{"id":"https://openalex.org/W3195763278","doi":"https://doi.org/10.1145/3577923.3583639","title":"CloudShield: Real-time Anomaly Detection in the Cloud","display_name":"CloudShield: Real-time Anomaly Detection in the Cloud","publication_year":2023,"publication_date":"2023-04-20","ids":{"openalex":"https://openalex.org/W3195763278","doi":"https://doi.org/10.1145/3577923.3583639","mag":"3195763278"},"language":"en","primary_location":{"id":"doi:10.1145/3577923.3583639","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3577923.3583639","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Thirteenth ACM Conference on Data and Application Security and Privacy","raw_type":"proceedings-article"},"type":"preprint","indexed_in":["arxiv","crossref","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2108.08977","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5052001217","display_name":"Zecheng He","orcid":"https://orcid.org/0000-0003-2639-2826"},"institutions":[{"id":"https://openalex.org/I20089843","display_name":"Princeton University","ror":"https://ror.org/00hx57361","country_code":"US","type":"education","lineage":["https://openalex.org/I20089843"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Zecheng He","raw_affiliation_strings":["Princeton University, Princeton, NJ, USA"],"raw_orcid":"https://orcid.org/0000-0003-2639-2826","affiliations":[{"raw_affiliation_string":"Princeton University, Princeton, NJ, USA","institution_ids":["https://openalex.org/I20089843"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5051022189","display_name":"Guangyuan Hu","orcid":"https://orcid.org/0009-0000-9554-258X"},"institutions":[{"id":"https://openalex.org/I20089843","display_name":"Princeton University","ror":"https://ror.org/00hx57361","country_code":"US","type":"education","lineage":["https://openalex.org/I20089843"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Guangyuan Hu","raw_affiliation_strings":["Princeton University, Princeton, NJ, USA"],"raw_orcid":"https://orcid.org/0009-0000-9554-258X","affiliations":[{"raw_affiliation_string":"Princeton University, Princeton, NJ, USA","institution_ids":["https://openalex.org/I20089843"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5035657440","display_name":"Ruby B. Lee","orcid":"https://orcid.org/0000-0001-9497-0777"},"institutions":[{"id":"https://openalex.org/I20089843","display_name":"Princeton University","ror":"https://ror.org/00hx57361","country_code":"US","type":"education","lineage":["https://openalex.org/I20089843"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ruby B. Lee","raw_affiliation_strings":["Princeton University, Princeton, NJ, USA"],"raw_orcid":"https://orcid.org/0000-0001-9497-0777","affiliations":[{"raw_affiliation_string":"Princeton University, Princeton, NJ, USA","institution_ids":["https://openalex.org/I20089843"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":1,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I20089843"],"apc_list":null,"apc_paid":null,"fwci":1.1265,"has_fulltext":false,"cited_by_count":6,"citation_normalized_percentile":{"value":0.78005911,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":94,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"91","last_page":"102"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12127","display_name":"Software System Performance and Reliability","score":0.9991000294685364,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9980000257492065,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/cloud-computing","display_name":"Cloud computing","score":0.8812026381492615},{"id":"https://openalex.org/keywords/anomaly-detection","display_name":"Anomaly detection","score":0.8478059768676758},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8338844180107117},{"id":"https://openalex.org/keywords/anomaly","display_name":"Anomaly (physics)","score":0.6745173335075378},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.45022010803222656},{"id":"https://openalex.org/keywords/scope","display_name":"Scope (computer science)","score":0.43547219038009644},{"id":"https://openalex.org/keywords/real-time-computing","display_name":"Real-time computing","score":0.4112960696220398},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.3576672077178955},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3507464528083801},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.3399859666824341},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.14567285776138306}],"concepts":[{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.8812026381492615},{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.8478059768676758},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8338844180107117},{"id":"https://openalex.org/C12997251","wikidata":"https://www.wikidata.org/wiki/Q567560","display_name":"Anomaly (physics)","level":2,"score":0.6745173335075378},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.45022010803222656},{"id":"https://openalex.org/C2778012447","wikidata":"https://www.wikidata.org/wiki/Q1034415","display_name":"Scope (computer science)","level":2,"score":0.43547219038009644},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.4112960696220398},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3576672077178955},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3507464528083801},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3399859666824341},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.14567285776138306},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C26873012","wikidata":"https://www.wikidata.org/wiki/Q214781","display_name":"Condensed matter