{"id":"https://openalex.org/W4389633842","doi":"https://doi.org/10.1109/access.2023.3341755","title":"Learning From Few Cyber-Attacks: Addressing the Class Imbalance Problem in Machine Learning-Based Intrusion Detection in Software-Defined Networking","display_name":"Learning From Few Cyber-Attacks: Addressing the Class Imbalance Problem in Machine Learning-Based Intrusion Detection in Software-Defined Networking","publication_year":2023,"publication_date":"2023-01-01","ids":{"openalex":"https://openalex.org/W4389633842","doi":"https://doi.org/10.1109/access.2023.3341755"},"language":"en","primary_location":{"id":"doi:10.1109/access.2023.3341755","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2023.3341755","pdf_url":"https://ieeexplore.ieee.org/ielx7/6287639/6514899/10353929.pdf","source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://ieeexplore.ieee.org/ielx7/6287639/6514899/10353929.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5040274129","display_name":"Seyed Mohammad Hadi Mirsadeghi","orcid":"https://orcid.org/0009-0009-1019-0366"},"institutions":[{"id":"https://openalex.org/I111112146","display_name":"Tallinn University of Technology","ror":"https://ror.org/0443cwa12","country_code":"EE","type":"education","lineage":["https://openalex.org/I111112146"]}],"countries":["EE"],"is_corresponding":true,"raw_author_name":"Seyed Mohammad Hadi Mirsadeghi","raw_affiliation_strings":["Department of Software Science, Centre for Digital Forensics and Cyber Security, Tallinn University of Technology, Tallinn, Estonia"],"raw_orcid":"https://orcid.org/0009-0009-1019-0366","affiliations":[{"raw_affiliation_string":"Department of Software Science, Centre for Digital Forensics and Cyber Security, Tallinn University of Technology, Tallinn, Estonia","institution_ids":["https://openalex.org/I111112146"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5075157158","display_name":"Hayretdin Bah\u015fi","orcid":"https://orcid.org/0000-0001-8882-4095"},"institutions":[{"id":"https://openalex.org/I111112146","display_name":"Tallinn University of Technology","ror":"https://ror.org/0443cwa12","country_code":"EE","type":"education","lineage":["https://openalex.org/I111112146"]},{"id":"https://openalex.org/I203172682","display_name":"Northern Arizona University","ror":"https://ror.org/0272j5188","country_code":"US","type":"education","lineage":["https://openalex.org/I203172682"]}],"countries":["EE","US"],"is_corresponding":false,"raw_author_name":"Hayretdin Bahsi","raw_affiliation_strings":["Department of Software Science, Centre for Digital Forensics and Cyber Security, Tallinn University of Technology, Tallinn, Estonia","School of Informatics, Computing, and Cyber Systems, Northern Arizona University, United States"],"raw_orcid":"https://orcid.org/0000-0001-8882-4095","affiliations":[{"raw_affiliation_string":"Department of Software Science, Centre for Digital Forensics and Cyber Security, Tallinn University of Technology, Tallinn, Estonia","institution_ids":["https://openalex.org/I111112146"]},{"raw_affiliation_string":"School of Informatics, Computing, and Cyber Systems, Northern Arizona University, United States","institution_ids":["https://openalex.org/I203172682"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5069019755","display_name":"Risto Vaarandi","orcid":"https://orcid.org/0000-0001-7781-5863"},"institutions":[{"id":"https://openalex.org/I111112146","display_name":"Tallinn University of Technology","ror":"https://ror.org/0443cwa12","country_code":"EE","type":"education","lineage":["https://openalex.org/I111112146"]}],"countries":["EE"],"is_corresponding":false,"raw_author_name":"Risto Vaarandi","raw_affiliation_strings":["Department of Software Science, Centre for Digital Forensics and Cyber Security, Tallinn University of Technology, Tallinn, Estonia"],"raw_orcid":"https://orcid.org/0000-0001-7781-5863","affiliations":[{"raw_affiliation_string":"Department of Software Science, Centre for Digital Forensics and Cyber Security, Tallinn University of Technology, Tallinn, Estonia","institution_ids":["https://openalex.org/I111112146"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5081139178","display_name":"Wissem