N-BaIoT—Network-Based Detection of IoT Botnet Attacks Using Deep Autoencoders

Yair MeidanMichael BohadanaYael MathovYisroel MirskyDominik BreitenbacherAsaf ShabtaiYuval Elovici

article2018IEEE pervasive computing1,444 citationsIEEE Pervasive Computing Best Paper Award

Presents a network-based anomaly detection framework using deep autoencoders to instantly identify active botnet attacks, such as Mirai and BASHLITE, originating from compromised IoT devices.

Listen

Enterprise networks face an escalating threat from the rapid proliferation of Internet of Things (IoT) devices, such as smart doorbells, thermostats, and surveillance cameras. Unlike traditional personal computers, these connected devices often lack robust built-in security, making them vulnerable targets for attackers who compromise them to form botnets that launch massive distributed denial-of-service (DDoS) attacks. Because early malware propagation stages and encrypted control channels can easily bypass perimeter defenses, organizations urgently need a reliable way to identify and neutralize infected endpoints at the moment an attack begins.

The article demonstrates and evaluates an automated, network-based anomaly detection framework called N-BaIoT. The objective is to determine whether training deep autoencoders—unsupervised neural networks designed to learn and compress baseline patterns—on benign network traffic from individual IoT devices can accurately and instantaneously detect attacks launched from compromised hardware.

The authors conducted empirical lab experiments using authentic network traffic captured via switch port mirroring from nine commercial IoT devices, including webcams, doorbells, a thermostat, and a baby monitor. The researchers infected these devices with two prominent IoT botnets, Mirai and BASHLITE, and executed ten distinct attack types, including network scans, spam, and various packet-flooding attacks. To monitor traffic without burdening device processing power, the system continuously extracted 115 statistical features across multiple temporal windows and trained a tailored deep autoencoder for each device using only benign behavior.

The evaluation showed that the proposed method achieved a 100% true positive rate, successfully detecting every attack launched across all nine infected devices. It generated a very low average false positive rate of 0.007, significantly outperforming standard anomaly detection algorithms such as Local Outlier Factor (0.086), Isolation Forest (0.027), and One-Class Support Vector Machines (0.026). Furthermore, the autoencoders detected attacks in an average of 174 milliseconds, enabling near-instantaneous threat discovery far below the typical 20-to-90-second duration of standard denial-of-service floods.

These findings indicate that anomaly detection using deep autoencoders can serve as an effective final line of defense for enterprise networks. By operating entirely at the network switch level, the approach secures resource-constrained IoT hardware without requiring host software installation or vendor cooperation. Detecting malicious behaviors in less than a second enables automated containment, dramatically lowering operational risk, preventing downstream service outages, and safeguarding network bandwidth.

Organizations should consider deploying centralized, network-level anomaly detection that maintains separate behavioral baselines for each connected IoT device type. Before introducing new hardware to production environments, security teams should assess device traffic predictability, as units with complex features—such as multi-sensor baby monitors—exhibit higher baseline traffic variance and longer detection times. Enterprises should also establish automated policy rules to isolate endpoints instantly upon receiving an anomaly alert.

While the empirical results provide high confidence in the method's accuracy under controlled conditions, several limitations remain. The evaluation was conducted in an isolated laboratory setting across nine specific device models and two botnet families, assuming that clean, uncompromised traffic is available during initial installation. Further validation is needed through transfer learning pilots to test whether pre-trained models can generalize across identical devices in different enterprise environments without requiring separate on-site training phases.

  • Paper: Isolation-Based Anomaly Detection, Fei Tony Liu et al. (2012). Introduces the Isolation Forest algorithm, providing the foundational principles of unsupervised, tree-based anomaly isolation that serve as a key baseline for modern network anomaly detection methods.
  • Paper: Support Vector Data Description, DAVID M.J. TAX et al. (2004). Establishes Support Vector Data Description for modeling nominal data boundaries, defining the core one-class boundary estimation paradigm adapted by modern deep network anomaly detectors.
Cover for N-BaIoT—Network-Based Detection of IoT Botnet Attacks Using Deep Autoencoders

Abstract

The proliferation of IoT devices which can be more easily compromised than desktop computers has led to an increase in the occurrence of IoT based botnet attacks. In order to mitigate this new threat there is a need to develop new methods for detecting attacks launched from compromised IoT devices and differentiate between hour and millisecond long IoTbased attacks. In this paper we propose and empirically evaluate a novel network based anomaly detection method which extracts behavior snapshots of the network and uses deep autoencoders to detect anomalous network traffic emanating from compromised IoT devices. To evaluate our method, we infected nine commercial IoT devices in our lab with two of the most widely known IoT based botnets, Mirai and BASHLITE. Our evaluation results demonstrated our proposed method's ability to accurately and instantly detect the attacks as they were being launched from the compromised IoT devices which were part of a botnet.

