<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">IASC</journal-id>
<journal-id journal-id-type="nlm-ta">IASC</journal-id>
<journal-id journal-id-type="publisher-id">IASC</journal-id>
<journal-title-group>
<journal-title>Intelligent Automation &#x0026; Soft Computing</journal-title>
</journal-title-group>
<issn pub-type="epub">2326-005X</issn>
<issn pub-type="ppub">1079-8587</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">26628</article-id>
<article-id pub-id-type="doi">10.32604/iasc.2022.026628</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>A Novel Anomaly Detection Method in Sensor Based Cyber-Physical Systems</article-title><alt-title alt-title-type="left-running-head">A Novel Anomaly Detection Method in Sensor Based Cyber-Physical Systems</alt-title><alt-title alt-title-type="right-running-head">A Novel Anomaly Detection Method in Sensor Based Cyber-Physical Systems</alt-title>
</title-group>
<contrib-group content-type="authors">
<contrib id="author-1" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Muthulakshmi</surname><given-names>K.</given-names></name>
<xref ref-type="aff" rid="aff-1">1</xref><email>promuthungp@gmail.com</email>
</contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western"><surname>Krishnaraj</surname><given-names>N.</given-names></name>
<xref ref-type="aff" rid="aff-2">2</xref>
</contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western"><surname>Sankar</surname><given-names>R. S. Ravi</given-names></name>
<xref ref-type="aff" rid="aff-3">3</xref>
</contrib>
<contrib id="author-4" contrib-type="author">
<name name-style="western"><surname>Balakumar</surname><given-names>A.</given-names></name>
<xref ref-type="aff" rid="aff-4">4</xref>
</contrib>
<contrib id="author-5" contrib-type="author">
<name name-style="western"><surname>Kanimozhi</surname><given-names>S.</given-names></name>
<xref ref-type="aff" rid="aff-5">5</xref>
</contrib>
<contrib id="author-6" contrib-type="author">
<name name-style="western"><surname>Kiruthika</surname><given-names>B.</given-names></name>
<xref ref-type="aff" rid="aff-6">6</xref>
</contrib>
<aff id="aff-1"><label>1</label><institution>Department of Electronics and Communication Engineering, Dr. NGP Institute of Technology</institution>, <addr-line>Coimbatore, 641048, Tamilnadu</addr-line>, <country>India</country></aff>
<aff id="aff-2"><label>2</label><institution>Department of Networking and Communications, School of Computing, SRM Institute of Science and Technology</institution>, <addr-line>Kattankulathur, 603203, Tamilnadu</addr-line>, <country>India</country></aff>
<aff id="aff-3"><label>3</label><institution>Department of Electrical and Electronics Engineering, Vignan&#x2019;s Institute of Information Technology</institution>, <addr-line>Visakhapatnam, 530049</addr-line>, <country>India</country></aff>
<aff id="aff-4"><label>4</label><institution>Department of Electronics and Communication Engineering, K. RamaKrishnan College of Engineering</institution>, <addr-line>Tiruchirapalli, 621112, Tamilnadu</addr-line>, <country>India</country></aff>
<aff id="aff-5"><label>5</label><institution>Department of Information Technology, M. Kumarasamy College of Engineering</institution>, <addr-line>Karur, 639113, Tamilnadu</addr-line>, <country>India</country></aff>
<aff id="aff-6"><label>6</label><institution>Department of Electronics and Communication Engineering, K. RamaKrishnan College of Technology</institution>, <addr-line>Tiruchirapalli, 621112, Tamilnadu</addr-line>, <country>India</country></aff>
</contrib-group><author-notes><corresp id="cor1"><label>&#x002A;</label>Corresponding Author: K. Muthulakshmi. Email: <email>promuthungp@gmail.com</email></corresp></author-notes>
<pub-date pub-type="epub" date-type="pub" iso-8601-date="2022-05-23"><day>23</day>
<month>05</month>
<year>2022</year></pub-date>
<volume>34</volume>
<issue>3</issue>
<fpage>2083</fpage>
<lpage>2096</lpage>
<history>
<date date-type="received"><day>31</day><month>12</month><year>2021</year></date>
<date date-type="accepted"><day>15</day><month>2</month><year>2022</year></date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2022 Muthulakshmi et al.</copyright-statement>
<copyright-year>2022</copyright-year>
<copyright-holder>Muthulakshmi et al.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_IASC_26628.pdf"></self-uri>
<abstract>
<p>In recent times, Cyber-physical system (CPS) integrates the cyber systems and physical world for performing critical processes that are started from the development in digital electronics. The sensors deployed in CPS are commonly employed for monitoring and controlling processes that are susceptible to anomalies. For identifying and detecting anomalies, an effective anomaly detection system (ADS) is developed. But ADS faces high false alarms and miss detection rate, which led to the degraded performance in CPS applications. This study develops a novel deep learning (DL) approach for anomaly detection in sensor-based CPS using Bidirectional Long Short Term Memory with Red Deer Algorithm (BiLSTM-RDA). The presented BiLSTM-RDA model comprises preprocessing classification, and parameter tuning. Initially, the sensor data undergoes preprocessing to remove the noise present in it. Afterward, the BiLSTM based classification process takes to detect the existence of anomalies in CPS. At last, parameter tuning of the Bi-LSTM model is carried out by the use of RDA for tuning the parameters such as the number of hidden layers, batch size, epoch count, and learning rate. For assessing the experimental outcome of the BiLSTM-RDA technique, a comprehensive experimentation is performed using the data from sensor-based CPS. A detailed comparative analysis takes place to ensure the effective detection performance of the BiLSTM-RDA model and The obtained experimental results verified the superior performance on the applied data over the compared methods with the maximum an average precision of 0.989, recall of 0.984, F-score of 0.985, and accuracy of 0.983.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Cyber physical system</kwd>
<kwd>deep learning</kwd>
<kwd>anomaly detection</kwd>
<kwd>BiLSTM</kwd>
<kwd>red deer algorithm</kwd>
</kwd-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>In recent times, Cyber-Physical Systems (CPS) have been applied extensively in a massive number of real-time applications, especially, in complicated sectors. In every year, the market rate of CPS would be extended to a greater extent and it is expected to reach a remarkable value within a short time interval [<xref ref-type="bibr" rid="ref-1">1</xref>]. Some of the eminent application of CPS are smart grids, transports, aerial system, and so forth. In general, CPS developed would be tedious, assorted, and unified to offer effective benefits. Unfortunately, these properties result in an extensive crisis. As depicted in <xref ref-type="fig" rid="fig-1">Fig. 1</xref>, CPS is composed of 5 units, they are Physical space with physical elements of CPS, such as engine, tank, and wheel. The actuators get the controlling command (implied as A2) from the controlling machines and modify the implemented parameters of physical devices (A1). Sensors determine the current state of a machine (S1) and send it to the controlling device (S2). Followed by, the control systems receive the sensor value (S2) and forward it to control commands and actuators (A2), which applies the above-mentioned control logic. Here, the data transmission among sensing devices and control system are mentioned as stage 0 communication (indicated as C0). The C0 communication traffic is considered as a sensor measurement (S2) and control commands (A2). In line with this, communication among control system and Supervisory control and Data Acquisition (SCADA) is meant to be stage 1 data transmission which is represented as C1. Then, information on C1 is D1. In particular, the newly presented work concentrates on 4 CPS classes namely, Industrial Control Systems (ICS), smart grid, Intrusion Technology System (ITS) as well as aerial systems. The original devices might be heterogeneous in 4 CPS; however, the infrastructure is identical.</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>Architecture of CPS</title></caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="IASC_26628-fig-1.png"/>
</fig>
