arXiv:2602.08331cs.NIcs.LG2026-02被引 1

提出分层冗余感知压缩框架,提升加密流量表征效率与精度

PACC: Protocol-Aware Cross-Layer Compression for Compact Network Traffic Representation

  • 将协议栈视为多视角输入,显式分离跨层共享与层内私有特征
  • 在加密应用分类等任务中,相比nPrint最高提升12.9%准确率,效率提升3.16倍
  • 适合需要高效精准流量分析的网络安全与物联网场景

网络流量分类是网络安全与管理的核心任务,但普遍加密和协议演进带来挑战。现有表征方式存在瓶颈:手工统计特征虽高效但信息损失大,原始比特编码准确但开销高,预训练嵌入虽具迁移能力却常模糊协议栈层次结构。我们发现真实流量在层间及层内均存在显著冗余,现有方法未显式识别与消除此冗余,导致容量浪费、捷径学习和泛化下降。为此,提出PACC——一种冗余感知、分层感知的表征框架。PACC将协议栈视为多视图输入,学习保持各层忠实性的紧凑投影,显式分解为共享(跨层)与私有(层内)成分。通过联合目标实现:利用重建保留层内信息,通过对比互信息学习捕捉共享结构,并以监督损失最大化任务相关性,生成适于高效推理的紧凑潜在表示。在涵盖加密应用分类、物联网设备识别和入侵检测的数据集上,PACC持续优于手工特征与原始比特基线。在加密子集上,相比nPrint最高提升12.9%准确率;性能匹配或超越强基线模型,同时端到端效率提升最高达3.16倍。

原文摘要 · Abstract (English)

Network traffic classification is a core primitive for network security and management, yet it is increasingly challenged by pervasive encryption and evolving protocols. A central bottleneck is representation: hand-crafted flow statistics are efficient but often too lossy, raw-bit encodings can be accurate but are costly, and recent pre-trained embeddings provide transfer but frequently flatten the protocol stack and entangle signals across layers. We observe that real traffic contains substantial redundancy both across network layers and within each layer; existing paradigms do not explicitly identify and remove this redundancy, leading to wasted capacity, shortcut learning, and degraded generalization. To address this, we propose PACC, a redundancy-aware, layer-aware representation framework. PACC treats the protocol stack as multi-view inputs and learns compact layer-wise projections that remain faithful to each layer while explicitly factorizing representations into shared (cross-layer) and private (layer-specific) components. We operationalize these goals with a joint objective that preserves layer-specific information via reconstruction, captures shared structure via contrastive mutual-information learning, and maximizes task-relevant information via supervised losses, yielding compact latents suitable for efficient inference. Across datasets covering encrypted application classification, IoT device identification, and intrusion detection, PACC consistently outperforms feature-engineered and raw-bit baselines. On encrypted subsets, it achieves up to a 12.9% accuracy improvement over nPrint. PACC matches or surpasses strong foundation-model baselines. At the same time, it improves end-to-end efficiency by up to 3.16x.

流量分类协议分析压缩表征加密流量

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。