{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T21:23:23Z","timestamp":1783632203197,"version":"3.55.0"},"reference-count":42,"publisher":"Frontiers Media SA","license":[{"start":{"date-parts":[[2025,10,3]],"date-time":"2025-10-03T00:00:00Z","timestamp":1759449600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["frontiersin.org"],"crossmark-restriction":true},"short-container-title":["Front. Comput. Sci."],"abstract":"<jats:sec><jats:title>Introduction<\/jats:title><jats:p>The integration of deep learning models into Network Intrusion Detection Systems (NIDS) has shown promising advancements in distinguishing normal network traffic from cyber-attacks due to their capability to learn complex non-linear patterns. These approaches typically rely on both benign and malicious network traffic during training. However, in many organizations, collecting malicious traffic is challenging due to privacy restrictions, high costs of manual labeling, and requirement for advanced security expertise.<\/jats:p><\/jats:sec><jats:sec><jats:title>Methods<\/jats:title><jats:p>In this study, we introduce a deep one-class classification model that is trained exclusively on flow-based benign network traffic data, with the goal of identifying attacks during inference. The proposed anomaly detection model consists of two steps, a One-Class Support Vector Machine (OC-SVM) and a deep AutoEncoder (AE). While autoencoders have shown great potential in anomaly detection, their effectiveness can be undermined by spurious network activity located on the boundaries of their discriminating capabilities, thus failing to identify malicious behavior. Our model leverages the topological structure of the OC-SVM to generate decision scores for each traffic flow, which are subsequently incorporated into an autoencoder as part of the input feature space.<\/jats:p><\/jats:sec><jats:sec><jats:title>Results<\/jats:title><jats:p>This approach enhances the ability of the autoencoder to detect incidents that deviate from normal patterns. Furthermore, we propose a heuristic method for tuning the trade-off parameter of the OC-SVM, based only on one-class data, achieving comparable performance to grid-based methods that require both benign and malicious labeled data. Experimental results on a benchmark network intrusion data set, the UNSW-NB15, suggest that OCSVM-AE performs well on unseen attacks and is more effective than traditional and deep-learning based one-class classifiers.<\/jats:p><\/jats:sec><jats:sec><jats:title>Discussion<\/jats:title><jats:p>The method makes no specific assumptions about the data distribution, making it broadly applicable and suitable as a complementary tool to signature-based intrusion detection systems.<\/jats:p><\/jats:sec>","DOI":"10.3389\/fcomp.2025.1646679","type":"journal-article","created":{"date-parts":[[2025,10,3]],"date-time":"2025-10-03T05:30:32Z","timestamp":1759469432000},"update-policy":"https:\/\/doi.org\/10.3389\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["A deep one-class classifier for network anomaly detection using autoencoders and one-class support vector machines"],"prefix":"10.3389","volume":"7","author":[{"given":"Polyzois","family":"Bountzis","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dimitris","family":"Kavallieros","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Theodora","family":"Tsikrika","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Stefanos","family":"Vrochidis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ioannis","family":"Kompatsiaris","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1965","published-online":{"date-parts":[[2025,10,3]]},"reference":[{"key":"B1","unstructured":"Abadi\n              M.\n            \n            \n              Agarwal\n              A.\n            \n            \n              Barham\n              P.\n            \n            \n              Brevdo\n              E.\n            \n            \n              Chen\n              Z.\n            \n            \n              Citro\n              C.