{"id":"https://openalex.org/W3200723554","doi":"https://doi.org/10.1145/3467470","title":"Meta-Learning to Improve Unsupervised Intrusion Detection in Cyber-Physical Systems","display_name":"Meta-Learning to Improve Unsupervised Intrusion Detection in Cyber-Physical Systems","publication_year":2021,"publication_date":"2021-09-22","ids":{"openalex":"https://openalex.org/W3200723554","doi":"https://doi.org/10.1145/3467470","mag":"3200723554"},"language":"en","primary_location":{"id":"doi:10.1145/3467470","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3467470","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3467470","source":{"id":"https://openalex.org/S2506189754","display_name":"ACM Transactions on Cyber-Physical Systems","issn_l":"2378-962X","issn":["2378-962X","2378-9638"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on Cyber-Physical Systems","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"bronze","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3467470","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5027443752","display_name":"Tommaso Zoppi","orcid":"https://orcid.org/0000-0001-9820-6047"},"institutions":[{"id":"https://openalex.org/I45084792","display_name":"University of Florence","ror":"https://ror.org/04jr1s763","country_code":"IT","type":"education","lineage":["https://openalex.org/I45084792"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Tommaso Zoppi","raw_affiliation_strings":["Dept. of Mathematics and Informatics, University of Florence, Florence - Italy"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Dept. of Mathematics and Informatics, University of Florence, Florence - Italy","institution_ids":["https://openalex.org/I45084792"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5081356359","display_name":"Mohamad Gharib","orcid":"https://orcid.org/0000-0003-2286-2819"},"institutions":[{"id":"https://openalex.org/I45084792","display_name":"University of Florence","ror":"https://ror.org/04jr1s763","country_code":"IT","type":"education","lineage":["https://openalex.org/I45084792"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Mohamad Gharib","raw_affiliation_strings":["Dept. of Mathematics and Informatics, University of Florence, Florence - Italy"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Dept. of Mathematics and Informatics, University of Florence, Florence - Italy","institution_ids":["https://openalex.org/I45084792"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5005797686","display_name":"Muhammad Atif","orcid":"https://orcid.org/0000-0002-3460-7164"},"institutions":[{"id":"https://openalex.org/I45084792","display_name":"University of Florence","ror":"https://ror.org/04jr1s763","country_code":"IT","type":"education","lineage":["https://openalex.org/I45084792"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Muhammad Atif","raw_affiliation_strings":["Dept. of Mathematics and Informatics, University of Florence, Florence - Italy"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Dept. of Mathematics and Informatics, University of Florence, Florence - Italy","institution_ids":["https://openalex.org/I45084792"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5016669256","display_name":"Andrea Bondavalli","orcid":"https://orcid.org/0000-0001-7366-6530"},"institutions":[{"id":"https://openalex.org/I45084792","display_name":"University of Florence","ror":"https://ror.org/04jr1s763","country_code":"IT","type":"education","lineage":["https://openalex.org/I45084792"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Andrea Bondavalli","raw_affiliation_strings":["Dept. of Mathematics and Informatics, University of Florence, Florence - Italy"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Dept. of Mathematics and Informatics, University of Florence, Florence - Italy","institution_ids":["https://openalex.org/I45084792"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":4.0083,"has_fulltext":true,"cited_by_count":41,"citation_normalized_percentile":{"value":0.93918223,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":94,"max":99},"biblio":{"volume":"5","issue":"4","first_page":"1","last_page":"27"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.991599977016449,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7870772480964661},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.7127519845962524},{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.7066676616668701},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6975254416465759},{"id":"https://openalex.org/keywords/unsupervised-learning","display_name":"Unsupervised learning","score":0.5801016092300415},{"id":"https://openalex.org/keywords/meta-learning","display_name":"Meta learning (computer science)","score":0.4492999017238617},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.33052945137023926},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.0850115716457367}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7870772480964661},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.7127519845962524},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.7066676616668701},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6975254416465759},{"id":"https://openalex.org/C8038995","wikidata":"https://www.wikidata.org/wiki/Q1152135","display_name":"Unsupervised