{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,22]],"date-time":"2025-10-22T23:08:33Z","timestamp":1761174513315,"version":"build-2065373602"},"reference-count":58,"publisher":"MDPI AG","issue":"11","license":[{"start":{"date-parts":[[2025,10,22]],"date-time":"2025-10-22T00:00:00Z","timestamp":1761091200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Computers"],"abstract":"<jats:p>Detecting anomalies in network traffic is a central task in cybersecurity and digital infrastructure management. Traditional approaches rely on statistical models, rule-based systems, or machine learning techniques to identify deviations from expected patterns, but often face limitations in generalization across domains. This study proposes a cross-domain data enrichment framework that integrates behavioral embeddings with network traffic features through adversarial autoencoders. Each network traffic record is paired with the most similar behavioral profile embedding from user web activity data (Charles dataset) using cosine similarity, thereby providing contextual enrichment for anomaly detection. The proposed system comprises (i) behavioral profile clustering via autoencoder embeddings and (ii) cross-domain latent alignment through adversarial autoencoders, with a discriminator to enable feature fusion. A Deep Feedforward Neural Network trained on the enriched feature space achieves 97.17% accuracy, 96.95% precision, 97.34% recall, and 97.14% F1-score, with stable cross-validation performance (99.79% average accuracy across folds). Behavioral clustering quality is supported by a silhouette score of 0.86 and a Davies\u2013Bouldin index of 0.57. To assess robustness and transferability, the framework was evaluated on the UNSW-NB15 and the CIC-IDS2017 datasets, where results confirmed consistent performance and reliability when compared to traffic-only baselines. This supports the feasibility of cross-domain alignment and shows that adversarial training enables stable feature integration without evidence of overfitting or memorization.<\/jats:p>","DOI":"10.3390\/computers14110450","type":"journal-article","created":{"date-parts":[[2025,10,22]],"date-time":"2025-10-22T07:03:51Z","timestamp":1761116631000},"page":"450","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Cross-Domain Adversarial Alignment for Network Anomaly Detection Through Behavioral Embedding Enrichment"],"prefix":"10.3390","volume":"14","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7130-3568","authenticated-orcid":false,"given":"Cristian","family":"Salvador-Najar","sequence":"first","affiliation":[{"name":"Instituto Tecnol\u00f3gico y de Estudios Superiores de Occidente (ITESO), Anillo Perif\u00e9rico Sur Manuel G\u00f3mez Mor\u00edn 8585, Santa Mar\u00eda Tequepexpan, Tlaquepaque 45604, Jalisco, Mexico"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3275-470X","authenticated-orcid":false,"given":"Luis Juli\u00e1n","family":"Dom\u00ednguez P\u00e9rez","sequence":"additional","affiliation":[{"name":"Instituto Tecnol\u00f3gico y de Estudios Superiores de Occidente (ITESO), Anillo Perif\u00e9rico Sur Manuel G\u00f3mez Mor\u00edn 8585, Santa Mar\u00eda Tequepexpan, Tlaquepaque 45604, Jalisco, Mexico"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2025,10,22]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Sen, J., and Dasgupta, S. (2023). Data Privacy Preservation on the Internet of Things. arXiv.","DOI":"10.5772\/intechopen.111477"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"84","DOI":"10.53469\/jssh.2024.06(07).19","article-title":"Growth of Internet Users with Special Emphasis on the Impact of New Coronary Pneumonia","volume":"6","author":"Hategekimana","year":"2024","journal-title":"J. Soc. Sci. Humanit."},{"key":"ref_3","first-page":"171","article-title":"Research on Computer Network Security Vulnerabilities and Encryption Technology in Cloud Computing Environment","volume":"9","author":"Peng","year":"2024","journal-title":"Appl. Math. Nonlinear Sci."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"345","DOI":"10.1515\/comp-2022-0257","article-title":"Big data network security defense mode of deep learning algorithm","volume":"12","author":"Yu","year":"2022","journal-title":"Open Comput. Sci."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"939","DOI":"10.1109\/TNET.2021.3128557","article-title":"Newton: Intent-Driven Network Traffic Monitoring","volume":"30","author":"Xi","year":"2022","journal-title":"IEEE\/ACM Trans. Netw."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"561","DOI":"10.1109\/TNET.2020.2967588","article-title":"Five Years at the Edge: Watching Internet From the ISP Network","volume":"28","author":"Trevisan","year":"2020","journal-title":"IEEE\/ACM Trans. Netw."