Table of Contents

  • I Introduction
  • II Related Work
  • III Proposed Detection Method
  • IV Empirical evaluation
  • V Conclusion
  • References

Knowls

  1. Knowl 1 — N-BaIoT Network Anomaly Detection Architecture

    model/method

    N-BaIoT is a network-based anomaly detection framework designed to detect botnet attacks launched from compromised Internet of Things (IoT) devices. The method operates by passively monitoring network traffic through switch port mirroring, without requiring software agents or computational resources on the IoT endpoints themselves.

    Because IoT devices are typically task-oriented and execute a limited set of communication protocols, their benign traffic exhibits lower variance and higher regularity than general-purpose computers. N-BaIoT constructs an individualized deep autoencoder for each monitored IoT device, trained exclusively on statistical features extracted from its early benign network traffic. During continuous monitoring, newly observed packet streams are compressed and reconstructed by the device's autoencoder. When an infected device executes botnet attacks (such as scanning or volumetric flooding), the anomalous traffic patterns produce high reconstruction errors (Mean Squared Error), enabling automated detection and alerting for device isolation.

  2. Knowl 2 — Multiscale Behavioral Snapshot Feature Extraction for IoT Traffic

    model/method

    Whenever a network packet arrives, N-BaIoT extracts a 115-dimensional behavioral snapshot vector capturing the immediate and decaying statistical context of the communicating hosts and protocols. The feature vector is formed by computing a base set of 23 statistical features over 5 temporal decay windows: 100 ms, 500 ms, 1.5 s, 10 s, and 1 min.

    The 23 base features are aggregated across four contextual levels:

    1. Source IP: Aggregates statistics for all outbound traffic from the device's host IP (capturing overall host behavior).
    2. Source MAC-IP: Aggregates traffic sharing both the source MAC address and source IP address (differentiating gateway traffic and detecting IP spoofing attacks).
    3. Channel: Aggregates traffic between a specific source IP and destination IP pair.
    4. Socket: Aggregates traffic between a specific source IP:port and destination IP:port socket pair.

    The 23 statistical features extracted per time window comprise:

    • Outbound packet size: Sample mean and variance across Source IP, Source MAC-IP, Channel, and Socket (8 features).
    • Packet count: Total packet count across Source IP, Source MAC-IP, Channel, and Socket (4 features).
    • Packet jitter (inter-arrival duration): Sample mean, variance, and count across Channel (3 features).
    • Bidirectional packet size (inbound and outbound combined): Magnitude, radius, covariance, and Pearson correlation coefficient across Channel and Socket (8 features).
  3. Knowl 3 — Deep Autoencoder Network Architecture for IoT Traffic Profiling

    model/method

    For each IoT device, N-BaIoT trains an individual deep autoencoder neural network. The input layer has a dimension equal to the number of extracted traffic features (115115).

    The encoder component consists of four successive hidden layers with progressively decreasing dimensions relative to the input layer size:

    1. First hidden layer: 75%75\% of input dimension (86 neurons)
    2. Second hidden layer: 50%50\% of input dimension (58 neurons)
    3. Third hidden layer: 33%33\% of input dimension (38 neurons)
    4. Fourth hidden layer (bottleneck code layer): 25%25\% of input dimension (29 neurons)

    The decoder component reconstructs the original feature representation using four symmetric layers with increasing dimensions:

    1. Fifth hidden layer: 33%33\% of input dimension (38 neurons)
    2. Sixth hidden layer: 50%50\% of input dimension (58 neurons)
    3. Seventh hidden layer: 75%75\% of input dimension (86 neurons)
    4. Output layer: 100%100\% of input dimension (115 neurons)

    Dimensionality reduction in the bottleneck prevents the network from learning the trivial identity function, constraining it to model the core non-linear correlations of benign traffic.

