Computer Science · Research topic

Open research questions in Network Security and Intrusion Detection

92 unresolved questions extracted from the limitations and future-work sections of 819 Network Security and Intrusion Detection papers in our library. Each links back to the study that raised it.

What the literature leaves open

  • No benchmark evaluation exists comparing the adversarial robustness of different deep learning architectures (VAEs, VAE-GANs, AAEs, Transformers) for NIDS under standardized adversarial attack scenarios, limiting practitioners' ability to select architecturally robust models for deployment.

    Deep Learning-Based Anomaly Detection in Network Intrusion Detection Systems: A Comparative Evaluation · 2026 · DOI
  • Although machine learning-based intrusion detection systems (IDSs) can detect attacks in encrypted OPC UA traffic, the relationship between residual structural observability and attack detectability remains insufficiently understood.

    Residual Observability and Attack Detectability in Encrypted OPC UA Traffic · 2026
  • Furthermore, the future research should investigate lightweight architectures to minimize computational load and support real-time CPS deployment. Additionally, the approach should be validated on a wider range of benchmark datasets and extended to detect broader Implementing and testing the system in real- attack types.

    Next-generation intrusion detection in cyber-physical systems using an ensemble of quantum-inspired and deep neural models · 2026 · DOI
  • The data preparation method, choice of features, explanation ofmodel selection, and scaling method are documented in enoughdetail that the experiment could be replicated. The adversarial machine learning evaluation islimited to the Feature Perturbation Attack discussed in therobustness and adversarial evaluation subsection. This artificial data set, althoughbased on the statistical measurements taken from published Another way in which the framework is incomplete is that ithas not been tested in a real environment.

    Intelligent adaptive authentication for zero-trust microservice architectures using AI-driven behavioral analytics · 2026 · DOI
  • This study presented a hybrid intrusion recognition structure which involves feature reduction using PCA algorithm, class balancing using SMote clustering and XGBoost algorithm, KMeans++ classification detection. Experimental evaluation based on the CICIDS2017 intrusion network for dataset showed that the usage of cluster derived structural information in boosted ensemble classifier can enhance the detection performance on multiple attack categories. The proposed framework was accurate and had low false positive rates when compared with several baseline ML and DL models. The results indicate that the combination of feature-level learning and structural clustering information can help improve the ability of intrusion detection systems to recognize complex attack patterns. The CICIDS2017 dataset has utilized to assess the performance of the hybrid approach rigorously, along with a comparison of the approach with traditional machine learning deep-learning-based approaches. In essence, we can say that these results were highly monolithic, where the proposed hybrid system produced rate of 99.87%, beyond all other an accuracy in all performance metrics, namely approaches Precision, Recall, F1-Score, AUC, and FPR. The proposed hybrid work accomplished an accuracy of 99.87%, precision of 99.5%, recall of 99.3%, F1-score of 99.4%, ROC-AUC of 0.999, and a false positive rate as low as 0.1%, representing its excellent performance across all assessment metrics. 5.1 Future Work Although this study leads to interesting results, there still exist some possibilities for future works and extensions: Real-Time Deployment: Despite being satisfactory at picking up batches of data well, it has not been deployed in an online streaming fashion that makes use of Apache Kafka or Spark Streaming to ensure improvements in latency and response time into live networks. Explainable AI (XAI): Given that XGBoost models are more interpretable when compared to deep- learning models, an additional step the incorporation of explainability frameworks, such as SHAP (Shapley Additive exPlanations) and LIME, should be encouraged so that the security analysts could understand the reasons behind the prediction, hence reinforcing trust and transparency. toward Hybridization with Other Techniques: There remains scope for further continuing the process in the current hybrid method by incorporating deep autoencoders and transformer-based architectures to improve learning for extremely complex patterns.

    Improved Hybrid Model-Based Machine and Deep Learning Approach for Intrusion Detection System · 2026 · DOI
  • Although this review provides a comprehensive overview of the latest developments in IDS/IPS techniques for CAN networks, several limitations should be acknowledged. First, many of the included studies did not report sample sizes or variance measures in a sufficiently consistent manner. As a result, the quantitative component of this review could not be conducted as a formal effect-size meta-analysis. Instead, a sensitivity-based quantitative trend analysis was used to explore reported performance patterns under explicit simplifying assumptions. Second, substantial heterogeneity exists across the reviewed studies in terms of datasets, feature representations, attack scenarios, evaluation metrics, and experimental protocols. This variability limits strict cross-study comparability and requires cautious interpretation of any quantitative summary. Third, some included studies rely on benchmark datasets that are not specific to in- vehicle communication environments. Although these studies were retained for contextual comparison, they should not be interpreted as equivalent to The authors declare that there are no conflicts of interest.

