf. Neural Inf. Process. Syst.","author":"Lundberg"},{"key":"ref67","article-title":"Understanding global feature contributions with additive importance measures","author":"Covert","year":"2020"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP57164.2023.00022"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560609"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1137\/120880811"},{"key":"ref71","first-page":"3054","article-title":"A comprehensive linear speedup analysis for asynchronous stochastic parallel optimization from zeroth-order to first-order","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Lian"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00045"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11150357\/10964202.pdf?arnumber=10964202","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,4]],"date-time":"2025-09-04T18:53:27Z","timestamp":1757012007000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10964202\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9]]},"references-count":73,"journal-issue":{"issue":"5"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2025.3560486","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9]]}}}