发表机构
National University of Defense Technology(国防科技大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对加密流量分类的泛化性局限,研究提出TDDM-Melatt框架,结合解耦内存模型Melatt与流量去噪扩散模型TDDM,在4个公开数据集上的实验性能优于6种基础分类模型和6种SOTA表示学习模型。
AI 中文摘要
加密流量的广泛应用给基于网络流量监测的当前安全态势感知系统带来了严峻挑战。在现有数据集驱动的训练与测试研究中,由虚假特征关联引发的捷径学习,以及真实流量长尾分布导致的样本不平衡等局限,使得流量识别性能向真实网络流量的泛化能力较弱。为解决这些局限,我们提出TDDM-Melatt,这是一个基于解耦内存的流量分类框架,结合了基于扩散的数据增强。首先,我们设计Melatt,一个内存解耦的流量表示模型,采用竞争门控长短期记忆网络(Competitive Gating Long Short-Term Memory,CG-LSTM)构建编码器和解码器。我们设计了无虚假关联的预训练与推理范式,采用严格的拓扑匿名化和冻结预训练编码器策略,切断模型学习虚假特征的路径;推理阶段,下游分类器对冻结后的表示进行高效分类。其次,我们提出适配流量数据特性的流量去噪扩散模型(Traffic Denoising Diffusion Model,TDDM)。在4个代表性公开基准数据集上开展了大量实验,在严格的流级别拆分与匿名化设置下,TDDM-Melatt的性能优于6种基础分类模型和6种SOTA表示学习模型。该方法为真实网络环境中的加密流量分类提供了新的有效技术路径。
英文摘要
The widespread adoption of encrypted traffic poses severe challenges to current security situational awareness systems based on network traffic monitoring. In existing dataset-driven training and testing studies, limitations such as shortcut learning induced by spurious feature correlations and sample imbalance caused by the long-tail distribution of real-world traffic result in weak generalization of traffic identification performance to real-world network traffic. To address these limitations, we propose TDDM-Melatt, a disentangled memory-based traffic classification framework with diffusion-based data augmentation. First, we design Melatt, a memory-decoupled traffic representation model, which employs Competitive Gating Long Short-Term Memory (CG-LSTM) to construct the encoder and decoder. We design a spurious-correlation-free pre-training and inference paradigm, employing strict topology anonymization and a frozen pre-trained encoder strategy to cut off the model's learning pathways for spurious features. During inference, classification is performed efficiently by a downstream classifier on the frozen representations. Second, we propose a Traffic Denoising Diffusion Model (TDDM) tailored to the characteristics of traffic data. Extensive experiments are conducted on 4 representative public benchmark datasets. Under strict flow-level splitting and anonymization, TDDM-Melatt outperforms 6 basic classification models and 6 SOTA representation learning models. The proposed method provides a new and effective technical pathway for encrypted traffic classification in real-world network environments.
Comments18 pages, 13 figures, 9 tables, accepted at the 2026 ACM Conference on Computer and Communications Security (CCS 2026)