  4. Knowl 4 — Anomaly Threshold Determination Formula

    equation

    For a trained autoencoder model evaluated on an independent benign optimization dataset DSoptDS_{\text{opt}}, the anomaly threshold tr∗tr^* for individual packet reconstruction Mean Squared Error (MSEMSE) is computed as:

    tr∗=MSE‾DSopt+s(MSEDSopt)tr^* = \overline{MSE}_{DS_{\text{opt}}} + s(MSE_{DS_{\text{opt}}})

    where MSE‾DSopt\overline{MSE}_{DS_{\text{opt}}} is the sample mean of the autoencoder's reconstruction errors across all feature vectors in DSoptDS_{\text{opt}}, and s(MSEDSopt)s(MSE_{DS_{\text{opt}}}) is the sample standard deviation of the reconstruction errors on DSoptDS_{\text{opt}}. Any packet whose feature snapshot produces a reconstruction error MSE>tr∗MSE > tr^* is categorized as an anomalous instance.

  5. Knowl 5 — Sliding Window Majority Voting for Anomaly Filtering

    equation

    To eliminate false positives caused by rare benign fluctuations without sacrificing true attack detection sensitivity, classification decisions are evaluated over a moving sequence of packets using majority voting. The optimal window size ws∗ws^* is the minimal integer length ∣ws∣|ws| that yields a 0% False Positive Rate on the benign optimization dataset DSoptDS_{\text{opt}}:

    ws∗=arg⁡min⁡∣ws∣(∣{packet∈ws∣MSE(packet)>tr∗}∣>∣ws∣2)ws^* = \arg\min_{|ws|} \left( \left| \left\{ \text{packet} \in ws \mid MSE(\text{packet}) > tr^* \right\} \right| > \frac{|ws|}{2} \right)

    where tr∗tr^* is the packet-level anomaly threshold, MSE(packet)MSE(\text{packet}) is the Mean Squared Error between the packet's 115-dimensional input vector and its autoencoder reconstruction, and ∣ws∣|ws| is the number of consecutive packets in the window. During continuous monitoring, a malicious stream alert is triggered only when more than half of the packets within the current window of length ws∗ws^* exceed tr∗tr^*.

  6. Knowl 6 — N-BaIoT Continuous Monitoring and Anomaly Detection Algorithm

    algorithm

    During live deployment, N-BaIoT extracts feature snapshots from incoming network packets and evaluates them through the per-device deep autoencoder. A moving window of size ws∗ws^* maintains the classifications of recent packets. If the number of anomalous packets in the window exceeds ⌊ws∗/2⌋\lfloor ws^* / 2 \rfloor, an attack alert is generated.

    Input: Packet stream P for an IoT device, trained deep autoencoder M, anomaly threshold tr*, optimal window size ws*
    Output: Attack alerts upon detecting malicious traffic
    Initialize window buffer W as an empty FIFO queue of maximum capacity ws*
    for each arriving packet p in P do
        x = ExtractFeatures(p) // 115-dimensional snapshot
        x_hat = M(x) // Reconstruct snapshot via autoencoder
        mse = MeanSquaredError(x, x_hat)
        if mse > tr* then
            is_anomalous = 1
        else
            is_anomalous = 0
        end if
        if length(W) == ws* then
            W.dequeue()
        end if
        W.enqueue(is_anomalous)
        if length(W) == ws* and sum(W) > ws* / 2 then
            TriggerAlert(device_id=p.source_mac, message="Device compromised; botnet attack detected")
        end if
    end for
  7. Knowl 7 — Experimental Testbed and Botnet Attack Configurations

    experimental setup

    The empirical evaluation of N-BaIoT was conducted in an isolated laboratory replicating an enterprise network. Nine commercial IoT devices were connected via Wi-Fi to access points and wired to a central switch configured for port mirroring with Wireshark:

    1. Danmini Doorbell
    2. Ennio Doorbell
    3. Ecobee Thermostat
    4. Philips B120N/10 Baby Monitor
    5. Provision PT-737E Security Camera
    6. Provision PT-838 Security Camera
    7. SimpleHome XCS7-1002-WHT Security Camera
    8. SimpleHome XCS7-1003-WHT Security Camera
    9. Samsung SNH 1011 N Webcam

    The devices were infected with authentic binaries from two IoT botnet families:

    • BASHLITE (Gafgyt): Executed 5 attack types: (1) Scan (scanning network for open Telnet ports and default credentials), (2) Junk (sending spam data), (3) UDP (UDP flooding), (4) TCP (TCP flooding), and (5) COMBO (sending spam data while opening connections to target IP and port).
    • Mirai: Executed 5 attack types: (1) Scan (automated network scanning), (2) Ack (TCP ACK flooding), (3) Syn (TCP SYN flooding), (4) UDP (UDP flooding), and (5) UDPplain (UDP flooding optimized for high packets per second).

