{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T05:06:50Z","timestamp":1750309610617,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":43,"publisher":"ACM","license":[{"start":{"date-parts":[[2025,3,31]],"date-time":"2025-03-31T00:00:00Z","timestamp":1743379200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/"}],"funder":[{"name":"EPSRC","award":["EP\/T027037\/1"],"award-info":[{"award-number":["EP\/T027037\/1"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,3,31]]},"DOI":"10.1145\/3672608.3707927","type":"proceedings-article","created":{"date-parts":[[2025,5,14]],"date-time":"2025-05-14T18:30:17Z","timestamp":1747247417000},"page":"1867-1876","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Formally Verifying Robustness and Generalisation of Network Intrusion Detection Models"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7171-3364","authenticated-orcid":false,"given":"Robert","family":"Flood","sequence":"first","affiliation":[{"name":"University of Edinburgh, Edinburgh, United Kingdom"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-7675-0743","authenticated-orcid":false,"given":"Marco","family":"Casadio","sequence":"additional","affiliation":[{"name":"Heriot-Watt University, Heriot-Watt University, United Kingdom"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6073-9013","authenticated-orcid":false,"given":"David","family":"Aspinall","sequence":"additional","affiliation":[{"name":"University of Edinburgh, Edinburgh, United Kingdom"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3240-0987","authenticated-orcid":false,"given":"Ekaterina","family":"Komendantskaya","sequence":"additional","affiliation":[{"name":"University of Southampton, Southampton, United Kingdom"}]}],"member":"320","published-online":{"date-parts":[[2025,5,14]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/3474369.3486864"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2022.3157344"},{"key":"e_1_3_2_1_3_1","volume-title":"The second international verification of neural networks competition: Summary and results. arXiv preprint arXiv:2109.00498","author":"Bak Stanley","year":"2021","unstructured":"Stanley Bak, Changliu Liu, and Taylor Johnson. 2021. The second international verification of neural networks competition: Summary and results. arXiv preprint arXiv:2109.00498 (2021)."},{"key":"e_1_3_2_1_4_1","volume-title":"2021 IEEE\/ACM 43rd International Conference on Software Engineering (ICSE). IEEE, 312\u2013323","author":"Baluta Teodora","year":"2021","unstructured":"Teodora Baluta, Zheng Leong Chua, Kuldeep S Meel, et al. 2021. Scalable quantitative verification for deep neural networks. In 2021 IEEE\/ACM 43rd International Conference on Software Engineering (ICSE). IEEE, 312\u2013323."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354245"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10009-023-00703-4"},{"key":"e_1_3_2_1_7_1","unstructured":"Nicholas Carlini Anish Athalye Nicolas Papernot et al. 2019. On evaluating adversarial robustness. arXiv preprint arXiv:1902.06705 (2019)."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-13185-1_11"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-85347-1_19"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00045"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484776"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-68167-2_18"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3464458.3464460"},{"key":"e_1_3_2_1_14_1","volume-title":"Vehicle: Bridging the Embedding Gap in the Verification of Neuro-Symbolic Programs. arXiv preprint arXiv:2401.06379","author":"Daggitt Matthew L","year":"2024","unstructured":"Matthew L Daggitt, Wen Kokke, Robert Atkey, et al. 2024. Vehicle: Bridging the Embedding Gap in the Verification of Neuro-Symbolic Programs. arXiv preprint arXiv:2401.06379 (2024)."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2020.2971776"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW53761.2021.00009"},{"key":"e_1_3_2_1_18_1","volume-title":"International Conference on Learning Representations.","author":"Ferrari Claudio","year":"2022","unstructured":"Claudio Ferrari, Mark Niklas Mueller, Nikola Jovanovi\u0107, et al. 2022. Complete Verification via Multi-Neuron Relaxation Guided Branch-and-Bound. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"crossref","unstructured":"Thomas Flinkow Barak A. Pearlmutter and Rosemary Monahan. 2024. Comparing Differentiable Logics for Learning with Logical Constraints. arXiv:2407.03847 [cs.LO]","DOI":"10.1016\/j.scico.2025.103280"},{"key":"e_1_3_2_1_20_1","volume-title":"Bad Design Smells in Benchmark NIDS Datasets. In 2024 IEEE 9th European Symposium on Security and Privacy (EuroS&P). IEEE, 658\u2013675","author":"Flood Robert","year":"2024","unstructured":"Robert Flood, Gints Engelen, David Aspinall, et al. 2024. Bad Design Smells in Benchmark NIDS Datasets. In 2024 IEEE 9th European Symposium on Security and Privacy (EuroS&P). IEEE, 658\u2013675."