Inoubli","orcid":"https://orcid.org/0000-0001-5121-9043"},"institutions":[{"id":"https://openalex.org/I1294671590","display_name":"Centre National de la Recherche Scientifique","ror":"https://ror.org/02feahw73","country_code":"FR","type":"government","lineage":["https://openalex.org/I1294671590"]},{"id":"https://openalex.org/I4210115519","display_name":"Centre de Recherche en Informatique","ror":"https://ror.org/020cdve92","country_code":"FR","type":"facility","lineage":["https://openalex.org/I190752583","https://openalex.org/I2746051580","https://openalex.org/I4210091621","https://openalex.org/I4210115519","https://openalex.org/I70768539"]},{"id":"https://openalex.org/I44563897","display_name":"Universit\u00e9 d'Artois","ror":"https://ror.org/053x9s498","country_code":"FR","type":"education","lineage":["https://openalex.org/I44563897"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Wissem Inoubli","raw_affiliation_strings":["CNRS, UMR 8188, Centre de Recherche en Informatique de Lens (CRIL), Artois University, Lens, France"],"raw_orcid":"https://orcid.org/0000-0001-5121-9043","affiliations":[{"raw_affiliation_string":"CNRS, UMR 8188, Centre de Recherche en Informatique de Lens (CRIL), Artois University, Lens, France","institution_ids":["https://openalex.org/I44563897","https://openalex.org/I1294671590","https://openalex.org/I4210115519"]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5040274129"],"corresponding_institution_ids":["https://openalex.org/I111112146"],"apc_list":{"value":1850,"currency":"USD","value_usd":1850},"apc_paid":{"value":1850,"currency":"USD","value_usd":1850},"fwci":3.6472,"has_fulltext":true,"cited_by_count":19,"citation_normalized_percentile":{"value":0.93599695,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":97,"max":100},"biblio":{"volume":"11","issue":null,"first_page":"140428","last_page":"140442"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9990000128746033,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11652","display_name":"Imbalanced Data Classification Techniques","score":0.998199999332428,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8234812021255493},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.8032408952713013},{"id":"https://openalex.org/keywords/random-forest","display_name":"Random forest","score":0.7783247232437134},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.7641716003417969},{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.7305653095245361},{"id":"https://openalex.org/keywords/oversampling","display_name":"Oversampling","score":0.6847142577171326},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.5023760795593262},{"id":"https://openalex.org/keywords/classifier","display_name":"Classifier (UML)","score":0.4868542551994324},{"id":"https://openalex.org/keywords/class","display_name":"Class (philosophy)","score":0.43641749024391174},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.3325694799423218},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.09747382998466492},{"id":"https://openalex.org/keywords/bandwidth","display_name":"Bandwidth (computing)","score":0.0854586660861969}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8234812021255493},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.8032408952713013},{"id":"https://openalex.org/C169258074","wikidata":"https://www.wikidata.org/wiki/Q245748","display_name":"Random forest","level":2,"score":0.7783247232437134},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.7641716003417969},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.7305653095245361},{"id":"https://openalex.org/C197323446","wikidata":"https://www.wikidata.org/wiki/Q331222","display_name":"Oversampling","level":3,"score":0.6847142577171326},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.5023760795593262},{"id":"https://openalex.org/C95623464","wikidata":"https://www.wikidata.org/wiki/Q1096149","display_name":"Classifier (UML)","level":2,"score":0.4868542551994324},{"id":"https://openalex.org/C2777212361","wikidata":"https://www.wikidata.org/wiki/Q5127848","display_name":"Class (philosophy)","level":2,"score":0.43641749024391174},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3325694799423218},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.09747382998466492},{"id":"https://openalex.org/C2776257435","wikidata":"https://www.wikidata.org/wiki/Q1576430","display_name":"Bandwidth (computing)","level":2,"score":0.0854586660861969}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1109/access.2023.3341755","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2023.3341755","pdf_url":"https://ieeexplore.ieee.org/ielx7/6287639/6514899/10353929.pdf","source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},{"id":"pmh:oai:HAL:hal-04799076v1","is_oa":true,"landing_page_url":"https://hal.science/hal-04799076","pdf_url":"https://hal.science/hal-04799076/document","source":{"id":"https://openalex.org/S4306402512","display_name":"HAL (Le Centre pour la Communication Scientifique Directe)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1294671590","host_organization_name":"Centre National de la Recherche Scientifique","host_organization_lineage":["https://openalex.org/I1294671590"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"IEEE Access, 2023, 11, pp.140428 - 140442. &#x27E8;10.1109/access.2023.3341755&#x27E9;","raw_type":"Journal articles"},{"id":"pmh:oai:doaj.org/article:3957ff742cb843709f2b76d6ee93a646","is_oa":true,"landing_page_url":"https://doaj.org/article/3957ff742cb843709f2b76d6ee93a646","pdf_url":null,"source":{"id":"https://openalex.org/S4306401280","display_name":"DOAJ (DOAJ: Directory of Open Access Journals)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by-sa","license_id":"https://openalex.org/licenses/cc-by-sa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"IEEE Access, Vol 11, Pp 140428-140442 (2023)","raw_type":"article"}],"best_oa_location":{"id":"doi:10.1109/access.2023.3341755","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2023.3341755","pdf_url":"https://ieeexplore.ieee.org/ielx7/6287639/6514899/10353929.pdf","source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4389633842.pdf","grobid_xml":"https://content.openalex.org/works/W4389633842.grobid-xml"},"referenced_works_count":63,"referenced_works":["https://openalex.org/W1524496078","https://openalex.org/W1574715085","https://openalex.org/W1766594731","https://openalex.org/W1885645786","https://openalex.org/W1941659294","https://openalex.org/W1993220166","https://openalex.org/W2018186689","https://openalex.org/W2023639956","https://openalex.org/W2045042261","https://openalex.org/W2047408376","https://openalex.org/W2099454382","https://openalex.org/W2099940443","https://openalex.org/W2106479238","https://openalex.org/W2111164709","https://openalex.org/W2115733720","https://openalex.org/W2118978333","https://openalex.org/W2126996952","https://openalex.org/W2137029138","https://openalex.org/W2148143831","https://openalex.org/W2152988830","https://openalex.org/W2164330572","https://openalex.org/W2168025622","https://openalex.org/W2194775991","https://openalex.org/W2259894692","https://openalex.org/W2296509296","https://openalex.org/W2508881195","https://openalex.org/W2557831587","https://openalex.org/W2577946330","https://openalex.org/W2767106145","https://openalex.org/W2790031975","https://openalex.org/W2899434936","https://openalex.org/W2936503027","https://openalex.org/W2963514896","https://openalex.org/W2964050365","https://openalex.org/W2973862992","https://openalex.org/W2988981864","https://openalex.org/W3005630930","https://openalex.org/W3024905798","https://openalex.org/W3043310823","https://openalex.org/W3084346886","https://openalex.org/W3090574047","https://openalex.org/W3100076810","https://openalex.org/W3109072952","https://openalex.org/W3116274835","https://openalex.org/W3126752450","https://openalex.org/W3142930122","https://openalex.org/W3150522965","https://openalex.org/W3197492934","https://openalex.org/W3202080502","https://openalex.org/W4287643567","https://openalex.org/W4287689466","https://openalex.org/W4295242637","https://openalex.org/W4313421210","https://openalex.org/W4384434470