{"id":"https://openalex.org/W4285110406","doi":"https://doi.org/10.1109/tnsm.2022.3173933","title":"Sneaking Through Security: Mutating Live Network Traffic to Evade Learning-Based NIDS","display_name":"Sneaking Through Security: Mutating Live Network Traffic to Evade Learning-Based NIDS","publication_year":2022,"publication_date":"2022-05-10","ids":{"openalex":"https://openalex.org/W4285110406","doi":"https://doi.org/10.1109/tnsm.2022.3173933"},"language":"en","primary_location":{"id":"doi:10.1109/tnsm.2022.3173933","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tnsm.2022.3173933","pdf_url":null,"source":{"id":"https://openalex.org/S173527311","display_name":"IEEE Transactions on Network and Service Management","issn_l":"1932-4537","issn":["1932-4537","2373-7379"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Network and Service Management","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5022611612","display_name":"Shuaishuai Tan","orcid":"https://orcid.org/0000-0002-8882-405X"},"institutions":[{"id":"https://openalex.org/I4210136793","display_name":"Peng Cheng Laboratory","ror":"https://ror.org/03qdqbt06","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210136793"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Shuaishuai Tan","raw_affiliation_strings":["Department of New Networks, Peng Cheng Laboratory, Shenzhen, China","Department of Technology, China (Qianhai) Internet Exchange, Shenzhen, China"],"affiliations":[{"raw_affiliation_string":"Department of New Networks, Peng Cheng Laboratory, Shenzhen, China","institution_ids":["https://openalex.org/I4210136793"]},{"raw_affiliation_string":"Department of Technology, China (Qianhai) Internet Exchange, Shenzhen, China","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100681423","display_name":"Xiaoxiong Zhong","orcid":"https://orcid.org/0000-0001-9307-6247"},"institutions":[{"id":"https://openalex.org/I4210136793","display_name":"Peng Cheng Laboratory","ror":"https://ror.org/03qdqbt06","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210136793"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiaoxiong Zhong","raw_affiliation_strings":["Department of New Networks, Peng Cheng Laboratory, Shenzhen, China"],"affiliations":[{"raw_affiliation_string":"Department of New Networks, Peng Cheng Laboratory, Shenzhen, China","institution_ids":["https://openalex.org/I4210136793"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5059567156","display_name":"Zhiyi Tian","orcid":"https://orcid.org/0000-0001-8905-0941"},"institutions":[{"id":"https://openalex.org/I114017466","display_name":"University of Technology Sydney","ror":"https://ror.org/03f0f6041","country_code":"AU","type":"education","lineage":["https://openalex.org/I114017466"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Zhiyi Tian","raw_affiliation_strings":["Faculty of Engineering and IT, University of Technology Sydney, Sydney, NSW, Australia"],"affiliations":[{"raw_affiliation_string":"Faculty of Engineering and IT, University of Technology Sydney, Sydney, NSW, Australia","institution_ids":["https://openalex.org/I114017466"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5109147094","display_name":"Qingkuan Dong","orcid":null},"institutions":[{"id":"https://openalex.org/I149594827","display_name":"Xidian University","ror":"https://ror.org/05s92vm98","country_code":"CN","type":"education","lineage":["https://openalex.org/I149594827"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Qingkuan Dong","raw_affiliation_strings":["State Key Laboratory of Integrated Services Networks, Xidian University, Xi&#x2019;an, China"],"affiliations":[{"raw_affiliation_string":"State Key Laboratory of Integrated Services Networks, Xidian University, Xi&#x2019;an, China","institution_ids":["https://openalex.org/I149594827"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5022611612"],"corresponding_institution_ids":["https://openalex.org/I4210136793"],"apc_list":null,"apc_paid":null,"fwci":2.555,"has_fulltext":false,"cited_by_count":18,"citation_normalized_percentile":{"value":0.89687572,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":99},"biblio":{"volume":"19","issue":"3","first_page":"2295","last_page":"2308"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9991000294685364,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9991000294685364,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8228423595428467},{"id":"https://openalex.org/keywords/network-packet","display_name":"Network