{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,13]],"date-time":"2026-06-13T05:40:32Z","timestamp":1781329232118,"version":"3.54.1"},"reference-count":91,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2021,9,22]],"date-time":"2021-09-22T00:00:00Z","timestamp":1632268800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Cyber-Phys. Syst."],"published-print":{"date-parts":[[2021,10,31]]},"abstract":"<jats:p>\n            <jats:bold>Artificial Intelligence (AI)-<\/jats:bold>\n            based classifiers rely on\n            <jats:bold>Machine Learning (ML)<\/jats:bold>\n            algorithms to provide functionalities that system architects are often willing to integrate into critical\n            <jats:bold>Cyber-Physical Systems (CPSs)<\/jats:bold>\n            . However, such algorithms may misclassify observations, with potential detrimental effects on the system itself or on the health of people and of the environment. In addition, CPSs may be subject to threats that were not previously known, motivating the need for building\n            <jats:bold>Intrusion Detectors (IDs)<\/jats:bold>\n            that can effectively deal with zero-day attacks. Different studies were directed to compare misclassifications of various algorithms to identify the most suitable one for a given system. Unfortunately, even the most suitable algorithm may still show an unsatisfactory number of misclassifications when system requirements are strict. A possible solution may rely on the adoption of meta-learners, which build ensembles of base-learners to reduce misclassifications and that are widely used for supervised learning. Meta-learners have the potential to reduce misclassifications with respect to non-meta learners: however, misleading base-learners may let the meta-learner leaning towards misclassifications and therefore their behavior needs to be carefully assessed through empirical evaluation. To such extent, in this paper we investigate, expand, empirically evaluate, and discuss meta-learning approaches that rely on ensembles of unsupervised algorithms to detect (zero-day) intrusions in CPSs. Our experimental comparison is conducted by means of public datasets belonging to network intrusion detection and biometric authentication systems, which are common IDSs for CPSs. Overall, we selected 21 datasets, 15 unsupervised algorithms and 9 different meta-learning approaches. Results allow discussing the applicability and suitability of meta-learning for unsupervised anomaly detection, comparing metric scores achieved by base algorithms and meta-learners. Analyses and discussion end up showing how the adoption of meta-learners significantly reduces misclassifications when detecting (zero-day) intrusions in CPSs.\n          <\/jats:p>","DOI":"10.1145\/3467470","type":"journal-article","created":{"date-parts":[[2021,9,22]],"date-time":"2021-09-22T21:36:34Z","timestamp":1632346594000},"page":"1-27","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":37,"title":["Meta-Learning to Improve Unsupervised Intrusion Detection in Cyber-Physical Systems"],"prefix":"10.1145","volume":"5","author":[{"given":"Tommaso","family":"Zoppi","sequence":"first","affiliation":[{"name":"Dept. of Mathematics and Informatics, University of Florence, Florence - Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mohamad","family":"Gharib","sequence":"additional","affiliation":[{"name":"Dept. of Mathematics and Informatics, University of Florence, Florence - Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Muhammad","family":"Atif","sequence":"additional","affiliation":[{"name":"Dept. of Mathematics and Informatics, University of Florence, Florence - Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Andrea","family":"Bondavalli","sequence":"additional","affiliation":[{"name":"Dept. of Mathematics and Informatics, University of Florence, Florence - Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,9,22]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/1541880.1541882"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0152173"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.5555\/1082161.1082198"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/3441140"},{"key":"e_1_2_1_5_1","volume-title":"Proceedings of the 2003 SIAM International Conference on Data Mining. Society for Industrial and Applied Mathematics, 25\u201336","author":"Lazarevic A.","unstructured":"A. Lazarevic , L. Ertoz , V. Kumar , A. Ozgur , and J. Srivastava . 