{"id":"https://openalex.org/W7162504853","doi":"https://doi.org/10.1145/3779208.3807482","title":"\u201cWhat is the Problem Space?\u201d Defining Host-space Adversarial Perturbations against Network Intrusion Detection Systems","display_name":"\u201cWhat is the Problem Space?\u201d Defining Host-space Adversarial Perturbations against Network Intrusion Detection Systems","publication_year":2026,"publication_date":"2026-06-01","ids":{"openalex":"https://openalex.org/W7162504853","doi":"https://doi.org/10.1145/3779208.3807482"},"language":null,"primary_location":{"id":"doi:10.1145/3779208.3807482","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3779208.3807482","pdf_url":null,"source":null,"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM Asia Conference on Computer and Communications Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["arxiv","crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://doi.org/10.1145/3779208.3807482","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5041516255","display_name":"Miel Verkerken","orcid":"https://orcid.org/0000-0002-1781-900X"},"institutions":[{"id":"https://openalex.org/I32597200","display_name":"Ghent University","ror":"https://ror.org/00cv9y106","country_code":"BE","type":"education","lineage":["https://openalex.org/I32597200"]}],"countries":["BE"],"is_corresponding":false,"raw_author_name":"Miel Verkerken","raw_affiliation_strings":["Ghent University - imec, Ghent, Belgium"],"raw_orcid":"https://orcid.org/0000-0002-1781-900X","affiliations":[{"raw_affiliation_string":"Ghent University - imec, Ghent, Belgium","institution_ids":["https://openalex.org/I32597200"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5137153876","display_name":"Laurens D'hooge","orcid":null},"institutions":[{"id":"https://openalex.org/I32597200","display_name":"Ghent University","ror":"https://ror.org/00cv9y106","country_code":"BE","type":"education","lineage":["https://openalex.org/I32597200"]}],"countries":["BE"],"is_corresponding":false,"raw_author_name":"Laurens D'hooge","raw_affiliation_strings":["Ghent University - imec, Ghent, Belgium"],"raw_orcid":"https://orcid.org/0000-0001-5086-6361","affiliations":[{"raw_affiliation_string":"Ghent University - imec, Ghent, Belgium","institution_ids":["https://openalex.org/I32597200"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5061693660","display_name":"Bruno Volckaert","orcid":"https://orcid.org/0000-0003-0575-5894"},"institutions":[{"id":"https://openalex.org/I32597200","display_name":"Ghent University","ror":"https://ror.org/00cv9y106","country_code":"BE","type":"education","lineage":["https://openalex.org/I32597200"]}],"countries":["BE"],"is_corresponding":false,"raw_author_name":"Bruno Volckaert","raw_affiliation_strings":["Ghent University - imec, Ghent, Belgium"],"raw_orcid":"https://orcid.org/0000-0003-0575-5894","affiliations":[{"raw_affiliation_string":"Ghent University - imec, Ghent, Belgium","institution_ids":["https://openalex.org/I32597200"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5051784384","display_name":"Filip De Turck","orcid":"https://orcid.org/0000-0003-4824-1199"},"institutions":[{"id":"https://openalex.org/I32597200","display_name":"Ghent University","ror":"https://ror.org/00cv9y106","country_code":"BE","type":"education","lineage":["https://openalex.org/I32597200"]}],"countries":["BE"],"is_corresponding":false,"raw_author_name":"Filip De Turck","raw_affiliation_strings":["Ghent University - imec, Ghent, Belgium"],"raw_orcid":"https://orcid.org/0000-0003-4824-1199","affiliations":[{"raw_affiliation_string":"Ghent University - imec, Ghent, Belgium","institution_ids":["https://openalex.org/I32597200"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5084036967","display_name":"Giovanni Apruzzese","orcid":"https://orcid.org/0000-0002-6890-9611"},"institutions":[{"id":"https://openalex.org/I184656255","display_name":"University of Liechtenstein","ror":"https://ror.org/01qjrx392","country_code":"LI","type":"education","lineage":["https://openalex.org/I184656255"]}],"countries":["LI"],"is_corresponding":false,"raw_author_name":"Giovanni Apruzzese","raw_affiliation_strings":["University of Liechtenstein, Vaduz, Liechtenstein and Reykjavik University, Reykjavik, Iceland"],"raw_orcid":"https://orcid.org/0000-0002-6890-9611","affiliations":[{"raw_affiliation_string":"University of Liechtenstein, Vaduz, Liechtenstein and Reykjavik University, Reykjavik, Iceland","institution_ids":["https://openalex.org/I184656255"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.85496299,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1043","last_page":"1059"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.7081000208854675,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.7081000208854675,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.07000000029802322,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10714","display_name":"Software-Defined Networks and 5G","score":0.05869999900460243,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8705000281333923},{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.6118000149726868},{"id":"https://openalex.org/keywords/intrusion-prevention-system","display_name":"Intrusion prevention system","score":0.453900009393692},{"id":"https://openalex.org/keywords/command-and-control","display_name":"Command and control","score":0.4514999985694885},{"id":"https://openalex.org/keywords/control","display_name":"Control (management)","score":0.41130000352859497},{"id":"https://openalex.org/keywords/network-security","display_name":"Network security","score":0.3776000142097473},{"id":"https://openalex.org/keywords/network-packet","display_name":"Network packet","score":0.37279999256134033},{"id":"https://openalex.org/keywords/attack-model","display_name":"Attack