    A Systematic Review and Meta-analysis Survey of IDS/IPS Techniques for CAN and Vehicular Networks · 2026 · DOI
  • Tested on a proxy task only; small evaluation sample; not yet deployed in real large-scale networks Lower detection accuracy compared to centralized IDS, additional computational overhead due to differential privacy and homomorphic encryption, increased communication complexity in large-scale…

    Quantized autonomous edge intrusion detection system for adaptive feature aware internet of medical things networks · 2026 · DOI
  • This paper presented a CSP-optimized DDoS detection framework that integrates bio-inspired feature selection, multi-model classification, and comprehensive visualization components. The framework successfully addresses the unique challenges of CSP environments, including massive traffic volumes, extreme class imbalances, and the “weak signal” problem where attack patterns become statistically diluted within normal traffic flows. Validation results demonstrated exceptional performance across multiple metrics, with all models achieving 99.9% accuracy and 0.999 AUC scores consistently across diverse attack scenarios. The framework maintains practical training times under five seconds for most models, confirming deployment readiness for real-time CSP security operations. A key achievement is the solution to the “weak signal” problem through sophisticated feature engineering that maintains high detection capability even with severe 1:10,000 attack-to-benign traffic ratios characteristic of production CSP environments. The proposed framework extends concepts from related research in IoT connectivity, adapting machine learning approaches from network topology prediction to large-scale security applications. This cross-domain application demonstrates the versatility of ML techniques in addressing diverse networking challenges, from connectivity optimization in IoT to security threat detection in CSP environments. For practical implementation, specific recommendations emerge from our analysis: Naive Bayes is recommended for resource-constrained environments due to its minimal computational requirements (1.2 s training, < 100 MB memory) and rapid inference capabilities (< 0.1 ms per sample).

    DDoS Detection Using Machine Learning for Cloud Service Providers · 2026 · DOI
  • Finally, (RQ5) we analyze open challenges, focusing on the IoT resource-constraint dilemma—where effective defenses like Adversarial Training are too computationally expensive for edge devices —and performance trade-offs.

    Adversarial Attacks on AI-Based Botnet Detection Systems in IoT: Key Threats and Countermeasures · 2026 · DOI
  • In this paper, we came up with an enhanced hybrid RFE IDS approach that improved feature selection in NIDS. It homog- enized RF and XGB models to achieve the intended target. The proposed research considered set theory operations to pinpoint the most representative features from RFE-RF and RFE-XGB models. The chosen features differentiated between benign and network attack traffic effectively. It maintained high intrusion detection accuracy across several machine learning models. This study used six classifiers for the evaluation of the proposed method by using the UNSW-NB15 benchmark. A set of parameters, like accuracy, F1-score, and some selected features, was used to evaluate system performance. The proposed IDS method achieved up to 95.36% accu- racy by using only nine features. To be specific, it helped in reducing 79% of features with minimal accuracy loss. The HREF approach and robust models selected for network traf- fic classification established that the proposed method can work accurately on any unseen network traffic. In real-world scenarios, this model is expected to sustain high intrusion detection performance. Nonetheless, the proposed system also has its own set of limitations. For instance, the binary classification framework does not differentiate between dif- ferent types of attacks. Consequently, it can lessen the granularity of the intrusion detection. Besides, in some situ- ations, the selected feature subset may exclude features that could be informative. The proposed anomaly-based IDS approach opened a number of future research prospects. For instance, testing the methodology on additional datasets and analyzing system 123 performance using parameters such as recall, false negative rate, false alarm rate, and sensitivity. Future research can be done by exploring the alternative machine learning models in order to identify and test the most important features. Acknowledgements This study was funded by Ajman University under Grant No. 2023-IRG-ENIT-26. This work was also partially funded by the Brazilian National Council for Scientific and Technological Devel- opment (CNPq) under Grant No. 306607/2023-9. Author Contributions All authors contributed equally. Funding The authors have not disclosed any funding. Data Availability No datasets were generated or analysed during the current study.

