{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,18]],"date-time":"2026-08-18T01:42:29Z","timestamp":1787017349382,"version":"build-2736575974"},"publisher-location":"New York, NY, USA","reference-count":42,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,8,29]],"date-time":"2023-08-29T00:00:00Z","timestamp":1693267200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,8,29]]},"DOI":"10.1145\/3600160.3605031","type":"proceedings-article","created":{"date-parts":[[2023,8,9]],"date-time":"2023-08-09T18:54:41Z","timestamp":1691607281000},"page":"1-8","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":15,"title":["A Case Study with CICIDS2017 on the Robustness of Machine Learning against Adversarial Attacks in Intrusion Detection"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5025-7969","authenticated-orcid":false,"given":"Marta","family":"Catillo","sequence":"first","affiliation":[{"name":"Universit\u00e0 degli Studi del Sannio, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-9422-7645","authenticated-orcid":false,"given":"Andrea","family":"Del Vecchio","sequence":"additional","affiliation":[{"name":"Universit\u00e0 degli Studi del Sannio, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2869-8423","authenticated-orcid":false,"given":"Antonio","family":"Pecchia","sequence":"additional","affiliation":[{"name":"Universit\u00e0 degli Studi del Sannio, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5382-4650","authenticated-orcid":false,"given":"Umberto","family":"Villano","sequence":"additional","affiliation":[{"name":"Universit\u00e0 degli Studi del Sannio, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,8,29]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2022.3157344"},{"key":"e_1_3_2_1_2_1","volume-title":"Proc. International Conference on Networking, Sensing and Control. IEEE, 617\u2013624","author":"Beer F.","unstructured":"F. Beer and U. Buehler. 2017. Feature selection for flow-based intrusion detection using rough set theory. In Proc. International Conference on Networking, Sensing and Control. IEEE, 617\u2013624."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"crossref","unstructured":"B. Biggio I. Corona G. Fumera G. Giacinto and F. Roli. 2011. Bagging Classifiers for Fighting Poisoning Attacks in Adversarial Classification Tasks. In Multiple Classifier Systems C.\u00a0Sansone J.\u00a0Kittler and F.\u00a0Roli (Eds.). Springer 350\u2013359.","DOI":"10.1007\/978-3-642-21557-5_37"},{"key":"e_1_3_2_1_4_1","volume-title":"Proc. Symposium on Security and Privacy. IEEE, 39\u201357","author":"Carlini N.","unstructured":"N. Carlini and D. Wagner. 2017. Towards Evaluating the Robustness of Neural Networks. In Proc. Symposium on Security and Privacy. IEEE, 39\u201357."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11219-022-09587-0"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103210"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.3390\/app13020837"},{"key":"e_1_3_2_1_8_1","volume-title":"Cloud: Current Status and Perspectives. In Advances on P2P, Parallel, Grid, Cloud and Internet Computing, L.\u00a0Barolli, P.\u00a0Hellinckx, and J.\u00a0Natwichai (Eds.)","author":"Catillo M.","year":"2020","unstructured":"M. Catillo, M. Rak, and U. Villano. 2020. Auto-scaling in the Cloud: Current Status and Perspectives. In Advances on P2P, Parallel, Grid, Cloud and Internet Computing, L.\u00a0Barolli, P.\u00a0Hellinckx, and J.\u00a0Natwichai (Eds.). Springer, 616\u2013625."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/1541880.1541882"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2013.03.022"},{"key":"e_1_3_2_1_11_1","first-page":"26","article-title":"Adversarial machine learning for cyber security","volume":"12","author":"De\u00a0Lucia J","year":"2019","unstructured":"M.\u00a0J De\u00a0Lucia and C. Cotton. 2019. Adversarial machine learning for cyber security. Journal of Information Systems Applied Research 12, 1 (2019), 26.","journal-title":"Journal of Information Systems Applied Research"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.iot.2021.100462"},{"key":"e_1_3_2_1_13_1","volume-title":"Proc. Security and Privacy Workshops. IEEE, 7\u201312","author":"Engelen G.","unstructured":"G. Engelen, V. Rimmer, and W. Joosen. 