2003. A comparative study of anomaly detection schemes in network intrusion detection . In Proceedings of the 2003 SIAM International Conference on Data Mining. Society for Industrial and Applied Mathematics, 25\u201336 . A. Lazarevic, L. Ertoz, V. Kumar, A. Ozgur, and J. Srivastava. 2003. A comparative study of anomaly detection schemes in network intrusion detection. In Proceedings of the 2003 SIAM International Conference on Data Mining. Society for Industrial and Applied Mathematics, 25\u201336."},{"key":"e_1_2_1_6_1","volume-title":"Proc. 4th Int. Conf. Internet Things, Big Data Secur. (IoTBDS) 1","author":"D'hooge L.","year":"2019","unstructured":"L. D'hooge , T. Wauters , B. Volckaert , and F. De Turck . 2019. In-depth comparative evaluation of supervised machine learning approaches for detection of cybersecurity threats . In Proc. 4th Int. Conf. Internet Things, Big Data Secur. (IoTBDS) 1 , ( 2019 ), 125\u2013136. L. D'hooge, T. Wauters, B. Volckaert, and F. De Turck. 2019. In-depth comparative evaluation of supervised machine learning approaches for detection of cybersecurity threats. In Proc. 4th Int. Conf. Internet Things, Big Data Secur. (IoTBDS) 1, (2019), 125\u2013136."},{"key":"e_1_2_1_7_1","volume-title":"Proceedings of the 3rd International Conference on Frontiers of Intelligent Computing: Theory and Applications (FICTA)","author":"Kenkre P. S.","year":"2014","unstructured":"P. S. Kenkre , A. Pai , and L. Colaco . 2015. Real time intrusion detection and prevention system . In Proceedings of the 3rd International Conference on Frontiers of Intelligent Computing: Theory and Applications (FICTA) 2014 . Springer, Cham, 405\u2013411. P. S. Kenkre, A. Pai, and L. Colaco. 2015. Real time intrusion detection and prevention system. In Proceedings of the 3rd International Conference on Frontiers of Intelligent Computing: Theory and Applications (FICTA) 2014. Springer, Cham, 405\u2013411."},{"key":"e_1_2_1_8_1","volume-title":"International Workshop on Recent Advances in Intrusion Detection. Springer","author":"Kruegel C.","unstructured":"C. Kruegel and T. Toth . 2003. Using decision trees to improve signature-based intrusion detection . In International Workshop on Recent Advances in Intrusion Detection. Springer , Berlin, 173\u2013191. C. Kruegel and T. Toth. 2003. Using decision trees to improve signature-based intrusion detection. In International Workshop on Recent Advances in Intrusion Detection. Springer, Berlin, 173\u2013191."},{"key":"e_1_2_1_9_1","volume-title":"International Conference on Computer Safety, Reliability, and Security. Springer, Cham, 145\u2013158","author":"Zoppi T.","unstructured":"T. Zoppi , A. Ceccarelli , and A. Bondavalli . 2016. Context-awareness to improve anomaly detection in dynamic service oriented architectures . In International Conference on Computer Safety, Reliability, and Security. Springer, Cham, 145\u2013158 . T. Zoppi, A. Ceccarelli, and A. Bondavalli. 2016. Context-awareness to improve anomaly detection in dynamic service oriented architectures. In International Conference on Computer Safety, Reliability, and Security. Springer, Cham, 145\u2013158."},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382284"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2012.01.016"},{"key":"e_1_2_1_12_1","volume-title":"\u201cCommittee on National Security Systems (CNSS) Glossary","author":"Committee on National Security Systems - CNSSI No. 4009","year":"2015","unstructured":"Committee on National Security Systems - CNSSI No. 4009 \u201cCommittee on National Security Systems (CNSS) Glossary \u201d, April 2015 . Committee on National Security Systems - CNSSI No. 4009 \u201cCommittee on National Security Systems (CNSS) Glossary\u201d, April 2015."},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2004.2"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1023\/A:1010933404324"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.5555\/3091696.3091715"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1023\/A:1018054314350"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1023\/A:1022648800760"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0893-6080(05)80023-1"},{"key":"e_1_2_1_19_1","first-page":"369","article-title":"Cascading classifiers","volume":"34","author":"Alpaydin E.","year":"1998","unstructured":"E. Alpaydin and C. Kaynak . 