<p>In order to predict and eliminate the intrusions and unwanted errors in the CPS system, a significant and effective anomaly prediction model has to be projected with the ability of reducing the crisis to a greater extent. Some of them are, state estimation, statistical models were applied for observing the CPS condition. But, these models demand professional experience; else, the knowledge about the basic distribution of normal data has to be known. In addition, Machine Learning (ML) techniques are independent of domain-based knowledge. However, it needs a massive amount of labeled data such as classification-related models. Moreover, it is not able to confine the exclusive features of CPS like spatial-temporal associations. Intrusion detection models have been applied to ensure the integrity of network communication. Physical parameters (noise of engines) were confined to demonstrate the immutable behavior of CPS. Then, program execution semantics are simplified for protecting the control systems. But, as mentioned before, CPS is highly complex and it is prone to attacks like APT attacks and it is impossible to monitor the complete state of CPS (secured multivariate physical value) and it requires professional domain knowledge.</p>
<p>The behavioral-related method is a crucial framework in Intrusion Detection Systems (IDS). These models are categorized as Supervised and Unsupervised techniques. Initially, supervised training labelled data with normal and anomalous behaviors are induced to the model for better learning. Therefore, labelled data of CPS is hard to retrieve and the attained data might not be an actual one. In this point, unsupervised learning is applied as it does not require anomalous data in the training phase. Even though it is better in predicting the abnormalities, massive works that apply unsupervised learning results in high false positives. Here, the Bi-directional Long Short Term Memory (Bi-LSTM) has been proposed for predicting the data sequence and perform the abnormality detection. Mostly, cyber-attacks exist in a time of correlating time-series data which offers the data over time is applied to predict the abnormality. Bi-LSTM is highly beneficial to learn sequences with pattern of unknown length. Also, the stacked recurrent hidden layers in the neural network (NN) is to confine the structure of a time series. Thus, an alternative is to apply Recurrent Neural Networks (RNN) as developed. In [<xref ref-type="bibr" rid="ref-2">2</xref>], researchers have utilized RNN to develop various realistic data sequence. Anomalies were predicted on the basis of the probability error of the previous threshold which results in higher false positives. Followed by, Deep Learning-relied anomaly detection (DLAD) models were presented for anomalous prediction in CPS. The recent works have found various Neural Network structures (ConvLSTM) for limiting the errors in diverse CPS systems.</p>
<p>This paper introduces an effective DL model for anomaly detection in sensor-based CPS using Bidirectional Long Short Term Memory with Red Deer Algorithm (BiLSTM-RDA). The presented BiLSTM-RDA model operates on three major stages, namely preprocessing, classification, and parameter tuning. At the initial stage, the sensor&#x2019;s data is preprocessed to discard the noise that exists in it. Afterward, the BiLSTM based classification process takes to detect the existence of anomalies in CPS. Finally, parameter tuning of the Bi-LSTM model is carried out by the use of RDA for tuning the parameters such as number of hidden layers, batch size, epoch count, and learning rate. The application of RDA helps to effectively choose the hyper-parameters of Bi-LSTM, and thereby improves the classification results. For assessing the experimental outcome of the BiLSTM-RDA model, a comprehensive set of simulations takes place using the data from sensor-based CPS.</p>
<p>The rest of the sections in the paper are organized as follows. Section 2 briefs the related works and section 3 introduces the presented model. Followed by, Section 4 performs the experimentation and Section 5 concludes the paper.</p>
</sec>
<sec id="s2">
<label>2</label>
<title>Literature Review</title>
<p>Anomaly detection in the CPS model results in various challenging issues. Consequently, different methods have been introduced on anomaly prediction. The formerly attained outcomes have concentrated on detectors rather than the optimal configuration of the previous detector. Followed by, numerous detectors were proposed on ML such as the NN approach. Goh et al. [<xref ref-type="bibr" rid="ref-3">3</xref>] established the unsupervised framework for anomalous detection in CPS relied on RNN as well as the cumulative sum approach. Krishnamurthy et al. [<xref ref-type="bibr" rid="ref-4">4</xref>] exploited another technique named as Bayesian networks. It is mainly applied for learning causal relations as well as temporal correlations in the CPS model for unlabeled data with the help of Bayesian networks. Then, it is applied for predicting the abnormalities and specify the major reasons. Jones et al. [<xref ref-type="bibr" rid="ref-5">5</xref>] presented a formal method relied on anomaly detection in CPS. Here, a model-free, unsupervised learning strategy which develops a signal temporal logic (STL) from the data collected in general applications. Next, anomalies are predicted using the flagging system trajectories which do not meet the applied equation. Chibani et al. [<xref ref-type="bibr" rid="ref-6">6</xref>] examined the issue of developing fault identification filtering technique in fuzzy system, s in fuzzy systems that considers the errors and interruptions in discrete-time polynomial fuzzy system. Additionally, a diagnostic observer relied system for fault prediction of fuzzy system that optimize the ineffective scenario and fault sensitivity [<xref ref-type="bibr" rid="ref-7">7</xref>]. Identification of anomalies is assumed in the content of security attacks where it predicts the CPS attack. For instance, Urbina et al. [<xref ref-type="bibr" rid="ref-8">8</xref>] investigate the physics based prediction of stealthy attacks over ICS. Followed by, a novel metric has been predicted to measure the effect and show that attacks are predicted with an appropriate configuration. Unlike the other model, Kleinmann et al. [<xref ref-type="bibr" rid="ref-9">9</xref>] considered the attacks over ICS relied on cyber anomalies. On the other hand, anomaly detection also predicts the faults and disturbances in traffic networks. Lu et al. [<xref ref-type="bibr" rid="ref-10">10</xref>] examined the previous issues of anomaly prediction in traffic sensors. According to the data level applied, the prediction is classified into 3 phases namely, Macroscopic, Mesoscopic, and Microscopic. Moreover, it reviews data correction models and offers real-time assistance for anomalous prediction in traffic systems.</p>
<p>Zygouras et al. [<xref ref-type="bibr" rid="ref-11">11</xref>] projected 3 approaches that depend upon Pearson correlation, cross-correlation, as well as multivariate Autoregressive Integrated Moving Average models (ARIMA) for predicting the faulty traffic measurement. The function of 3 modules was defined and depicted that, they are complementary to one another. Furthermore, crowd-sourcing has been applied to overcome the unwanted measurements which occur because of defective sensing devices and abnormal traffic. Lastly, Robinson [<xref ref-type="bibr" rid="ref-12">12</xref>] provided an association among adjacent sensors which predicts the faulty loop detectors. Regardless, no works have considered the performance of the controller while developing the anomaly detection techniques, and it does not carry out the application ware optimization technique for the enhancement of the prediction process. Though several works have been available in the literature, only few works have concentrated on CPS environment. In addition, most of the works have not focused on parameter tuning process, which plays an important role in improved detection results.</p>
</sec>
<sec id="s3">
<label>3</label>
<title>The Proposed Bi-LSTM-RDA Model</title>