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00058"},{"key":"e_1_3_2_1_22_1","unstructured":"Ian J. Goodfellow Jonathon Shlens and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. arXiv:1412.6572 [stat.ML]"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2021.3087242"},{"key":"e_1_3_2_1_24_1","unstructured":"Soumyadeep Hore Jalal Ghadermazi Diwas Paudel et al. 2023. Deep packgen: A deep reinforcement learning framework for adversarial network packet generation. arXiv preprint arXiv:2305.11039 (2023)."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560609"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/DASC.2016.7778091"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3649847"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-63387-9_5"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179303"},{"key":"e_1_3_2_1_30_1","unstructured":"Gordon Fyodor Lyon. 2009. Nmap network scanning: The official Nmap project guide to network discovery and security scanning. Insecure."},{"key":"e_1_3_2_1_31_1","volume-title":"International Conference on Learning Representations.","author":"Madry Aleksander","year":"2018","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, et al. 2018. Towards Deep Learning Models Resistant to Adversarial Attacks. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"crossref","unstructured":"Yisroel Mirsky Tomer Doitshman Yuval Elovici et al. 2018. Kitsune: an ensemble of autoencoders for online network intrusion detection. arXiv preprint arXiv:1802.09089 (2018).","DOI":"10.14722\/ndss.2018.23204"},{"key":"e_1_3_2_1_33_1","unstructured":"Kexin Pei Linjie Zhu Yinzhi Cao et al. 2017. Towards practical verification of machine learning: The case of computer vision systems. arXiv preprint arXiv:1712.01785 (2017)."},{"key":"e_1_3_2_1_34_1","first-page":"108","article-title":"Toward generating a new intrusion detection dataset and intrusion traffic characterization","volume":"1","author":"Sharafaldin Iman","year":"2018","unstructured":"Iman Sharafaldin, Arash Habibi Lashkari, Ali A Ghorbani, et al. 2018. Toward generating a new intrusion detection dataset and intrusion traffic characterization. ICISSp 1 (2018), 108\u2013116.","journal-title":"ICISSp"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484570"},{"key":"e_1_3_2_1_36_1","unstructured":"Vincent Tjeng Kai Xiao and Russ Tedrake. 2019. Evaluating robustness of neural networks with mixed integer programming. n International Conference on Learning Representations (2019)."},{"key":"e_1_3_2_1_37_1","unstructured":"Florian Tram\u00e8r Alexey Kurakin Nicolas Papernot et al. 2017. Ensemble adversarial training: Attacks and defenses. arXiv preprint arXiv:1705.07204 (2017)."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3555776.3577651"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/3471621.3471841"},{"key":"e_1_3_2_1_40_1","unstructured":"Kai Wang Zhiliang Wang Dongqi Han et al. [n. d.]. BARS: Local Robustness Certification for Deep Learning based Traffic Analysis Systems."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"crossref","unstructured":"Wei Wang Yiqiang Sheng Jinlin Wang et al. 2017. HAST-IDS: Learning hierarchical spatial-temporal features using deep neural networks to improve intrusion detection. IEEE access 6 (2017) 1792\u20131806.","DOI":"10.1109\/ACCESS.2017.2780250"},{"key":"e_1_3_2_1_42_1","unstructured":"Haoze Wu Omri Isac Aleksandar Zelji\u0107 et al. 2024. Marabou 2.0: A Versatile Formal Analyzer of Neural Networks. arXiv:2401.14461 [cs.AI]"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2021.3137084"}],"event":{"name":"SAC '25: 40th ACM\/SIGAPP Symposium on Applied Computing","sponsor":["SIGAPP ACM Special Interest Group on Applied Computing"],"location":"Catania International Airport Catania Italy","acronym":"SAC '25"},"container-title":["Proceedings of the 40th ACM\/SIGAPP Symposium on Applied Computing"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3672608.3707927","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3672608.3707927","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:57:36Z","timestamp":1750298256000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3672608.3707927"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,3,31]]},"references-count":43,"alternative-id":["10.1145\/3672608.3707927","10.1145\/3672608"],"URL":"https:\/\/doi.org\/10.1145\/3672608.3707927","relation":{},"subject":[],"published":{"date-parts":[[2025,3,31]]},"assertion":[{"value":"2025-05-14","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}