    Ennio Doorbell and Samsung Webcam were evaluated under BASHLITE attacks; the remaining seven devices were evaluated under both BASHLITE and Mirai attacks.

  8. Knowl 8 — Per-Device Training Parameters and Optimized Model Configurations

    data/table

    The benign data collected for each device was partitioned chronologically into three equal sets: training set (DStrnDS_{\text{trn}}), optimization set (DSoptDS_{\text{opt}}), and test set (DStstDS_{\text{tst}}). Hyperparameters (learning rate η\eta and epochs) were optimized using early stopping on DSoptDS_{\text{opt}} to minimize Mean Squared Error, followed by computing the anomaly threshold tr∗tr^* and window size ws∗ws^*.

    Device Make and Model Device Type Benign Instances Training Time (s) Size (kB) η\eta Epochs tr∗tr^* ws∗ws^* Botnets
    Danmini Doorbell Doorbell 49,548 555 172 0.012 800 0.042 82 Mirai, BASHLITE
    Ennio Doorbell Doorbell 39,100 215 172 0.003 350 0.011 22 BASHLITE
    Ecobee Thermostat Thermostat 13,113 54 172 0.028 250 0.011 20 Mirai, BASHLITE
    Philips B120N/10 Baby Monitor 175,240 292 172 0.016 100 0.030 65 Mirai, BASHLITE
    Provision PT-737E Security Camera 62,154 275 172 0.026 300 0.035 32 Mirai, BASHLITE
    Provision PT-838 Security Camera 98,514 795 172 0.008 450 0.038 43 Mirai, BASHLITE
    SimpleHome XCS7-1002-WHT Security Camera 46,585 220 172 0.017 230 0.056 23 Mirai, BASHLITE
    SimpleHome XCS7-1003-WHT Security Camera 19,528 190 172 0.006 500 0.004 25 Mirai, BASHLITE
    Samsung SNH 1011 N Webcam 52,150 150 172 0.013 150 0.074 32 BASHLITE

    The trained models had an object size of 172 kB across all devices, and training times ranged from 54 seconds (Ecobee) to 795 seconds (Provision PT-838).

  9. Knowl 9 — Empirical Detection Accuracy and Latency Benchmark

    empirical result

    N-BaIoT was evaluated against three standard anomaly detection algorithms: Local Outlier Factor (LOF), One-Class Support Vector Machine (One-Class SVM), and Isolation Forest, with all baseline hyperparameters (trtr and wsws) optimized equivalently to the autoencoders on DSoptDS_{\text{opt}}:

    • True Positive Rate (TPR): N-BaIoT achieved a 100% TPR across all 9 devices and all tested attack types from both Mirai and BASHLITE. LOF and One-Class SVM achieved similar near-100% TPRs, whereas Isolation Forest demonstrated lower and highly variable TPRs across devices.
    • False Positive Rate (FPR): N-BaIoT achieved a mean FPR of 0.007±0.010.007 \pm 0.01 on benign test traffic. This was lower and more consistent than One-Class SVM (0.026±0.0290.026 \pm 0.029), Isolation Forest (0.027±0.0410.027 \pm 0.041), and LOF (0.086±0.0810.086 \pm 0.081).
    • Detection Latency: N-BaIoT detected attacks in an average time of 174±212174 \pm 212 milliseconds across all tested devices, substantially outperforming the baseline methods (which often required between 1 and 8 seconds) and allowing compromised devices to be flagged within fractions of a second.
  10. Knowl 10 — Impact of IoT Traffic Predictability on Anomaly Detection Errors and Detection Time

    empirical result

    Regression analysis relating static and dynamic traffic features to anomaly detection performance revealed that device behavioral predictability directly impacts error rates and latency:

    1. Inbound Traffic Variability vs. FPR: An increase in the standard deviation of hourly inbound traffic volume has a statistically significant positive effect on the average FPR (p=0.019p = 0.019). Devices with multifaceted hardware capabilities and user interactions (such as the Philips B120N/10 baby monitor, which includes 2-way intercom audio, motion detection, and ambient light/temperature/humidity sensing) produce higher variance and less predictable benign traffic, leading to higher baseline FPR.
    2. Inbound Traffic Volume vs. Detection Time: An increase in the maximum volume of hourly inbound traffic has a statistically significant positive effect on detection latency (p=0.001p = 0.001). Under lower traffic predictability, enforcing a 0% FPR on the optimization set requires selecting a larger sliding window size ws∗ws^*, which increases the number of packets required for majority voting and consequently increases the detection time.

Coverage note — None was omitted; all key contributed elements including the feature extraction scheme, autoencoder architecture, thresholding/majority voting equations, empirical setup, benchmark results, per-device model parameters, and predictability regressions are represented.

References

  1. 1.C. Kolias, G. Kambourakis, A. Stavrou, and J. Voas, “DDoS in the IoT: Mirai and Other Botnets,” Computer, vol. 50, no. 7, pp. 80–84, 2017.
  2. 2.E. Bertino and N. Islam, “Botnets and Internet of Things Security,” Computer, 2017.
  3. 3.R. Hallman, J. Bryan, G. Palavicini, J. Divita, and J. Romero-Mariona, “IoDDoS The Internet of Distributed Denial of Service Attacks - A Case Study of the Mirai Malware and IoT-Based Botnets,” in Proceedings of the 2nd International Conference on Internet of Things, Big Data and Security - Volume 1: IoTBDS. SciTePress, 9 2017, pp. 47–58.
  4. 4.M. Ozcelik, N. Chalabianloo, and G. Gur, “Software-Defined Edge Defense Against IoT-Based DDoS,” in 2017 IEEE International Conference on Computer and Information Technology (CIT). IEEE, 8 2017, pp. 308–313.
  5. 5.D. H. Summerville, K. M. Zach, and Y. Chen, “Ultra-lightweight deep packet anomaly detection for Internet of Things devices,” in 2015 IEEE 34th International Performance Computing and Communications Conference, IPCCC 2015, 2016.
  6. 6.Y. M. P. Pa, S. Suzuki, K. Yoshioka, T. Matsumoto, T. Kasama, and C. Rossow, “IoTPOT: A Novel Honeypot for Revealing Current IoT Threats,” Journal of Information Processing, vol. 24, no. 3, pp. 522–533, 2016.
  7. 7.H. Sedjelmaci, S. M. Senouci, and M. Al-Bahri, “A lightweight anomaly detection technique for low-resource IoT devices: A game-theoretic methodology,” in 2016 IEEE International Conference on Communications (ICC). IEEE, 5 2016, pp. 1–6.
  8. 8.H. Bostani and M. Sheikhan, “Hybrid of anomaly-based and specification-based IDS for Internet of Things using unsupervised OPF based on MapReduce approach,” Computer Communications, 2017.
  9. 9.I. Butun, B. Kantarci, and M. Erol-Kantarci, “Anomaly detection and privacy preservation in cloud-centric Internet of Things,” in 2015 IEEE International Conference on Communication Workshop (ICCW). IEEE, 6 2015, pp. 2610–2615.
  10. 10.D. Midi, A. Rullo, A. Mudgerikar, and E. Bertino, “Kalis A System for Knowledge-Driven Adaptable Intrusion Detection for the Internet of Things,” in 2017 IEEE 37th International Conference on Distributed Computing Systems (ICDCS). IEEE, 6 2017, pp. 656–666.
  11. 11.S. Raza, L. Wallgren, and T. Voigt, “SVELTE: Real-time intrusion detection in the Internet of Things,” Ad Hoc Networks, vol. 11, no. 8, 2013.
  12. 12.B. B. Zarpelo, R. S. Miani, C. T. Kawakani, and S. C. de Alvarenga, “A survey of intrusion detection in Internet of Things,” Journal of Network and Computer Applications, vol. 84, pp. 25–37, 4 2017.
  13. 13.A. Tuor, S. Kaplan, B. Hutchinson, N. Nichols, and S. Robinson, “Deep learning for unsupervised insider threat detection in structured cybersecurity data streams,” in Artificial Intelligence for Cybersecurity Workshop at AAAI, 2017.
  14. 14.S. Garc´ıa, A. Zunino, and M. Campo, “Survey on network-based botnet detection methods,” Security and Communication Networks, vol. 7, no. 5, pp. 878–903, 2014.
  15. 15.I. Arnaldo, A. Cuesta-Infante, A. Arun, M. Lam, C. Bassias, and K. Veeramachaneni, “Learning Representations for Log Data in Cybersecurity,” in International Conference on Cyber Security Cryptography and Machine Learning. Springer, 2017, pp. 250–268.
  16. 16.Y. Li, R. Ma, and R. Jiao, “A hybrid malicious code detection method based on deep learning,” International Journal of Security and Its Applications, vol. 9, no. 5, 2015.
  17. 17.K. Veeramachaneni, I. Arnaldo, V. Korrapati, C. Bassias, and K. Li, “Aiˆ 2: training a big data machine to defend,” in Big Data Security on Cloud, IEEE International Conference on High Performance and Smart Computing (HPSC), and IEEE International Conference on Intelligent Data and Security (IDS), 2016 IEEE 2nd International Conference on. IEEE, 2016, pp. 49–54.
  18. 18.Y. Yu, J. Long, and Z. Cai, “Network intrusion detection through stacking dilated convolutional autoencoders,” Security and Communication Networks, vol. 2017, 2017.
  19. 19.“GitHub - jgamblin/Mirai-Source-Code: Leaked Mirai Source Code for Research/IoC Development Purposes.” [Online]. Available: https://github.com/jgamblin/Mirai-Source-Code
  20. 20.N. Blenn, V. Ghiette, and C. Doerr, “Quantifying the Spectrum ¨ of Denial-of-Service Attacks through Internet Backscatter,” in Proceedings of the 12th International Conference on Availability, Reliability and Security - ARES ’17. ACM Press, 2017, pp. 1–10.