<p>The working process of the Bi-LSTM-RDA model is exhibited in <xref ref-type="fig" rid="fig-2">Fig. 2</xref>. As depicted, it involves initial preprocessing in two stages namely format conversion and normalization. Next to that, the classification process takes place by the Bi-LSTM model, where the parameters are tuned by the RDA. These processes are neatly discussed in the subsequent sections.</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>Block diagram of Bi-LSTM-RDA model</title></caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="IASC_26628-fig-2.png"/>
</fig>
<sec id="s3_1">
<label>3.1</label>
<title>Preprocessing</title>
<p>Generally, the selection of appropriate data preprocessing technique is important for improving the accuracy of the detection process. Certainly, as the data created in real time might contain problems like variations in format or order of magnitudes, they need to be preprocessed prior to perform detection operation [<xref ref-type="bibr" rid="ref-13">13</xref>]. In this study, data preprocessing of sensor based CPS data takes place in two ways namely format conversion and data normalization.</p>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Format Conversion</title>
<p>Since the data for anomaly recognition is commonly gathered from the network, every network link record comprises many attribute characteristics. Along with the fundamental numeral data type, the features include data in a nominal type. But several classification models can handle only numeric data, it is needed to transform the nominal type data. Here, the probabilistic mass function (PMF) process is employed for the conversion of nominal to numerical data, as the numeric data lies in the interval of [0, 1].</p>
</sec>
<sec id="s3_3">
<label>3.3</label>
<title>Normalization Process</title>
<p>Data normalization of the numerical kind is important in any dataset. At the same time, for every individual record in the data, the range of values may vary as the values of the features are distinct under every aspect. The normalization tasks make the saved feature attributes into related values, thereby enhances the convergence rate and classification accuracy. Two commonly available normalization approaches are the Min-Max and Z-score normalization methods. The min-max model is employed in this study, which brings the actual data comes into the range of [0, 1], using <xref ref-type="disp-formula" rid="eqn-1">Eq. (1)</xref>:<disp-formula id="eqn-1"><label>(1)</label>
<mml:math id="mml-eqn-1" display="block"><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>s</mml:mi><mml:mi>c</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi><mml:mi>e</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mrow><mml:mfrac><mml:mrow><mml:mi>x</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mfrac></mml:mrow><mml:mspace width="thickmathspace" /></mml:mstyle></mml:math>
</disp-formula>where <italic>x</italic> denotes a recent value, <italic>x</italic><sub><italic>min</italic></sub> and <italic>x</italic><sub><italic>max</italic></sub> are the minimal and maximum value of the attributes and <italic>x</italic><sub><italic>scale</italic></sub> represents the measure next to the attribute matching process.</p>
</sec>
<sec id="s3_4">
<label>3.4</label>
<title>Bi-LSTM Model</title>
<p>The central premises of LSTM is to handle the elongated term dependency which is not capable to develop a diminishing gradient problem as the LSTM makes use of a memory cell state for data transmission. A cell state is suitable for computing the data which is not used for a longer duration. Hence, an LSTM is comprised of 3 gates such as, Forget, Update as well as Reset gates. Additionally, some of the major units of LSTM are given below.<list list-type="bullet"><list-item>
<p><bold>Constant error carousel (CEC):</bold> A crucial element with repeated connections along with unit weight. Then, recurrent links indicate a feedback loop and a time step 1. The CEC&#x2019;s activation is an inner state that is operated as a memory for example data.</p></list-item><list-item>
<p><bold>Input Gate:</bold> A multiplicative unit that defends a data saved in CEC from an irregular input.</p></list-item><list-item>
<p><bold>Output Gate:</bold> A multiplicative unit that defends an alternative unit from interruption by the content saved in CEC.</p></list-item></list></p>
<p>Here, the input and output gate handles the access to CEC control. In the training phase, the input gate is recognized and enables new data inside the CEC. If the input gate is 0, then the data is not connected. Likewise, the output gate is examined and allows the data to be received from CEC. Additionally, if the gates are closed, then the data is stuck into the memory cell. It then enables the error signals to flow numerous times without the consideration of diminishing gradients. The LSTM surpasses the RNN while learning prolonged dependency. It is an insignificant data sequence. The LSTM state is unorganized if the input stream is detached physically and modified into appropriate sequences. Especially, LSTM learns to reset the memory cell as the sequence is completed and gets a new sequence. These problems are resolved by applying LSTM with forget gates. The structure of the LSTM unit with forget gates is described in the following:</p><list list-type="bullet"><list-item>
<p><bold>Input:</bold> The LSTM unit applies the current input vector implied as xt and indicates the time step as ht&#x2212;1. Therefore, weighted inputs are consolidated and induced by tanh activation that is represented as zt.</p></list-item><list-item>
<p><bold>Input gate:</bold> It learns the x<sub>t</sub> and ht&#x2212;1, computes the weighted sum, and uses sigmoid activation. Finally, the result is improved with zt, to offer the input flow of a memory cell.</p></list-item><list-item>
<p><bold>Forget gate:</bold> It is operated by an LSTM unit which resets memory data only when it is irregular and noisy. This happens when the system invokes to compute a new data series. A forget gate reads x<sub>t</sub> and h<sub>t&#x2212;1</sub> and uses a sigmoid activation for weighted inputs. Finally, the results f<sub>t</sub> are improved under the application of a cell state previously s<sub>t&#x2212;1</sub> which activates the gate to forget the memory data that is unnecessary.</p></list-item><list-item>
<p><bold>Memory cell:</bold> It is limited to CEC as well as recurrent edge and unit weight. A recent cell state s<sub>t</sub> is determined to forget the unwanted data from the former time step and confirm the related data from recent input.</p></list-item><list-item>
<p><bold>Output gate:</bold> It utilizes a weighted sum of x<sub>t</sub> and h<sub>t&#x2212;1</sub> and applies a sigmoid activation and handles the data flow from the LSTM unit.</p></list-item><list-item>
<p><bold>Output:</bold> The simulation outcome of LSTM unit h<sub>t</sub>, is estimated by changing a cell state s<sub>t</sub> by a tanh and maximize the output gate, o<sub>t</sub>. The performance of the LSTM unit is depicted as provided below:</p></list-item></list>
<p><disp-formula id="eqn-2"><label>(2)</label>
<mml:math id="mml-eqn-2" display="block"><mml:msub><mml:mi>z</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mi>tanh</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msup><mml:mi>W</mml:mi><mml:mi>z</mml:mi></mml:msup><mml:msub><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msup><mml:mi>R</mml:mi><mml:mi>z</mml:mi></mml:msup><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msup><mml:mi>b</mml:mi><mml:mi>z</mml:mi></mml:msup></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>p</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math>
</disp-formula></p>
<p><disp-formula id="eqn-3"><label>(3)</label>
<mml:math id="mml-eqn-3" display="block"><mml:msub><mml:mi>i</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x03C3;</mml:mi></mml:mrow></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msup><mml:mi>W</mml:mi><mml:mi>i</mml:mi></mml:msup><mml:msub><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msup><mml:mi>R</mml:mi><mml:mi>i</mml:mi></mml:msup><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msup><mml:mi>b</mml:mi><mml:mi>i</mml:mi></mml:msup></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>p</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi><mml:mi>g</mml:mi><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>e</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math>
</disp-formula></p>