1998 . Cascading classifiers . Kybernetika 34 (1998), 369 \u2013 374 . E. Alpaydin and C. Kaynak. 1998. Cascading classifiers. Kybernetika 34 (1998), 369\u2013374.","journal-title":"Kybernetika"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1023\/A:1007652114878"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/1015330.1015395"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1007\/PL00011679"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.5555\/3000767.3000789"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-013-9406-y"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.5555\/1823045"},{"key":"e_1_2_1_27_1","volume-title":"2019 15th European Dependable Computing Conference (EDCC). IEEE, 141\u2013144","author":"Gharib M.","unstructured":"M. Gharib and A. Bondavalli . 2019. On the evaluation measures for machine learning algorithms for safety-critical systems . In 2019 15th European Dependable Computing Conference (EDCC). IEEE, 141\u2013144 . M. Gharib and A. Bondavalli. 2019. On the evaluation measures for machine learning algorithms for safety-critical systems. In 2019 15th European Dependable Computing Conference (EDCC). IEEE, 141\u2013144."},{"key":"e_1_2_1_28_1","volume-title":"Cyber Attack Trend: 2019 Mid-Year Report","author":"Research Check Point","year":"2019","unstructured":"Check Point Research . 2019. Cyber Attack Trend: 2019 Mid-Year Report , vol. 1 , 2019 . Check Point Research. 2019. Cyber Attack Trend: 2019 Mid-Year Report, vol. 1, 2019."},{"key":"e_1_2_1_30_1","volume-title":"Proc. 8th IEEE Int. Symp. on Fault-Tolerant Computing (FTCS-8). 1.","author":"Liming Chen","year":"1978","unstructured":"Chen Liming and Algirdas Avizienis . 1978 . N-version programming: A fault-tolerance approach to reliability of software operation . Proc. 8th IEEE Int. Symp. on Fault-Tolerant Computing (FTCS-8). 1. 1978. Chen Liming and Algirdas Avizienis. 1978. N-version programming: A fault-tolerance approach to reliability of software operation. Proc. 8th IEEE Int. Symp. on Fault-Tolerant Computing (FTCS-8). 1. 1978."},{"key":"e_1_2_1_31_1","doi-asserted-by":"crossref","first-page":"42","DOI":"10.1109\/24.765926","article-title":"Weighted voting systems","volume":"48","author":"Lars Nordmann","year":"2018","unstructured":"Nordmann Lars and Hoang Pham . 2018 . Weighted voting systems . IEEE Transactions on Reliability 48 , 1 (1999), 42 \u2013 49 . Nordmann Lars and Hoang Pham. 2018. Weighted voting systems. IEEE Transactions on Reliability 48, 1 (1999), 42\u201349.","journal-title":"IEEE Transactions on Reliability"},{"key":"e_1_2_1_32_1","volume-title":"Threat landscape report 7","author":"ENISA.","year":"2018","unstructured":"ENISA. 2018. Threat landscape report 7 , 2018 . ENISA. 2018. Threat landscape report 7, 2018."},{"key":"e_1_2_1_33_1","doi-asserted-by":"crossref","unstructured":"M. Ring S. Wunderlich D. Scheuring D. Landes and A. Hotho. 2019. A survey of network-based intrusion detection data sets. Computers & Security.  M. Ring S. Wunderlich D. Scheuring D. Landes and A. Hotho. 2019. A survey of network-based intrusion detection data sets. Computers & Security.","DOI":"10.1016\/j.cose.2019.06.005"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2011.12.012"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.5555\/1736481.1736489"},{"key":"e_1_2_1_36_1","volume-title":"Proceedings of the 16th European Conference on Cyber Warfare and Security. ACPI, 361\u2013369","author":"Ring M.","unstructured":"M. Ring , S. Wunderlich , D. Gr\u00fcdl , D. Landes , and A. Hotho . 2017. Flow-based benchmark data sets for intrusion detection . In Proceedings of the 16th European Conference on Cyber Warfare and Security. ACPI, 361\u2013369 . M. Ring, S. Wunderlich, D. Gr\u00fcdl, D. Landes, and A. Hotho. 2017. Flow-based benchmark data sets for intrusion detection. In Proceedings of the 16th European Conference on Cyber Warfare and Security. ACPI, 361\u2013369."