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"152379","DOI":"10.1109\/ACCESS.2021.3126834","article-title":"Machine learning in network anomaly detection: A survey","volume":"9","author":"Wang","year":"2021","journal-title":"IEEE Access"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"228","DOI":"10.1049\/cit2.12078","article-title":"Network anomaly detection using deep learning techniques","volume":"7","author":"Hooshmand","year":"2022","journal-title":"CAAI Trans. Intell. Technol."},{"key":"ref_9","first-page":"1","article-title":"Physical Unclonable Functions (PUF) for IoT Devices","volume":"55","year":"2022","journal-title":"ACM Comput. Surv."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"424","DOI":"10.1038\/s41928-022-00787-x","article-title":"Twin physically unclonable functions based on aligned carbon nanotube arrays","volume":"5","author":"Zhong","year":"2022","journal-title":"Nat. Electron."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"23989","DOI":"10.1021\/acsnano.3c08740","article-title":"Programmable Physical Unclonable Functions Using Randomly Anisotropic Two-Dimensional Flakes","volume":"17","author":"Chen","year":"2023","journal-title":"ACS Nano"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"5","DOI":"10.15680\/IJIRCCE.2024.1212001","article-title":"A Study on FPGA Implementation of Physical Unclonable Functions (PUFs)","volume":"12","author":"Marri","year":"2024","journal-title":"Int. J. Innov. Res. Comput. Commun. Eng."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"886","DOI":"10.1109\/TIFS.2024.3518065","article-title":"Learnability of Optical Physical Unclonable Functions Through the Lens of Learning with Errors","volume":"20","author":"Albright","year":"2025","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"206","DOI":"10.1016\/j.comcom.2022.10.024","article-title":"Network traffic anomaly detection method based on multi-scale residual classifier","volume":"198","author":"Duan","year":"2023","journal-title":"Comput. Commun."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3703447","article-title":"Deep learning on network traffic prediction: Recent advances, analysis, and future directions","volume":"57","author":"Aouedi","year":"2025","journal-title":"ACM Comput. Surv."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Kamal, H., and Mashaly, M. (2025). Enhanced Hybrid Deep Learning Models-Based Anomaly Detection Method for Two-Stage Binary and Multi-Class Classification of Attacks in Intrusion Detection Systems. Algorithms, 18.","DOI":"10.3390\/a18020069"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"58851","DOI":"10.1109\/ACCESS.2024.3389096","article-title":"A comparative study of using deep learning algorithms in network intrusion detection","volume":"12","author":"Elsayed","year":"2024","journal-title":"IEEE Access"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"120","DOI":"10.1016\/j.aej.2024.03.041","article-title":"Robust network anomaly detection using ensemble learning approach and explainable artificial intelligence (XAI)","volume":"94","author":"Hooshmand","year":"2024","journal-title":"Alex. Eng. J."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Marfo, W., Tosh, D.K., and Moore, S.V. (2024, January 11\u201313). Enhancing network anomaly detection using graph neural networks. Proceedings of the 2024 22nd Mediterranean Communication and Computer Networking Conference (MedComNet), Nice, France.","DOI":"10.1109\/MedComNet62012.2024.10578278"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Altulaihan, E., Almaiah, M.A., and Aljughaiman, A. (2024). Anomaly detection IDS for detecting DoS attacks in IoT networks based on machine learning algorithms. Sensors, 24.","DOI":"10.3390\/s24020713"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"11573","DOI":"10.1007\/s00500-021-06028-1","article-title":"IoT-based smart environment using intelligent intrusion detection system","volume":"25","author":"Kalnoor","year":"2021","journal-title":"Soft Comput."},{"key":"ref_22","first-page":"52509","article-title":"Design of an intrusion detection model for IoT-enabled smart home","volume":"11","author":"Rani","year":"2023","journal-title":"IEEE Access"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"e386","DOI":"10.1002\/spy2.386","article-title":"A lightweight Intrusion Detection for Internet of Things-based smart buildings","volume":"7","author":"Murthy","year":"2024","journal-title":"Security Priv."