<p><disp-formula id="eqn-4"><label>(4)</label>
<mml:math id="mml-eqn-4" display="block"><mml:msub><mml:mi>f</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x03C3;</mml:mi></mml:mrow></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msup><mml:mi>W</mml:mi><mml:mi>f</mml:mi></mml:msup><mml:msub><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msup><mml:mi>R</mml:mi><mml:mi>f</mml:mi></mml:msup><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msup><mml:mi>b</mml:mi><mml:mi>f</mml:mi></mml:msup></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi>f</mml:mi><mml:mi>o</mml:mi><mml:mi>r</mml:mi><mml:mi>g</mml:mi><mml:mi>e</mml:mi><mml:mi>t</mml:mi><mml:mi>g</mml:mi><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>e</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math>
</disp-formula></p>
<p><disp-formula id="eqn-5"><label>(5)</label>
<mml:math id="mml-eqn-5" display="block"><mml:msub><mml:mi>o</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x03C3;</mml:mi></mml:mrow></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msup><mml:mi>W</mml:mi><mml:mi>o</mml:mi></mml:msup><mml:msub><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msup><mml:mi>R</mml:mi><mml:mi>o</mml:mi></mml:msup><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msup><mml:mi>b</mml:mi><mml:mi>o</mml:mi></mml:msup></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi><mml:mi>p</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi><mml:mi>g</mml:mi><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>e</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math>
</disp-formula></p>
<p><disp-formula id="eqn-6"><label>(6)</label>
<mml:math id="mml-eqn-6" display="block"><mml:msub><mml:mi>s</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>z</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>&#x2299;</mml:mo><mml:msub><mml:mi>i</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>&#x2299;</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi>c</mml:mi><mml:mi>e</mml:mi><mml:mi>l</mml:mi><mml:mi>l</mml:mi><mml:mi>s</mml:mi><mml:mi>t</mml:mi><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>e</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math>
</disp-formula></p>
<p><disp-formula id="eqn-7"><label>(7)</label>
<mml:math id="mml-eqn-7" display="block"><mml:msub><mml:mi>h</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mi mathvariant="normal">t</mml:mi><mml:mi mathvariant="normal">a</mml:mi><mml:mi mathvariant="normal">n</mml:mi><mml:mi mathvariant="normal">h</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msub><mml:mi>s</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2299;</mml:mo><mml:msub><mml:mi>o</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi><mml:mi>p</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math>
</disp-formula></p>
<p>Besides, the Bi-LSTM is an improved model of LSTM in which 2 LSTM methodologies were applied for the input data. Previously, an LSTM is used for the input sequence. Then, the inverse form of the forward layer has been provided to the LSTM approach. Under the application of LSTM, the maximized learning of long term dependency enhances the model&#x2019;s performance [<xref ref-type="bibr" rid="ref-14">14</xref>]. The variations among LSTM and Bi-LSTM methods are depicted in <xref ref-type="fig" rid="fig-3">Fig. 3</xref>.</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>Difference between LSTM and Bi-LSTM models</title></caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="IASC_26628-fig-3.png"/>
</fig>
</sec>
<sec id="s3_5">
<label>3.5</label>
<title>Parameter Tuning of Bi-LSTM Model</title>
<p>Hyperparameter tuning of the Bi-LSTM model plays a vital part and greatly influences the anomaly detection performance. Therefore, the hyperparameters of Bi-LSTM are tuned by RDA for raising the effective performance. RDA depends upon the mating nature of Scottish red deer during the time of breading. Alike to several metaheuristic algorithms, the RDA begins with an arbitrary popular and some of the optimal RDs are chosen as male RDs (MRD) whereas the remaining RDs are termed as hinds [<xref ref-type="bibr" rid="ref-15">15</xref>]. Basically, all of the MRDs will roar and they are split into two groups (commander and stage) based on the roaring strength. Then, the commander and stage of every harem fought with one another to get a harem. In addition, the harem is generally organized by commanders. The hind count in the harem is proportional to the roaring capability and fighting nature of commanders. As a result, the commander undergoes mating with several hinds in a harem. It is noted that the stage undergoes mating with the closer hind with no consideration of the boundary of the harem.</p>
<p>The general intention of the optimization process is the identification of near-optimum or globalized solution with respect to the parameters of the issue. Here, RD represents a possible solution X in the search area. The dimensions of the solution X are represented as <italic>N</italic><sub><italic>var</italic></sub>. For a &#x201C;<italic>N</italic><sub><italic>var</italic></sub> dimension optimization issue, an RD is a 1&#x2009;&#x00D7;&#x2009;<italic>N</italic><sub><italic>var</italic></sub> array, which can be represented as follows.<disp-formula id="eqn-8"><label>(8)</label>
<mml:math id="mml-eqn-8" display="block"><mml:mi>R</mml:mi><mml:mi>e</mml:mi><mml:mi>d</mml:mi><mml:mi>D</mml:mi><mml:mi>e</mml:mi><mml:mi>e</mml:mi><mml:mi>r</mml:mi><mml:mo>=</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mrow><mml:mi>X</mml:mi><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>X</mml:mi><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>X</mml:mi><mml:mn>3</mml:mn><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>X</mml:mi><mml:mrow><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>v</mml:mi><mml:mi>a</mml:mi><mml:mi>r</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">]</mml:mo><mml:mo>.</mml:mo></mml:math>
</disp-formula></p>
<p>Besides, the function value can be determined for every RD, as given below.<disp-formula id="eqn-9"><label>(9)</label>
<mml:math id="mml-eqn-9" display="block"><mml:mi>V</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi><mml:mi>u</mml:mi><mml:mi>e</mml:mi><mml:mo>=</mml:mo><mml:mi>f</mml:mi><mml:mspace width="thickmathspace" /><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi>R</mml:mi><mml:mi>e</mml:mi><mml:mi>d</mml:mi><mml:mi>D</mml:mi><mml:mi>e</mml:mi><mml:mi>e</mml:mi><mml:mi>r</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>f</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi>X</mml:mi><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>X</mml:mi><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>X</mml:mi><mml:mn>3</mml:mn><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>X</mml:mi><mml:mrow><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>v</mml:mi><mml:mi>a</mml:mi><mml:mi>r</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math>
</disp-formula></p>
<p>At the beginning point, a set of initial population Npop is generated. Then, the optimal RD is chosen as Nmale and the remaining are Nhind (Nhind &#x003D; <italic>Npop</italic>&#x2009;&#x2212;Nmale). It is given that the Nmale count represents the elitist criteria of the RDA. Alternatively, the Nmale count controls the intensification features whereas the Nhind assumes the diversification stage of RDA. Next, the MRD will try to raise the grace through roaring. At the same time, this process might be success or failure. It should be noted that MRDs are the optimal solution. The nearby RDs of the MRD is determined and when the objective function of nearby RD is better than the MRD, it gets replaced. The RDA allows each MRD to update its location using the following <xref ref-type="disp-formula" rid="eqn-3">Eq. (3)</xref>:<disp-formula id="eqn-10"><label>(10)</label>
