{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,25]],"date-time":"2026-04-25T14:33:49Z","timestamp":1777127629577,"version":"3.51.4"},"reference-count":55,"publisher":"MDPI AG","issue":"12","license":[{"start":{"date-parts":[[2022,11,25]],"date-time":"2022-11-25T00:00:00Z","timestamp":1669334400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100006769","name":"RSF","doi-asserted-by":"publisher","award":["22-21-00724"],"award-info":[{"award-number":["22-21-00724"]}],"id":[{"id":"10.13039\/501100006769","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Information"],"abstract":"<jats:p>Recently, approaches based on the transformation of tabular data into images have gained a lot of scientific attention. This is explained by the fact that convolutional neural networks (CNNs) have shown good results in computer vision and other image-based classification tasks. Transformation of features without spatial relations to images allows the application of deep neural networks to a wide range of analysis tasks. This paper analyzes existing approaches to feature transformation based on the conversion of the features of network traffic into images and discusses their advantages and disadvantages. The authors also propose an approach to the transformation of raw network packets into images and analyze its efficiency in the task of network attack detection in a cyber-physical object, including its robustness to novel and unseen attacks.<\/jats:p>","DOI":"10.3390\/info13120553","type":"journal-article","created":{"date-parts":[[2022,11,25]],"date-time":"2022-11-25T03:34:24Z","timestamp":1669347264000},"page":"553","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":12,"title":["Image-Based Approach to Intrusion Detection in Cyber-Physical Objects"],"prefix":"10.3390","volume":"13","author":[{"given":"Sergey","family":"Golubev","sequence":"first","affiliation":[{"name":"Saint Petersburg Institute for Informatics and Automation, Federal Research Center of the Russian Academy of Sciences, 199178 Saint Petersburg, Russia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2923-4954","authenticated-orcid":false,"given":"Evgenia","family":"Novikova","sequence":"additional","affiliation":[{"name":"Saint Petersburg Institute for Informatics and Automation, Federal Research Center of the Russian Academy of Sciences, 199178 Saint Petersburg, Russia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6707-9153","authenticated-orcid":false,"given":"Elena","family":"Fedorchenko","sequence":"additional","affiliation":[{"name":"Saint Petersburg Institute for Informatics and Automation, Federal Research Center of the Russian Academy of Sciences, 199178 Saint Petersburg, Russia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2022,11,25]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Chollet, F. (2017, January 21\u201326). Xception: Deep Learning with Depthwise Separable Convolutions. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), Honolulu, HI, USA.","DOI":"10.1109\/CVPR.2017.195"},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Debnath, B., O\u2019Brient, M., Kumar, S., and Behera, A. (2021, January 10\u201315). Attention-Driven Body Pose Encoding for Human Activity Recognition. Proceedings of the 25th International Conference on Pattern Recognition (ICPR), Milan, Italy.","DOI":"10.1109\/ICPR48806.2021.9412487"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"11399","DOI":"10.1038\/s41598-019-47765-6","article-title":"DeepInsight: A methodology to transform a non-image data to an image for convolution neural network architecture","volume":"9","author":"Sharma","year":"2019","journal-title":"Sci. Rep."},{"key":"ref_4","first-page":"1087","article-title":"A Transfer Learning with Deep Neural Network Approach for Network Intrusion Detection","volume":"12","author":"Chollet","year":"2021","journal-title":"Int. J. Intell. Comput. Res."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Noever, D.A., and Noever, S.E.M. (2021). Image Classifiers for Network Intrusions. arXiv.","DOI":"10.5121\/csit.2021.110504"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Wu, P., Guo, H., and Buckland, R. (2019, January 15\u201318). A Transfer Learning Approach for Network Intrusion Detection. Proceedings of the 2019 IEEE 4th International Conference on Big Data Analytics (ICBDA), Suzhou, China.","DOI":"10.1109\/ICBDA.2019.8713213"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"207","DOI":"10.15622\/sp.45.13","article-title":"Analysis and Classification of Methods for Network Attack Detection","volume":"2","author":"Branitskiy","year":"2016","journal-title":"SPIIRAS Proc."