arXiv:2608.30745cs.LG2026-08中稿 · the 2026 ACM Confe…

解决加密流量分类泛化差问题,用记忆解耦+扩散增强提升真实场景表现。

TDDM-Melatt: A Decoupled Memory and Diffusion Framework for Generalizable Encrypted Traffic Classification

论文配图:TDDM-Melatt: A Decoupled Memory and Diffusion Framework for Generalizable Encrypted Traffic Classification
图 1 · 摘自论文原文
  • 分离内存与特征学习,通过冻结编码器切断虚假关联路径。
  • 在4个公开数据集上超越6种基线和6种先进模型,准确率显著提升。
  • 适合需要高泛化能力的网络安全系统开发者使用。

加密流量的广泛使用给基于网络监控的安全态势感知系统带来严峻挑战。现有数据驱动训练与测试方法受限于虚假特征相关性引发的捷径学习,以及真实流量中长尾分布导致的样本不平衡,致使流量识别性能在真实网络环境中泛化能力弱。为此,本文提出TDDM-Melatt,一种基于解耦记忆与扩散数据增强的通用加密流量分类框架。首先,设计了梅拉特(Melatt)记忆解耦流量表示模型,采用竞争门控长短期记忆(CG-LSTM)构建编码器与解码器,并提出无虚假相关性的预训练与推理范式,通过严格拓扑匿名化与冻结预训练编码器策略,阻断模型对虚假特征的学习路径。推理阶段,下游分类器基于冻结表示高效完成分类。其次,提出针对流量数据特性的流量去噪扩散模型(TDDM)。在4个代表性公开基准数据集上开展大量实验,采用严格的流级划分与匿名化设置,TDDM-Melatt在准确率上超越6种基础分类模型与6种主流表示学习模型,验证了其在真实网络环境中的有效性。

原文摘要 · Abstract (English)

The widespread adoption of encrypted traffic poses severe challenges to current security situational awareness systems based on network traffic monitoring. In existing dataset-driven training and testing studies, limitations such as shortcut learning induced by spurious feature correlations and sample imbalance caused by the long-tail distribution of real-world traffic result in weak generalization of traffic identification performance to real-world network traffic. To address these limitations, we propose TDDM-Melatt, a disentangled memory-based traffic classification framework with diffusion-based data augmentation. First, we design Melatt, a memory-decoupled traffic representation model, which employs Competitive Gating Long Short-Term Memory (CG-LSTM) to construct the encoder and decoder. We design a spurious-correlation-free pre-training and inference paradigm, employing strict topology anonymization and a frozen pre-trained encoder strategy to cut off the model's learning pathways for spurious features. During inference, classification is performed efficiently by a downstream classifier on the frozen representations. Second, we propose a Traffic Denoising Diffusion Model (TDDM) tailored to the characteristics of traffic data. Extensive experiments are conducted on 4 representative public benchmark datasets. Under strict flow-level splitting and anonymization, TDDM-Melatt outperforms 6 basic classification models and 6 SOTA representation learning models. The proposed method provides a new and effective technical pathway for encrypted traffic classification in real-world network environments.

加密流量分类扩散模型泛化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。