<mml:math id="mml-eqn-10" display="block"><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mi>n</mml:mi><mml:mi>e</mml:mi><mml:mi>w</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:mrow><mml:mtable rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd columnalign="left"><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mn>1</mml:mn><mml:mi>d</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi>U</mml:mi><mml:mi>B</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>L</mml:mi><mml:mi>B</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mi>L</mml:mi><mml:mi>B</mml:mi></mml:mrow></mml:mtd><mml:mtd columnalign="left"><mml:mrow><mml:mi>i</mml:mi><mml:mi>f</mml:mi><mml:msub><mml:mi>a</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo>&#x2265;</mml:mo><mml:mn>0.5</mml:mn></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd columnalign="left"><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mi>o</mml:mi><mml:mn>1</mml:mn><mml:mi>d</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi>U</mml:mi><mml:mi>B</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>L</mml:mi><mml:mi>B</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mi>L</mml:mi><mml:mi>B</mml:mi></mml:mrow></mml:mtd><mml:mtd columnalign="left"><mml:mrow><mml:mi>i</mml:mi><mml:mi>f</mml:mi><mml:msub><mml:mi>a</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo>&#x003C;</mml:mo><mml:mn>0.5</mml:mn></mml:mrow></mml:mtd></mml:mtr></mml:mtable></mml:mrow><mml:mo>}</mml:mo></mml:mrow></mml:math>
</disp-formula></p>
<p>For generating the possible nearby solution of males, the upper and lower bounds restricts the searching area. Naturally, the MRDs may vary in nature where some RDs are strong, fascinating, and effectively expand the territory compared to other RDs. The commander male count is defined as follows.<disp-formula id="eqn-11"><label>(11)</label>
<mml:math id="mml-eqn-11" display="block"><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>C</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>n</mml:mi><mml:mi>d</mml:mi><mml:mrow><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>&#x03B3;</mml:mi><mml:mo>.</mml:mo><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi><mml:mi>e</mml:mi></mml:mrow></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:mrow></mml:math>
</disp-formula>where <italic>N</italic><sub><italic>Com</italic></sub> denotes the male count and <italic>&#x03B3;</italic> is defined as the initial value of RDA, which lies in the interval of [10, 1]. Besides, the stage count <italic>N</italic><sub><italic>stag</italic></sub> is determined as:<disp-formula id="eqn-12"><label>(12)</label>
<mml:math id="mml-eqn-12" display="block"><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>s</mml:mi><mml:mi>t</mml:mi><mml:mi>a</mml:mi><mml:mi>g</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi><mml:mi>e</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>C</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi></mml:mrow></mml:msub></mml:math>
</disp-formula></p>
<p>Then, every commander fight with the stags in a random way. With respect to the solution space, the commander and stage approach to one another. Also, two novel solutions are obtained and replaced with the commander with the better one. The fighting process can be formulated as follows.</p>
<p><disp-formula id="eqn-13"><label>(13)</label>
<mml:math id="mml-eqn-13" display="block"><mml:mi>N</mml:mi><mml:mi>e</mml:mi><mml:mi>w</mml:mi><mml:mn>1</mml:mn><mml:mo>=</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mrow><mml:mfrac><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi>C</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi><mml:mo>+</mml:mo><mml:mi>S</mml:mi><mml:mi>t</mml:mi><mml:mi>a</mml:mi><mml:mi>g</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:mfrac></mml:mrow><mml:mo>+</mml:mo><mml:msub><mml:mi>b</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi>U</mml:mi><mml:mi>B</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>L</mml:mi><mml:mi>B</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>b</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mi>L</mml:mi><mml:mi>B</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mstyle></mml:math>
</disp-formula></p>
<p><disp-formula id="eqn-14"><label>(14)</label>
<mml:math id="mml-eqn-14" display="block"><mml:mi>N</mml:mi><mml:mi>e</mml:mi><mml:mi>w</mml:mi><mml:mn>2</mml:mn><mml:mo>=</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mrow><mml:mfrac><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi>C</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi><mml:mo>+</mml:mo><mml:mi>S</mml:mi><mml:mi>t</mml:mi><mml:mi>a</mml:mi><mml:mi>g</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:mfrac></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>b</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi>U</mml:mi><mml:mi>B</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>L</mml:mi><mml:mi>B</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>b</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mi>L</mml:mi><mml:mi>B</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mstyle></mml:math>
</disp-formula>where New1 and New2 are newly created solutions in the fight task.</p>
<p>Afterward, the harems are formed, which is a swarm of hinds under the control of the male commander. The harem size is solely based on the strength of the male commander. For forming a harem, the hinds are divided between the commanders, as given below.<disp-formula id="eqn-15"><label>(15)</label>
<mml:math id="mml-eqn-15" display="block"><mml:msub><mml:mi>y</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mi mathvariant="normal">m</mml:mi><mml:mi mathvariant="normal">a</mml:mi><mml:mi mathvariant="normal">x</mml:mi><mml:mspace width="thickmathspace" /></mml:mrow><mml:mrow><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:mrow></mml:math>
</disp-formula>where <italic>v</italic><sub><italic>n</italic></sub> denotes the strength of the nth commander and <italic>y</italic><sub><italic>n</italic></sub> is its normalized value. For determining the normalization strength of the commander, the following equation is used.<disp-formula id="eqn-16"><label>(16)</label>
<mml:math id="mml-eqn-16" display="block"><mml:msub><mml:mi>P</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mrow><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mrow><mml:mfrac><mml:mrow><mml:msub><mml:mi>V</mml:mi><mml:mi>n</mml:mi></mml:msub></mml:mrow><mml:mrow><mml:msubsup><mml:mrow><mml:mo movablelimits="false">&#x2211;</mml:mo></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="normal">i</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>C</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:msubsup><mml:mo>&#x2061;</mml:mo><mml:msub><mml:mi>V</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:mfrac></mml:mrow></mml:mstyle></mml:mrow><mml:mo>|</mml:mo></mml:mrow></mml:math>
</disp-formula></p>
<p>Alternatively, the normalized strength of the male commander is part of the hind, which needs to be carried out by the male. Next, the hind count of the harem is defined below.<disp-formula id="eqn-17"><label>(17)</label>
<mml:math id="mml-eqn-17" display="block"><mml:mi>N</mml:mi><mml:mo>.</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>h</mml:mi><mml:mi>a</mml:mi><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>m</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>n</mml:mi><mml:mi>d</mml:mi><mml:mrow><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>P</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo>.</mml:mo><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>h</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:mrow></mml:math>
</disp-formula>where <italic>N</italic>.<italic>harem</italic><sub><italic>n</italic></sub> indicates the hind count in nth harem and Nhind is the hind count. Alike to other species, RDs are mates with one another. This operation is carried out using a commander, and <italic>&#x03B1;</italic> percent of hinds in the harem are the parents.<disp-formula id="eqn-18"><label>(18)</label>
<mml:math id="mml-eqn-18" display="block"><mml:mi>N</mml:mi><mml:mo>.</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>h</mml:mi><mml:mi>a</mml:mi><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:msubsup><mml:mi>m</mml:mi><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>e</mml:mi></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>n</mml:mi><mml:mi>d</mml:mi><mml:mrow><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo>.</mml:mo><mml:mi>N</mml:mi><mml:mo>.</mml:mo><mml:mi>h</mml:mi><mml:mi>a</mml:mi><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>m</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:mrow><mml:mspace width="thickmathspace" /></mml:math>