physics","level":1,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1145/3577923.3583639","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3577923.3583639","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Thirteenth ACM Conference on Data and Application Security and Privacy","raw_type":"proceedings-article"},{"id":"pmh:oai:arXiv.org:2108.08977","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2108.08977","pdf_url":"https://arxiv.org/pdf/2108.08977","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"text"},{"id":"doi:10.48550/arxiv.2108.08977","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2108.08977","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2108.08977","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2108.08977","pdf_url":"https://arxiv.org/pdf/2108.08977","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"text"},"sustainable_development_goals":[{"score":0.6399999856948853,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":58,"referenced_works":["https://openalex.org/W58545800","https://openalex.org/W1427174644","https://openalex.org/W1442292319","https://openalex.org/W1488058190","https://openalex.org/W1503814339","https://openalex.org/W1555558540","https://openalex.org/W1934458198","https://openalex.org/W2007388836","https://openalex.org/W2035247360","https://openalex.org/W2036853599","https://openalex.org/W2104691641","https://openalex.org/W2105497548","https://openalex.org/W2111556044","https://openalex.org/W2131202839","https://openalex.org/W2143039774","https://openalex.org/W2144182447","https://openalex.org/W2157331557","https://openalex.org/W2157444450","https://openalex.org/W2166844173","https://openalex.org/W2172060328","https://openalex.org/W2186910770","https://openalex.org/W2296719434","https://openalex.org/W2317519233","https://openalex.org/W2337480911","https://openalex.org/W2344380211","https://openalex.org/W2350778671","https://openalex.org/W2404948481","https://openalex.org/W2495778067","https://openalex.org/W2507765405","https://openalex.org/W2589579018","https://openalex.org/W2614393686","https://openalex.org/W2625408821","https://openalex.org/W2762776925","https://openalex.org/W2766026515","https://openalex.org/W2767094836","https://openalex.org/W2807415350","https://openalex.org/W2868863044","https://openalex.org/W2883613460","https://openalex.org/W2902455138","https://openalex.org/W2932551155","https://openalex.org/W2948833786","https://openalex.org/W2962986039","https://openalex.org/W2963311060","https://openalex.org/W2963341956","https://openalex.org/W2970417003","https://openalex.org/W2972034624","https://openalex.org/W2975816306","https://openalex.org/W2982379618","https://openalex.org/W2988337058","https://openalex.org/W2989885118","https://openalex.org/W3084432478","https://openalex.org/W3090475639","https://openalex.org/W3094636577","https://openalex.org/W3115360974","https://openalex.org/W3134195539","https://openalex.org/W3159715284","https://openalex.org/W4247881240","https://openalex.org/W4254182148"],"related_works":["https://openalex.org/W2806741695","https://openalex.org/W4290647774","https://openalex.org/W3189286258","https://openalex.org/W3207797160","https://openalex.org/W3210364259","https://openalex.org/W4300558037","https://openalex.org/W2667207928","https://openalex.org/W2912112202","https://openalex.org/W4377864969","https://openalex.org/W2972971679"],"abstract_inverted_index":{"In":[0],"cloud":[1,30,40,71,83,136,153],"computing,":[2],"it":[3,26,194],"is":[4,106],"desirable":[5],"if":[6],"suspicious":[7],"activities":[8],"can":[9,146,160],"be":[10],"detected":[11],"by":[12,96,123,199],"automatic":[13],"anomaly":[14,18,65,105],"detection":[15,19,68,95],"systems.":[16],"Although":[17],"has":[20],"been":[21],"investigated":[22],"in":[23,29,173],"the":[24,35,87,98,125,131,162],"past,":[25],"remains":[27],"unsolved":[28],"computing.":[31,72],"Challenges":[32],"are:":[33],"characterizing":[34],"normal":[36,88],"behavior":[37,89],"of":[38,152],"a":[39,60,75,149],"server,":[41],"distinguishing":[42],"between":[43,115],"benign":[44,116,191],"and":[45,49,62,66,90,93,120,170,182,186],"malicious":[46],"anomalies":[47],"(attacks),":[48],"preventing":[50],"alert":[51,110],"fatigue":[52],"due":[53],"to":[54,85,108,148,201],"false":[55,197],"alarms.":[56],"We":[57,129],"propose":[58],"CloudShield,":[59,142],"practical":[61],"generalizable":[63],"real-time":[64,92],"attack":[67],"system":[69],"for":[70],"Cloudshield":[73],"uses":[74],"general,":[76],"pretrained":[77],"deep":[78],"learning":[79],"model":[80,99,144],"with":[81],"different":[82],"workloads,":[84],"predict":[86],"provide":[91],"continuous":[94],"examining":[97,124],"reconstruction":[100,126],"error":[101,127],"distributions.":[102,128],"Once":[103],"an":[104],"detected,":[107],"reduce":[109],"fatigue,":[111],"CloudShield":[112,133,159,179],"automatically":[113],"distinguishes":[114],"programs,":[117],"known":[118,184],"attacks,":[119,122,167,172,185,189],"zero-day":[121,188],"evaluate":[130],"proposed":[132,164],"on":[134],"representative":[135],"benchmarks.":[137],"Our":[138],"evaluation":[139],"shows":[140],"that":[141,158,178],"using":[143],"pretraining,":[145],"apply":[147],"wide":[150],"scope":[151],"workloads.":[154],"Especially,":[155],"we":[156,176],"observe":[157],"detect":[161],"recently":[163],"speculative":[165],"execution":[166],"e.g.,":[168],"Spectre":[169],"Meltdown":[171],"milliseconds.":[174],"Furthermore,":[175],"show":[177],"accurately":[180],"differentiates":[181],"prioritizes":[183],"potential":[187],"from":[190],"programs.":[192],"Thus,":[193],"significantly":[195],"reduces":[196],"alarms":[198],"up":[200],"99.0%.":[202]},"counts_by_year":[{"year":2025,"cited_by_count":4},{"year":2024,"cited_by_count":2}],"updated_date":"2026-06-26T08:34:08.712188","created_date":"2021-08-30T00:00:00"}