},{"key":"ref_8","unstructured":"Sako, K., Schneider, S., and Ryan, P.Y.A. (2019). BinEye: Towards Efficient Binary Authorship Characterization Using Deep Learning. Proceedings of the Computer Security\u2014ESORICS 2019, Springer International Publishing."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Kaur, R., Ning, Y., Gonzalez, H., and Stakhanova, N. (2018, January 28\u201330). Unmasking Android obfuscation tools using spatial analysis. Proceedings of the 2018 16th Annual Conference on Privacy, Security and Trust (PST), Belfast, Ireland.","DOI":"10.1109\/PST.2018.8514207"},{"key":"ref_10","unstructured":"Park, N., Sun, K., Foresti, S., Butler, K., and Saxena, N. (2020). TransNet: Unseen Malware Variants Detection Using Deep Transfer Learning. Proceedings of the Security and Privacy in Communication Networks, Springer International Publishing."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Wang, F., Chai, G., Li, Q., and Wang, C. (2022). An Efficient Deep Unsupervised Domain Adaptation for Unknown Malware Detection. Symmetry, 14.","DOI":"10.3390\/sym14020296"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., and Sun, J. (2016, January 27\u201330). Deep Residual Learning for Image Recognition. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), Las Vegas, NV, USA.","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref_13","unstructured":"Braubach, L., Jander, K., and B\u0103dic, C. (2022). Image-based Intrusion Detection in Network Traffic. Proceedings of the Intelligent Distributed Computing XV, Springer."},{"key":"ref_14","unstructured":"Zhu, W. (2018). On the model-checking-based IDS. arXiv."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Vigna, G., Kruegel, C., and Jonsson, E. (2003). Using Decision Trees to Improve Signature-Based Intrusion Detection. Proceedings of the Recent Advances in Intrusion Detection, Springer.","DOI":"10.1007\/b13476"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"2617","DOI":"10.1016\/j.cor.2004.03.019","article-title":"Application of SVM and ANN for intrusion detection","volume":"32","author":"Chen","year":"2005","journal-title":"Comput. Oper. Res."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Holmes, D.E., and Jain, L.C. (2008). A Tutorial on Learning with Bayesian Networks. Innovations in Bayesian Networks: Theory and Applications, Springer.","DOI":"10.1007\/978-3-540-85066-3"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Barbar\u00e1, D., Wu, N., and Jajodia, S. (2001, January 5\u20137). Detecting Novel Network Intrusions Using Bayes Estimators. Proceedings of the 2001 SIAM International Conference on Data Mining (SDM), Chicago, IL, USA.","DOI":"10.1137\/1.9781611972719.28"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Seruca, I., Cordeiro, J., Hammoudi, S., and Filipe, J. (2006). Intrusion Detection Systems Using Adaptive Regression Spines. Proceedings of the Enterprise Information Systems VI, Springer.","DOI":"10.1007\/1-4020-3675-2"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"29","DOI":"10.5121\/ijdkp.2014.4203","article-title":"A New Clustering Approach for Anomaly Intrusion Detection","volume":"4","author":"Ranjan","year":"2014","journal-title":"Int. J. Data Min. Knowl. Manag. Process."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"662","DOI":"10.1016\/j.cose.2005.05.003","article-title":"A multinomial logistic regression modeling approach for anomaly intrusion detection","volume":"24","author":"Wang","year":"2005","journal-title":"Comput. Secur."},{"key":"ref_22","first-page":"17","article-title":"A Survey on RBF Neural Network for Intrusion Detection System","volume":"4","author":"Sheth","year":"2014","journal-title":"Int. J. Eng. Res. Appl."},{"key":"ref_23","unstructured":"Sammany, M., Sharawi, M., El-beltagy, M., and Saroit, I. (2007, January 24\u201326). Artificial Neural Networks Architecture For Intrusion Detection Systems and Classification of Attacks. Proceedings of the 5th International Conference INFO2007, Cairo University, Giza, Egypt."