{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T09:47:50Z","timestamp":1781084870349,"version":"3.54.1"},"reference-count":136,"publisher":"Association for Computing Machinery (ACM)","issue":"5","license":[{"start":{"date-parts":[[2018,11,19]],"date-time":"2018-11-19T00:00:00Z","timestamp":1542585600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100004543","name":"China Scholarship Council","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100004543","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2019,9,30]]},"abstract":"<jats:p>In a contemporary data center, Linux applications often generate a large quantity of real-time system call traces, which are not suitable for traditional host-based intrusion detection systems deployed on every single host. Training data mining models with system calls on a single host that has static computing and storage capacity is time-consuming, and intermediate datasets are not capable of being efficiently handled. It is cumbersome for the maintenance and updating of host-based intrusion detection systems (HIDS) installed on every physical or virtual host, and comprehensive system call analysis can hardly be performed to detect complex and distributed attacks among multiple hosts. Considering these limitations of current system-call-based HIDS, in this article, we provide a review of the development of system-call-based HIDS and future research trends. Algorithms and techniques relevant to system-call-based HIDS are investigated, including feature extraction methods and various data mining algorithms. The HIDS dataset issues are discussed, including currently available datasets with system calls and approaches for researchers to generate new datasets. The application of system-call-based HIDS on current embedded systems is studied, and related works are investigated. Finally, future research trends are forecast regarding three aspects, namely, the reduction of the false-positive rate, the improvement of detection efficiency, and the enhancement of collaborative security.<\/jats:p>","DOI":"10.1145\/3214304","type":"journal-article","created":{"date-parts":[[2018,11,20]],"date-time":"2018-11-20T14:19:23Z","timestamp":1542723563000},"page":"1-36","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":119,"title":["Host-Based Intrusion Detection System with System Calls"],"prefix":"10.1145","volume":"51","author":[{"given":"Ming","family":"Liu","sequence":"first","affiliation":[{"name":"Shanghai Jiao Tong University, China, and University of Technology Sydney, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhi","family":"Xue","sequence":"additional","affiliation":[{"name":"Shanghai Jiao Tong University, Minhang, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xianghua","family":"Xu","sequence":"additional","affiliation":[{"name":"Hangzhou Dianzi University, Hangzhou, Zhejiang, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Changmin","family":"Zhong","sequence":"additional","affiliation":[{"name":"Joowing Australia, Glen Waverley, VIC, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1677-9525","authenticated-orcid":false,"given":"Jinjun","family":"Chen","sequence":"additional","affiliation":[{"name":"Swinburne University of Technology, Hawthorn, VIC, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2018,11,19]]},"reference":[{"key":"e_1_2_1_1_1","volume-title":"International Conference on Electrical and Electronics Engineering","author":"Abdel-Azim Mohamed","year":"2009","unstructured":"Mohamed Abdel-Azim, AI Abdel-Fatah, and Mohammed Awad. 2009. Performance analysis of artificial neural network intrusion detection systems. In International Conference on Electrical and Electronics Engineering, 2009 (ELECO\u201909). IEEE, II--385--II--389."},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2015.11.016"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICET.2009.5353204"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-38631-2_24"},{"key":"e_1_2_1_5_1","volume-title":"2012 International Conference for Internet Technology And Secured Transactions. IEEE, 211--218","author":"Suaad","unstructured":"Suaad S. Alarifi and Stephen D. Wolthusen. 2012. Detecting anomalies in IaaS environments through virtual machine host system call analysis. In 2012 International Conference for Internet Technology And Secured Transactions. IEEE, 211--218."},{"key":"e_1_2_1_6_1","unstructured":"AlienVault. 