This work demonstrates the use of compartmentalisation of execution timelines into distinct units, i.e., execution phases, and introduces the generation of representations for these phases, i.e., behavioural signatures and behavioural passports, as their way of behavioural fingerprinting.
This work introduces the concept of software passports, intended to act as a signature construct for runtime performance behaviour of reference executions, based on Extra-Functional Behaviour metrics, and is capable of detecting synthetically introduced performance anomalies to the real execution tracing data from a semiconductor photolithography machine.
Uraz Odyurt, Hugo Meyer, A. Pimentel et al.· 0 citations
This paper presents a comprehensive and systematic review of deep learning techniques applied to cyber intrusion detection within IoV systems, conducted in accordance with the PRISMA framework across 83 selected studies published between 2020 and 2025.
Duygu Kayaoğlu, Eyup Emre Ulku, Onder Demir· Journal of Supercomputing· 0 citations
Emerging technologies such as Cloud Computing, 5G, the Internet of Things (IoT), and Edge Computing demand the management of large-scale and highly dynamic network infrastructures. Traditional network configuration does not scale efficiently, whereas Software-Defined Networking (SDN) enables centralized control and simplified management. Despite these benefits, SDN environments still face significant challenges related to security and fine-grained anomaly detection. Several studies have demonstrated the effectiveness of computational intelligence (CI) techniques for anomaly detection in SDN. However, the diversity of network anomalies and CI-based solutions introduces substantial heterogeneity, making model selection and integration challenging. This paper proposes a reference architecture designed to validate, promote, and explain the suitability of different CI techniques for distinct network anomaly scenarios. The proposed architecture adopts a hexagonal microservices design and a unified information model aligned with the application, information, and process layers of the TM Forum Open Digital Architecture (ODA). Validation was performed through a proofof-concept prototype using two datasets and seven machine learning algorithms. The results demonstrate the importance of architectural flexibility, enabling the dynamic integration and replacement of CI models to support adaptive and scalable SDN anomaly detection.
Rivaldo Fernandes, B. Dalmazo, A. Riker et al.· International Conference on...· 0 citations
The approach models inter-device state correlations using a heterogeneous graph structure and partitions behavior patterns through iterative community detection and automated semantic annotation, and represents normal behavior by embedding and clustering of state sequences.
Yifan Lu, Qixiao Lin, Jian Mao et al.· 0 citations
Per-ID behavioral residualization is presented, a CAN-specific representation that extracts fourteen temporal, protocol, and payload features from sliding windows and residualizes them against each arbitration ID's normal baseline, which improves mean F1 in the majority of evaluations.