packet","score":0.6743494272232056},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.545001208782196},{"id":"https://openalex.org/keywords/evasion","display_name":"Evasion (ethics)","score":0.5336630344390869},{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.46835723519325256},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.4577989876270294},{"id":"https://openalex.org/keywords/network-security","display_name":"Network security","score":0.45758357644081116},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.378028929233551},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3258816599845886}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8228423595428467},{"id":"https://openalex.org/C158379750","wikidata":"https://www.wikidata.org/wiki/Q214111","display_name":"Network packet","level":2,"score":0.6743494272232056},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.545001208782196},{"id":"https://openalex.org/C2781251061","wikidata":"https://www.wikidata.org/wiki/Q5416089","display_name":"Evasion (ethics)","level":3,"score":0.5336630344390869},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.46835723519325256},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4577989876270294},{"id":"https://openalex.org/C182590292","wikidata":"https://www.wikidata.org/wiki/Q989632","display_name":"Network security","level":2,"score":0.45758357644081116},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.378028929233551},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3258816599845886},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C8891405","wikidata":"https://www.wikidata.org/wiki/Q1059","display_name":"Immune system","level":2,"score":0.0},{"id":"https://openalex.org/C203014093","wikidata":"https://www.wikidata.org/wiki/Q101929","display_name":"Immunology","level":1,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tnsm.2022.3173933","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tnsm.2022.3173933","pdf_url":null,"source":{"id":"https://openalex.org/S173527311","display_name":"IEEE Transactions on Network and Service Management","issn_l":"1932-4537","issn":["1932-4537","2373-7379"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Network and Service Management","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.8199999928474426,"display_name":"Peace, Justice and strong institutions"}],"awards":[{"id":"https://openalex.org/G3007617677","display_name":null,"funder_award_id":"2020JM-184","funder_id":"https://openalex.org/F4320336567","funder_display_name":"Natural Science Basic Research Program of Shaanxi Province"},{"id":"https://openalex.org/G782231657","display_name":null,"funder_award_id":"2014ZT05G157","funder_id":"https://openalex.org/F4320333334","funder_display_name":"Guangdong Province Introduction of Innovative R&D Team"}],"funders":[{"id":"https://openalex.org/F4320333334","display_name":"Guangdong Province Introduction of Innovative R&D Team","ror":null},{"id":"https://openalex.org/F4320336567","display_name":"Natural Science Basic Research Program of Shaanxi Province","ror":null}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":54,"referenced_works":["https://openalex.org/W1481573196","https://openalex.org/W1490025813","https://openalex.org/W1553177637","https://openalex.org/W1608222975","https://openalex.org/W1985902740","https://openalex.org/W2012210084","https://openalex.org/W2026258420","https://openalex.org/W2152575748","https://openalex.org/W2155300758","https://openalex.org/W2170316384","https://openalex.org/W2537766808","https://openalex.org/W2588675103","https://openalex.org/W2728257130","https://openalex.org/W2766612868","https://openalex.org/W2783320270","https://openalex.org/W2788194436","https://openalex.org/W2793756773","https://openalex.org/W2839900884","https://openalex.org/W2886533716","https