2018. Host-based Intrusion Detection System. Retrieved from https:\/\/www.alienvault.com\/solutions\/host-intrusion-detection-system."},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2016.2519914"},{"key":"e_1_2_1_8_1","unstructured":"Austin Appleby. 2017. Murmurhash. Retrieved from https:\/\/sites.google.com\/site\/murmurhash\/."},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2011.08.009"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.5815\/ijitcs.2013.08.08"},{"key":"e_1_2_1_11_1","first-page":"1","article-title":"Standardizing cyber threat intelligence information with the structured threat information eXpression (STIX)","volume":"11","author":"Barnum Sean","year":"2012","unstructured":"Sean Barnum. 2012. Standardizing cyber threat intelligence information with the structured threat information eXpression (STIX). MITRE Corporation 11 (2012), 1--22.","journal-title":"MITRE Corporation"},{"key":"e_1_2_1_12_1","unstructured":"VMware Knowledge Base. 2017. esxtop. Retrieved from https:\/\/kb.vmware.com\/selfservice\/microsites\/search.do?language=en_US8cmd&equals;displayKC&externalId&equals;&equals;&equals;1008205."},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/MALWARE.2010.5665792"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1080\/15427951.2004.10129096"},{"key":"e_1_2_1_15_1","unstructured":"Bsd. 2017. Kernel Virtual Machine. Retrieved from http:\/\/www.linux-kvm.org\/page\/Main_Page."},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046614.2046619"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/2338965.2336768"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/1541880.1541882"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2010.235"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2017.2676110"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2015.7280371"},{"key":"e_1_2_1_22_1","unstructured":"The MITRE Corporation. 2017. Common Vulnerabilities and Exposures. Retrieved from https:\/\/cve.mitre.org\/."},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/WCNC.2013.6555301"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2013.13"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2015.2491300"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/1143844.1143874"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICPR.2002.1048264"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.asoc.2010.12.004"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2015.02.001"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/MASS.2014.65"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1023\/A:1007469218079"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2008.54"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.5555\/1947337.1947356"},{"key":"e_1_2_1_35_1","unstructured":"Alluxio Open Foundation. 2017. Alluxio. Retrieved from http:\/\/www.alluxio.org\/."},{"key":"e_1_2_1_36_1","unstructured":"Apache Software Foundation. 2017. Apache Hadoop YARN. Retrieved from https:\/\/hadoop.apache.org\/docs\/r2.7.2\/hadoop-yarn\/hadoop-yarn-site\/YARN.html."},{"key":"e_1_2_1_37_1","unstructured":"Apache Software Foundation. 2017. Apache Kafka a distributed streaming platform. Retrieved from https:\/\/kafka.apache.org\/."},{"key":"e_1_2_1_38_1","unstructured":"The Apache Software Foundation. 2017. Apache Flume. Retrieved from https:\/\/flume.apache.org\/."},{"key":"e_1_2_1_39_1","unstructured":"The Apache Software Foundation. 2018. Spark. Retrieved from http:\/\/spark.apache.org\/."},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.5555\/647593.728880"},{"key":"e_1_2_1_41_1","unstructured":"Sebastien Godard. 2017. mpstat. Retrieved from http:\/\/linuxcommand.org\/man_pages\/mpstat1.html."},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/ROBIO.2013.6739538"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11277-014-2136-x"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.3390\/fi8030029"},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2017.03.018"},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICIEA.2015.7334166"},{"key":"e_1_2_1_47_1","volume-title":"Detecting anomalous behavior in cloud servers by nested arc hidden SEMI-Markov model with state summarization","author":"Haider Waqas","year":"2017","unstructured":"Waqas Haider, Jiankun Hu, Yi Xie, Xinghuo Yu, and Qianhong Wu. 2017. Detecting anomalous behavior in cloud servers by nested arc hidden SEMI-Markov model with state summarization. IEEE Transactions on Big Data (2017)."