{"id":"https://openalex.org/W4386520500","doi":"https://doi.org/10.1145/3587716.3587732","title":"Ensemble Two Stage Machine Learning for Network Abnormal Detection","display_name":"Ensemble Two Stage Machine Learning for Network Abnormal Detection","publication_year":2023,"publication_date":"2023-02-17","ids":{"openalex":"https://openalex.org/W4386520500","doi":"https://doi.org/10.1145/3587716.3587732"},"language":"en","primary_location":{"id":"doi:10.1145/3587716.3587732","is_oa":false,"landing_page_url":"http://dx.doi.org/10.1145/3587716.3587732","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2023 15th International Conference on Machine Learning and Computing","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5053812484","display_name":"R. H. Du","orcid":"https://orcid.org/0009-0002-1001-1806"},"institutions":[{"id":"https://openalex.org/I38877650","display_name":"Zhengzhou University","ror":"https://ror.org/04ypx8c21","country_code":"CN","type":"education","lineage":["https://openalex.org/I38877650"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Runze Du","raw_affiliation_strings":["Zhengzhou University, China"],"raw_orcid":"https://orcid.org/0009-0002-1001-1806","affiliations":[{"raw_affiliation_string":"Zhengzhou University, China","institution_ids":["https://openalex.org/I38877650"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101605770","display_name":"Runzhi Li","orcid":"https://orcid.org/0000-0001-7259-9321"},"institutions":[{"id":"https://openalex.org/I38877650","display_name":"Zhengzhou University","ror":"https://ror.org/04ypx8c21","country_code":"CN","type":"education","lineage":["https://openalex.org/I38877650"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Runzhi Li","raw_affiliation_strings":["Zhengzhou University, China"],"raw_orcid":"https://orcid.org/0000-0001-7259-9321","affiliations":[{"raw_affiliation_string":"Zhengzhou University, China","institution_ids":["https://openalex.org/I38877650"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5070853810","display_name":"Zijiao Zhang","orcid":"https://orcid.org/0000-0003-0018-3524"},"institutions":[{"id":"https://openalex.org/I38877650","display_name":"Zhengzhou University","ror":"https://ror.org/04ypx8c21","country_code":"CN","type":"education","lineage":["https://openalex.org/I38877650"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zijiao Zhang","raw_affiliation_strings":["Zhengzhou University, China"],"raw_orcid":"https://orcid.org/0000-0003-0018-3524","affiliations":[{"raw_affiliation_string":"Zhengzhou University, China","institution_ids":["https://openalex.org/I38877650"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5053812484"],"corresponding_institution_ids":["https://openalex.org/I38877650"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.1329148,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"39","issue":null,"first_page":"97","last_page":"102"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9987999796867371,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9909999966621399,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8213413953781128},{"id":"https://openalex.org/keywords/construct","display_name":"Construct (python library)","score":0.6848006844520569},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.654205322265625},{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.6417146921157837},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.6226955056190491},{"id":"https://openalex.org/keywords/anomaly-detection","display_name":"Anomaly detection","score":0.5762783885002136},{"id":"https://openalex.org/keywords/class","display_name":"Class (philosophy)","score":0.518001139163971},{"id":"https://openalex.org/keywords/feature","display_name":"Feature (linguistics)","score":0.5133904218673706},{"id":"https://openalex.org/keywords/network-security","display_name":"Network security","score":0.4682055115699768},{"id":"https://openalex.org/keywords/scale","display_name":"Scale (ratio)","score":0.44160905480384827},{"id":"https://openalex.org/keywords/convolutional-neural-network","display_name":"Convolutional neural network","score":0.4414902925491333},{"id":"https://openalex.org/keywords/feature-extraction","display_name":"Feature extraction","score":0.4162980914115906},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.33917665481567383},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.11644303798675537},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.0704546570777893}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8213413953781128},{"id":"https://openalex.org/C2780801425","wikidata":"https://www.wikidata.org/wiki/Q5164392","display_name":"Construct (python