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Javed, A., Awais, M., Qureshi, A., Jawad, M., Arshad, J., and Larijani, H. (2024). Embedding tree-based intrusion detection system in smart thermostats for enhanced IoT security. Sensors, 24.","DOI":"10.3390\/s24227320"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Wang, M., Yang, N., and Weng, N. (2023). Securing a smart home with a transformer-based IoT intrusion detection system. Electronics, 12.","DOI":"10.3390\/electronics12092100"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Garroppo, R., Giardina, P., Landi, G., and Ruta, M. (2025). Trustworthy AI and federated learning for intrusion detection in 6G-connected smart buildings. Future Internet, 17.","DOI":"10.3390\/fi17050191"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Oran, S., and Ko\u00e7ak, A. (2022, January 19\u201320). Security review and performance analysis of QUIC and TCP protocols. Proceedings of the 15th International Conference on Information Security and Cryptography (ISCTURKEY), Ankara, Turkey.","DOI":"10.1109\/ISCTURKEY56345.2022.9931821"},{"key":"ref_28","unstructured":"Almuhammadi, S., and Al-Bakhat, L. (2022, January 1\u20133). Intrusion detection on QUIC traffic: A machine learning approach. Proceedings of the 2022 7th International Conference on Data Science and Machine Learning Applications (CDMA), Riyadh, Saudi Arabia."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Benova, L., and Hudec, L. (2024). Comprehensive Analysis and Evaluation of Anomalous User Activity in Web Server Logs. Sensors, 24.","DOI":"10.3390\/s24030746"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"2254","DOI":"10.1109\/JSAC.2021.3078497","article-title":"Machine Learning for Detecting Anomalies and Intrusions in Communication Networks","volume":"39","author":"Li","year":"2021","journal-title":"IEEE J. Sel. Areas Commun."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Modell, A., Larson, J., Turcotte, M.J.M., and Bertiger, A. (2021, January 15\u201318). A Graph Embedding Approach to User Behavior Anomaly Detection. Proceedings of the 2021 IEEE International Conference on Big Data (Big Data), Orlando, FL, USA.","DOI":"10.1109\/BigData52589.2021.9671423"},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"6029","DOI":"10.1007\/s10489-020-02160-x","article-title":"A survey for user behavior analysis based on machine learning techniques: Current models and applications","volume":"51","year":"2021","journal-title":"Appl. Intell."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Tun, M.T., Nyaung, D.E., and Phyu, M.P. (2020, January 1\u20133). Network anomaly detection using threshold-based sparse. Proceedings of the 11th International Conference on Advances in Information Technology, Bangkok, Thailand.","DOI":"10.1145\/3406601.3406626"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Pandhurnekar, V., Iyyappan, A., Dhok, D., Khante, V., and Wazalwar, S.S. (2023, January 10\u201311). Proposed Method for Threat Detection Using User Behavior Analysis. Proceedings of the 2023 IEEE 3rd International Conference on Technology, Engineering, Management for Societal impact using Marketing, Entrepreneurship and Talent (TEMSMET), Mysuru, India.","DOI":"10.1109\/TEMSMET56707.2023.10150053"},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"1679","DOI":"10.32604\/csse.2023.026526","article-title":"Cyberattack Detection Framework Using Machine Learning and User Behavior Analytics","volume":"44","author":"Alshehri","year":"2023","journal-title":"Comput. Syst. Sci. Eng."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"He, J., and Yin, X. (July, January 28). Internet User Behavior Analysis Based on Big Data. Proceedings of the 2021 International Wireless Communications and Mobile Computing (IWCMC), Harbin, China.","DOI":"10.1109\/IWCMC51323.2021.9498875"},{"key":"ref_37","first-page":"410","article-title":"Big Data Analytics in Cyber Security: Network Traffic and Attacks","volume":"61","author":"Wang","year":"2020","journal-title":"J. Comput. Inf. Syst."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"2493","DOI":"10.1109\/TNSM.2024.3355698","article-title":"User Behavior Threat Detection Based on Adaptive Sliding Window GAN","volume":"21","author":"Tao","year":"2024","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Moustafa, N., and Slay, J. (2015, January 10\u201312). UNSW-NB15: A comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). Proceedings of the 2015 Military Communications and Information Systems Conference (MilCIS), Canberra, Australia.","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Rosay, A., Cheval, E., Carlier, F., and Leroux, P. (2022, January 8\u201310). Network intrusion detection: A comprehensive analysis of CIC-IDS2017. Proceedings of the 8th International Conference on Information Systems Security and Privacy, Online.","DOI":"10.5220\/0010774000003120"},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"12053","DOI":"10.1109\/TKDE.2022.3176478","article-title":"Adaptive label propagation for group anomaly detection in large-scale networks","volume":"35","author":"Li","year":"2023","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"2450","DOI":"10.1007\/s12083-024-01694-y","article-title":"Dynamic behavioral profiling for anomaly detection in software-defined IoT networks: A machine learning approach","volume":"17","author":"P","year":"2024","journal-title":"Peer-to-Peer Netw. Appl."