},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSCloud.2015.11"},{"key":"e_1_2_1_49_1","unstructured":"Fabian Frederick Henry Ware. 2017. vmstat. Retrieved from http:\/\/www.linuxcommand.org\/man_pages\/vmstat8.html."},{"key":"e_1_2_1_50_1","volume-title":"The 11th IEEE International Conference on Networks","author":"Hoang Xuan Dau","year":"2003","unstructured":"Xuan Dau Hoang, Jiankun Hu, and Peter Bertok. 2003. A multi-layer model for anomaly intrusion detection using program sequences of system calls. In The 11th IEEE International Conference on Networks, 2003 (ICON\u201903). Citeseer."},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2009.05.004"},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1162\/neco.1997.9.8.1735"},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.5555\/1298081.1298084"},{"key":"e_1_2_1_54_1","volume-title":"Host-based anomaly intrusion detection. Handbook of Information and Communication Security","author":"Jiankun Hu.","year":"2010","unstructured":"Jiankun Hu. 2010. Host-based anomaly intrusion detection. Handbook of Information and Communication Security (2010), 235--255."},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.2009.4804323"},{"key":"e_1_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2005.12.126"},{"key":"e_1_2_1_57_1","unstructured":"Ixia. 2017. PerfectStorm. Retrieved from https:\/\/www.ixiacom.com\/products\/perfectstorm."},{"key":"e_1_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2013.03.009"},{"key":"e_1_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/2647868.2654889"},{"key":"e_1_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSMCC.2006.871569"},{"key":"e_1_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2014.99"},{"key":"e_1_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jpdc.2016.11.003"},{"key":"e_1_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.5555\/1817271.1817451"},{"issue":"2018","key":"e_1_2_1_64_1","first-page":"415","article-title":"Combining heterogeneous anomaly detectors for improved software security","volume":"137","author":"Khreich Wael","year":"2017","unstructured":"Wael Khreich, Syed Shariyar Murtaza, Abdelwahab Hamou-Lhadj, and Chamseddine Talhi. 2017. Combining heterogeneous anomaly detectors for improved software security. Journal of Systems and Software 137 (2018), 415--429.","journal-title":"Journal of Systems and Software"},{"key":"e_1_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1109\/LGRS.2012.2224315"},{"key":"e_1_2_1_66_1","volume-title":"2016 International Conference on Communication and Signal Processing (ICCSP\u201916)","author":"Kulariya Manish","year":"1973","unstructured":"Manish Kulariya, Priyanka Saraf, Raushan Ranjan, and Govind P. Gupta. 2016. Performance analysis of network intrusion detection schemes using Apache Spark. In 2016 International Conference on Communication and Signal Processing (ICCSP\u201916). IEEE, 1973--1977."},{"key":"e_1_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1145\/2898375.2898399"},{"key":"e_1_2_1_68_1","volume-title":"Deep learning. Nature 521, 7553","author":"LeCun Yann","year":"2015","unstructured":"Yann LeCun, Yoshua Bengio, and Geoffrey Hinton. 2015. Deep learning. Nature 521, 7553 (2015), 436--444."},{"key":"e_1_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.5555\/1267549.1267555"},{"key":"e_1_2_1_70_1","volume-title":"AAAI Workshop on AI Approaches to Fraud Detection and Risk Management. 50--56","author":"Lee Wenke","unstructured":"Wenke Lee, Salvatore J. Stolfo, and Philip K. Chan. 1996. Learning patterns from unix process execution traces for intrusion detection. In AAAI Workshop on AI Approaches to Fraud Detection and Risk Management. 50--56."},{"key":"e_1_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.5555\/882495.884435"},{"key":"e_1_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.5555\/647253.720290"},{"key":"e_1_2_1_73_1","volume-title":"IEEE International Joint Conference on Neural Networks. 1714--1719","author":"Lichodzijewski Peter","unstructured":"Peter Lichodzijewski, A. Nur Zincir-Heywood, and Malcolm I. Heywood. 2002. Host-based intrusion detection using self-organizing maps. In IEEE International Joint Conference on Neural Networks. 1714--1719."