arXiv AI

Treat Traffic Like Trees: A Semantic-Preserving Hierarchical Graph-Based Expert Framework for Encrypted Traffic Analysis

arXiv:2606. 04517v1 Announce Type: cross Abstract: Graph-based deep learning methods have been widely employed in encrypted traffic analysis to exploit latent correlations across different granularities.

arXiv Machine Learning
Sep 16

Beyond Measurement Metrics: A Human-Centered Framework for Semantic Validation of Network Traffic Classification

The paper proposes a human-centered framework for validating the semantic soundness of machine learning models used in network traffic classification. It extends existing knowledge-generation methods by integrating data, models, explainability tools, visualizations, and expert reasoning to iteratively explore, verify, and refine model behavior and preprocessing steps. The framework is built on literature findings, benchmark analyses, XAI experience, and expert feedback, offering practical guidance for ensuring models learn trustworthy, semantically meaningful patterns rather than spurious correlations.

By Igor Cherepanov, David Sessler, Alex Ulmer, Thorsten May, J\"orn Kohlhammer
arXiv AI
Aug 17

Interactive Analysis of Global Explanations using Aggregated Class Activation Maps for Network Data

arXiv:2608. 13575v1 Announce Type: cross Abstract: Recent machine learning (ML) advances have demonstrated that deep learning (DL) achieves impressive results in different application domains, including the classification of computer network traffic to corresponding applications.

By Igor Cherepanov, David Sessler, Alex Ulmer, Felix Wagner, Throsten May, J\"orn Kohlhammer
arXiv Machine Learning
Aug 19

General Semantic Knowledge Infusion for Spatio-Temporal Traffic Forecasting

The paper introduces a spatio‑temporal traffic forecasting framework that fuses Graph Neural Networks with semantic knowledge from general-purpose knowledge graphs such as Wikidata. By generating embeddings that capture relationships like nearby points of interest, administrative hierarchies, and functional roles of locations, the framework creates additional adjacency matrices that enrich the sensor graph beyond physical connectivity. Experiments with established forecasting methods demonstrate that this external knowledge improves prediction accuracy and offers a path toward better interpretability.

By Mattis thor Straten, Yannick Wolker, Steffen Strohm, Prathvish Mithare, Ralf Krestel, Matthias Renz
arXiv Machine Learning
Jun 29

CO-DEFEND: Continuous Decentralized Federated Learning for Secure DoH-Based Threat Detection

arXiv:2504. 01882v2 Announce Type: replace Abstract: The use of DNS over HTTPS (DoH) tunneling by an attacker to hide malicious activity within encrypted DNS traffic poses a serious threat to network security, as it allows malicious actors to bypass traditional monitoring and intrusion detection systems while evading detection by conventional traffic analysis techniques.

By Diego Cajaraville-Aboy, Marta Moure-Garrido, Carlos Beis-Penedo, Carlos Garcia-Rubio, Rebeca P. D\'iaz-Redondo, Celeste Campo, Ana Fern\'andez-Vilas, Manuel Fern\'andez-Veiga