Machine learning (ML) has become the dominant approach for network traffic classification, achieving very high predictive performance. However, a model is only valuable if it learns semantically meani...
arXiv:2608.21874v1 Announce Type: cross
Abstract: Deep learning has achieved strong performance in encrypted traffic classification (ETC), yet its computational cost limits deployment on resource-con...
By Yuantu Luo, Jun Tao, Xiangyu Xu, Linxiao Yu, Kangying Li
The paper proposes a human-centered framework for validating the semantic soundness of machine learning models used in network traffic classification. It extends existing knowledge-generation methods by integrating data, models, explainability tools, visualizations, and expert reasoning to iteratively explore, verify, and refine model behavior and preprocessing steps. The framework is built on literature findings, benchmark analyses, XAI experience, and expert feedback, offering practical guidance for ensuring models learn trustworthy, semantically meaningful patterns rather than spurious correlations.
By Igor Cherepanov, David Sessler, Alex Ulmer, Thorsten May, J\"orn Kohlhammer
arXiv:2608.30745v1 Announce Type: new
Abstract: The widespread adoption of encrypted traffic poses severe challenges to current security situational awareness systems based on network traffic monitor...
By Ze Chen, Qiming Yu, Zijia Song, Guozheng Yang, Wei Yan
arXiv:2608. 15504v1 Announce Type: new Abstract: Encrypted traffic classification is vital for network security, yet real-world deployments are inherently sensitive to rare but high-loss errors such as misclassification of malicious traffic.
By Wumei Du, Jiarong Wen, Kaiyu Zhang, Zi Yang, Yiqin Lv, Longfei Zhang, Dong Liang, Zheng Xie
arXiv:2603.25507v2 Announce Type: replace-cross
Abstract: Network Traffic Classification (NTC) increasingly relies on data-driven models, yet its practical deployment is often constrained by limited...
By Giampaolo Bovenzi, Domenico Ciuonzo, Jonatan Krolikowski, Antonio Montieri, Alfredo Nascita, Antonio Pescap\`e, Dario Rossi
arXiv:2608. 13905v1 Announce Type: cross Abstract: HTTPS website fingerprinting (WF) aims to identify visited websites from metadata observable in encrypted traffic.
By Runhan Song, Qiqi Liu, Chuanzhou Pan, Zhenquan Ding, Youquan Xian, Chongru Fan, Lei Cui, Wei Wang, Zhiyu Hao
arXiv:2606. 17109v1 Announce Type: cross Abstract: Given their effectiveness in modeling the relational structure among network traffic flows, graph neural networks (GNNs) have been widely adopted in network intrusion detection systems (NIDSs).
By Jianli Dai, Guangwei Wu, Jiacheng Li, Weiping Wang, An He, Xinjun Xiao
arXiv:2608. 13575v1 Announce Type: cross Abstract: Recent machine learning (ML) advances have demonstrated that deep learning (DL) achieves impressive results in different application domains, including the classification of computer network traffic to corresponding applications.
By Igor Cherepanov, David Sessler, Alex Ulmer, Felix Wagner, Throsten May, J\"orn Kohlhammer
The paper introduces a spatio‑temporal traffic forecasting framework that fuses Graph Neural Networks with semantic knowledge from general-purpose knowledge graphs such as Wikidata. By generating embeddings that capture relationships like nearby points of interest, administrative hierarchies, and functional roles of locations, the framework creates additional adjacency matrices that enrich the sensor graph beyond physical connectivity. Experiments with established forecasting methods demonstrate that this external knowledge improves prediction accuracy and offers a path toward better interpretability.
By Mattis thor Straten, Yannick Wolker, Steffen Strohm, Prathvish Mithare, Ralf Krestel, Matthias Renz
arXiv:2512. 24625v3 Announce Type: replace-cross Abstract: Accurate traffic prediction is essential for Intelligent Transportation Systems, including ride-hailing, urban road planning, and vehicle fleet management.
By Zijian Zhao, Yitong Shang, Sen Li
arXiv:2504. 01882v2 Announce Type: replace Abstract: The use of DNS over HTTPS (DoH) tunneling by an attacker to hide malicious activity within encrypted DNS traffic poses a serious threat to network security, as it allows malicious actors to bypass traditional monitoring and intrusion detection systems while evading detection by conventional traffic analysis techniques.
By Diego Cajaraville-Aboy, Marta Moure-Garrido, Carlos Beis-Penedo, Carlos Garcia-Rubio, Rebeca P. D\'iaz-Redondo, Celeste Campo, Ana Fern\'andez-Vilas, Manuel Fern\'andez-Veiga