},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"104160","DOI":"10.1016\/j.cose.2024.104160","article-title":"NTLFlowLyzer: Towards generating an intrusion detection dataset and intruders behavior profiling through network and transport layers traffic analysis and pattern extraction","volume":"148","author":"Shafi","year":"2024","journal-title":"Comput. Secur."},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"2573","DOI":"10.1007\/s13042-023-02049-4","article-title":"Outlier based intrusion detection in databases for user behaviour analysis using weighted sequential pattern mining","volume":"15","author":"Singh","year":"2023","journal-title":"Int. J. Mach. Learn. Cybern."},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Abiramasundari, S., and Ramaswamy, V. (2025). Distributed denial-of-service (DDOS) attack detection using supervised machine learning algorithms. Sci. Rep., 15.","DOI":"10.1038\/s41598-024-84879-y"},{"key":"ref_46","first-page":"82","article-title":"Anomaly detection in network traffic using entropy-based methods: Application to various types of cyberattacks","volume":"24","author":"Bashurov","year":"2023","journal-title":"Issues Inf. Syst."},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"Zhao, Z., Guo, H., and Wang, Y. (2024). A multi-information fusion anomaly detection model based on convolutional neural networks and AutoEncoder. Sci. Rep., 14.","DOI":"10.1038\/s41598-024-66760-0"},{"key":"ref_48","doi-asserted-by":"crossref","first-page":"105","DOI":"10.1186\/s40537-020-00379-6","article-title":"Performance analysis of intrusion detection systems using a feature selection method on the UNSW-NB15 dataset","volume":"7","author":"Kasongo","year":"2020","journal-title":"J. Big Data"},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"100","DOI":"10.1038\/s43586-022-00184-w","article-title":"Principal component analysis","volume":"2","author":"Greenacre","year":"2022","journal-title":"Nat. Rev. Methods Prim."},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Aggarwal, C.C. (2016). Recommender Systems: The Textbook, Springer.","DOI":"10.1007\/978-3-319-29659-3"},{"key":"ref_51","doi-asserted-by":"crossref","unstructured":"Cover, T.M., and Thomas, J.A. (2006). Elements of Information Theory, John Wiley & Sons.","DOI":"10.1002\/047174882X"},{"key":"ref_52","doi-asserted-by":"crossref","first-page":"178","DOI":"10.1016\/j.ins.2022.11.139","article-title":"K-means clustering algorithms: A comprehensive review, variants analysis, and advances in the era of big data","volume":"622","author":"Ikotun","year":"2023","journal-title":"Inf. Sci."},{"key":"ref_53","doi-asserted-by":"crossref","first-page":"126433","DOI":"10.1016\/j.physa.2021.126433","article-title":"Revisiting agglomerative clustering","volume":"585","author":"Tokuda","year":"2022","journal-title":"Phys. A Stat. Mech. Its Appl."},{"key":"ref_54","doi-asserted-by":"crossref","unstructured":"Singh, H.V., Girdhar, A., and Dahiya, S. (2022, January 25\u201327). A Literature survey based on DBSCAN algorithms. Proceedings of the 2022 6th International Conference on Intelligent Computing and Control Systems (ICICCS), Madurai, India.","DOI":"10.1109\/ICICCS53718.2022.9788440"},{"key":"ref_55","doi-asserted-by":"crossref","unstructured":"Shahapure, K.R., and Nicholas, C. (2020, January 6\u20139). Cluster quality analysis using silhouette score. Proceedings of the 2020 IEEE 7th international conference on data science and advanced analytics (DSAA), Sydney, Australia.","DOI":"10.1109\/DSAA49011.2020.00096"},{"key":"ref_56","unstructured":"Muntean, M., and Militaru, F.D. (2022, January 26\u201327). Metrics for evaluating classification algorithms. Proceedings of the Education, Research and Business Technologies: Proceedings of 21st International Conference on Informatics in Economy (IE 2022), Bucharest, Romania."},{"key":"ref_57","doi-asserted-by":"crossref","first-page":"120882","DOI":"10.1016\/j.ins.2024.120882","article-title":"Worthiness Benchmark: A novel concept for analyzing binary classification evaluation metrics","volume":"678","author":"Shirdel","year":"2024","journal-title":"Inf. Sci."},{"key":"ref_58","doi-asserted-by":"crossref","first-page":"930","DOI":"10.1038\/s41592-024-02301-x","article-title":"Seeing data as t-SNE and UMAP do","volume":"21","author":"Marx","year":"2024","journal-title":"Nat. Methods"}],"container-title":["Computers"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-431X\/14\/11\/450\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,22]],"date-time":"2025-10-22T07:10:34Z","timestamp":1761117034000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-431X\/14\/11\/450"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,22]]},"references-count":58,"journal-issue":{"issue":"11","published-online":{"date-parts":[[2025,11]]}},"alternative-id":["computers14110450"],"URL":"https:\/\/doi.org\/10.3390\/computers14110450","relation":{},"ISSN":["2073-431X"],"issn-type":[{"type":"electronic","value":"2073-431X"}],"subject":[],"published":{"date-parts":[[2025,10,22]]}}}