{"id":"https://openalex.org/W7128495018","doi":"https://doi.org/10.1007/s00354-026-00318-8","title":"A Generative AI Method for Minority Class Handling in Anomaly Detection with Drift and Explainability Analysis","display_name":"A Generative AI Method for Minority Class Handling in Anomaly Detection with Drift and Explainability Analysis","publication_year":2026,"publication_date":"2026-02-10","ids":{"openalex":"https://openalex.org/W7128495018","doi":"https://doi.org/10.1007/s00354-026-00318-8"},"language":"en","primary_location":{"id":"doi:10.1007/s00354-026-00318-8","is_oa":true,"landing_page_url":"https://doi.org/10.1007/s00354-026-00318-8","pdf_url":"https://link.springer.com/content/pdf/10.1007/s00354-026-00318-8.pdf","source":{"id":"https://openalex.org/S165364243","display_name":"New Generation Computing","issn_l":"0288-3635","issn":["0288-3635","1882-7055"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"journal"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"New Generation Computing","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://link.springer.com/content/pdf/10.1007/s00354-026-00318-8.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5125494911","display_name":"Kelvin J. Mwiga","orcid":null},"institutions":[{"id":"https://openalex.org/I140534913","display_name":"Ardhi University","ror":"https://ror.org/05k903r09","country_code":"TZ","type":"education","lineage":["https://openalex.org/I140534913"]},{"id":"https://openalex.org/I97231232","display_name":"Nelson Mandela African Institution of Science and Technology","ror":"https://ror.org/041vsn055","country_code":"TZ","type":"education","lineage":["https://openalex.org/I97231232"]}],"countries":["TZ"],"is_corresponding":true,"raw_author_name":"Kelvin J. Mwiga","raw_affiliation_strings":["Land Management and Valuation, Ardhi University, Dar es Salaam, Tanzania","School of Computational and Communication Sciences and Engineering (CoCSE), The Nelson Mandela African Institution of Science and Technology, Arusha, Tanzania"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Land Management and Valuation, Ardhi University, Dar es Salaam, Tanzania","institution_ids":["https://openalex.org/I140534913"]},{"raw_affiliation_string":"School of Computational and Communication Sciences and Engineering (CoCSE), The Nelson Mandela African Institution of Science and Technology, Arusha, Tanzania","institution_ids":["https://openalex.org/I97231232"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5024150835","display_name":"Mussa Ally Dida","orcid":"https://orcid.org/0000-0002-7143-8953"},"institutions":[{"id":"https://openalex.org/I97231232","display_name":"Nelson Mandela African Institution of Science and Technology","ror":"https://ror.org/041vsn055","country_code":"TZ","type":"education","lineage":["https://openalex.org/I97231232"]}],"countries":["TZ"],"is_corresponding":false,"raw_author_name":"Mussa A. Dida","raw_affiliation_strings":["School of Computational and Communication Sciences and Engineering (CoCSE), The Nelson Mandela African Institution of Science and Technology, Arusha, Tanzania"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Computational and Communication Sciences and Engineering (CoCSE), The Nelson Mandela African Institution of Science and Technology, Arusha, Tanzania","institution_ids":["https://openalex.org/I97231232"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5003096709","display_name":"Ahmad Mohsin","orcid":"https://orcid.org/0000-0001-9023-0851"},"institutions":[{"id":"https://openalex.org/I12079687","display_name":"Edith Cowan University","ror":"https://ror.org/05jhnwe22","country_code":"AU","type":"education","lineage":["https://openalex.org/I12079687"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Ahmad Mohsin","raw_affiliation_strings":["Centre for Securing Digital Futures, Edith Cowan University, Perth, WA, 