</disp-formula>where <inline-formula id="ieqn-1">
<mml:math id="mml-ieqn-1"><mml:mi>N</mml:mi><mml:mo>.</mml:mo><mml:mi>h</mml:mi><mml:mi>a</mml:mi><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:msubsup><mml:mi>m</mml:mi><mml:mi>n</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>e</mml:mi></mml:mrow></mml:msubsup></mml:math>
</inline-formula> is the hind count of the nth harem. A harem is chosen in a random way and the male commander can mate with <italic>&#x03B2;</italic> percent of hinds. Actually, the commander fights with other harem for expanding the region. The hind count in the harem that can mate with the commander is determined as follows:<disp-formula id="eqn-19"><label>(19)</label>
<mml:math id="mml-eqn-19" display="block"><mml:mi>N</mml:mi><mml:mo>.</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>h</mml:mi><mml:mi>a</mml:mi><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:msubsup><mml:mi>m</mml:mi><mml:mi>k</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>e</mml:mi></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>n</mml:mi><mml:mi>d</mml:mi><mml:mrow><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>&#x03B2;</mml:mi><mml:mo>.</mml:mo><mml:mi>N</mml:mi><mml:mo>.</mml:mo><mml:mi>h</mml:mi><mml:mi>a</mml:mi><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>m</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:mrow></mml:math>
</disp-formula>where <inline-formula id="ieqn-2">
<mml:math id="mml-ieqn-2"><mml:mi>N</mml:mi><mml:mo>.</mml:mo><mml:mi>h</mml:mi><mml:mi>a</mml:mi><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:msubsup><mml:mi>m</mml:mi><mml:mi>k</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>e</mml:mi></mml:mrow></mml:msubsup></mml:math>
</inline-formula> is the hind count in the k-th harem. Every individual stag mate with the nearer hind. During the breeding season, the MRD follows the handy hind. It might be the favorite hind between every hind with no assumption of the harem territory. Every stage undergoes mating with the closer hind. For identifying the closer hind, the distance among the stage and every hind in the <italic>J</italic>-dimension space can be determined as<disp-formula id="eqn-20"><label>(20)</label>
<mml:math id="mml-eqn-20" display="block"><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:munderover><mml:mrow><mml:mo movablelimits="false">&#x2211;</mml:mo></mml:mrow><mml:mrow><mml:mi>j</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>J</mml:mi></mml:mrow><mml:mrow></mml:mrow></mml:munderover><mml:mo>&#x2061;</mml:mo><mml:msup><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>s</mml:mi><mml:mi>t</mml:mi><mml:mi>a</mml:mi><mml:msub><mml:mi>g</mml:mi><mml:mi>j</mml:mi></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mi>h</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:msubsup><mml:mi>d</mml:mi><mml:mi>j</mml:mi><mml:mi>i</mml:mi></mml:msubsup><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:msup></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mn>1</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:math>
</disp-formula>where <italic>d</italic><sub><italic>i</italic></sub> is the distance among the i-th hind and a stag. Therefore, the least value in the matrix defines the chosen hind. The process next to hind selection is mating. For selecting the subsequent generation, two mechanisms are followed. Initially, every MRD is ket. Next is considering the rest of the population in the subsequent generation. The hinds are chosen and offspring is produced through the mating process with respect to the fitness value. When a sufficient number of iterations are reached, the termination criteria gets satisfied.</p>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Experimental Evaluation</title>
<p>This section examines the performance of the Bi-LSTM-RDA model on the applied NSL-KDDCup dataset [<xref ref-type="bibr" rid="ref-16">16</xref>] and the experimental outcome is investigated with respect to distinct evaluation parameters such as precision, recall, accuracy, and F-score. For experimental validation, 10 fold cross validation process is employed.</p>
<sec id="s4_1">
<label>4.1</label>
<title>Dataset Used</title>
<p>For experimentation, the most popular KDD CUP99 dataset is employed for anomaly detection. The dataset finds useful for good and real time validation of the performance of the presented method. The dataset includes the instances from 4 class labels such as 45927 instances under Denial of service (Dos) attack, 995 instances under Root to local (R2l) attack, 11656 instances under Probe attacks, 52 instances under User to root (U2r) attacks, and finally 67343 instances under Normal class label. These details are shown in <xref ref-type="fig" rid="fig-4">Fig. 4</xref>.</p>
<fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>Different kinds of attacks in NSL-KDD dataset</title></caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="IASC_26628-fig-4.png"/>
</fig>
</sec>
<sec id="s4_2">
<label>4.2</label>
<title>Results Analysis</title>
<p><xref ref-type="table" rid="table-1">Tab. 1</xref> and <xref ref-type="fig" rid="fig-5">Fig. 5</xref> illustrate the anomaly detection performance of the Bi-LSTM-RDA model in terms of distinct measures with compared methods [<xref ref-type="bibr" rid="ref-17">17</xref>&#x2013;<xref ref-type="bibr" rid="ref-22">22</xref>]. While classifying the DoS attack in the network data, the Bi-LSTM-RDA model has detected it effectively with the recall of 0.985, precision of 0.993, F-score of 0.991 and accuracy of 0.984.</p>
<fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>Result analysis of BiLSTM-RDA method with different measures</title></caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="IASC_26628-fig-5.png"/>
</fig>
<table-wrap id="table-1"><label>Table 1</label>
<caption>
<title>Result analysis of proposed BiLSTM-RDA method</title></caption>
<table><colgroup><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left">Attack type</th>
<th align="left">Precision</th>
<th align="left">Recall</th>
<th align="left">F-score</th>
<th align="left">Accuracy</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">Dos</td>
<td align="left">0.993</td>
<td align="left">0.985</td>
<td align="left">0.991</td>
<td align="left">0.984</td>
</tr>
<tr>
<td align="left">R2l</td>
<td align="left">0.977</td>
<td align="left">0.978</td>
<td align="left">0.976</td>
<td align="left">0.976</td>
</tr>
<tr>
<td align="left">Probe</td>
<td align="left">0.991</td>
<td align="left">0.988</td>
<td align="left">0.984</td>
<td align="left">0.983</td>
</tr>
<tr>
<td align="left">U2r</td>
<td align="left">0.988</td>
<td align="left">0.981</td>
<td align="left">0.98</td>
<td align="left">0.984</td>
</tr>
<tr>
<td align="left">Normal</td>
<td align="left">0.994</td>
<td align="left">0.989</td>
<td align="left">0.992</td>
<td align="left">0.989</td>
</tr>
<tr>
<td align="left">Average</td>
<td align="left">0.989</td>
<td align="left">0.984</td>
<td align="left">0.985</td>
<td align="left">0.983</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="fig" rid="fig-6">Fig. 6</xref> shows the average analysis of BiLSTM-RDA Method with different measures. The figure exhibited that BiLSTM-RDA model has outperformed better results with an average precision of 0.989, recall of 0.984, F-score of 0.985 and accuracy of 0.983.</p>
<fig id="fig-6">
<label>Figure 6</label>
<caption>
<title>Average analysis of BiLSTM-RDA method</title></caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="IASC_26628-fig-6.png"/>
</fig>
<p><xref ref-type="table" rid="table-2">Tab. 2</xref> and <xref ref-type="fig" rid="fig-7">Fig. 7</xref> investigate the outcome of the Bi-LSTM-RDA model with the set of different optimization algorithms interms of accuracy. The resultant values indicated that the Bi-LSTM-PSO (Particle Swarm Optimization) and Bi-LSTM-ACO (Ant Colony Optimization) algorithms have obtained worse results with the accuracy of 0.967 and 0.969 respectively. Along with that, the BiLSTM-FF (Firefly Algorithm), BiLSTM-CS (Crow Search) and BiLSTM-GWO (Greedy Wolf Algorithm) algorithms have showcased moderate and closer results with the accuracy of 0.97, 0.972, and 0.979. However, the Bi-LSTM-RDA model has outperformed the earlier models with the maximum accuracy of 0.983.</p>
<fig id="fig-7">
<label>Figure 7</label>