    HREF-IDS: a hybrid recursive feature elimination model for enhanced feature selection in network intrusion detection systems · 2026 · DOI
  • Signature-based detection is highly effective and accurate in detecting attacks that resemble the existing signatures or patterns (Adenusi et al., 2025; Aydin et al., 2025; Jeniffer et al., 2026; Khalid et al., 2025). Nevertheless, some research reports that the signature-based detection fails to detect new or zero-day attacks that cannot be matched with any signatures in the database (Liu et al., 2026; Singha et al., 2025; Xu et al., 2025). This disadvantage can be overcome with a continuous rule update and assessments to make sure that it continues to identify new threats. Based on the results of the preliminary evaluation undertaken in this research and the final evaluation, it can be concluded that the proposed detection algorithm can solve the problem stated in Section 4. Hence, in the future, the automated rules to detect attacks and continuous evaluation mechanisms need to be explored to enhance the capability of the signature-based attack detection while also decreasing the amount of manual effort needed for rule creation and management by the administrator. The adoption of hybrid ARTICLE IN PRESS ARTICLE IN PRESS detection has the potential to mitigate the drawbacks of signature- and AI-based detection, and the exploration of temporal contrastive graph learning, as utilized by Wu et al. (2025), could serve as an enhancement of this proposed work. It is also important to note that most modern web services implement security in the data in transit and not at rest or in use. The TLS encryption does not eliminate the structure of HTTP requests. Instead, it encapsulates HTTP within an encrypted channel, such that the user-agent, referrer, host, and query string remain present at the application layer. App DDoS attacks continue to exploit these components by forging the header to evade detection. The proposed detection strategy remains valid in HTTPS environments, as it operates on the decrypted request header after TLS termination. Therefore, future research should focus on detecting the attack during data in transit, specifically during the encryption phase before it reaches a web server. At this moment, the proposed detection algorithm is designed in a modular mode, and combining all the detection algorithms to detect App DDoS attacks is not feasible. The integration of all algorithms will be conducted in future work, with evaluation using larger, more diverse datasets, unseen attack tools, mutated attack variants, and deployment-based validation through edge gateways, web application firewalls, or reverse proxy environments.

    Detecting application layer DDoS attack using an advanced signature detection algorithm · 2026 · DOI
  • Future work will focus on the integration of AEGIS AI into Security Information and Event Management (SIEM) platforms, extending AEGIS AI to the Internet of Things (IoT) as well as the 5G environment, and testing adversarial robustness against attackers who are aware of the honeypot.

    AEGIS-AI: Autonomous Threat Deception and Detection Using Honeypot Networks · 2026 · DOI
  • 16Indeed, if a paper used CICIDS17 (or CICIDS18) but does not cite (or), there is a high risk that the evaluation is carried out on the “flawed” data of CICIDS17 (or CICIDS18) without even acknowledging potential threat to validity. 17There are other works that discussed issues in CICIDS17 or CICIDS18, such as [65, 88], but they received even less citations than [62, 92], hence we omit them from this analysis as our conclusions would not be affected. 18Note that it would be unfair to question the ecological validity of papers (such as) considering CICIDS17 but which have been published before. 19Publicly observable at: https://openreview.net/forum?id=KYHVBsEHuC We seek to induce a change in the landscape of NIDS research. The assertions stated in this work are rooted in established security principles and may appear well-known to some readers; similarly, some recommendations also echo those made in securityfocused literature. For instance, the seminal work by Sommer and 20We would be delighted if the authors of another submission under review can “convince” a referee (e.g., during a rebuttal) by referencing this work!