6027, Australia"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Centre for Securing Digital Futures, Edith Cowan University, Perth, WA, 6027, Australia","institution_ids":["https://openalex.org/I12079687"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5055312229","display_name":"Iqbal H. Sarker","orcid":"https://orcid.org/0000-0003-1740-5517"},"institutions":[{"id":"https://openalex.org/I12079687","display_name":"Edith Cowan University","ror":"https://ror.org/05jhnwe22","country_code":"AU","type":"education","lineage":["https://openalex.org/I12079687"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Iqbal H. Sarker","raw_affiliation_strings":["Centre for Securing Digital Futures, Edith Cowan University, Perth, WA, 6027, Australia"],"raw_orcid":"https://orcid.org/0000-0003-1740-5517","affiliations":[{"raw_affiliation_string":"Centre for Securing Digital Futures, Edith Cowan University, Perth, WA, 6027, Australia","institution_ids":["https://openalex.org/I12079687"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5125494911"],"corresponding_institution_ids":["https://openalex.org/I140534913","https://openalex.org/I97231232"],"apc_list":{"value":2490,"currency":"EUR","value_usd":3090},"apc_paid":{"value":2490,"currency":"EUR","value_usd":3090},"fwci":0.0,"has_fulltext":true,"cited_by_count":0,"citation_normalized_percentile":{"value":0.27712449,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"44","issue":"2","first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12761","display_name":"Data Stream Mining Techniques","score":0.4377000033855438,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12761","display_name":"Data Stream Mining Techniques","score":0.4377000033855438,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11652","display_name":"Imbalanced Data Classification Techniques","score":0.1477999985218048,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.13279999792575836,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/anomaly-detection","display_name":"Anomaly detection","score":0.7944999933242798},{"id":"https://openalex.org/keywords/benchmark","display_name":"Benchmark (surveying)","score":0.715499997138977},{"id":"https://openalex.org/keywords/generative-grammar","display_name":"Generative grammar","score":0.6010000109672546},{"id":"https://openalex.org/keywords/feature","display_name":"Feature (linguistics)","score":0.5088000297546387},{"id":"https://openalex.org/keywords/anomaly","display_name":"Anomaly (physics)","score":0.4388999938964844},{"id":"https://openalex.org/keywords/adaptation","display_name":"Adaptation (eye)","score":0.4124000072479248},{"id":"https://openalex.org/keywords/concept-drift","display_name":"Concept drift","score":0.39570000767707825}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8555999994277954},{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.7944999933242798},{"id":"https://openalex.org/C185798385","wikidata":"https://www.wikidata.org/wiki/Q1161707","display_name":"Benchmark (surveying)","level":2,"score":0.715499997138977},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.7146999835968018},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.70169997215271},{"id":"https://openalex.org/C39890363","wikidata":"https://www.wikidata.org/wiki/Q36108","display_name":"Generative grammar","level":2,"score":0.6010000109672546},{"id":"https://openalex.org/C2776401178","wikidata":"https://www.wikidata.org/wiki/Q12050496","display_name":"Feature (linguistics)","level":2,"score":0.5088000297546387},{"id":"https://openalex.org/C12997251","wikidata":"https://www.wikidata.org/wiki/Q567560","display_name":"Anomaly (physics)","level":2,"score":0.4388999938964844},{"id":"https://openalex.org/C139807058","wikidata":"https://www.wikidata.org/wiki/Q352374","display_name":"Adaptation (eye)","level":2,"score":0.4124000072479248},{"id":"https://openalex.org/C60777511","wikidata":"https://www.wikidata.org/wiki/Q3045002","display_name":"Concept drift","level":3,"score":0.39570000767707825},{"id":"https://openalex.org/C167966045","wikidata":"https://www.wikidata.org/wiki/Q5532625","display_name":"Generative model","level":3,"score":0.37119999527931213},{"id":"https://openalex.org/C2777212361","wikidata":"https://www.wikidata.org/wiki/Q5127848","display_name":"Class (philosophy)","level":2,"score":0.351500004529953},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3352999985218048},{"id":"https://openalex.org/C52622490","wikidata":"https://www.wikidata.org/wiki/Q1026626","display_name":"Feature extraction","level":2,"score":0.3100999891757965},{"id":"https://openalex.org/C110332635","wikidata":"https://www.wikidata.org/wiki/Q629498","display_name":"Genetic programming","level":2,"score":0.29739999771118164},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.2718999981880188},{"id":"https://openalex.org/C160920958","wikidata":"https://www.wikidata.org/wiki/Q7662746","display_name":"Synthetic data","level":2,"score":0.2624000012874603}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1007/s00354-026-00318-8","is_oa":true,"landing_page_url":"https://doi.org/10.1007/s00354-026-00318-8","pdf_url":"https://link.springer.com/content/pdf/10.1007/s00354-026-00318-8.pdf","source":{"id":"https://openalex.org/S165364243","display_name":"New Generation Computing","issn_l":"0288-3635","issn":["0288-3635","1882-7055"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"journal"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"New Generation Computing","raw_type":"journal-article"},{"id":"pmh:oai:ro.ecu.edu.au:ecuworks2022-2026-8712","is_oa":true,"landing_page_url":"https://ro.ecu.edu.au/ecuworks2022-2026/7712","pdf_url":null,"source":{"id":"https://openalex.org/S4306400464","display_name":"Research Online (Edith Cowan University)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I12079687","host_organization_name":"Edith Cowan University","host_organization_lineage":["https://openalex.org/I12079687"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Research outputs 2022 to 2026","raw_type":"text"}],"best_oa_location":{"id":"doi:10.1007/s00354-026-00318-8","is_oa":true,"landing_page_url":"https://doi.org/10.1007/s00354-026-00318-8","pdf_url":"https://link.springer.com/content/pdf/10.1007/s00354-026-00318-8.pdf","source":{"id":"https://openalex.org/S165364243","display_name":"New Generation Computing","issn_l":"0288-3635","issn":["0288-3635","1882-7055"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"journal"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"New Generation Computing","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[],"funders":[{"id":"https://openalex.org/F4320320988","display_name":"Edith Cowan University","ror":"https://ror.org/05jhnwe22"}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W7128495018.pdf","grobid_xml":"https://content.openalex.org/works/W7128495018.grobid-xml"},"referenced_works_count":52,"referenced_works":["https://openalex.org/W1988812547","https://openalex.org/W1993220166","https://openalex.org/W2024223694","https://openalex.org/W2053724458","https://openalex.org/W2087787741","https://openalex.org/W2104933073","https://openalex.org/W2118978333","https://openalex.org/W2129905273","https://openalex.org/W2132791018","https://openalex.org/W2148143831","https://openalex.org/W2164341120","https://openalex.org/W2166840159","https://openalex.org/W2296509296","https://openalex.org/W2517990807","https://openalex.org/W3000057629","https://openalex.org/W3017093935","https://openalex.org/W3021503072","https://openalex.org/W3033659610","https://openalex.org/W3035231859","https://openalex.org/W3043844898","https://openalex.org/W3106741970","https://openalex.org/W3110899937","https://openalex.org/W3112696791","https://openalex.org/W3118