发表机构
School of Cyber Science and Engineering, Southeast University; School of Computer Science and Engineering, Southeast University(东南大学网络科学与工程学院; 东南大学计算机科学与工程学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究提出PTT模型族,将协议结构作为压缩单元,在加密流量分类任务中实现了性能与效率的有效权衡,PTT-Lite在大幅减少参数和计算量的同时保持了较高分类性能。
AI 中文摘要
深度学习在加密流量分类(ETC)中取得了优异性能,但其计算成本限制了在路由器、中间盒等资源受限网络设备上的部署。现有压缩方法主要作用于权重、通道、隐层表示或预测结果,未明确确定应保留哪些协议字段和结构上下文。本文提出Pruned Traffic Trees(PTT),这是一种三级协议结构化模型族,将原生协议结构作为压缩单元。PTT-Full从完整协议树图(PTGs)中学习协议结构化表示和字段显著性,采用流级自监督学习和协议感知稀疏执行。学习到的显著性和TopK+$k$闭包为PTT-Distilled构建蒸馏PTGs(PTG-Ds),而PTT-Lite继承该拓扑,通过结构对齐迁移和流级逻辑蒸馏减少宽度。在流不相交和强信息(SII)掩码设置下,PTT-Full在CSTNET-TLS1.3和CipherSpectrum数据集上的Macro-F1分数分别为0.9519和0.9416,而PTT-Lite保留0.9325和0.9136的分数,参数减少80.3%和61.3%,有效GFLOPs降低98.85%和98.78%,CPU推理速度提升8.75倍和8.46倍。这些结果表明,将协议结构本身作为压缩对象可实现轻量级ETC的有效性能-效率权衡。
英文摘要
Deep learning has achieved strong performance in encrypted traffic classification (ETC), yet its computational cost limits deployment on resource-constrained network devices such as routers and middleboxes. Existing compression methods mainly operate on weights, channels, hidden representations, or predictions, but do not explicitly determine which protocol fields and structural contexts should remain. We propose Pruned Traffic Trees (PTT), a three-level protocol-structured model family that treats native protocol structures as compression units. PTT-Full learns protocol-structured representations and field salience from complete Protocol Tree Graphs (PTGs), with flow-level self-supervised learning and protocol-presence-aware sparse execution. The learned salience and TopK+$k$ closure construct Distilled PTGs (PTG-Ds) for PTT-Distilled, while PTT-Lite inherits this topology and reduces width through structure-aligned transfer and flow-level logits distillation. Under flow-disjoint and Strong Information Information (SII)-masked settings, PTT-Full achieves Macro-F1 scores of 0.9519 and 0.9416 on CSTNET-TLS1.3 and CipherSpectrum, while PTT-Lite retains 0.9325 and 0.9136 with 80.3\% and 61.3\% fewer parameters, 98.85\% and 98.78\% lower effective GFLOPs, and 8.75$\times$ and 8.46$\times$ CPU inference speedups. These results demonstrate that treating protocol structure itself as the compression object enables effective performance-efficiency trade-offs for lightweight ETC.
CommentsThis paper is submitted to INFOCOM 2027