    SoK: Reshaping Research on Network Intrusion Detection Systems · 2026 · DOI
  • This study presented an AI-enhanced hybrid intrusion detection system for detecting zero-day attacks in enterprise networks. The proposed architecture improved detection accuracy and demonstrates reduced false positives compared to conventional IDS solutions. Future work will focus on integrating explainable AI techniques, evaluating performance using implementing automated incident response mechanisms. Further learning research will also explore threat to approaches intelligence while preserving data privacy. federated collaborative live enterprise traffic, and support REFERENCES Sommer, R., & Paxson, V. (2010). Outside the closed world: On using machine learning for network intrusion detection. Proceedings of the IEEE Symposium on Security and Privacy, 305– 316. https://doi.org/10.1109/SP.2010.25 Buczak, A. L., & Guven, E. (2016). A survey of data mining and machine learning methods for cybersecurity IEEE Communications Surveys & Tutorials, 18(2), 1153–1176. https://doi.org/10.1109/COMST.2015.2494502 detection. intrusion Kim, G., Lee, S., & Kim, S. (2014). A novel hybrid intrusion detection method integrating anomaly detection with misuse detection. Expert Systems with Applications, 41(4), 1690–1700. https://doi.org/10.1016/j.eswa.2013.08.066 Shone, N., Ngoc, T. N., Phai, V. D., & Shi, Q. (2018). A deep learning approach to network intrusion detection. IEEE Transactions on Emerging Topics in Computational Intelligence, 2(1), 41–50. https://doi.org/10.1109/TETCI.2017.2772792 Chandola, V., Banerjee, A., & Kumar, V. (2009). Anomaly detection: A survey. ACM Computing Surveys, 1–58. https://doi.org/10.1145/1541880.1541882 41(3), Zhang, J., & Zulkernine, M. (2006). Anomaly detection with intrusion network based IRE 1718202 ICONIC RESEARCH AND ENGINEERING JOURNALS 4832 © MAY 2026 | IRE Journals | Volume 9 Issue 11 | ISSN: 2456-8880 DOI: https://doi.org/10.64388/IREV9I11-1718202 unsupervised outlier detection. Proceedings of the on IEEE Communications, 2388–2393.

    Development of an AI-Enhanced Intrusion Detection System for Detecting Zero-Day Attacks in Enterprise Networks · 2026 · DOI
  • The extension of Theorem 2’s graph cov- erage result to federated enterprise environments—wherein the host interaction graph is distributed across organizational boundaries and centralized graph analysis is precluded by data sovereignty requirements—represents an important open problem.

    A Unified Framework for Adversarial Threat Detection and Zero-Day Mitigation in Enterprise Networks · 2026 · DOI
  • Whether an effective attack detection model can be trained from unlabelled data deserves further research. We believe existing log-based methods for training attack detection models are viable. AirTag, for example, has the potential to produce similar or better results in the anomaly detection process. However, such methods require training from a large amount of audit log data to ensure that the model learns common behavioral pat- terns. This makes it difficult to improve attack detec- tion performance based on a small amount of audit data. Therefore, our next work will attempt to exploit these ele- ments. However, such methods require training from a large amount of audit log data to ensure that the model learns common behavioral patterns. This makes it diffi- cult to improve attack detection performance based on a small amount of audit data. Therefore, our future work will attempt to explore these aspects.

    Apmp: APT attack detection in few-shot scenarios based on entity potential relations · 2026 · DOI
  • This research introduces a novel cyber threat detection framework for IIoT networks that integrates dual attention mechanisms with CNN and LSTM networks, optimized using the Grey Wolf Optimizer (GWO) to achieve superior performance. The proposed system demonstrates an overall accuracy of 96.5% when processing IIoT datasets, outperforming conventional machine learning models in terms of accuracy, recall, and F1‑score. By leveraging both spatial feature extraction through CNNs and temporal sequence learning via LSTMs, the model can effectively capture complex patterns in network traffic and device communications. The incorporation of GWO ensures intelligent hyperparameter tuning, optimizing learning rate, dropout rate, and batch size to balance model precision, convergence speed, and generalization. The framework maintains high‑quality input data through robust preprocessing techniques, including noise reduction, 1 3Peer-to-Peer Networking and Applications (2026) 19:92 92 Page 36 of 39 normalization, and handling of missing values, which strengthens the reliability of its predictions. The dual attention mechanism enhances the model’s ability to prioritize critical temporal and spatial information, enabling real‑time detection of anomalies, unauthorized access, and malware activity within IIoT environments. These capabilities are particularly crucial for industrial scenarios where rapid identification of threats can prevent operational downtime and data breaches. Furthermore, the research highlights the importance of adaptive deep learning techniques for IIoT cybersecurity. The GWO‑based hyperparameter optimization not only improves overall accuracy but also enhances the system’s robustness against varying traffic patterns and evolving attack behaviors. This demonstrates the model’s potential to serve as an intelligent automated defense system capable of supporting smart manufacturing infrastructures. Despite its high performance, the study identifies areas for future improvement. Expanding the scope of datasets to include a broader range of industrial environments and emerging attack types will ensure the system performs consistently across sectors. Additionally, developing time‑efficient and lightweight deployment strategies for resource‑constrained IIoT devices will enable wider adoption of real‑time threat detection capabilities. Future implementations can also integrate dynamic adaptation mechanisms to respond to zero‑day attacks and other sophisticated cyber threats, further increasing the resilience of IIoT networks.