model","score":0.35589998960494995},{"id":"https://openalex.org/keywords/string","display_name":"String (physics)","score":0.3467000126838684}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8705000281333923},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7799000144004822},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.6118000149726868},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5001999735832214},{"id":"https://openalex.org/C27061796","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion prevention system","level":3,"score":0.453900009393692},{"id":"https://openalex.org/C506615639","wikidata":"https://www.wikidata.org/wiki/Q21662260","display_name":"Command and control","level":2,"score":0.4514999985694885},{"id":"https://openalex.org/C2775924081","wikidata":"https://www.wikidata.org/wiki/Q55608371","display_name":"Control (management)","level":2,"score":0.41130000352859497},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.40310001373291016},{"id":"https://openalex.org/C182590292","wikidata":"https://www.wikidata.org/wiki/Q989632","display_name":"Network security","level":2,"score":0.3776000142097473},{"id":"https://openalex.org/C158379750","wikidata":"https://www.wikidata.org/wiki/Q214111","display_name":"Network packet","level":2,"score":0.37279999256134033},{"id":"https://openalex.org/C65856478","wikidata":"https://www.wikidata.org/wiki/Q3991682","display_name":"Attack model","level":2,"score":0.35589998960494995},{"id":"https://openalex.org/C157486923","wikidata":"https://www.wikidata.org/wiki/Q1376436","display_name":"String (physics)","level":2,"score":0.3467000126838684},{"id":"https://openalex.org/C22735295","wikidata":"https://www.wikidata.org/wiki/Q317671","display_name":"Botnet","level":3,"score":0.3463999927043915},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.3458999991416931},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.32280001044273376},{"id":"https://openalex.org/C2778403875","wikidata":"https://www.wikidata.org/wiki/Q20312394","display_name":"Adversarial machine learning","level":3,"score":0.3172000050544739},{"id":"https://openalex.org/C2780310539","wikidata":"https://www.wikidata.org/wiki/Q12547192","display_name":"Imperfect","level":2,"score":0.31049999594688416},{"id":"https://openalex.org/C158251709","wikidata":"https://www.wikidata.org/wiki/Q354025","display_name":"Intrusion","level":2,"score":0.2937999963760376},{"id":"https://openalex.org/C18762648","wikidata":"https://www.wikidata.org/wiki/Q42213","display_name":"Work (physics)","level":2,"score":0.2906999886035919},{"id":"https://openalex.org/C114809511","wikidata":"https://www.wikidata.org/wiki/Q1412924","display_name":"Flow network","level":2,"score":0.27959999442100525},{"id":"https://openalex.org/C143095724","wikidata":"https://www.wikidata.org/wiki/Q515895","display_name":"Odds","level":3,"score":0.27639999985694885},{"id":"https://openalex.org/C160191386","wikidata":"https://www.wikidata.org/wiki/Q868299","display_name":"Control flow","level":2,"score":0.2700999975204468},{"id":"https://openalex.org/C2778562939","wikidata":"https://www.wikidata.org/wiki/Q1298791","display_name":"Synchronization (alternating current)","level":3,"score":0.27000001072883606},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.2696000039577484},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.26010000705718994},{"id":"https://openalex.org/C34947359","wikidata":"https://www.wikidata.org/wiki/Q665189","display_name":"Complex network","level":2,"score":0.25690001249313354},{"id":"https://openalex.org/C204679922","wikidata":"https://www.wikidata.org/wiki/Q734252","display_name":"Deep packet inspection","level":3,"score":0.2558000087738037}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1145/3779208.3807482","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3779208.3807482","pdf_url":null,"source":null,"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM Asia Conference on Computer and Communications Security","raw_type":"proceedings-article"},{"id":"pmh:oai:arXiv.org:2605.25822","is_oa":true,"landing_page_url":"https://arxiv.org/abs/2605.25822","pdf_url":"https://arxiv.org/pdf/2605.25822","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"}],"best_oa_location":{"id":"doi:10.1145/3779208.3807482","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3779208.3807482","pdf_url":null,"source":null,"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM Asia Conference on Computer and Communications Security","raw_type":"proceedings-article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions","score":0.5613094568252563}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Network":[0],"Intrusion":[1],"Detection":[2],"Systems":[3],"(NIDS)":[4],"are":[5],"now":[6],"increasingly":[7],"leveraging":[8],"Machine":[9],"Learning":[10],"(ML)":[11],"techniques":[12],"to":[13,46],"detect":[14],"malicious":[15],"network":[16],"activities.":[17],"Numerous":[18],"papers":[19],"have":[20,71],"scrutinized":[21],"the":[22],"security":[23],"of":[24],"ML-based":[25],"NIDS":[26],"(ML-NIDS)":[27],"by":[28,42],"testing":[29],"them":[30],"against":[31],"various":[32],"attacks":[33],"involving":[34],"adversarial":[35],"perturbations.":[36],"The":[37],"findings":[38],"were":[39],"oftentimes":[40],"worrying:":[41],"making":[43],"imperceptible":[44],"changes":[45],"a":[47,61],"given":[48],"input,":[49],"powerful":[50],"ML":[51],"models":[52],"would":[53],"be":[54],"bypassed.":[55],"In":[56],"this":[57],"context,":[58],"we":[59],"took":[60],"step":[62],"back":[63],"and":[64],"wondered:":[65],"where":[66],"(i.e.,":[67],"in":[68],"what":[69],"\u201cspace\u201d)":[70],"these":[72],"perturbations":[73],"been":[74],"applied?":[75]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-05-28T00:00:00"}
