{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,20]],"date-time":"2026-06-20T02:08:41Z","timestamp":1781921321198,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":45,"publisher":"ACM","license":[{"start":{"date-parts":[[2025,4,22]],"date-time":"2025-04-22T00:00:00Z","timestamp":1745280000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"the Major Key Project of PCL","award":["PCL2023A06"],"award-info":[{"award-number":["PCL2023A06"]}]},{"name":"the National Key Research and Development Program of China","award":["2022YFB3105000"],"award-info":[{"award-number":["2022YFB3105000"]}]},{"name":"the Shenzhen Key Lab of Software Defined Networking","award":["ZDSYS20140509172959989"],"award-info":[{"award-number":["ZDSYS20140509172959989"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,4,22]]},"DOI":"10.1145\/3696410.3714742","type":"proceedings-article","created":{"date-parts":[[2025,5,5]],"date-time":"2025-05-05T16:42:02Z","timestamp":1746463322000},"page":"2319-2329","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["Helios: Learning and Adaptation of Matching Rules for Continual In-Network Malicious Traffic Detection"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-9194-7810","authenticated-orcid":false,"given":"Zhenning","family":"Shi","sequence":"first","affiliation":[{"name":"Tsinghua University, Shenzhen, China and Peng Cheng Laboratory, Shenzhen, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9016-5594","authenticated-orcid":false,"given":"Dan","family":"Zhao","sequence":"additional","affiliation":[{"name":"Peng Cheng Laborotary, Shenzhen, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-6289-8209","authenticated-orcid":false,"given":"Yijia","family":"Zhu","sequence":"additional","affiliation":[{"name":"School of Artificial Intelligence, Xidian University, Xian, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7532-9116","authenticated-orcid":false,"given":"Guorui","family":"Xie","sequence":"additional","affiliation":[{"name":"Peng Cheng Laborotary, Shenzhen, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6071-473X","authenticated-orcid":false,"given":"Qing","family":"Li","sequence":"additional","affiliation":[{"name":"Peng Cheng Laboratory, Shenzhen, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4260-1395","authenticated-orcid":false,"given":"Yong","family":"Jiang","sequence":"additional","affiliation":[{"name":"Tsinghua University, Shenzhen, China and Peng Cheng Laboratory, Shenzhen, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,4,22]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Proceedings of the International Conference on Computer Communications. IEEE, 1--10","author":"Tanyi-Jong Akem Aristide","year":"2023","unstructured":"Aristide Tanyi-Jong Akem, Michele Gucciardo, and Marco Fiore. 2023. Flowrest: Practical flow-level inference in programmable switches with random forests. In Proceedings of the International Conference on Computer Communications. IEEE, 1--10."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382284"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3085194"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/2656877.2656890"},{"key":"e_1_3_2_1_5_1","volume-title":"A survey of data mining and machine learning methods for cyber security intrusion detection","author":"Buczak Anna L","year":"2015","unstructured":"Anna L Buczak and Erhan Guven. 2015. A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Communications surveys & tutorials, Vol. 18, 2 (2015), 1153--1176."},{"key":"e_1_3_2_1_6_1","volume-title":"This looks like that: deep learning for interpretable image recognition. Advances in neural information processing systems","author":"Chen Chaofan","year":"2019","unstructured":"Chaofan Chen, Oscar Li, Daniel Tao, Alina Barnett, Cynthia Rudin, and Jonathan K Su. 2019. This looks like that: deep learning for interpretable image recognition. Advances in neural information processing systems, Vol. 32 (2019)."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/2939672.2939785"},{"key":"e_1_3_2_1_8_1","unstructured":"Catalin Cimpanu. [n. d.]. Australian banks targeted by DDoS extortionists. https:\/\/www.zdnet.com\/article\/australian-banks-targeted-by-ddos-extortionists\/. Accessed: 2024-08-04."},{"key":"e_1_3_2_1_9_1","unstructured":"The P4 Language Consortium. [n. d.]. P4_16 Language Specification. https:\/\/p4.org\/p4-spec\/docs\/P4--16-v1.0.0-spec.html. Accessed: 2024-06--10.."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3127985"},{"key":"e_1_3_2_1_11_1","volume-title":"Proceedings of the 32nd USENIX Security Symposium. 571--588","author":"Dong Yutao","year":"2023","unstructured":"Yutao Dong, Qing Li, Kaidong Wu, Ruoyu Li, Dan Zhao, Gareth Tyson, Junkun Peng, Yong Jiang, Shutao Xia, and Mingwei Xu. 2023. {HorusEye}: A Realtime {IoT} Malicious Traffic Detection Framework using Programmable Switches. In Proceedings of the 32nd USENIX Security Symposium. 571--588."