提出可解释框架Traffic-Explainer,让深度学习网络分类更透明
Building Transparency in Deep Learning-Powered Network Traffic Classification: A Traffic-Explainer Framework
- 通过输入扰动与互信息最大化,自动找出影响预测的关键特征
- 相比现有方法,解释效果提升约42%,在三项任务中验证有效性
- 适合关注模型可信度的网络运维人员与安全研究人员
深度学习显著提升了网络流量分类的性能和效率,但其决策过程缺乏透明性,导致运营商不愿在生产环境中部署。为此,本文提出Traffic-Explainer,一种模型无关、基于输入扰动的流量解释框架。该框架通过最大化原始流量序列与其掩码版本预测结果间的互信息,自动识别驱动模型判断的关键特征。大量实验表明,Traffic-Explainer相较现有方法解释能力提升约42%。实际应用中,该框架被用于识别关键流量特征,在应用分类、流量定位和网络测绘三项任务中增强透明度:在前两项任务中,精准定位决定应用类型与位置的关键字节,揭示潜在漏洞与隐私风险;在网络测绘中,识别驱动traceroute映射至物理路径的海底光缆,支持基于traceroute的威胁分析。
原文摘要 · Abstract (English)
Recent advancements in deep learning have significantly enhanced the performance and efficiency of traffic classification in networking systems. However, the lack of transparency in their predictions and decision-making has made network operators reluctant to deploy DL-based solutions in production networks. To tackle this challenge, we propose Traffic-Explainer, a model-agnostic and input-perturbation-based traffic explanation framework. By maximizing the mutual information between predictions on original traffic sequences and their masked counterparts, Traffic-Explainer automatically uncovers the most influential features driving model predictions. Extensive experiments demonstrate that Traffic-Explainer improves upon existing explanation methods by approximately 42%. Practically, we further apply Traffic-Explainer to identify influential features and demonstrate its enhanced transparency across three critical tasks: application classification, traffic localization, and network cartography. For the first two tasks, Traffic-Explainer identifies the most decisive bytes that drive predicted traffic applications and locations, uncovering potential vulnerabilities and privacy concerns. In network cartography, Traffic-Explainer identifies submarine cables that drive the mapping of traceroute to physical path, enabling a traceroute-informed risk analysis.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。