\n            \n          \n          TensorFlow: Large-scale machine learning on heterogeneous systems\n          \n          2015"},{"key":"B2","doi-asserted-by":"publisher","first-page":"e4150","DOI":"10.1002\/ett.4150","article-title":"Network intrusion detection system: a systematic study of machine learning and deep learning approaches","volume":"32","author":"Ahmad","year":"2021","journal-title":"Trans. Emer. Telecommun. Technol"},{"key":"B3","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1016\/j.jnca.2015.11.016","article-title":"A survey of network anomaly detection techniques","volume":"60","author":"Ahmed","year":"2016","journal-title":"J. Netw. Comput. Applic"},{"key":"B4","doi-asserted-by":"publisher","first-page":"e2311878121","DOI":"10.1073\/pnas.2311878121","article-title":"Explaining neural scaling laws","volume":"121","author":"Bahri","year":"2024","journal-title":"Proc. Nat. Acad. Sci"},{"key":"B5","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/1541880.1541882","article-title":"Anomaly detection: a survey","volume":"41","author":"Chandola","year":"2009","journal-title":"ACM Comput. Surv"},{"key":"B6","article-title":"Pyod 2: a python library for outlier detection with LLM-powered model selection","author":"Chen","year":"2024","journal-title":"arXiv preprint arXiv:2412.12154"},{"key":"B7","doi-asserted-by":"publisher","DOI":"10.17487\/rfc3954","author":"Claise","year":"2004","journal-title":"Cisco systems netflow services export version 9"},{"key":"B8","doi-asserted-by":"crossref","first-page":"183","DOI":"10.1007\/978-3-319-31750-2_15","article-title":"\u201cUnsupervised parameter estimation for one-class support vector machines,\u201d","volume-title":"Advances in Knowledge Discovery and Data Mining: 20th Pacific-Asia Conference, PAKDD 2016, Auckland, New Zealand, April 19\u201322, 2016, Proceedings, Part II 20","author":"Ghafoori","year":"2016"},{"key":"B9","doi-asserted-by":"publisher","first-page":"1705","DOI":"10.1109\/ICCV.2019.00179","article-title":"\u201cMemorizing normality to detect anomaly: memory-augmented deep autoencoder for unsupervised anomaly detection,\u201d","author":"Gong","year":"2019","journal-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision"},{"key":"B10","doi-asserted-by":"publisher","first-page":"6737","DOI":"10.1609\/aaai.v36i6.20629","article-title":"\u201cLunar: unifying local outlier detection methods via graph neural networks,\u201d","author":"Goodge","year":"2022","journal-title":"Proceedings of the AAAI Conference on Artificial Intelligence"},{"key":"B11","article-title":"Deep learning scaling is predictable, empirically","author":"Hestness","year":"2017","journal-title":"arXiv preprint arXiv:1712.00409"},{"key":"B12","doi-asserted-by":"publisher","first-page":"90","DOI":"10.1109\/MCSE.2007.55","article-title":"Matplotlib: a 2D graphics environment","volume":"9","author":"Hunter","year":"2007","journal-title":"Comput. Sci. Eng"},{"key":"B13","article-title":"Auto-encoding variational bayes","author":"Kingma","year":"2013","journal-title":"arXiv preprint arXiv:1312.6114"},{"key":"B14","doi-asserted-by":"publisher","first-page":"106887","DOI":"10.1016\/j.knosys.2021.106887","article-title":"Network intrusion detection with a novel hierarchy of distances between embeddings of hash IP addresses","volume":"219","author":"Lopez-Martin","year":"2021","journal-title":"Knowl. Based Syst"},{"key":"B15","doi-asserted-by":"publisher","first-page":"12","DOI":"10.1109\/MPRV.2018.03367731","article-title":"N-baiot\u2013network-based detection of IoT botnet attacks using deep autoencoders","volume":"17","author":"Meidan","year":"2018","journal-title":"IEEE Perv. Comput"},{"key":"B16","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/ComNet47917.2020.9306073","article-title":"\u201cA deep learning approach combining autoencoder with one-class SVM for DDOS attack detection in SDNS,\u201d","author":"Mhamdi","year":"2020","journal-title":"2020 IEEE Eighth International Conference on Communications and Networking (ComNet)"},{"key":"B17","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/IMCOM64595.2025.10857434","article-title":"\u201cDynkdd: dynamic graph-based network intrusion detection using graph neural networks,\u201d","author":"Mir","year":"2025","journal-title":"2025 19th International Conference on Ubiquitous Information Management and Communication (IMCOM)"},{"key":"B18","article-title":"Kitsune: an ensemble of autoencoders for online network intrusion detection","author":"Mirsky","year":"2018","journal-title":"arXiv preprint arXiv:1802.09089"},{"key":"B19","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/MilCIS.2015.7348942","article-title":"\u201cUnsw-nb15: a comprehensive data set for network intrusion detection systems (unsw-nb15 network data set),\u201d","author":"Moustafa","year":"2015","journal-title":"2015 Military Communications and Information Systems Conference (MilCIS)"},{"key":"B20","doi-asserted-by":"publisher","first-page":"3074","DOI":"10.1109\/TCYB.2018.2838668","article-title":"Learning neural representations for network anomaly detection","volume":"49","author":"Nicolau","year":"2018","journal-title":"IEEE Trans. Cybern"},{"key":"B21","doi-asserted-by":"publisher","first-page":"5059","DOI":"10.1007\/s11276-022-03214-3","article-title":"Network intrusion detection system for DDOS attacks in ICS using deep autoencoders","volume":"30","author":"Ortega-Fernandez","year":"2024","journal-title":"Wirel. Netw"},{"key":"B22","first-page":"2825","article-title":"Scikit-learn: machine learning in python","volume":"12","author":"Pedregosa","year":"2011","journal-title":"J. Mach. Learn. Res"},{"key":"B23","doi-asserted-by":"publisher","first-page":"1184","DOI":"10.1109\/TPAMI.2002.1033211","article-title":"Constructing boosting algorithms from SVMS: an application to one-class classification","volume":"24","author":"Ratsch","year":"2002","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell"},{"key":"B24","first-page":"4393","article-title":"\u201cDeep one-class classification,\u201d","author":"Ruff","year":"2018","journal-title":"International Conference on Machine Learning"},{"key":"B25","doi-asserted-by":"publisher","DOI":"10.21236\/ADA164453","author":"Rumelhart","year":"1985","journal-title":"Learning internal representations by error propagation"},{"key":"B26","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/CCGridW59191.2023.00016","article-title":"\u201cDoc-nad: a hybrid deep one-class classifier for network anomaly detection,\u201d","author":"Sarhan","year":"2023","journal-title":"2023 IEEE\/ACM 23rd International Symposium on Cluster, Cloud and Internet Computing Workshops (CCGridW)"},{"key":"B27","doi-asserted-by":"crossref","first-page":"117","DOI":"10.1007\/978-3-030-72802-1_9","article-title":"\u201cNetflow datasets for machine learning-based network intrusion detection systems,\u201d","volume-title":"Big Data Technologies and Applications: 10th EAI International Conference, BDTA 2020, and 13th EAI International Conference on Wireless Internet, WiCON 2020, Virtual Event, December 11, 2020, Proceedings 10","author":"Sarhan","year":"2021"},{"key":"B28","doi-asserted-by":"publisher","first-page":"357","DOI":"10.1007\/s11036-021-01843-0","article-title":"Towards a standard feature set for network intrusion detection system datasets","volume":"27","author":"Sarhan","year":"2022","journal-title":"Mobile Netw. Applic"},{"key":"B29","doi-asserted-by":"publisher","first-page":"1443","DOI":"10.1162\/089976601750264965","article-title":"Estimating the support of a high-dimensional distribution","volume":"13","author":"Sch\u00f6lkopf","year":"2001","journal-title":"Neural Comput"},{"key":"B30","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/CISDA.2009.5356528","article-title":"\u201cA detailed analysis of the kdd cup 99 data set,\u201d","author":"Tavallaee","year":"2009","journal-title":"2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications"},{"key":"B31","doi-asserted-by":"publisher","first-page":"453","DOI":"10.1007\/s10462-021-10037-9","article-title":"A survey on intrusion detection system: feature