2021. Troubleshooting an Intrusion Detection Dataset: the CICIDS2017 Case Study. In Proc. Security and Privacy Workshops. IEEE, 7\u201312."},{"key":"e_1_3_2_1_14_1","unstructured":"I.\u00a0J. Goodfellow J. Shlens and C. Szegedy. 2015. Explaining and Harnessing Adversarial Examples. arxiv:1412.6572\u00a0[stat.ML]"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2022.3233793"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1016\/0020-0190(76)90095-8"},{"key":"e_1_3_2_1_17_1","volume-title":"Proc. European Signal Processing Conference. EURASIP, 533\u2013537","author":"Kolosnjaji B.","unstructured":"B. Kolosnjaji, A. Demontis, B. Biggio, D. Maiorca, G. Giacinto, C. Eckert, and F. Roli. 2018. Adversarial Malware Binaries: Evading Deep Learning for Malware Detection in Executables. In Proc. European Signal Processing Conference. EURASIP, 533\u2013537."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1002\/aic.690370209"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICECOS.2018.8605181"},{"key":"e_1_3_2_1_20_1","volume-title":"Proc. International Conference of Network and Distributed System Security Symposium.","author":"Mirsky Y.","unstructured":"Y. Mirsky, T. Doitshman, Y. Elovici, and A. Shabtai. 2018. Kitsune: An Ensemble of Autoencoders for Online Network Intrusion Detection. In Proc. International Conference of Network and Distributed System Security Symposium."},{"key":"e_1_3_2_1_21_1","unstructured":"T. Miyato S. Maeda M. Koyama K. Nakae and S. Ishii. 2016. Distributional Smoothing with Virtual Adversarial Training. arxiv:1507.00677\u00a0[stat.ML]"},{"key":"e_1_3_2_1_22_1","volume-title":"Proc. Conference on Computer Vision and Pattern Recognition. IEEE, 2574\u20132582","author":"Moosavi-Dezfooli S.","unstructured":"S. Moosavi-Dezfooli, A. Fawzi, and P. Frossard. 2016. DeepFool: A Simple and Accurate Method to Fool Deep Neural Networks. In Proc. Conference on Computer Vision and Pattern Recognition. IEEE, 2574\u20132582."},{"key":"e_1_3_2_1_23_1","volume-title":"Proc. Military Communications and Information Systems Conference. IEEE, 1\u20136.","author":"Moustafa N.","unstructured":"N. Moustafa and J. Slay. 2015. UNSW-NB15: a comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). In Proc. Military Communications and Information Systems Conference. IEEE, 1\u20136."},{"key":"e_1_3_2_1_24_1","volume-title":"Misleading Learners: Co-opting Your Spam Filter. In Machine Learning in Cyber Trust: Security, Privacy, and Reliability","author":"Nelson B.","year":"2009","unstructured":"B. Nelson, M. Barreno, F. Jack\u00a0Chi, A.\u00a0D. Joseph, B.\u00a0I.\u00a0P. Rubinstein, U. Saini, C. Sutton, J.\u00a0D. Tygar, and K. Xia. 2009. Misleading Learners: Co-opting Your Spam Filter. In Machine Learning in Cyber Trust: Security, Privacy, and Reliability. Springer, 17\u201351."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2019.8802833"},{"key":"e_1_3_2_1_26_1","unstructured":"M. Nicolae M. Sinn M.\u00a0N. Tran B. Buesser A. Rawat M. Wistuba V. Zantedeschi N. Baracaldo B. Chen H. Ludwig I.\u00a0M. Molloy and B. Edwards. 2019. Adversarial Robustness Toolbox v1.0.0. arxiv:1807.01069\u00a0[cs.LG]"},{"key":"e_1_3_2_1_27_1","first-page":"38","article-title":"Deep Learning for Anomaly Detection","volume":"54","author":"Pang G.","year":"2021","unstructured":"G. Pang, C. Shen, L. Cao, and A.\u00a0V.\u00a0D. Hengel. 2021. Deep Learning for Anomaly Detection: A Review. ACM Computing Surveys 54, 2 (2021), 38.","journal-title":"A Review. ACM Computing Surveys"},{"key":"e_1_3_2_1_28_1","unstructured":"N. Papernot P. McDaniel and I. Goodfellow. 2016. Transferability in Machine Learning: from Phenomena to Black-Box Attacks using Adversarial Samples. arxiv:1605.07277\u00a0[cs.CR]"},{"key":"e_1_3_2_1_29_1","volume-title":"Proc. Asia Conference on Computer and Communications Security. ACM, 506\u2013519","author":"Papernot N.","unstructured":"N. Papernot, P. McDaniel, I. Goodfellow, S. Jha, Z.