    A GWO-optimized dual-attention CNN-LSTM model for robust IIoT intrusion detection · 2026 · DOI
  • SentinelGuard is a hybrid intrusion detection and prevention system designed for protecting computer environments against malware attacks carried out via USB devices and network-based attacks. Through its integration of machine learning and real-time monitoring mechanisms, it offers an intelligent security solution for identifying and detecting malicious activities carried out via removable storage devices and suspicious network traffic patterns, including port scanning and SYN flooding attacks.

    Sentinel Guard: An Hybrid Firewall for USB and Network Intrusion Detection · 2026 · DOI
  • Although Sentinel Guard provides effective hybrid protection, several enhancements can further strengthen the system: 1. Raspberry Pi Integration: Integrating the Raspberry Pi hardware control module with the Raspberry Pi hardware would allow for physical level enforcement for USB and network interfaces. This would enable the hardware level monitoring and controlling of malicious devices connected through the USB and network interfaces. 2.

    Sentinel Guard: An Hybrid Firewall for USB and Network Intrusion Detection · 2026 · DOI
  • Could only detect known attacks; poor scalability; high false negatives; manual tuning required Depended heavily on feature engineering; struggled with high-dimensional data; limited real-time capability High false positive rates; limited adaptability to novel attacks; resource-intensive for IoT/WBAN devices High computational cost; requires large labeled datasets; deployment complexity in resource-constrained environments (IoT/WBAN); explainability challenges Richard et al. Discover Networks (2026) 2:11 Page 6 of 32 models, such as SVMs, Decision Trees, and RFs, which leveraged labeled datasets of normal versus malicious traffic to detect anomalies in real time. This represented a breakthrough compared to static rule systems, as it enabled high-volume classification of traffic and adaptive anomaly detection and prevention. In parallel, clustering methods like k-Means and k-Nearest Neighbor were introduced to uncover hidden patterns of ARP spoofing within campus LANs, providing the first automated mechanisms for identifying insider threats and local man-in-the-middle attacks. A critical limitation identified in traditional protocol-based defenses is their inability to scale in response to emerging trends such as the proliferation of IoT, the adoption of BYOD, the implementation of SDNs, and the increasing integration of WBANs within campus infrastructures. While mechanisms like Dynamic ARP Inspection and DHCP snooping have improved ARP security, their reliance on significant administrative overhead and specialized hardware has constrained deployment in resource-limited academic settings. TCP hardening measures, such as SYN cookies, were effective against basic volumetric floods but fell short against more sophisticated multi-vector DDoS campaigns. These shortcomings highlighted a critical gap; although protocol rules provided baseline resilience, they lacked the intelligence to detect unknown anomalies, adapt to evolving adversarial strategies, or autonomously respond to subtle deviations in network behavior. These challenges become more pronounced in environments shaped by SDN-driven traffic management, IoT device diversity, and WBAN communications. Significant advancement in campus network prevention has been the integration of multiple machine learning algorithms into ensemble learning frameworks, improving detection and prevention accuracy, robustness, and reliability by leveraging the strengths of different models. Recent breakthroughs have increasingly focused on embedding ML intelligence into protocol monitoring and enforcement, transforming static defenses into adaptive and proactive prevention. Supervised approaches, such as RFs and SVMs, facilitated the classification of malicious versus legitimate flows.

    Securing campus networks with intelligence: a review of machine learning techniques for ddos and arp protection · 2026 · DOI
  • Future work will investigate replacing or augmenting the Ran- dom Forest classifier with CNN–LSTM hybrid architectures in order to improve the detection of complex and multi-stage cyber attacks. Finally, future work will focus on extending the protocol- aware detection modules to support IoT-specific communica- tion protocols such as MQTT, CoAP, and Zigbee. Future work will focus on integrating deep learning models, supporting edge-based deployment, and exploring federated learning approaches to further enhance scalability, adaptability, and privacy in large-scale network environments.

    Hybrid Protocol-Based Network Anomaly Detection Using Machine Learning · 2026 · DOI
  • Future research will focus on optimizing the system’s processing infrastructure - especially by leveraging AI inference on GPUs to reduce the computational load on CPUs.

    Enhancing network security based on anomaly detection using deep learning for intelligent IDS/IPS systems · 2026 · DOI
  • This study is limited to intrusion detection in IoT environment using secondary quantitative dataset, future studies may consider the following: • Exploration of Ensemble Techniques: Ensemble techniques that fuse multiple models, such as stacking or boosting, may be employed to enhance detection stability and accuracy.