selection, model, performance measures, application perspective, challenges, and future research directions","volume":"55","author":"Thakkar","year":"2022","journal-title":"Artif. Intell. Rev"},{"key":"B32","doi-asserted-by":"publisher","first-page":"3639","DOI":"10.1109\/COMST.2019.2922584","article-title":"Intrusion detection systems: a cross-domain overview","volume":"21","author":"Tidjon","year":"2019","journal-title":"IEEE Commun. Surv. Tutor"},{"key":"B33","doi-asserted-by":"publisher","first-page":"198","DOI":"10.1016\/j.patcog.2017.09.012","article-title":"Hyperparameter selection of one-class support vector machine by self-adaptive data shifting","volume":"74","author":"Wang","year":"2018","journal-title":"Pattern Recognit"},{"key":"B34","doi-asserted-by":"publisher","first-page":"941","DOI":"10.1109\/TCYB.2014.2340433","article-title":"Parameter selection of gaussian kernel for one-class svm","volume":"45","author":"Xiao","year":"2014","journal-title":"IEEE Trans. Cybern"},{"key":"B35","doi-asserted-by":"publisher","first-page":"3538","DOI":"10.1109\/TIFS.2021.3083422","article-title":"Conditional variational auto-encoder and extreme value theory aided two-stage learning approach for intelligent fine-grained known\/unknown intrusion detection","volume":"16","author":"Yang","year":"2021","journal-title":"IEEE Trans. Inf. Forens. Secur"},{"key":"B36","doi-asserted-by":"publisher","first-page":"5730","DOI":"10.1109\/TSMC.2025.3572738","article-title":"Link-based attributed graph clustering via approximate generative Bayesian learning","volume":"55","author":"Yang","year":"2025","journal-title":"IEEE Trans. Syst. Man Cybern. Syst"},{"key":"B37","doi-asserted-by":"publisher","first-page":"1112","DOI":"10.1109\/TNSE.2024.3524077","article-title":"Integrating fuzzy clustering and graph convolution network to accurately identify clusters from attributed graph","volume":"12","author":"Yang","year":"2024","journal-title":"IEEE Trans. Netw. Sci. Eng"},{"key":"B38","doi-asserted-by":"publisher","first-page":"108346","DOI":"10.1109\/ACCESS.2020.3001350","article-title":"Anomaly-based intrusion detection from network flow features using variational autoencoder","volume":"8","author":"Zavrak","year":"2020","journal-title":"IEEE Access"},{"key":"B39","doi-asserted-by":"publisher","first-page":"122","DOI":"10.1109\/SIEDS.2017.7937701","article-title":"\u201cComparing unsupervised learning approaches to detect network intrusion using netflow data,\u201d","author":"Zhang","year":"2017","journal-title":"2017 Systems and Information Engineering Design Symposium (SIEDS)"},{"key":"B40","doi-asserted-by":"publisher","first-page":"102","DOI":"10.1109\/MSN.2015.40","article-title":"\u201cAn anomaly detection model based on one-class svm to detect network intrusions,\u201d","author":"Zhang","year":"2015","journal-title":"2015 11th International conference on mobile ad-hoc and sensor networks (MSN)"},{"key":"B41","first-page":"1","article-title":"Pyod: a python toolbox for scalable outlier detection","volume":"20","author":"Zhao","year":"2019","journal-title":"J. Mach. Learn. Res"},{"key":"B42","article-title":"\u201cDeep autoencoding gaussian mixture model for unsupervised anomaly detection,\u201d","author":"Zong","year":"2018","journal-title":"International Conference on Learning Representations"}],"container-title":["Frontiers in Computer Science"],"original-title":[],"link":[{"URL":"https:\/\/www.frontiersin.org\/articles\/10.3389\/fcomp.2025.1646679\/full","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,3]],"date-time":"2025-10-03T05:30:35Z","timestamp":1759469435000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.frontiersin.org\/articles\/10.3389\/fcomp.2025.1646679\/full"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,3]]},"references-count":42,"alternative-id":["10.3389\/fcomp.2025.1646679"],"URL":"https:\/\/doi.org\/10.3389\/fcomp.2025.1646679","relation":{},"ISSN":["2624-9898"],"issn-type":[{"value":"2624-9898","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,10,3]]},"article-number":"1646679"}}