<caption>
<title>Accuracy analysis of BiLSTM-RDA method</title></caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="IASC_26628-fig-7.png"/>
</fig>
<table-wrap id="table-2"><label>Table 2</label>
<caption>
<title>Result analysis of different optimization algorithm with BiLSTM</title></caption>
<table><colgroup><col align="left"/><col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left">Methods</th>
<th align="left">Accuracy</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">BiLSTM-RDA</td>
<td align="left">0.983</td>
</tr>
<tr>
<td align="left">BiLSTM-GWO</td>
<td align="left">0.979</td>
</tr>
<tr>
<td align="left">BiLSTM-PSO</td>
<td align="left">0.967</td>
</tr>
<tr>
<td align="left">BiLSTM-ACO</td>
<td align="left">0.969</td>
</tr>
<tr>
<td align="left">BiLSTM-CS</td>
<td align="left">0.972</td>
</tr>
<tr>
<td align="left">BiLSTM-FF</td>
<td align="left">0.970</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="fig" rid="fig-8">Fig. 8</xref> examines the comparative analysis of the BiLSTM-RDA method with respect to precision and recall. The presented Bi-LSTM-RDA method has attained a maximum precision of 0.989 and recall of 0.984.</p>
<fig id="fig-8">
<label>Figure 8</label>
<caption>
<title>Precision and recall analysis of BiLSTM-RDA model</title></caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="IASC_26628-fig-8.png"/>
</fig>
<p><xref ref-type="fig" rid="fig-9">Fig. 9</xref> investigates the comparative analysis of the BiLSTM-RDA model interms of accuracy and F-score. The proposed Bi-LSTM-RDA model has reached a maximum accuracy of 0.983 and F-score of 0.985.</p>
<fig id="fig-9">
<label>Figure 9</label>
<caption>
<title>F-score and accuracy analysis of BiLSTM-RDA model</title></caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="IASC_26628-fig-9.png"/>
</fig>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Conclusion</title>
<p>This paper has developed a new DL based BiLSTM-RDA model for anomaly detection in sensor-based CPS. The presented BiLSTM-RDA model operates on three major stages, namely preprocessing, classification, and parameter tuning. At the initial stage, preprocessing is carried out in two stages namely format conversion and normalization. Next to that, the classification process takes place by Bi-LSTM model, where the parameters are tuned by the RDA for tuning the parameters such as number of hidden layers, batch size, epoch count, and learning rate. The application of RDA helps to effectively choose the hyperparameters of Bi-LSTM, and thereby improves the classification results. An extensive experimentations is done to ensure the effective detection efficiency of the Bi-LSTM-RDA model. The attained results demonstrated that the BiLSTM-RDA model has exhibited superior results with an average precision of 0.989, recall of 0.984, F-score of 0.985, and accuracy of 0.983. The experimental outcome stated that the Bi-LSTM-RDA model has appeared as an effective performer over the earlier models. In future, the performance of the Bi-LSTM-RDA model can be improved using lightweight cryptographic techniques to achieve security.</p>
</sec>
</body>
<back><fn-group>
<fn fn-type="other">
<p><bold>Funding Statement:</bold> The authors received no specific funding for this study.</p>
</fn>
<fn fn-type="conflict">
<p><bold>Conflicts of Interest:</bold> The authors declare that they have no conflicts of interest to report regarding the present study.</p>
</fn>
</fn-group>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>N.</given-names> <surname>Krishnaraj</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Elhoseny</surname></string-name>, <string-name><given-names>E. L.</given-names> <surname>Lydia</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Shankar</surname></string-name> and <string-name><given-names>O.</given-names> <surname>ALDabbas</surname></string-name></person-group>, &#x201C;<article-title>An efficient radix trie-based semantic visual indexing model for large-scale image retrieval in cloud environment</article-title>,&#x201D; <source>Software: Practice and Experience</source>, vol. <volume>51</volume>, no. <issue>3</issue>, pp. <fpage>489</fpage>&#x2013;<lpage>502</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>P.</given-names> <surname>Malhotra</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Vig</surname></string-name>, <string-name><given-names>G.</given-names> <surname>Shroff</surname></string-name> and <string-name><given-names>P.</given-names> <surname>Agarwal</surname></string-name></person-group>, &#x201C;<article-title>Long short term memory networks for anomaly detection in time series</article-title>,&#x201D; in <source>European Symp. on Artificial Neural Networks, Computational Intelligence and Machine Learning</source>, Bruges, Belgium, vol. <volume>89</volume>, pp. <fpage>89</fpage>&#x2013;<lpage>94</lpage>, <year>2015</year>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Goh</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Adepu</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Tan</surname></string-name> and <string-name><given-names>Z. S.</given-names> <surname>Lee</surname></string-name></person-group>, &#x201C;<article-title>Anomaly detection in cyber physical systems using recurrent neural networks</article-title>,&#x201D; in <conf-name>Proc. IEEE 18th International Symposium on High Assurance Systems Engineering (HASE)</conf-name>, <conf-loc>Singapore</conf-loc>, pp. <fpage>140</fpage>&#x2013;<lpage>145</lpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Krishnamurthy</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Sarkar</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Tewari</surname></string-name></person-group>, &#x201C;<article-title>Scalable anomaly detection and isolation in cyber-physical systems using Bayesian networks</article-title>,&#x201D; in <conf-name>Proc. ASME 2014 Dynamic Systems and Control Conf., American Society of Mechanical Engineers</conf-name>, <conf-loc>New York, USA</conf-loc>, vol. <volume>46193</volume>, pp. <fpage>1</fpage>&#x2013;<lpage>6</lpage>, <year>2014</year>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Jones</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Kong</surname></string-name> and <string-name><given-names>C.</given-names> <surname>Belta</surname></string-name></person-group>, &#x201C;<article-title>Anomaly detection in cyber-physical systems: A formal methods approach</article-title>,&#x201D; in <conf-name>Proc. IEEE 53rd Annual Conf. on Decision and Control (CDC)</conf-name>, <conf-loc>Los Angeles, USA</conf-loc>, pp. <fpage>848</fpage>&#x2013;<lpage>853</lpage>, <year>2014</year>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Chibani</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Chadli</surname></string-name>, <string-name><given-names>S. X.</given-names> <surname>Ding</surname></string-name> and <string-name><given-names>N. B.</given-names> <surname>Braiek</surname></string-name></person-group>, &#x201C;<article-title>Design of robust fuzzy fault detection filter for polynomial fuzzy systems with new finite frequency specifications</article-title>,&#x201D; <source>Automatica</source>, vol. <volume>93</volume>, pp. <fpage>42</fpage>&#x2013;<lpage>54</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>L.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Chadli</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Ding</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Qiu</surname></string-name> and <string-name><given-names>Y.</given-names> <surname>Yang</surname></string-name></person-group>, &#x201C;<article-title>Diagnostic observer design for T&#x2013;S fuzzy systems: Application to real-time-weighted fault-detection approach</article-title>,&#x201D; <source>IEEE Transactions on Fuzzy Systems</source>, vol. <volume>26</volume>, no. <issue>2</issue>, pp. <fpage>805</fpage>&#x2013;<lpage>816</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>D. I.</given-names> <surname>Urbina</surname></string-name>, <string-name><given-names>J. A.</given-names> <surname>Giraldo</surname></string-name>, <string-name><given-names>A. A.</given-names> <surname>Cardenas</surname></string-name>, <string-name><given-names>N. O.