},{"key":"e_1_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2008.69"},{"key":"e_1_2_1_75_1","volume-title":"Chan","author":"Mahoney Matthew V.","year":"2003","unstructured":"Matthew V. Mahoney and Philip K. Chan. 2003. An analysis of the 1999 DARPA\/lincoln laboratory evaluation data for network anomaly detection. In International Workshop on Recent Advances in Intrusion Detection. Springer, 220--237."},{"key":"e_1_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.5555\/951949.952127"},{"key":"e_1_2_1_77_1","unstructured":"McAfee. 2018. McAfee Host Intrusion Prevention for Desktop. Retrieved from https:\/\/www.mcafee.com\/uk\/products\/host-ips-for-desktop.aspx."},{"key":"e_1_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1145\/382912.382923"},{"key":"e_1_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.5555\/2946645.2946679"},{"key":"e_1_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1093\/imaman\/dpm026"},{"key":"e_1_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1145\/2808691"},{"key":"e_1_2_1_82_1","volume-title":"Jordan","author":"Moritz Philipp","year":"2015","unstructured":"Philipp Moritz, Robert Nishihara, Ion Stoica, and Michael I. Jordan. 2015. Sparknet: Training deep networks in spark. arXiv Preprint arXiv:1511.06051 (2015)."},{"key":"e_1_2_1_83_1","doi-asserted-by":"publisher","DOI":"10.1109\/SCAM.2014.37"},{"key":"e_1_2_1_84_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISSRE.2013.6698896"},{"key":"e_1_2_1_85_1","doi-asserted-by":"publisher","DOI":"10.1109\/CISDA.2015.7208644"},{"key":"e_1_2_1_86_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2014.2337256"},{"key":"e_1_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.1145\/1127345.1127348"},{"key":"e_1_2_1_88_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2016.09.037"},{"key":"e_1_2_1_89_1","unstructured":"University of New Mexico. 2017. Sequence-Based Intrusion Detection. Retrieved from http:\/\/www.cs.unm.edu\/ immsec\/systemcalls.htm."},{"key":"e_1_2_1_90_1","unstructured":"OSSIM. 2018. AlienVault OSSIM: The World\u2019s Most Widely Used Open Source SIEM. Retrieved from https:\/\/www.alienvault.com\/products\/ossim."},{"key":"e_1_2_1_91_1","volume-title":"Hierarchical recurrent neural encoder for video representation with application to captioning. arXiv Preprint arXiv:1511.03476","author":"Pan Pingbo","year":"2015","unstructured":"Pingbo Pan, Zhongwen Xu, Yi Yang, Fei Wu, and Yueting Zhuang. 2015. Hierarchical recurrent neural encoder for video representation with application to captioning. arXiv Preprint arXiv:1511.03476 (2015)."},{"key":"e_1_2_1_92_1","doi-asserted-by":"publisher","DOI":"10.5555\/2075658.2075669"},{"key":"e_1_2_1_93_1","doi-asserted-by":"publisher","DOI":"10.1049\/el:20020467"},{"key":"e_1_2_1_94_1","doi-asserted-by":"publisher","DOI":"10.1109\/5.18626"},{"key":"e_1_2_1_95_1","unstructured":"Rapid7. 2017. Metasploit. Retrieved from https:\/\/www.metasploit.com\/."},{"key":"e_1_2_1_96_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSST.2010.5496972"},{"key":"e_1_2_1_97_1","doi-asserted-by":"publisher","DOI":"10.1109\/BigData.2014.7004343"},{"key":"e_1_2_1_98_1","doi-asserted-by":"publisher","DOI":"10.1002\/spe.2390"},{"key":"e_1_2_1_99_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.25"},{"key":"e_1_2_1_100_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSN.2012.43"},{"key":"e_1_2_1_101_1","doi-asserted-by":"publisher","DOI":"10.1109\/TFUZZ.1993.390281"},{"key":"e_1_2_1_102_1","doi-asserted-by":"publisher","DOI":"10.5555\/829514.830544"},{"key":"e_1_2_1_103_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPDS.2013.146"},{"key":"e_1_2_1_104_1","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2014.2375218"},{"key":"e_1_2_1_105_1","doi-asserted-by":"publisher","DOI":"10.1109\/MCC.2014.53"},{"key":"e_1_2_1_106_1","doi-asserted-by":"publisher","unstructured":"Gaurav Tandon. 2008. Machine Learning for Host-Based Anomaly Detection. Thesis.","DOI":"10.5555\/1414960"},{"key":"e_1_2_1_107_1","unstructured":"OSSEC Project Team. 2017. OSSEC Open Source HIDS SECurity. Retrieved from http:\/\/ossec.github.io\/."},{"key":"e_1_2_1_108_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICTAI.2006.17"},{"key":"e_1_2_1_109_1","doi-asserted-by":"publisher","DOI":"10.1145\/2716260"},{"key":"e_1_2_1_110_1","unstructured":"vmware. 2017. vSphere Guest SDK. Retrieved from https:\/\/www.vmware.com\/support\/developer\/guest-sdk\/."