},{"key":"ref_24","first-page":"2165","article-title":"Detecting New Forms of Network Intrusion Using Genetic Programming","volume":"Volume 20","author":"Lu","year":"2004","journal-title":"Proceedings of the Congress on Evolutionary Computation"},{"key":"ref_25","first-page":"7517","article-title":"A Survey on Intrusion Detection System Using Fuzzy Logic","volume":"9","author":"Mahendiran","year":"2016","journal-title":"Int. J. Control Theory Appl."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"3024","DOI":"10.1016\/j.ins.2007.11.028","article-title":"A hybrid artificial immune system and Self Organising Map for network intrusion detection","volume":"178","author":"Powers","year":"2008","journal-title":"Inf. Sci."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Barford, P., Kline, J., Plonka, D., and Ron, A. (2002, January 6\u20138). A signal analysis of network traffic anomalies. Proceedings of the IMW\u201902, Marseille, France.","DOI":"10.1145\/637209.637210"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"222","DOI":"10.1109\/TSE.1987.232894","article-title":"An Intrusion-Detection Model","volume":"SE-13","author":"Denning","year":"1987","journal-title":"IEEE Trans. Softw. Eng."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Gu, Y., Mccallum, A., and Towsley, D. (2005). Detecting Anomalies in Network Traffic Using Maximum Entropy Estimation, USENIX Association.","DOI":"10.1145\/1330107.1330148"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"271","DOI":"10.1007\/978-3-319-11248-0_21","article-title":"Network Anomaly Detection Based on the Statistical Self-similarity Factor","volume":"324","author":"Dymora","year":"2015","journal-title":"Lect. Notes Electr. Eng."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"1659","DOI":"10.1016\/j.eswa.2007.01.040","article-title":"DDoS attack detection method using cluster analysis","volume":"34","author":"Lee","year":"2008","journal-title":"Expert Syst. Appl."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"4391","DOI":"10.1038\/s41467-020-18197-y","article-title":"Representation of features as images with neighborhood dependencies for compatibility with convolutional neural networks","volume":"11","author":"Bazgir","year":"2020","journal-title":"Nat. Commun."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"91","DOI":"10.1016\/j.ymeth.2019.02.009","article-title":"Deep-Resp-Forest: A deep forest model to predict anti-cancer drug response","volume":"166","author":"Su","year":"2019","journal-title":"Methods"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"3981","DOI":"10.1021\/acs.jcim.9b00387","article-title":"Predicting drug-target interaction using a novel graph neural network with 3D structure-embedded graph representation","volume":"59","author":"Lim","year":"2019","journal-title":"J. Chem. Inf. Model."},{"key":"ref_35","unstructured":"(2022, November 23). NCI60 Drug Response Data Set, Available online: https:\/\/dtp.cancer.gov\/databases_tools\/bulk_data.htm."},{"key":"ref_36","unstructured":"(2022, November 23). Drug Sensitivity in Cancer (GDSC) Data Set. Available online: https:\/\/www.cancerrxgene.org\/downloads\/bulk_download."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"11325","DOI":"10.1038\/s41598-021-90923-y","article-title":"Converting tabular data into images for deep learning with convolutional neural networks","volume":"11","author":"Zhu","year":"2021","journal-title":"Sci. Rep."},{"key":"ref_38","unstructured":"(2022, November 23). Cancer Therapeutics Response Portal v2 (CTRP). Available online: https:\/\/portals.broadinstitute.org\/ctrp.v2.1\/."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Masum, M., and Shahriar, H. (2020, January 8\u201310). TL-NID: Deep Neural Network with Transfer Learning for Network Intrusion Detection. Proceedings of the 15th International Conference for Internet Technology and Secured Transactions (ICITST), London, UK.","DOI":"10.23919\/ICITST51030.2020.9351317"},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"821","DOI":"10.26599\/TST.2020.9010041","article-title":"Anomaly detection of industrial control systems based on transfer learning","volume":"26","author":"Wang","year":"2021","journal-title":"Tsinghua Sci. Technol."