arXiv:2608.30745v1 Announce Type: new
Abstract: The widespread adoption of encrypted traffic poses severe challenges to current security situational awareness systems based on network traffic monitor...
By Ze Chen, Qiming Yu, Zijia Song, Guozheng Yang, Wei Yan
arXiv:2504. 01882v2 Announce Type: replace Abstract: The use of DNS over HTTPS (DoH) tunneling by an attacker to hide malicious activity within encrypted DNS traffic poses a serious threat to network security, as it allows malicious actors to bypass traditional monitoring and intrusion detection systems while evading detection by conventional traffic analysis techniques.
By Diego Cajaraville-Aboy, Marta Moure-Garrido, Carlos Beis-Penedo, Carlos Garcia-Rubio, Rebeca P. D\'iaz-Redondo, Celeste Campo, Ana Fern\'andez-Vilas, Manuel Fern\'andez-Veiga
RiskTraf introduces a risk-extrapolated residual learning approach for multi-variate traffic flow prediction, leveraging raw flow, speed, and occupancy data from the new PEMSB-3V benchmark. The method freezes a trained spatio-temporal backbone and adds a lightweight residual head that learns from historical speed and occupancy to correct flow predictions across different traffic regimes. Experiments show consistent improvements over various backbones and outperform existing debiasing and distribution-shift adaptation techniques.
By Guangyu Wang, Zhidan Liu
The paper proposes a human-centered framework for validating the semantic soundness of machine learning models used in network traffic classification. It extends existing knowledge-generation methods by integrating data, models, explainability tools, visualizations, and expert reasoning to iteratively explore, verify, and refine model behavior and preprocessing steps. The framework is built on literature findings, benchmark analyses, XAI experience, and expert feedback, offering practical guidance for ensuring models learn trustworthy, semantically meaningful patterns rather than spurious correlations.
By Igor Cherepanov, David Sessler, Alex Ulmer, Thorsten May, J\"orn Kohlhammer
arXiv:2606. 04517v1 Announce Type: cross Abstract: Graph-based deep learning methods have been widely employed in encrypted traffic analysis to exploit latent correlations across different granularities.
By Yuantu Luo, Jun Tao, Linxiao Yu, Guang Cheng
SecureDrive‑FL combines differential privacy (DP‑SGD) with a novel Gradient‑Aware Selective Homomorphic Encryption (GASHE) scheme to protect federated driver‑monitoring models. GASHE encrypts only gradient components that exceed a DP‑calibrated sensitivity threshold, avoiding full‑parameter encryption. In experiments on a ten‑class distracted driver task, SecureDrive‑FL matches DP‑SGD’s poisoning resistance while also defending against Man‑in‑the‑Middle attacks, adding only 8–10% runtime overhead.