220620","https://openalex.org/W3126752450","https://openalex.org/W3155962425","https://openalex.org/W3160590016","https://openalex.org/W3198054520","https://openalex.org/W3200219001","https://openalex.org/W3208097639","https://openalex.org/W3208919862","https://openalex.org/W3210728649","https://openalex.org/W4205481247","https://openalex.org/W4205884137","https://openalex.org/W4220982217","https://openalex.org/W4285248859","https://openalex.org/W4288941200","https://openalex.org/W4297538900","https://openalex.org/W4300906944","https://openalex.org/W4310172539","https://openalex.org/W4313586675","https://openalex.org/W4321240473","https://openalex.org/W4382196153","https://openalex.org/W4385557349","https://openalex.org/W4395700348","https://openalex.org/W4396220530","https://openalex.org/W4398147821","https://openalex.org/W4398165763","https://openalex.org/W4399203348","https://openalex.org/W4399430451","https://openalex.org/W4404520990","https://openalex.org/W4409061134"],"related_works":[],"abstract_inverted_index":{"Abstract":[0],"Artificial":[1,165],"Intelligence,":[2],"particularly":[3],"machine":[4,20],"learning":[5,21],"(ML)":[6],"algorithms,":[7],"plays":[8],"a":[9,47,70,113],"crucial":[10],"role":[11],"in":[12,78,102],"detecting":[13],"cyberattacks,":[14],"including":[15,169],"anomalies":[16],"and":[17,36,85,137,151,157,171,206],"intrusions.":[18],"However,":[19],"models":[22],"trained":[23],"on":[24,129,189,202,213],"imbalanced":[25,214],"cybersecurity":[26],"datasets":[27,190],"often":[28],"struggle":[29],"to":[30,64,74,95,154,175,179,210],"accurately":[31],"detect":[32],"minority":[33,58,76,100],"data":[34,59],"instances":[35],"potential":[37],"threats,":[38],"thereby":[39],"weakening":[40],"overall":[41],"system":[42],"security.":[43],"Despite":[44],"extensive":[45],"research,":[46],"persistent":[48],"challenge":[49],"is":[50],"the":[51,97,103,140,199,203],"inadequate":[52],"explanation":[53],"for":[54,122],"model":[55,180],"predictions":[56],"concerning":[57],"classes.":[60],"This":[61],"study":[62],"aims":[63],"address":[65],"these":[66],"limitations":[67],"by":[68,196],"developing":[69],"generative":[71],"AI-based":[72],"approach":[73],"manage":[75],"classes":[77,101],"anomaly":[79,104],"detection,":[80],"incorporating":[81],"concept":[82,148],"drift":[83,149],"handling":[84],"explainability":[86],"analysis.":[87],"We":[88,146],"introduce":[89],"an":[90],"over-sampling":[91],"technique,":[92],"CGGReaT,":[93],"designed":[94],"enhance":[96,162],"presence":[98],"of":[99,142],"detection":[105,150],"domain.":[106],"Leveraging":[107],"Large":[108],"Language":[109],"Models":[110],"(LLMs)":[111],"as":[112],"hybrid":[114],"approach,":[115],"we":[116],"use":[117],"pre-trained":[118],"transformer-based":[119],"LLM":[120],"DistilGPT-2":[121],"generating":[123],"synthetic":[124,193],"tabular":[125],"data.":[126],"Extensive":[127,182],"experiments":[128,183],"two":[130],"publicly":[131],"available":[132],"benchmark":[133],"datasets,":[134,208],"UNSW":[135,204],"NB15":[136,205],"CIC-IDS2017,":[138],"underscore":[139],"efficacy":[141],"our":[143],"proposed":[144],"approach.":[145],"employed":[147,174],"adaptation":[152],"techniques":[153],"maintain":[155],"reliable":[156],"sustainable":[158],"ML":[159,187],"performance.":[160],"To":[161],"interpretability,":[163],"eXplainable":[164],"Intelligence":[166],"(XAI)":[167],"methods,":[168],"SHAP":[170],"LIME,":[172],"are":[173],"quantify":[176],"feature":[177],"contributions":[178],"outputs.":[181],"reveal":[184],"that":[185],"testing":[186],"algorithms":[188],"balanced":[191],"with":[192],"samples":[194],"generated":[195],"cGGReaT":[197],"boosts":[198],"prediction":[200],"accuracy":[201],"CIC-IDS2017":[207],"compared":[209],"classifiers":[211],"tested":[212],"datasets.":[215]},"counts_by_year":[],"updated_date":"2026-03-13T14:20:09.374765","created_date":"2026-02-11T00:00:00"}