},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"e_1_2_1_38_1","doi-asserted-by":"crossref","unstructured":"I. Sharafaldin A. H. Lashkari and A. A. Ghorbani. 2018. Toward generating a new intrusion detection dataset and intrusion traffic characterization. In ICISSP 108\u2013116.  I. Sharafaldin A. H. Lashkari and A. A. Ghorbani. 2018. Toward generating a new intrusion detection dataset and intrusion traffic characterization. In ICISSP 108\u2013116.","DOI":"10.5220\/0006639801080116"},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2017.03.018"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2014.05.011"},{"key":"e_1_2_1_41_1","volume-title":"2018 International Carnahan Conference on Security Technology (ICCST). IEEE, 1\u20137.","author":"Lashkari A. H.","unstructured":"A. H. Lashkari , A. F. A. Kadir , L. Taheri , and A. A. Ghorbani . 2018. Toward developing a systematic approach to generate benchmark android malware datasets and classification . In 2018 International Carnahan Conference on Security Technology (ICCST). IEEE, 1\u20137. A. H. Lashkari, A. F. A. Kadir, L. Taheri, and A. A. Ghorbani. 2018. Toward developing a systematic approach to generate benchmark android malware datasets and classification. In 2018 International Carnahan Conference on Security Technology (ICCST). IEEE, 1\u20137."},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2017.11.004"},{"key":"e_1_2_1_43_1","volume-title":"Retrieved on","author":"Biometrics Ideal Test BIT","year":"2020","unstructured":"BIT \u2013 Biometrics Ideal Test , CASIA-FingerprintV5. Retrieved on 15 December , 2020 from http:\/\/biometrics.idealtest.org\/ BIT \u2013 Biometrics Ideal Test, CASIA-FingerprintV5. Retrieved on 15 December, 2020 from http:\/\/biometrics.idealtest.org\/"},{"key":"e_1_2_1_44_1","unstructured":"MathWorks - FingerPrint Matching: A simple approach https:\/\/it.mathworks.com\/matlabcentral\/fileexchange\/44369-fingerprint-matching-a-simple-approach (online) accessed: 2019-11-20  MathWorks - FingerPrint Matching: A simple approach https:\/\/it.mathworks.com\/matlabcentral\/fileexchange\/44369-fingerprint-matching-a-simple-approach (online) accessed: 2019-11-20"},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0188226"},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/2663204.2663257"},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/3242969.3242985"},{"key":"e_1_2_1_48_1","volume-title":"STAG: Smart Tools & Apps for Graphics","author":"Memo A.","year":"2015","unstructured":"A. Memo , L. Minto , and P. Zanuttigh . 2015 . Exploiting Silhouette Descriptors and Synthetic Data for Hand Gesture Recognition . STAG: Smart Tools & Apps for Graphics , 2015 A. Memo, L. Minto, and P. Zanuttigh. 2015. Exploiting Silhouette Descriptors and Synthetic Data for Hand Gesture Recognition. STAG: Smart Tools & Apps for Graphics, 2015"},{"key":"e_1_2_1_49_1","unstructured":"A. Vajdi M. R. Zaghian S. Farahmand E. Rastegar K. Maroofi S. Jia and A. Bayat. 2019. Human gait database for normal walk collected by smart phone accelerometer. arXiv preprint arXiv:1905.03109.  A. Vajdi M. R. Zaghian S. Farahmand E. Rastegar K. Maroofi S. Jia and A. Bayat. 2019. Human gait database for normal walk collected by smart phone accelerometer. arXiv preprint arXiv:1905.03109."},{"key":"e_1_2_1_50_1","unstructured":"Kaggle - Voice Recognition Jeganathan Kolappan. https:\/\/www.kaggle.com\/jeganathan\/voice-recognition (online) accessed: 2019-11-20  Kaggle - Voice Recognition Jeganathan Kolappan. https:\/\/www.kaggle.com\/jeganathan\/voice-recognition (online) accessed: 2019-11-20"},{"key":"e_1_2_1_51_1","unstructured":"Kaggle - Face Images with Marked Landmark Points Omri Goldstein. https:\/\/www.kaggle.com\/drgilermo\/face-images-with-marked-landmark-points (online) accessed: 2019-11-20  Kaggle - Face Images with Marked Landmark Points Omri Goldstein. https:\/\/www.kaggle.com\/drgilermo\/face-images-with-marked-landmark-points (online) accessed: 2019-11-20"},{"key":"e_1_2_1_52_1","volume-title":"Cyber-Physical Systems (CPS) - nsf20563","author":"National Science Foundation","year":"2020","unstructured":"National Science Foundation , \u201c Cyber-Physical Systems (CPS) - nsf20563 \u201d, April 2020 National Science Foundation, \u201cCyber-Physical Systems (CPS) - nsf20563\u201d, April 2020"},{"key":"e_1_2_1_53_1","volume-title":"2016 7th IEEE International Conference on Software Engineering and Service Science (ICSESS). IEEE, 422\u2013425","author":"Wang Y.","unstructured":"Y. Wang , Y. Shen , and G. Zhang . 