},{"key":"e_1_3_2_1_12_1","first-page":"20434","article-title":"Siren: Shaping representations for detecting out-of-distribution objects","volume":"35","author":"Du Xuefeng","year":"2022","unstructured":"Xuefeng Du, Gabriel Gozum, Yifei Ming, and Yixuan Li. 2022. Siren: Shaping representations for detecting out-of-distribution objects. Advances in Neural Information Processing Systems, Vol. 35 (2022), 20434--20449.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_13_1","volume-title":"Proceedings of the International Conference on Knowledge Discovery and Data Mining","volume":"96","author":"Ester Martin","year":"1996","unstructured":"Martin Ester, Hans-Peter Kriegel, J\u00f6rg Sander, Xiaowei Xu, et al. 1996. A density-based algorithm for discovering clusters in large spatial databases with noise. In Proceedings of the International Conference on Knowledge Discovery and Data Mining, Vol. 96. 226--231."},{"key":"e_1_3_2_1_14_1","volume-title":"Greedy function approximation: a gradient boosting machine. Annals of statistics","author":"Friedman Jerome H","year":"2001","unstructured":"Jerome H Friedman. 2001. Greedy function approximation: a gradient boosting machine. Annals of statistics (2001), 1189--1232."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484585"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3589334.3645479"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.2307\/2346830"},{"key":"e_1_3_2_1_18_1","volume-title":"A baseline for detecting misclassified and out-of-distribution examples in neural networks. arXiv preprint arXiv:1610.02136","author":"Hendrycks Dan","year":"2016","unstructured":"Dan Hendrycks and Kevin Gimpel. 2016. A baseline for detecting misclassified and out-of-distribution examples in neural networks. arXiv preprint arXiv:1610.02136 (2016)."},{"key":"e_1_3_2_1_19_1","volume-title":"Distilling the Knowledge in a Neural Network. arXiv preprint arXiv:1503.02531","author":"Hinton Geoffrey","year":"2015","unstructured":"Geoffrey Hinton. 2015. Distilling the Knowledge in a Neural Network. arXiv preprint arXiv:1503.02531 (2015)."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623123"},{"key":"e_1_3_2_1_21_1","volume-title":"Advances in Neural Information Processing Systems","volume":"36","author":"Li Ruoyu","year":"2024","unstructured":"Ruoyu Li, Qing Li, Yu Zhang, Dan Zhao, Yong Jiang, and Yong Yang. 2024a. Interpreting unsupervised anomaly detection in security via rule extraction. Advances in Neural Information Processing Systems, Vol. 36 (2024)."},{"key":"e_1_3_2_1_22_1","volume-title":"Genos: General In-Network Unsupervised Intrusion Detection by Rule Extraction. arXiv preprint arXiv:2403.19248","author":"Li Ruoyu","year":"2024","unstructured":"Ruoyu Li, Qing Li, Yu Zhang, Dan Zhao, Xi Xiao, and Yong Jiang. 2024b. Genos: General In-Network Unsupervised Intrusion Detection by Rule Extraction. arXiv preprint arXiv:2403.19248 (2024)."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02293"},{"key":"e_1_3_2_1_24_1","volume-title":"Proceedings of the 30th USENIX Security Symposium. 3829--3846","author":"Liu Zaoxing","year":"2021","unstructured":"Zaoxing Liu, Hun Namkung, Georgios Nikolaidis, Jeongkeun Lee, Changhoon Kim, Xin Jin, Vladimir Braverman, Minlan Yu, and Vyas Sekar. 2021. Jaqen: A {High-Performance}{Switch-Native} approach for detecting and mitigating volumetric {DDoS} attacks with programmable switches. In Proceedings of the 30th USENIX Security Symposium. 3829--3846."},{"key":"e_1_3_2_1_25_1","volume-title":"Landscape Report","author":"McKeever Grainne","year":"2023","unstructured":"Grainne McKeever. [n.,d.]. Imperva releases its Global DDoS Threat Landscape Report 2023. https:\/\/www.imperva.com\/blog\/imperva-releases-its-global-ddos-threat-landscape-report-2023\/. Accessed: 2024-08-04."},{"key":"e_1_3_2_1_26_1","volume-title":"Proceedings of the Eleventh International Conference on Learning Representations.","author":"Ming Yifei","year":"2023","unstructured":"Yifei Ming, Yiyou Sun, Ousmane Dia, and Yixuan Li. 2023. How to Exploit Hyperspherical Embeddings for Out-of-Distribution Detection?. In Proceedings of the Eleventh International Conference on Learning Representations."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"e_1_3_2_1_28_1","first-page":"108","article-title":"Toward generating a new intrusion detection dataset and intrusion traffic characterization","volume":"1","author":"Sharafaldin Iman","year":"2018","unstructured":"Iman Sharafaldin, Arash Habibi Lashkari, Ali A Ghorbani, et al. 2018. Toward generating a new intrusion detection dataset and intrusion traffic characterization. ICISSp, Vol. 1 (2018), 108--116.","journal-title":"ICISSp"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3485447.3512023"},{"key":"e_1_3_2_1_30_1","volume-title":"Vu Dinh Phai, and Qi Shi.","author":"Shone Nathan","year":"2018","unstructured":"Nathan Shone, Tran Nguyen Ngoc, Vu Dinh Phai, and Qi Shi. 2018. A deep learning approach to network intrusion detection. IEEE transactions on emerging topics in computational intelligence, Vol. 2, 1 (2018), 41--50."