},{"key":"ref_41","first-page":"1","article-title":"Transfer learning for detecting unknown network attacks","volume":"2019","author":"Zhao","year":"2019","journal-title":"Int. J. Comput. Vision"},{"key":"ref_42","unstructured":"Simonyan, K., and Zisserman, A. (2015). Very Deep Convolutional Networks for Large-Scale Image Recognition. arXiv."},{"key":"ref_43","unstructured":"(2022, November 23). NSL-KDD Data Set. Available online: https:\/\/www.unb.ca\/cic\/datasets\/nsl.html."},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"6419","DOI":"10.3233\/JIFS-220444","article-title":"An effective network intrusion detection and classification system for securing WSN using VGG-19 and hybrid deep neural network techniques","volume":"43","author":"Manjula","year":"2022","journal-title":"J. Intell. Fuzzy Syst."},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Sandler, M., Howard, A., Zhu, M., Zhmoginov, A., and Chen, L.C. (2018, January 18\u201323). MobileNetV2: Inverted Residuals and Linear Bottlenecks. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Salt Lake City, UT, USA.","DOI":"10.1109\/CVPR.2018.00474"},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Moustafa, N., and Slay, J. (2015, January 10\u201312). UNSW-NB15: A comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). Proceedings of the Military Communications and Information Systems Conference (MilCIS), Canberra, Australia.","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"70884","DOI":"10.1109\/ACCESS.2018.2881003","article-title":"Anomaly Detection for HTTP Using Convolutional Autoencoders","volume":"6","author":"Park","year":"2018","journal-title":"IEEE Access"},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Nataraj, L., Karthikeyan, S., Jacob, G., and Manjunath, B.S. (2011, January 20). Malware Images: Visualization and Automatic Classification. Proceedings of the 8th International Symposium on Visualization for Cyber Security, Pittsburgh, PA, USA.","DOI":"10.1145\/2016904.2016908"},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"91992","DOI":"10.1109\/ACCESS.2019.2927465","article-title":"A Multiple-Layer Representation Learning Model for Network-Based Attack Detection","volume":"7","author":"Zhang","year":"2019","journal-title":"IEEE Access"},{"key":"ref_50","unstructured":"Howard, A., Sandler, M., Chen, B., Wang, W., Chen, L.C., Tan, M., Chu, G., Vasudevan, V., Zhu, Y., and Pang, R. (November, January 27). Searching for MobileNetV3. Proceedings of the IEEE\/CVF International Conference on Computer Vision (ICCV), Seoul, Republic of Korea."},{"key":"ref_51","doi-asserted-by":"crossref","unstructured":"Havarneanu, G., Setola, R., Nassopoulos, H., and Wolthusen, S. (2017, January 8\u201313). A Dataset to Support Research in the Design of Secure Water Treatment Systems. Proceedings of the Critical Information Infrastructures Security, Lucca, Italy.","DOI":"10.1007\/978-3-319-71368-7"},{"key":"ref_52","unstructured":"(2022, November 23). PyTorch Model Hub. Available online: https:\/\/pytorch.org\/vision\/stable\/models.html."},{"key":"ref_53","doi-asserted-by":"crossref","first-page":"55","DOI":"10.5815\/ijigsp.2013.05.07","article-title":"A Comparative Analysis of Image Scaling Algorithms","volume":"5","author":"Suresh","year":"2013","journal-title":"Int. J. Image Graph. Signal Process."},{"key":"ref_54","doi-asserted-by":"crossref","first-page":"310","DOI":"10.1016\/j.procs.2018.07.177","article-title":"Detection of DNS DDoS Attacks with Random Forest Algorithm on Spark","volume":"134","author":"Chen","year":"2018","journal-title":"Procedia Comput. Sci."},{"key":"ref_55","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3178582","article-title":"A Survey of Random Forest Based Methods for Intrusion Detection Systems","volume":"51","author":"Resende","year":"2018","journal-title":"ACM Comput. Surv."}],"container-title":["Information"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2078-2489\/13\/12\/553\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T01:26:31Z","timestamp":1760145991000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2078-2489\/13\/12\/553"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11,25]]},"references-count":55,"journal-issue":{"issue":"12","published-online":{"date-parts":[[2022,12]]}},"alternative-id":["info13120553"],"URL":"https:\/\/doi.org\/10.3390\/info13120553","relation":{},"ISSN":["2078-2489"],"issn-type":[{"value":"2078-2489","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,11,25]]}}}