</given-names> <surname>Tippenhauer</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Valente</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Limiting the impact of stealthy attacks on industrial control systems</article-title>,&#x201D; in <conf-name>Proc. of the 2016 ACM SIGSAC Conf. on Computer and Communications Security (CCS)</conf-name>, <conf-loc>Vienna, Austria, ACM: New York, NY, USA</conf-loc>, pp. <fpage>1092</fpage>&#x2013;<lpage>1105</lpage>, <year>2016</year>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Kleinmann</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Wool</surname></string-name></person-group>, &#x201C;<article-title>Automatic construction of statechart-based anomaly detection models for multi-threaded industrial control systems</article-title>,&#x201D; <source>ACM Transactions on Intelligent Systems and Technology (TIST)</source>, vol. <volume>8</volume>, no. <issue>4</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>21</lpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>X. Y.</given-names> <surname>Lu</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Varaiya</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Horowitz</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Palen</surname></string-name></person-group>, &#x201C;<article-title>Faulty loop data analysis/correction and loop fault detection</article-title>,&#x201D; in <conf-name>Proc. of the 15th World Congress on Intelligent Transport Systems</conf-name>, <conf-loc>New York, NY, USA</conf-loc>, pp. <fpage>16</fpage>&#x2013;<lpage>20</lpage>, <year>2008</year>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>N.</given-names> <surname>Zygouras</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Panagiotou</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Zacheilas</surname></string-name>, <string-name><given-names>I.</given-names> <surname>Boutsis</surname></string-name>, <string-name><given-names>V.</given-names> <surname>Kalogeraki</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Towards detection of faulty traffic sensors in real-time</article-title>,&#x201D; in <conf-name>Proc. of the 2nd Int. Conf. on Mining Urban Data (MUD)</conf-name>, <conf-loc>Lille, France</conf-loc>, pp. <fpage>53</fpage>&#x2013;<lpage>62</lpage>, <year>2015</year>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="thesis"><person-group person-group-type="author"><string-name><given-names>S. P.</given-names> <surname>Robinson</surname></string-name></person-group>, &#x201C;<article-title>The development and application of an urban link travel time model using data derived from inductive loop detectors</article-title>,&#x201D; <source><italic>Ph.D. Thesis</italic></source>, <publisher-name>University of London</publisher-name>, <publisher-loc>London, UK</publisher-loc>, pp. <fpage>1</fpage>&#x2013;<lpage>148</lpage>, <year>2006</year>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Q.</given-names> <surname>Tian</surname></string-name>, <string-name><given-names>D.</given-names> <surname>Han</surname></string-name>, <string-name><given-names>K. C.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Liu</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Duan</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>An intrusion detection approach based on improved deep belief network</article-title>,&#x201D; <source>Applied Intelligence</source>, vol. <volume>50</volume>, no. <issue>10</issue>, pp. <fpage>3162</fpage>&#x2013;<lpage>3178</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>S. S.</given-names> <surname>Namini</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Tavakoli</surname></string-name> and <string-name><given-names>A. S.</given-names> <surname>Namin</surname></string-name></person-group>, &#x201C;<article-title>The performance of LSTM and BiLSTM in forecasting time series</article-title>,&#x201D; in <conf-name>Proc. IEEE Int. Conf. on Big Data (Big Data)</conf-name>, <conf-loc>Los Angels, USA</conf-loc>, pp. <fpage>3285</fpage>&#x2013;<lpage>3292</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A. M. F.</given-names> <surname>Fard</surname></string-name>, <string-name><given-names>M. H.</given-names> <surname>Keshteli</surname></string-name> and <string-name><given-names>R. T.</given-names> <surname>Moghaddam</surname></string-name></person-group>, &#x201C;<article-title>Red deer algorithm (RDA): A new nature-inspired meta-heuristic</article-title>,&#x201D; <source>Soft Computing</source>, vol. <volume>24</volume>, no. <issue>19</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>29</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M. R.</given-names> <surname>Parsaei</surname></string-name>, <string-name><given-names>S. M.</given-names> <surname>Rostami</surname></string-name> and <string-name><given-names>R.</given-names> <surname>Javidan</surname></string-name></person-group>, &#x201C;<article-title>A hybrid data mining approach for intrusion detection on imbalanced NSL-KDD dataset</article-title>,&#x201D; <source>International Journal of Advanced Computer Science and Applications</source>, vol. <volume>7</volume>, no. <issue>6</issue>, pp. <fpage>20</fpage>&#x2013;<lpage>25</lpage>, <year>2016</year>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Zhao</surname></string-name> and <string-name><given-names>R.</given-names> <surname>Li</surname></string-name></person-group>, &#x201C;<article-title>AI-based two-stage intrusion detection for software defined IoT networks</article-title>,&#x201D; <source>IEEE Internet of Things Journal</source>, vol. <volume>6</volume>, no. <issue>2</issue>, pp. <fpage>2093</fpage>&#x2013;<lpage>2102</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A. A.</given-names> <surname>Diro</surname></string-name> and <string-name><given-names>N.</given-names> <surname>Chilamkurti</surname></string-name></person-group>, &#x201C;<article-title>Distributed attack detection scheme using deep learning approach for internet of things</article-title>,&#x201D; <source>Future Generation Computer Systems</source>, vol. <volume>82</volume>, pp. <fpage>761</fpage>&#x2013;<lpage>768</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y.</given-names> <surname>Yang</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Zheng</surname></string-name> and <string-name><given-names>C.</given-names> <surname>Wu</surname></string-name></person-group>, &#x201C;<article-title>Building an effective intrusion detection system using the modified density peak clustering algorithm and deep belief networks</article-title>,&#x201D; <source>Applied Sciences</source>, vol. <volume>9</volume>, no. <issue>2</issue>, pp. <fpage>238</fpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y.</given-names> <surname>Djenouri</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Belhadi</surname></string-name> and <string-name><given-names>J. C. W.</given-names> <surname>Lin</surname></string-name></person-group>, &#x201C;<article-title>Adapted k-nearest neighbors for detecting anomalies on spatio&#x2013;temporal traffic flow</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>7</volume>, pp. <fpage>10015</fpage>&#x2013;<lpage>10027</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>O. A.</given-names> <surname>Arqub</surname></string-name> and <string-name><given-names>Z. A.</given-names> <surname>Hammour</surname></string-name></person-group>, &#x201C;<article-title>Numerical solution of systems of second-order boundary value problems using continuous genetic algorithm,&#x201D;</article-title> <source>Information Sciences</source>, vol. <volume>279</volume>, no. <issue>1</issue>, pp. <fpage>396</fpage>&#x2013;<lpage>415</lpage>, <year>2014</year>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Z. H.</given-names> <surname>Hammour</surname></string-name>, <string-name><given-names>O. A.</given-names> <surname>Arqub</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Mamoni</surname></string-name> and <string-name><given-names>N.</given-names> <surname>Shawagfeh</surname></string-name></person-group>, &#x201C;<article-title>Optimization solution of troesch&#x2019;s and bratu&#x2019;s problems of ordinary type using novel continuous genetic algorithm</article-title>,&#x201D; <source>Discrete Dynamics in Nature and Society</source>, vol. <volume>2014</volume>, no. <issue>401696</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>17</lpage>, <year>2014</year>.</mixed-citation></ref>
</ref-list>
</back>
</article>