learning","level":2,"score":0.5801016092300415},{"id":"https://openalex.org/C2781002164","wikidata":"https://www.wikidata.org/wiki/Q6822311","display_name":"Meta learning (computer science)","level":3,"score":0.4492999017238617},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.33052945137023926},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.0850115716457367},{"id":"https://openalex.org/C201995342","wikidata":"https://www.wikidata.org/wiki/Q682496","display_name":"Systems engineering","level":1,"score":0.0},{"id":"https://openalex.org/C2780451532","wikidata":"https://www.wikidata.org/wiki/Q759676","display_name":"Task (project management)","level":2,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1145/3467470","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3467470","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3467470","source":{"id":"https://openalex.org/S2506189754","display_name":"ACM Transactions on Cyber-Physical Systems","issn_l":"2378-962X","issn":["2378-962X","2378-9638"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on Cyber-Physical Systems","raw_type":"journal-article"},{"id":"pmh:oai:flore.unifi.it:2158/1245850","is_oa":true,"landing_page_url":"http://hdl.handle.net/2158/1245850","pdf_url":"https://flore.unifi.it/bitstream/2158/1245850/1/3467470.pdf","source":{"id":"https://openalex.org/S4306402033","display_name":"Florence Research (University of Florence)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I45084792","host_organization_name":"University of Florence","host_organization_lineage":["https://openalex.org/I45084792"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"info:eu-repo/semantics/article"},{"id":"pmh:oai:iris.unitn.it:11572/390274","is_oa":true,"landing_page_url":"https://hdl.handle.net/11572/390274","pdf_url":null,"source":{"id":"https://openalex.org/S4306401913","display_name":"Institutional Research Information System (Universit\u00e0 degli Studi di Trento)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I193223587","host_organization_name":"University of Trento","host_organization_lineage":["https://openalex.org/I193223587"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"info:eu-repo/semantics/article"}],"best_oa_location":{"id":"doi:10.1145/3467470","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3467470","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3467470","source":{"id":"https://openalex.org/S2506189754","display_name":"ACM Transactions on Cyber-Physical Systems","issn_l":"2378-962X","issn":["2378-962X","2378-9638"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on Cyber-Physical Systems","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G1464101492","display_name":null,"funder_award_id":"FESR 2014-2020","funder_id":"https://openalex.org/F4320335322","funder_display_name":"European Regional Development Fund"},{"id":"https://openalex.org/G2628364946","display_name":null,"funder_award_id":"H2020","funder_id":"https://openalex.org/F4320335322","funder_display_name":"European Regional Development Fund"},{"id":"https://openalex.org/G3795512937","display_name":null,"funder_award_id":"823788","funder_id":"https://openalex.org/F4320332999","funder_display_name":"Horizon 2020 Framework Programme"},{"id":"https://openalex.org/G384288435","display_name":null,"funder_award_id":"POR FESR 2014-2020","funder_id":"https://openalex.org/F4320326084","funder_display_name":"Regione Toscana"},{"id":"https://openalex.org/G5634946813","display_name":null,"funder_award_id":"2014-2020","funder_id":"https://openalex.org/F4320335322","funder_display_name":"European Regional Development Fund"},{"id":"https://openalex.org/G72824567","display_name":null,"funder_award_id":"POR FESR 2014-2020","funder_id":"https://openalex.org/F4320335322","funder_display_name":"European Regional Development Fund"}],"funders":[{"id":"https://openalex.org/F4320321133","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35"},{"id":"https://openalex.org/F4320326084","display_name":"Regione Toscana","ror":null},{"id":"https://openalex.org/F4320332999","display_name":"Horizon 2020 Framework Programme","ror":"https://ror.org/00k4n6c32"},{"id":"https://openalex.org/F4320335322","display_name":"European Regional Development Fund","ror":"https://ror.org/00k4n6c32"}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W3200723554.pdf","grobid_xml":"https://content.openalex.org/works/W3200723554.grobid-xml"},"referenced_works_count":54,"referenced_works":["https://openalex.org/W28412257","https://openalex.org/W46659105","https://openalex.org/W1975415766","https://openalex.org/W1986332411","https://openalex.org/W2026891775","https://openalex.org/W2031163547","https://openalex.org/W2031173026","https://openalex.org/W2065890363","https://openalex.org/W2075183129","https://openalex.org/W2077488147","https://openalex.org/W2091118421","https://openalex.org/W2093717447","https://openalex.org/W2098613164","https://openalex.org/W2112076978","https://openalex.org/W2122646361","https://openalex.org/W2123256336","https://openalex.org/W2134490011","https://openalex.org/W2145071552","https://openalex.org/W2150753219","https://openalex.org/W2282861