library)","level":2,"score":0.6848006844520569},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.654205322265625},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.6417146921157837},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.6226955056190491},{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.5762783885002136},{"id":"https://openalex.org/C2777212361","wikidata":"https://www.wikidata.org/wiki/Q5127848","display_name":"Class (philosophy)","level":2,"score":0.518001139163971},{"id":"https://openalex.org/C2776401178","wikidata":"https://www.wikidata.org/wiki/Q12050496","display_name":"Feature (linguistics)","level":2,"score":0.5133904218673706},{"id":"https://openalex.org/C182590292","wikidata":"https://www.wikidata.org/wiki/Q989632","display_name":"Network security","level":2,"score":0.4682055115699768},{"id":"https://openalex.org/C2778755073","wikidata":"https://www.wikidata.org/wiki/Q10858537","display_name":"Scale (ratio)","level":2,"score":0.44160905480384827},{"id":"https://openalex.org/C81363708","wikidata":"https://www.wikidata.org/wiki/Q17084460","display_name":"Convolutional neural network","level":2,"score":0.4414902925491333},{"id":"https://openalex.org/C52622490","wikidata":"https://www.wikidata.org/wiki/Q1026626","display_name":"Feature extraction","level":2,"score":0.4162980914115906},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.33917665481567383},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.11644303798675537},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.0704546570777893},{"id":"https://openalex.org/C41895202","wikidata":"https://www.wikidata.org/wiki/Q8162","display_name":"Linguistics","level":1,"score":0.0},{"id":"https://openalex.org/C62520636","wikidata":"https://www.wikidata.org/wiki/Q944","display_name":"Quantum mechanics","level":1,"score":0.0},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3587716.3587732","is_oa":false,"landing_page_url":"http://dx.doi.org/10.1145/3587716.3587732","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2023 15th International Conference on Machine Learning and Computing","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":15,"referenced_works":["https://openalex.org/W2022729754","https://openalex.org/W2099940443","https://openalex.org/W2409097990","https://openalex.org/W2726872669","https://openalex.org/W2772317693","https://openalex.org/W2793241948","https://openalex.org/W2896339784","https://openalex.org/W2899372475","https://openalex.org/W2921453769","https://openalex.org/W2924353071","https://openalex.org/W2969863169","https://openalex.org/W2990225485","https://openalex.org/W2997400351","https://openalex.org/W3011049529","https://openalex.org/W7008685525"],"related_works":["https://openalex.org/W2061466315","https://openalex.org/W2376886931","https://openalex.org/W2010561419","https://openalex.org/W2374845301","https://openalex.org/W2351448539","https://openalex.org/W1977863481","https://openalex.org/W2384741105","https://openalex.org/W3157271777","https://openalex.org/W2377372927","https://openalex.org/W1495178644"],"abstract_inverted_index":{"With":[0],"the":[1,11,16,30,35,61,125,163],"endless":[2],"emergence":[3],"of":[4],"network":[5,26,33,62,77],"security":[6,13],"problems,":[7],"it":[8],"also":[9],"brings":[10],"corresponding":[12],"threats":[14],"to":[15,23,49,75,98,119],"society.":[17],"IDS":[18,37],"is":[19,128],"an":[20,67],"effective":[21],"means":[22],"deal":[24],"with":[25,94],"threats,":[27],"but":[28],"in":[29,149],"modern":[31],"large-scale":[32],"environment,":[34],"traditional":[36],"has":[38],"a":[39,91,110],"high":[40],"false":[41],"positive":[42],"rate.":[43],"Researchers":[44],"apply":[45],"machine":[46,71],"learning":[47,72],"method":[48,73,137],"intrusion":[50],"detection":[51],"and":[52,86,138],"get":[53],"good":[54],"results.":[55],"In":[56,124],"this":[57],"work,":[58],"based":[59],"on":[60,162],"traffic":[63,102,106],"features,":[64],"we":[65,89,114,152],"proposed":[66,136],"ensemble":[68],"two":[69],"stage":[70],"CNN-CatBoost":[74,146],"detect":[76],"attacking":[78,122],"behavior.":[79],"To":[80],"solve":[81],"imbalance":[82],"problem":[83],"between":[84],"normal":[85],"anomaly":[87,105],"traffic,":[88],"construct":[90],"CNN":[92],"model":[93,118],"multi-scale":[95],"convolutional":[96],"adopted":[97],"extract":[99],"relations":[100],"among":[101,135],"features":[103,160],"for":[104,109],"recognition.":[107],"Next":[108],"multi-class":[111],"classification":[112],"problem,":[113],"use":[115],"classic":[116],"CatBoost":[117],"identify":[120],"different":[121],"types.":[123],"experiments,":[126],"datasets":[127],"from":[129],"CICIDS2017.":[130],"We":[131],"deploy":[132],"comparison":[133],"experiments":[134],"other":[139],"methods.":[140],"The":[141],"experimental":[142],"results":[143],"show":[144],"that":[145],"outperforms":[147],"others":[148],"performance.":[150],"Lastly,":[151],"give":[153],"feature":[154],"analysis":[155],"by":[156],"SHAP,":[157],"understand":[158],"how":[159],"influence":[161],"model.":[164]},"counts_by_year":[],"updated_date":"2025-12-22T23:10:17.713674","created_date":"2025-10-10T00:00:00"}