    Machine learning based approach to intrusion detection in internet of things environments · 2026 · DOI
  • This study presented a hybrid FS for IoMT intrusion detection that addresses the computational bottleneck of wrapper-based optimisation by leveraging DL-accelerated fitness evaluation. The proposed MI + DL-BDA combines mutual information filtering with Binary Dragonfly Algorithm search, augmented by ProxyNet — a lightweight MLP-ECA surrogate that replaces repeated full classifier retraining with frozen-weight inference during metaheuristic search. The two-stage architecture separates the complementary roles of statistical relevance filtering and combinatorial wrapper optimisation, achieving dimensionality reduction and detection performance that neither stage can achieve on its own. Evaluation on CICIoMT2024 demonstrated 65.1% dimensionality reduction (43 → 15 features) while preserving 98.6–99.4% of full-feature detection performance across RF, DNN, and LR classifiers, with Recall @ FPR ≤ 1% = 0.938 and PR-AUC = 0.956 achieved in 502.6 seconds — a 9.2–10.6× speedup relative to conventional WM. IoMT-TrafficData (IP-flow) cross-dataset evaluation confirmed those findings on its own dataset, with reduced dimensionality of 55.6% (27 features to 12) and performance retention of 99.0-99.7% in 234.5 seconds. This result demonstrates that the technique is adaptable across numerous device ecosystems, protocol stacks, and attack classification systems. Flow ARTICLE IN PRESS ARTICLE IN PRESS ACCEPTED MANUSCRIPT ARTICLE IN PRESS ARTICLE IN PRESS Duration, Flow Bytes/s, and PSH Flag Count are high-importance features that converge across both datasets. These results indicate that the system can identify distinct IoMT traffic features, rather than objects specific to individual datasets. The performance-efficiency balance is influenced by 5 components: MI filtering, ProxyNet surrogate, ECA attention, BDA wrapper optimisation, and elite preservation. The two most significant components, according to ablation analysis, are BDA optimization and ECA attention. Assuming that the recommended model's CC accounts for 87% of total latency in ProxyNet training and only 7.3% in BDA search, this shows that the availability of a one-time training phase, rather than per-inference overhead, is the most significant factor in deployment adaptability. Application deployment on computing devices with limited CC has been enabled by minimising memory and inference requirements relative to the full 43-feature space, using the selected 15-feature subset. The design is important for conducting direct validation on medical edge devices with limited resources before deployment, as the current study was tested on server-grade computer hardware. In the future, research will focus on developing federated FS for distributed IoMT environments. The result will allow collaborative model training without requiring the sharing of raw patient data, which is a demand for centralized data aggregation in environments where privacy regulations can be a limitation. When it comes to safety-critical CDSS, where detection decisions need to be auditable, the use of accessible mechanisms, such as attention-based FS and SHAP-based importance analysis, would enhance interpretability and support regulatory compliance. The temporal non-stationarity of IoMT traffic would be addressed by a variant of the data stream FS that handles concept drift. This feature was important because device populations are constantly evolving, and new attack variants are emerging.

    Hybrid feature selection for IoMT based intrusion detection system for integrating mutual information filtering with deep learning based accelerated metaheuristic optimization · 2026 · DOI
  • The paper lacks detailed analysis of which specific attack patterns (by attack class, payload size, temporal characteristics) are missed by the DEL models, contributing to false negatives. Root cause analysis of detection failures and targeted improvements to CNN-LSTM-GRU architectures for missed threat categories is needed.

    Securing Fog-assisted IoT: An Adaptable and Efficient Threat Identification Approach · 2026 · DOI

Most-cited papers in Network Security and Intrusion Detection

Most recent work

Find a gap in your own Network Security and Intrusion Detection sub-topic

This page shows what the Network Security and Intrusion Detection literature already flags as unresolved. To narrow it to your specific question, run the guided finder — it searches the gap library on demand and checks candidates against 250M+ OpenAlex works.

Open the Research Gap Finder →

Related topics in Computer Science

92 open questions have been extracted from the limitations and future-work passages of 819 Network Security and Intrusion Detection papers in our library. Each one below links back to the study that raised it, so you can read the original claim in context.

Tools for your next paper

Compare the categoryHonest roundups of the AI research tools, ours listed alongside the alternatives.

Command palette

Jump anywhere, run any action.