2016. Research on intrusion detection model using ensemble learning methods . In 2016 7th IEEE International Conference on Software Engineering and Service Science (ICSESS). IEEE, 422\u2013425 . Y. Wang, Y. Shen, and G. Zhang. 2016. Research on intrusion detection model using ensemble learning methods. In 2016 7th IEEE International Conference on Software Engineering and Service Science (ICSESS). IEEE, 422\u2013425."},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2928048"},{"key":"e_1_2_1_55_1","first-page":"5","article-title":"A stacked generalization ensemble approach for improved intrusion detection","volume":"18","author":"Oriola O.","year":"2020","unstructured":"O. Oriola . 2020 . A stacked generalization ensemble approach for improved intrusion detection . International Journal of Computer Science and Information Security (IJCSIS) 18 (2020), 5 . O. Oriola. 2020. A stacked generalization ensemble approach for improved intrusion detection. International Journal of Computer Science and Information Security (IJCSIS) 18 (2020), 5.","journal-title":"International Journal of Computer Science and Information Security (IJCSIS)"},{"key":"e_1_2_1_56_1","volume-title":"2019 IEEE Symposium on Computers and Communications (ISCC). IEEE, 1\u20136.","author":"Possebon I. P.","unstructured":"I. P. Possebon , A. S. Silva , L. Z. Granville , A. Schaeffer-Filho , and A. Marnerides . 2019. Improved network traffic classification using ensemble learning . In 2019 IEEE Symposium on Computers and Communications (ISCC). IEEE, 1\u20136. I. P. Possebon, A. S. Silva, L. Z. Granville, A. Schaeffer-Filho, and A. Marnerides. 2019. Improved network traffic classification using ensemble learning. In 2019 IEEE Symposium on Computers and Communications (ISCC). IEEE, 1\u20136."},{"key":"e_1_2_1_57_1","article-title":"An ensemble of classification techniques for intrusion detection systems","volume":"17","author":"Alaba A.","year":"2019","unstructured":"A. Alaba , S. Maitanmi , and O. Ajayi . 2019 . An ensemble of classification techniques for intrusion detection systems . International Journal of Computer Science and Information Security (IJCSIS) 17 , 11 (2019) A. Alaba, S. Maitanmi, and O. Ajayi. 2019. An ensemble of classification techniques for intrusion detection systems. International Journal of Computer Science and Information Security (IJCSIS) 17, 11 (2019)","journal-title":"International Journal of Computer Science and Information Security (IJCSIS)"},{"key":"e_1_2_1_58_1","volume-title":"Security and Communication Networks","author":"Rajagopal S.","year":"2020","unstructured":"S. Rajagopal , P. P. Kundapur , and K. S. Hareesha . 2020. A stacking ensemble for network intrusion detection using heterogeneous datasets . Security and Communication Networks , 2020 . S. Rajagopal, P. P. Kundapur, and K. S. Hareesha. 2020. A stacking ensemble for network intrusion detection using heterogeneous datasets. Security and Communication Networks, 2020."},{"key":"e_1_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10618-015-0444-8"},{"key":"e_1_2_1_60_1","volume-title":"Evaluation: from precision, recall and f-measure to roc, informedness, markedness and correlation","author":"Powers D. M.","year":"2011","unstructured":"D. M. Powers . 2011. Evaluation: from precision, recall and f-measure to roc, informedness, markedness and correlation , 2011 D. M. Powers. 2011. Evaluation: from precision, recall and f-measure to roc, informedness, markedness and correlation, 2011"},{"key":"e_1_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1186\/s12864-019-6413-7"},{"key":"e_1_2_1_62_1","volume-title":"Proceedings of the 30th Int. Symposium on Soft-ware Reliability Engineering (ISSRE). IEEE, 446\u2013455","author":"Zoppi T.","year":"2019","unstructured":"T. Zoppi , A. Ceccarelli , and A. Bondavalli . 2019. Evaluation of anomaly detection algorithms made easy with RELOAD . In Proceedings of the 30th Int. Symposium on Soft-ware Reliability Engineering (ISSRE). IEEE, 446\u2013455 . DOI:https:\/\/doi.org\/10.1109\/ISSRE. 