arXiv Machine Learning

PERO: Efficient Robust Post-Training Foundation Models for Encrypted Traffic Classification

arXiv:2608. 15504v1 Announce Type: new Abstract: Encrypted traffic classification is vital for network security, yet real-world deployments are inherently sensitive to rare but high-loss errors such as misclassification of malicious traffic.

arXiv Machine Learning
Jun 29

CO-DEFEND: Continuous Decentralized Federated Learning for Secure DoH-Based Threat Detection

arXiv:2504. 01882v2 Announce Type: replace Abstract: The use of DNS over HTTPS (DoH) tunneling by an attacker to hide malicious activity within encrypted DNS traffic poses a serious threat to network security, as it allows malicious actors to bypass traditional monitoring and intrusion detection systems while evading detection by conventional traffic analysis techniques.

By Diego Cajaraville-Aboy, Marta Moure-Garrido, Carlos Beis-Penedo, Carlos Garcia-Rubio, Rebeca P. D\'iaz-Redondo, Celeste Campo, Ana Fern\'andez-Vilas, Manuel Fern\'andez-Veiga
arXiv AI
Aug 24

RiskTraf: Risk-Extrapolated Residual Learning for Multi-Variate Traffic Flow Prediction

RiskTraf introduces a risk-extrapolated residual learning approach for multi-variate traffic flow prediction, leveraging raw flow, speed, and occupancy data from the new PEMSB-3V benchmark. The method freezes a trained spatio-temporal backbone and adds a lightweight residual head that learns from historical speed and occupancy to correct flow predictions across different traffic regimes. Experiments show consistent improvements over various backbones and outperform existing debiasing and distribution-shift adaptation techniques.

By Guangyu Wang, Zhidan Liu
arXiv Machine Learning
Sep 16

Beyond Measurement Metrics: A Human-Centered Framework for Semantic Validation of Network Traffic Classification

The paper proposes a human-centered framework for validating the semantic soundness of machine learning models used in network traffic classification. It extends existing knowledge-generation methods by integrating data, models, explainability tools, visualizations, and expert reasoning to iteratively explore, verify, and refine model behavior and preprocessing steps. The framework is built on literature findings, benchmark analyses, XAI experience, and expert feedback, offering practical guidance for ensuring models learn trustworthy, semantically meaningful patterns rather than spurious correlations.

By Igor Cherepanov, David Sessler, Alex Ulmer, Thorsten May, J\"orn Kohlhammer
Hugging Face Trending Papers
Aug 27

SecureDrive-FL: Joint Differential Privacy and Gradient-Aware Selective Homomorphic Encryption for Federated Driver Monitoring

SecureDrive‑FL combines differential privacy (DP‑SGD) with a novel Gradient‑Aware Selective Homomorphic Encryption (GASHE) scheme to protect federated driver‑monitoring models. GASHE encrypts only gradient components that exceed a DP‑calibrated sensitivity threshold, avoiding full‑parameter encryption. In experiments on a ten‑class distracted driver task, SecureDrive‑FL matches DP‑SGD’s poisoning resistance while also defending against Man‑in‑the‑Middle attacks, adding only 8–10% runtime overhead.

arXiv Machine Learning
Aug 28

SecureDrive-FL: Joint Differential Privacy and Gradient-Aware Selective Homomorphic Encryption for Federated Driver Monitoring

The paper introduces GASHE, a gradient‑aware selective homomorphic encryption scheme that encrypts only those gradient components exceeding a differential‑privacy‑calibrated sensitivity threshold, rather than encrypting all parameters. Building on GASHE, SecureDrive‑FL combines DP‑SGD with this selective encryption to form a closed‑loop DP+HE privacy pipeline for federated driver monitoring. Experiments on a ten‑class distracted driver classification task show that SecureDrive‑FL retains the poisoning resistance of DP‑SGD while also defending against Man‑in‑the‑Middle interception, with only an 8–10% runtime overhead.

By Baran Can G\"ul, Hanuma Siddhartha Tunuguntla, Anjana Arvind Naik, Abhishek Vijay Potekar, Nasser Jazdi, Michael Weyrich
arXiv Machine Learning
2d ago

ModSec-Learn: Boosting ModSecurity with Machine Learning

arXiv:2406.13547v2 Announce Type: replace Abstract: ModSecurity is widely recognized as the standard open-source Web Application Firewall (WAF), maintained by the OWASP Foundation. It detects malicio...

By Christian Scano, Giuseppe Floris, Biagio Montaruli, Luca Demetrio, Andrea Valenza, Luca Compagna, Davide Ariu, Luca Piras, Davide Balzarotti, Battista Biggio
arXiv Machine Learning
Aug 7

Enhancing Anomaly Resilience in Research Networks: A Large-Scale Forecasting Benchmark for Dynamic Security Baselining

arXiv:2608. 05605v1 Announce Type: cross Abstract: Research and Education Networks (RENs) serve as critical infrastructure for scientific discovery, yet they face a unique security paradox: their normal traffic patterns which are characterized by massive, bursty "elephant flows" are statistically indistinguishable from volumetric attacks such as DDoS to conventional monitoring systems.

By Mohammad Arafath Uddin Shariff, Byrav Ramamurthy