},{"key":"e_1_2_1_111_1","doi-asserted-by":"publisher","DOI":"10.1145\/586110.586145"},{"key":"e_1_2_1_112_1","volume-title":"Sequence-based prediction of RNA-protein interactions. Dissertations and Theses - Gradworks","author":"Walia Rasna Rani","year":"2014","unstructured":"Rasna Rani Walia. 2014. Sequence-based prediction of RNA-protein interactions. Dissertations and Theses - Gradworks (2014)."},{"key":"e_1_2_1_113_1","doi-asserted-by":"publisher","DOI":"10.1007\/11856214_12"},{"key":"e_1_2_1_114_1","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.1999.766910"},{"key":"e_1_2_1_115_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2015.2457918"},{"key":"e_1_2_1_116_1","first-page":"2736","article-title":"ANNs on co-occurrence matrices for mobile malware detection","volume":"9","author":"Xiao Xi","year":"2015","unstructured":"Xi Xiao, Zhenlong Wang, Qi Li, Qing Li, and Yong Jiang. 2015. ANNs on co-occurrence matrices for mobile malware detection. KSII Transactions on Internet and Information Systems (TIIS) 9, 7 (2015), 2736--2754.","journal-title":"KSII Transactions on Internet and Information Systems (TIIS)"},{"key":"e_1_2_1_117_1","doi-asserted-by":"publisher","DOI":"10.1109\/CISP.2013.6743952"},{"key":"e_1_2_1_118_1","doi-asserted-by":"publisher","DOI":"10.1109\/FSKD.2014.6980972"},{"key":"e_1_2_1_119_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-11698-3_44"},{"key":"e_1_2_1_120_1","volume-title":"attend and tell: Neural image caption generation with visual attention. arXiv Preprint arXiv:1502.03044 2, 3","author":"Xu Kelvin","year":"2015","unstructured":"Kelvin Xu, Jimmy Ba, Ryan Kiros, Kyunghyun Cho, Aaron Courville, Ruslan Salakhutdinov, Richard S. Zemel, and Yoshua Bengio. 2015. Show, attend and tell: Neural image caption generation with visual attention. arXiv Preprint arXiv:1502.03044 2, 3 (2015), 5."},{"key":"e_1_2_1_121_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSCloud.2016.27"},{"key":"e_1_2_1_122_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2016.2531684"},{"key":"e_1_2_1_123_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPDS.2013.2295810"},{"key":"e_1_2_1_124_1","doi-asserted-by":"publisher","DOI":"10.1109\/MCE.2017.2714695"},{"key":"e_1_2_1_125_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jcss.2014.04.022"},{"key":"e_1_2_1_126_1","doi-asserted-by":"publisher","DOI":"10.5555\/3157096.3157361"},{"key":"e_1_2_1_127_1","doi-asserted-by":"publisher","DOI":"10.1109\/EBISS.2010.5473675"},{"key":"e_1_2_1_128_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0031-3203(02)00026-2"},{"key":"e_1_2_1_129_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2011.05.007"},{"key":"e_1_2_1_130_1","doi-asserted-by":"publisher","unstructured":"Matei Zaharia. 2016. An Architecture for Fast and General Data Processing on Large Clusters. Morgan 8 Claypool. 10.1145\/2886107","DOI":"10.1145\/2886107"},{"key":"e_1_2_1_131_1","doi-asserted-by":"publisher","DOI":"10.5555\/2228298.2228301"},{"key":"e_1_2_1_132_1","doi-asserted-by":"publisher","DOI":"10.1145\/2517349.2522737"},{"key":"e_1_2_1_133_1","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2014.2360516"},{"key":"e_1_2_1_134_1","volume-title":"Security, Privacy and Trust in Cloud Systems","author":"Zhang Xuyun","unstructured":"Xuyun Zhang, Chang Liu, Surya Nepal, Chi Yang, and Jinjun Chen. 2014. Privacy preservation over big data in cloud systems. In Security, Privacy and Trust in Cloud Systems. Springer, 239--257."},{"key":"e_1_2_1_135_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jcss.2014.02.007"},{"key":"e_1_2_1_136_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPDS.2013.48"},{"key":"e_1_2_1_137_1","doi-asserted-by":"publisher","DOI":"10.1186\/s40537-015-0013-4"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3214304","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3214304","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T22:54:19Z","timestamp":1750287259000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3214304"}},"subtitle":["Review and Future Trends"],"short-title":[],"issued":{"date-parts":[[2018,11,19]]},"references-count":136,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2019,9,30]]}},"alternative-id":["10.1145\/3214304"],"URL":"https:\/\/doi.org\/10.1145\/3214304","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,11,19]]},"assertion":[{"value":"2017-07-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2018-04-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2018-11-19","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}