2019 .00051 10.1109\/ISSRE.2019.00051 T. Zoppi, A. Ceccarelli, and A. Bondavalli. 2019. Evaluation of anomaly detection algorithms made easy with RELOAD. In Proceedings of the 30th Int. Symposium on Soft-ware Reliability Engineering (ISSRE). IEEE, 446\u2013455. DOI:https:\/\/doi.org\/10.1109\/ISSRE.2019.00051"},{"key":"e_1_2_1_63_1","first-page":"18","article-title":"Feature selection based on information gain","volume":"2","author":"Azhagusundari B.","year":"2013","unstructured":"B. Azhagusundari and Antony Selvadoss Thanamani . 2013 . Feature selection based on information gain . International Journal of Innovative Technology and Exploring Engineering (IJITEE) 2 , 2 (2013), 18 \u2013 21 . B. Azhagusundari and Antony Selvadoss Thanamani. 2013. Feature selection based on information gain. International Journal of Innovative Technology and Exploring Engineering (IJITEE) 2, 2 (2013), 18\u201321.","journal-title":"International Journal of Innovative Technology and Exploring Engineering (IJITEE)"},{"key":"e_1_2_1_64_1","volume-title":"Histogram-based outlier score (hbos): A fast unsupervised anomaly detection algorithm. KI-2012: Poster \/Demo Track","author":"Markus Goldstein","year":"2012","unstructured":"Goldstein Markus and Andreas Dengel . 2012. Histogram-based outlier score (hbos): A fast unsupervised anomaly detection algorithm. KI-2012: Poster \/Demo Track ( 2012 ), 59\u201363. Goldstein Markus and Andreas Dengel. 2012. Histogram-based outlier score (hbos): A fast unsupervised anomaly detection algorithm. KI-2012: Poster \/Demo Track (2012), 59\u201363."},{"key":"e_1_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1145\/1401890.1401946"},{"key":"e_1_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.5555\/1018429.1021000"},{"key":"e_1_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1145\/2500853.2500857"},{"key":"e_1_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDMW.2018.00140"},{"key":"e_1_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.5555\/306795.306798"},{"key":"e_1_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.5555\/2981345.2981381"},{"key":"e_1_2_1_71_1","volume-title":"Proceedings of the 3rd RapidMiner Community Meeting and Conference (RCOMM","author":"Amer Mennatallah","year":"2012","unstructured":"Mennatallah Amer and Markus Goldstein . 2012 . Nearest-neighbor and clustering based anomaly detection algorithms for rapidminer . In Proceedings of the 3rd RapidMiner Community Meeting and Conference (RCOMM 2012). Mennatallah Amer and Markus Goldstein. 2012. Nearest-neighbor and clustering based anomaly detection algorithms for rapidminer. In Proceedings of the 3rd RapidMiner Community Meeting and Conference (RCOMM 2012)."},{"key":"e_1_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.5555\/646420.693665"},{"key":"e_1_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.5555\/3001460.3001507"},{"key":"e_1_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1145\/342009.335388"},{"key":"e_1_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2014.2365790"},{"key":"e_1_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2008.17"},{"key":"e_1_2_1_78_1","first-page":"100","article-title":"Algorithm AS 136: A k-means clustering algorithm. Journal of the Royal Statistical Society","volume":"28","author":"Hartigan J. A.","year":"1979","unstructured":"J. A. Hartigan and M. A. Wong . 1979 . Algorithm AS 136: A k-means clustering algorithm. Journal of the Royal Statistical Society . Series C , 28 , 1 (1979), 100 \u2013 108 . J. A. Hartigan and M. A. Wong. 1979. Algorithm AS 136: A k-means clustering algorithm. Journal of the Royal Statistical Society. Series C, 28, 1 (1979), 100\u2013108.","journal-title":"Series C"},{"key":"e_1_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.5555\/1795765"},{"key":"e_1_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2006.12.008"},{"key":"e_1_2_1_81_1","first-page":"25","article-title":"Multimodal biometric system: A review","volume":"4","author":"Dahea W.","year":"2018","unstructured":"W. Dahea and H. S. Fadewar . 2018 . Multimodal biometric system: A review . International Journal of Research in Advanced Engineering and Technology 4 , 1 (2018), 25 \u2013 31 . W. Dahea and H. S. Fadewar. 