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM41043.2020.9155278"},{"key":"e_1_3_2_1_32_1","first-page":"30479","article-title":"Scalable rule-based representation learning for interpretable classification","volume":"34","author":"Wang Zhuo","year":"2021","unstructured":"Zhuo Wang, Wei Zhang, Ning Liu, and Jianyong Wang. 2021. Scalable rule-based representation learning for interpretable classification. Advances in Neural Information Processing Systems, Vol. 34 (2021), 30479--30491.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_33_1","volume-title":"Proceedings of the International conference on machine learning. PMLR, 23631--23644","author":"Wei Hongxin","year":"2022","unstructured":"Hongxin Wei, Renchunzi Xie, Hao Cheng, Lei Feng, Bo An, and Yixuan Li. 2022. Mitigating neural network overconfidence with logit normalization. In Proceedings of the International conference on machine learning. PMLR, 23631--23644."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2024.110836"},{"key":"e_1_3_2_1_35_1","volume-title":"Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining. 3551--3562","author":"Xiao Jingyu","unstructured":"Jingyu Xiao, Zhiyao Xu, Qingsong Zou, Qing Li, Dan Zhao, Dong Fang, Ruoyu Li, Wenxin Tang, Kang Li, Xudong Zuo, Penghui Hu, Yong Jiang, Zixuan Weng, and Michael R. Lyu. 2024b. Make Your Home Safe: Time-aware Unsupervised User Behavior Anomaly Detection in Smart Homes via Loss-guided Mask. In Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining. 3551--3562."},{"key":"e_1_3_2_1_36_1","volume-title":"Proceedings of the 2023 International Conference on Autonomous Agents and Multiagent Systems (AAMAS). 1634--1642","author":"Xiao Jingyu","year":"2023","unstructured":"Jingyu Xiao, Qingsong Zou, Qing Li, Dan Zhao, Kang Li, Wenxin Tang, Runjie Zhou, and Yong Jiang. 2023a. User Device Interaction Prediction via Relational Gated Graph Attention Network and Intent-aware Encoder. In Proceedings of the 2023 International Conference on Autonomous Agents and Multiagent Systems (AAMAS). 1634--1642."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3610906","article-title":"I Know Your Intent: Graph-enhanced Intent-aware User Device Interaction Prediction via Contrastive Learning","volume":"7","author":"Xiao Jingyu","year":"2023","unstructured":"Jingyu Xiao, Qingsong Zou, Qing Li, Dan Zhao, Kang Li, Zixuan Weng, Ruoyu Li, and Yong Jiang. 2023b. I Know Your Intent: Graph-enhanced Intent-aware User Device Interaction Prediction via Contrastive Learning. Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies (IMUWT\/UbiComp), Vol. 7, 3 (2023), 1--28.","journal-title":"Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies (IMUWT\/UbiComp)"},{"key":"e_1_3_2_1_38_1","volume-title":"FlexNF: Flexible Network Function Orchestration for Scalable On-Path Service Chain Serving","author":"Xiao Jingyu","year":"2023","unstructured":"Jingyu Xiao, Xudong Zuo, Qing Li, Dan Zhao, Hanyu Zhao, Yong Jiang, Jiyong Sun, Bin Chen, Yong Liang, and Jie Li. 2023c. FlexNF: Flexible Network Function Orchestration for Scalable On-Path Service Chain Serving. IEEE\/ACM Transactions on Networking (ToN) (2023)."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM48880.2022.9796936"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2023.3287091"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3365609.3365864"},{"key":"e_1_3_2_1_42_1","volume-title":"Advances in Neural Information Processing Systems","volume":"36","author":"Zhang Zhengxin","year":"2024","unstructured":"Zhengxin Zhang, Yucheng Huang, Guanglin Duan, Qing Li, Dan Zhao, Yong Jiang, Lianbo Ma, Xi Xiao, and Hengyang Xu. 2024. Metis: understanding and enhancing in-network regular expressions. Advances in Neural Information Processing Systems, Vol. 36 (2024)."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/3589334.3645407"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/3472716.3472846"},{"key":"e_1_3_2_1_45_1","volume-title":"Proceedings of the 32nd USENIX Security Symposium. 6203--6220","author":"Zhou Guangmeng","year":"2023","unstructured":"Guangmeng Zhou, Zhuotao Liu, Chuanpu Fu, Qi Li, and Ke Xu. 2023. An efficient design of intelligent network data plane. In Proceedings of the 32nd USENIX Security Symposium. 6203--6220."}],"event":{"name":"WWW '25: The ACM Web Conference 2025","location":"Sydney NSW Australia","acronym":"WWW '25","sponsor":["SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web"]},"container-title":["Proceedings of the ACM on Web Conference 2025"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3696410.3714742","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3696410.3714742","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:18:41Z","timestamp":1750295921000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3696410.3714742"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,22]]},"references-count":45,"alternative-id":["10.1145\/3696410.3714742","10.1145\/3696410"],"URL":"https:\/\/doi.org\/10.1145\/3696410.3714742","relation":{},"subject":[],"published":{"date-parts":[[2025,4,22]]},"assertion":[{"value":"2025-04-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}