Efficient Malicious Encrypted Traffic Detection via Multi-Scale Convolution-Augmented Transformer: The NetFlowClassifier Approach
Эффективное обнаружение вредоносного зашифрованного трафика с помощью многомасштабного сверточно-усиленного трансформера: подход NetFlowClassifier
2026-01-23
SCID: 54.1/yea3tffk
Discuss with AI
NetFlowClassifierimproved Transformer encoderlearnable feature position encodingmalicious encrypted traffic detectionmulti-scale depthwise separable convolution
Figures from the paper
Abstract (AI)
With the widespread adoption of encryption technologies, an increasing proportion of Internet traffic is encrypted, which fundamentally weakens traditional traffic inspection mechanisms. Existing port-based and payload-based detection methods have become ineffective, while approaches relying on handcrafted features suffer from limited discriminative capability and poor generalization. To address the problem of malicious encrypted traffic identification, this paper proposes a lightweight hybrid model named NetFlowClassifier, together with a targeted data preprocessing pipeline. An encrypted traffic dataset is first constructed from CSE-CIC-IDS2018 for binary classification of benign and malicious flows. The proposed model integrates multi-scale depthwise separable convolution and an improved Transformer encoder to jointly capture local discriminative patterns and long-range dependencies. In addition, learnable feature position encoding and attention-weighted pooling are introduced to enhance feature representation. Experimental results show that NetFlowClassifier achieves an F1-score of 0.9661, outperforming baseline CNN and Transformer models by 1.8%–3.2%. With 11.2 million parameters and a throughput of 128 samples per second, the model effectively balances detection accuracy and computational efficiency. These results demonstrate the effectiveness of the proposed approach for malicious encrypted traffic detection in modern network environments.
Key Findings
1
Constructed an encrypted traffic dataset from CSE-CIC-IDS2018 for binary classification of benign versus malicious flows.
2
Introduced NetFlowClassifier, a lightweight hybrid model combining multi-scale depthwise separable convolution and an improved Transformer encoder for encrypted traffic detection.
3
Model complexity is 11.2 million parameters with a throughput of 128 samples per second, balancing accuracy and computational efficiency.
4
NetFlowClassifier achieves an F1-score of 0.9661, outperforming baseline CNN and Transformer models by 1.8%–3.2%.
5
Proposed learnable feature position encoding and attention-weighted pooling to enhance feature representation.
Research Object
Malicious encrypted network traffic flows (binary-class dataset of benign vs. malicious NetFlow records)
Research Subject
Detection/classification performance and efficiency of the NetFlowClassifier model in identifying maliciousness in encrypted traffic, including feature representation (multi-scale depthwise separable convolution, Transformer encoder, learnable position encoding, attention-weighted pooling), accuracy (F1-score), model size and throughput
Publication Details
Publication Date
2026-01-23
Journal
Publisher
ISSN
Cited by
0
Access Type
Author Information
Download PDF
Subscribe to digest