2018. Multimodal biometric system: A review. International Journal of Research in Advanced Engineering and Technology 4, 1 (2018), 25\u201331.","journal-title":"International Journal of Research in Advanced Engineering and Technology"},{"key":"e_1_2_1_82_1","volume-title":"Retrieved on","author":"Archive","year":"2020","unstructured":"Archive of full metric scores (online). Retrieved on 15 December , 2020 from https:\/\/drive.google.com\/file\/d\/1D3M9tLxtG9yvG689LbAONykjBz3XXHJ8\/view?usp=sharing Archive of full metric scores (online). Retrieved on 15 December, 2020 from https:\/\/drive.google.com\/file\/d\/1D3M9tLxtG9yvG689LbAONykjBz3XXHJ8\/view?usp=sharing"},{"key":"e_1_2_1_83_1","volume-title":"Explaining adaboost. Empirical inference","author":"Schapire Robert E.","unstructured":"Robert E. Schapire . 2013. Explaining adaboost. Empirical inference . Springer , Berlin , 37\u201352. Robert E. Schapire. 2013. Explaining adaboost. Empirical inference. Springer, Berlin, 37\u201352."},{"key":"e_1_2_1_84_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2020.102474"},{"key":"e_1_2_1_85_1","unstructured":"Hindy Hanan et al. 2018. A taxonomy and survey of intrusion detection system design techniques network threats and datasets. arXiv preprint arXiv:1806.03517 (2018).  Hindy Hanan et al. 2018. A taxonomy and survey of intrusion detection system design techniques network threats and datasets. arXiv preprint arXiv:1806.03517 (2018)."},{"key":"e_1_2_1_86_1","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-019-0038-7"},{"key":"e_1_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0177678"},{"key":"e_1_2_1_88_1","doi-asserted-by":"crossref","unstructured":"Q. Zhu. 2020. On the performance of Matthews correlation coefficient (MCC) for imbalanced dataset. Pattern Recognition Letters.  Q. Zhu. 2020. On the performance of Matthews correlation coefficient (MCC) for imbalanced dataset. Pattern Recognition Letters.","DOI":"10.1016\/j.patrec.2020.03.030"},{"key":"e_1_2_1_89_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2019.12.013"},{"key":"e_1_2_1_90_1","volume-title":"International Conference on Advances in Computing and Data Sciences","author":"Bansal A.","unstructured":"A. Bansal and S. Kaur . 2018. Extreme gradient boosting based tuning for classification in intrusion detection systems . In International Conference on Advances in Computing and Data Sciences . Springer, Singapore, 372\u2013380. A. Bansal and S. Kaur. 2018. Extreme gradient boosting based tuning for classification in intrusion detection systems. In International Conference on Advances in Computing and Data Sciences. Springer, Singapore, 372\u2013380."},{"key":"e_1_2_1_91_1","doi-asserted-by":"publisher","DOI":"10.1109\/NAECON.2017.8268746"},{"key":"e_1_2_1_92_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3001350"},{"key":"e_1_2_1_93_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2903723"},{"key":"e_1_2_1_94_1","doi-asserted-by":"crossref","unstructured":"L. Torrey and J. Shavlik. 2010. Transfer learning. In Handbook of Research on Machine Learning Applications and Trends: Algorithms Methods and Techniques. IGI global 242\u2013264.  L. Torrey and J. Shavlik. 2010. Transfer learning. In Handbook of Research on Machine Learning Applications and Trends: Algorithms Methods and Techniques. IGI global 242\u2013264.","DOI":"10.4018\/978-1-60566-766-9.ch011"}],"container-title":["ACM Transactions on Cyber-Physical Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3467470","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3467470","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T21:25:07Z","timestamp":1750195507000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3467470"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,9,22]]},"references-count":91,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2021,10,31]]}},"alternative-id":["10.1145\/3467470"],"URL":"https:\/\/doi.org\/10.1145\/3467470","relation":{},"ISSN":["2378-962X","2378-9638"],"issn-type":[{"value":"2378-962X","type":"print"},{"value":"2378-9638","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,9,22]]},"assertion":[{"value":"2020-08-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-05-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-09-22","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}