Citation

MLA
Meidan, Y., et al. “N-BaIoT—Network-Based Detection of IoT Botnet Attacks Using Deep Autoencoders”. IEEE Pervasive Computing, vol. 17, no. 3, 2018, pp. 12–22, https://doi.org/10.1109/MPRV.2018.03367731.
APA
Meidan, Y., Bohadana, M., Mathov, Y., Mirsky, Y., Shabtai, A., Breitenbacher, D., & Elovici, Y. (2018). N-BaIoT—Network-Based Detection of IoT Botnet Attacks Using Deep Autoencoders. IEEE Pervasive Computing, 17(3), 12–22. https://doi.org/10.1109/MPRV.2018.03367731
Chicago
Meidan, Y., M. Bohadana, Y. Mathov, et al. 2018. “N-BaIoT—Network-Based Detection of IoT Botnet Attacks Using Deep Autoencoders”. IEEE Pervasive Computing 17 (3): 12–22. https://doi.org/10.1109/MPRV.2018.03367731.
Harvard
Meidan, Y. et al. (2018) “N-BaIoT—Network-Based Detection of IoT Botnet Attacks Using Deep Autoencoders”, IEEE Pervasive Computing, 17(3), pp. 12–22. Available at: https://doi.org/10.1109/MPRV.2018.03367731.
Vancouver
1. Meidan Y, Bohadana M, Mathov Y, Mirsky Y, Shabtai A, Breitenbacher D, Elovici Y (2018) N-BaIoT—Network-Based Detection of IoT Botnet Attacks Using Deep Autoencoders. IEEE Pervasive Computing 17:12–22

BibTeX

@article{Meidan_2018, title={N-BaIoT—Network-Based Detection of IoT Botnet Attacks Using Deep Autoencoders}, volume={17}, ISSN={1558-2590}, url={http://dx.doi.org/10.1109/MPRV.2018.03367731}, DOI={10.1109/mprv.2018.03367731}, number={3}, journal={IEEE Pervasive Computing}, publisher={Institute of Electrical and Electronics Engineers (IEEE)}, author={Meidan, Yair and Bohadana, Michael and Mathov, Yael and Mirsky, Yisroel and Shabtai, Asaf and Breitenbacher, Dominik and Elovici, Yuval}, year={2018}, month=July, pages={12–22} }
Metadata:Crossref

Access the Paper

This paper is available from its original source. Click below to access the PDF.

Open PDF