\u00a0B. Celik, and A. Swami. 2017. Practical Black-Box Attacks against Machine Learning. In Proc. Asia Conference on Computer and Communications Security. ACM, 506\u2013519."},{"key":"e_1_3_2_1_30_1","volume-title":"Proc. European Symposium on Security and Privacy. IEEE, 372\u2013387","author":"Papernot N.","unstructured":"N. Papernot, P. McDaniel, S. Jha, M. Fredrikson, Z.\u00a0B. Celik, and A. Swami. 2016. The Limitations of Deep Learning in Adversarial Settings. In Proc. European Symposium on Security and Privacy. IEEE, 372\u2013387."},{"key":"e_1_3_2_1_31_1","volume-title":"Proc. Symposium on Security and Privacy. IEEE, 1332\u20131349","author":"Pierazzi F.","unstructured":"F. Pierazzi, F. Pendlebury, J. Cortellazzi, and L. Cavallaro. 2020. Intriguing Properties of Adversarial ML Attacks in the Problem Space. In Proc. Symposium on Security and Privacy. IEEE, 1332\u20131349."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.06.005"},{"key":"e_1_3_2_1_33_1","first-page":"108","article-title":"Adversarial Machine Learning Attacks and Defense Methods in the Cyber Security Domain","volume":"54","author":"Rosenberg I.","year":"2021","unstructured":"I. Rosenberg, A. Shabtai, Y. Elovici, and L. Rokach. 2021. Adversarial Machine Learning Attacks and Defense Methods in the Cyber Security Domain. ACM Computing Surveys 54, 5 (2021), 108.","journal-title":"ACM Computing Surveys"},{"key":"e_1_3_2_1_34_1","volume-title":"Proc. International Conference on Information Systems Security and Privacy. SciTePress, 108\u2013116","author":"Sharafaldin I.","unstructured":"I. Sharafaldin, A.\u00a0H. Lashkari, and A.\u00a0A. Ghorbani.2018. Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization. In Proc. International Conference on Information Systems Security and Privacy. SciTePress, 108\u2013116."},{"key":"e_1_3_2_1_35_1","volume-title":"Proc. Security and Privacy Workshops. IEEE, 69\u201375","author":"Siva\u00a0Kumar S.","unstructured":"R.\u00a0S. Siva\u00a0Kumar, M. Nystrom, J. Lambert, A. Marshall, M. Goertzel, A. Comissoneru, M. Swann, and S. Xia. 2020. Adversarial Machine Learning-Industry Perspectives. In Proc. Security and Privacy Workshops. IEEE, 69\u201375."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"crossref","unstructured":"Y. Song S. Hyun and Y. Cheong. 2021. Analysis of Autoencoders for Network Intrusion Detection. Sensors 21 13 (2021).","DOI":"10.3390\/s21134294"},{"key":"e_1_3_2_1_37_1","volume-title":"Proc. International Conference on Learning Representations. 1\u201310","author":"Szegedy C.","unstructured":"C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus. 2014. Intriguing properties of neural networks. In Proc. International Conference on Learning Representations. 1\u201310."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2009.05.029"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10922-021-09615-7"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11219-021-09553-2"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101851"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102675"}],"event":{"name":"ARES 2023: The 18th International Conference on Availability, Reliability and Security","location":"Benevento Italy","acronym":"ARES 2023"},"container-title":["Proceedings of the 18th International Conference on Availability, Reliability and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3600160.3605031","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3600160.3605031","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T13:49:16Z","timestamp":1750168156000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3600160.3605031"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,8,29]]},"references-count":42,"alternative-id":["10.1145\/3600160.3605031","10.1145\/3600160"],"URL":"https:\/\/doi.org\/10.1145\/3600160.3605031","relation":{},"subject":[],"published":{"date-parts":[[2023,8,29]]},"assertion":[{"value":"2023-08-29","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}