://openalex.org/W2889836475","https://openalex.org/W2897256107","https://openalex.org/W2898318153","https://openalex.org/W2904539465","https://openalex.org/W2907236248","https://openalex.org/W2908449057","https://openalex.org/W2912711574","https://openalex.org/W2914899172","https://openalex.org/W2921434519","https://openalex.org/W2924689635","https://openalex.org/W2959169310","https://openalex.org/W2963197901","https://openalex.org/W2963391384","https://openalex.org/W2964210735","https://openalex.org/W2981880399","https://openalex.org/W3005097670","https://openalex.org/W3009195050","https://openalex.org/W3010612350","https://openalex.org/W3015248254","https://openalex.org/W3017217726","https://openalex.org/W3032638893","https://openalex.org/W3035366542","https://openalex.org/W3045016378","https://openalex.org/W3102091066","https://openalex.org/W3103656239","https://openalex.org/W3104735167","https://openalex.org/W3111088413","https://openalex.org/W3111390419","https://openalex.org/W3115360974","https://openalex.org/W3134894590","https://openalex.org/W6629285517","https://openalex.org/W6633219197","https://openalex.org/W6636391385","https://openalex.org/W6740230398","https://openalex.org/W6754600771"],"related_works":["https://openalex.org/W2808001300","https://openalex.org/W1548771250","https://openalex.org/W2376886931","https://openalex.org/W2061466315","https://openalex.org/W2010561419","https://openalex.org/W2374845301","https://openalex.org/W2351448539","https://openalex.org/W1977863481","https://openalex.org/W2384741105","https://openalex.org/W1495178644"],"abstract_inverted_index":{"Machine":[0],"learning":[1,81,189],"based":[2,82,94,137],"network":[3,45,78],"intrusion":[4,16],"system":[5],"(NIDS)":[6],"is":[7,143,148,182],"known":[8],"to":[9,12,18,26,57,96,121,130],"be":[10],"vulnerable":[11],"evasions.":[13],"Attackers":[14],"conceal":[15],"activities":[17],"make":[19],"them":[20],"undetected.":[21],"Researching":[22],"evasion":[23,35,74,163],"techniques":[24],"contributes":[25],"evaluating":[27],"and":[28,113,154,172,180],"increasing":[29],"the":[30,63,72,98,131],"robustness":[31],"of":[32,42,87,101,106,165,198],"NIDS.":[33],"Previous":[34],"approaches":[36],"modify":[37],"feature":[38,99],"values":[39,100],"or":[40],"packets":[41,61,128],"an":[43,162,196],"offline":[44],"trace":[46],"as":[47],"a":[48,90,104,114],"whole.":[49],"However,":[50],"in":[51],"real":[52],"scenarios,":[53],"attackers":[54],"are":[55],"constrained":[56],"manipulate":[58],"only":[59],"outbound":[60,127],"on":[62,126,138,150,169,177,188,202],"fly.":[64],"To":[65],"bridge":[66],"this":[67],"assumption":[68],"gap,":[69],"we":[70],"present":[71],"first":[73],"solution":[75,85],"for":[76],"live":[77,102],"traffic":[79],"against":[80],"NIDSs.":[83],"The":[84,192],"consists":[86],"three":[88,183],"components:":[89],"devised":[91],"Kalman":[92],"filter":[93],"algorithm":[95],"predicate":[97],"flows,":[103],"set":[105],"formally":[107],"constructed":[108],"atomic":[109],"packet":[110],"mutation":[111,124,190],"operators,":[112],"proposed":[115],"Strength":[116],"Enhanced":[117],"Deep":[118],"Q-learning":[119],"(SE-DQN)":[120],"determine":[122],"effective":[123],"operators":[125],"according":[129],"predicted":[132],"features.":[133],"A":[134],"defense":[135,193],"scheme":[136,194],"adaptive":[139],"decision":[140],"threshold":[141],"adjustment":[142],"also":[144],"provided.":[145],"Experimental":[146],"evaluation":[147],"presented":[149],"various":[151],"NIDS":[152],"classifiers":[153,171],"cyber":[155],"attacks.":[156],"Results":[157],"show":[158],"that":[159],"SE-DQN":[160],"achieves":[161],"rate":[164],"at":[166,199],"least":[167,200],"64.2%":[168],"most":[170],"even":[173],"more":[174],"than":[175,186],"90%":[176],"certain":[178],"ones,":[179],"it":[181],"times":[184],"faster":[185],"DQN":[187],"policy.":[191],"shows":[195],"improvement":[197],"76.4%":[201],"recall":[203],"measurement.":[204]},"counts_by_year":[{"year":2025,"cited_by_count":3},{"year":2024,"cited_by_count":10},{"year":2023,"cited_by_count":4},{"year":2022,"cited_by_count":1}],"updated_date":"2026-03-27T05:58:40.876381","created_date":"2025-10-10T00:00:00"}