","https://openalex.org/W6602002561","https://openalex.org/W6631506987","https://openalex.org/W6634333142","https://openalex.org/W6692991205","https://openalex.org/W6729414304","https://openalex.org/W6732248266","https://openalex.org/W6766978945","https://openalex.org/W6781905506","https://openalex.org/W6783596713"],"related_works":["https://openalex.org/W4401045170","https://openalex.org/W3172259201","https://openalex.org/W3196098778","https://openalex.org/W3211250490","https://openalex.org/W2903618681","https://openalex.org/W3184937791","https://openalex.org/W4401052546","https://openalex.org/W4360584310","https://openalex.org/W2981515171","https://openalex.org/W80466363"],"abstract_inverted_index":{"The":[0],"class":[1,67,101,120,186,196,270],"imbalance":[2,49,68,102,121,197,271],"problem":[3,50,58,69,103,122,272],"negatively":[4],"impacts":[5],"learning":[6,32,134,179,238],"algorithms\u2019":[7],"performance":[8,235],"in":[9,51,59,90,96,123,128,181,223,241,273,302],"minority":[10,185,227],"classes":[11],"which":[12],"may":[13,294],"constitute":[14],"more":[15],"severe":[16],"attacks":[17],"than":[18],"the":[19,25,43,48,66,91,100,119,182,190,211,218,224,269],"majority":[20],"ones.":[21],"This":[22,150,188],"study":[23],"investigates":[24],"benefits":[26],"of":[27,81,84,93,117,184,226,250],"balancing":[28,204,259],"strategies":[29,260],"and":[30,63,106,139,146,166,207],"imbalanced":[31],"approaches":[33],"on":[34,87,137,299],"intrusion":[35,54,77,94,126,148,275,289],"data":[36],"from":[37,155],"Software":[38],"Defined":[39],"Networking":[40],"(SDN).":[41],"Although":[42,265],"research":[44,89,110],"community":[45],"has":[46],"covered":[47],"machine":[52,124],"learning-based":[53,125],"detection,":[55],"addressing":[56,118],"this":[57,266,303],"SDN":[60,76,274],"is":[61,83,112],"novel":[62],"powerful.":[64],"Addressing":[65],"over":[70,236],"InSDN":[71],"(the":[72],"only":[73],"publicly":[74],"available":[75],"detection":[78,95,127,290],"dataset":[79],"as":[80],"recent)":[82],"significant":[85,297],"impact":[86,298],"future":[88,300],"area":[92],"SDN.":[97,129],"We":[98,130,170,199],"address":[99],"through":[104],"data-level":[105,231],"classifier-level":[107],"techniques.":[108],"Our":[109],"objective":[111],"to":[113,261],"determine":[114],"suitable":[115],"methods":[116,232],"propose":[131],"custom":[132],"deep":[133,178,237],"architectures":[135],"based":[136],"GANs":[138],"Siamese":[140],"Neural":[141],"Networks":[142],"for":[143,286],"generative":[144],"modeling":[145],"similarity-based":[147],"detection.":[149],"paper":[151],"provides":[152,278],"benchmarking":[153],"results":[154],"classification":[156,183,225,234],"with":[157],"Random":[158,164,174],"Oversampling":[159],"(ROS),":[160],"SMOTE,":[161,208],"GANs,":[162],"weighted":[163],"Forest,":[165],"Siamese-based":[167],"one-shot":[168],"learning.":[169],"have":[171,295],"found":[172],"that":[173,192,202,282],"Forest":[175],"(RF)":[176],"outperforms":[177],"models":[180],"instances.":[187],"supports":[189],"notion":[191],"RF":[193,254],"can":[194,283],"handle":[195],"well.":[198],"also":[200],"observe":[201],"widely-used":[203],"techniques,":[205],"ROS":[206],"drastically":[209],"decrease":[210],"False":[212,219],"Positive":[213],"Rate":[214,221],"(FPR)":[215],"but":[216],"increase":[217],"Negative":[220],"(FNR)":[222],"classes.":[228],"Conclusively,":[229],"while":[230],"improve":[233],"models,":[239],"they,":[240],"fact,":[242],"degrade":[243],"RF\u2019s":[244],"performance,":[245],"i.e.":[246],"cause":[247],"higher":[248,263],"numbers":[249],"false":[251],"predictions.":[252],"Therefore,":[253],"does":[255],"not":[256],"need":[257],"additional":[258],"get":[262],"performance.":[264],"work":[267],"addresses":[268],"data,":[276],"it":[277,293],"a":[279,296],"well-designed":[280],"benchmark":[281],"be":[284],"exemplary":[285],"any":[287],"network":[288],"data.":[291],"Thus,":[292],"studies":[301],"respective":[304],"domain.":[305]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":13},{"year":2024,"cited_by_count":4}],"updated_date":"2026-05-24T08:33:08.758527","created_date":"2025-10-10T00:00:00"}