635","https://openalex.org/W2296509296","https://openalex.org/W2296719434","https://openalex.org/W2337344967","https://openalex.org/W2601474892","https://openalex.org/W2620760558","https://openalex.org/W2770942607","https://openalex.org/W2773982115","https://openalex.org/W2789828921","https://openalex.org/W2790100928","https://openalex.org/W2894771803","https://openalex.org/W2911964244","https://openalex.org/W2912573428","https://openalex.org/W2912744730","https://openalex.org/W2912934387","https://openalex.org/W2913775009","https://openalex.org/W2914392974","https://openalex.org/W2921134108","https://openalex.org/W2924689635","https://openalex.org/W2944552134","https://openalex.org/W2958285686","https://openalex.org/W2958489519","https://openalex.org/W2995589933","https://openalex.org/W2999309192","https://openalex.org/W3010886159","https://openalex.org/W3030391949","https://openalex.org/W3035311645","https://openalex.org/W3153580016","https://openalex.org/W4243100117","https://openalex.org/W4246308772","https://openalex.org/W4254182148","https://openalex.org/W4255421341","https://openalex.org/W4285719527","https://openalex.org/W6758967114","https://openalex.org/W7055120948"],"related_works":["https://openalex.org/W2364419519","https://openalex.org/W2017948608","https://openalex.org/W2360767377","https://openalex.org/W2360951146","https://openalex.org/W2091347716","https://openalex.org/W98577079","https://openalex.org/W3196155444","https://openalex.org/W328659180","https://openalex.org/W4321844043","https://openalex.org/W3210156800"],"abstract_inverted_index":{"Artificial":[0],"Intelligence":[1],"(AI)-":[2],"based":[3],"classifiers":[4],"rely":[5,123,195],"on":[6,38,43,124,196],"Machine":[7],"Learning":[8],"(ML)":[9],"algorithms":[10,30,89,200,239,264],"to":[11,20,58,84,90,134,149,154,172,201,218],"provide":[12],"functionalities":[13],"that":[14,60,73,138,194],"system":[15,40,115],"architects":[16],"are":[17,117,139,227],"often":[18],"willing":[19],"integrate":[21],"into":[22],"critical":[23],"Cyber-Physical":[24],"Systems":[25],"(CPSs)":[26],".":[27],"However,":[28],"such":[29,180],"may":[31,55,106,122,160],"misclassify":[32],"observations,":[33],"with":[34,77,152],"potential":[35,148],"detrimental":[36],"effects":[37],"the":[39,44,50,66,92,102,125,147,162,248,274],"itself":[41],"or":[42],"health":[45],"of":[46,49,87,112,127,132,198,214,252,276],"people":[47],"and":[48,137,167,190,222,240,250,265,268],"environment.":[51],"In":[52],"addition,":[53],"CPSs":[54],"be":[56,173],"subject":[57],"threats":[59],"were":[61,82],"not":[62],"previously":[63],"known,":[64],"motivating":[65],"need":[67],"for":[68,96,142,230,254],"building":[69],"Intrusion":[70],"Detectors":[71],"(IDs)":[72],"can":[74],"effectively":[75],"deal":[76],"zero-day":[78],"attacks.":[79],"Different":[80],"studies":[81],"directed":[83],"compare":[85],"misclassifications":[86,113,136,151,166,280],"various":[88],"identify":[91],"most":[93,103],"suitable":[94,104],"one":[95],"a":[97],"given":[98],"system.":[99],"Unfortunately,":[100],"even":[101],"algorithm":[105],"still":[107],"show":[108],"an":[109],"unsatisfactory":[110],"number":[111],"when":[114,281],"requirements":[116],"strict.":[118],"A":[119],"possible":[120],"solution":[121],"adoption":[126,275],"meta-learners,":[128],"which":[129,226],"build":[130],"ensembles":[131,197],"base-learners":[133,159],"reduce":[135,150],"widely":[140],"used":[141],"supervised":[143],"learning.":[144],"Meta-learners":[145],"have":[146],"respect":[153],"non-meta":[155],"learners:":[156],"however,":[157],"misleading":[158],"let":[161],"meta-learner":[163],"leaning":[164],"towards":[165],"therefore":[168],"their":[169],"behavior":[170],"needs":[171],"carefully":[174],"assessed":[175],"through":[176],"empirical":[177],"evaluation.":[178],"To":[179],"extent,":[181],"in":[182,205,285],"this":[183],"paper":[184],"we":[185,233],"investigate,":[186],"expand,":[187],"empirically":[188],"evaluate,":[189],"discuss":[191],"meta-learning":[192,243,253],"approaches":[193],"unsupervised":[199,238,255],"detect":[202],"(zero-day)":[203,283],"intrusions":[204,284],"CPSs.":[206,231,286],"Our":[207],"experimental":[208],"comparison":[209],"is":[210],"conducted":[211],"by":[212,262],"means":[213],"public":[215],"datasets":[216],"belonging":[217],"network":[219],"intrusion":[220],"detection":[221],"biometric":[223],"authentication":[224],"systems,":[225],"common":[228],"IDSs":[229],"Overall,":[232],"selected":[234],"21":[235],"datasets,":[236],"15":[237],"9":[241],"different":[242],"approaches.":[244],"Results":[245],"allow":[246],"discussing":[247],"applicability":[249],"suitability":[251],"anomaly":[256],"detection,":[257],"comparing":[258],"metric":[259],"scores":[260],"achieved":[261],"base":[263],"meta-learners.":[266],"Analyses":[267],"discussion":[269],"end":[270],"up":[271],"showing":[272],"how":[273],"meta-learners":[277],"significantly":[278],"reduces":[279],"detecting":[282]},"counts_by_year":[{"year":2026,"cited_by_count":4},{"year":2025,"cited_by_count":12},{"year":2024,"cited_by_count":9},{"year":2023,"cited_by_count":9},{"year":2022,"cited_by_count":5},{"year":2021,"cited_by_count":2}],"updated_date":"2026-06-13T07:54:00.901334","created_date":"2025-10-10T00:00:00"}
