Efficient Malicious Encrypted Traffic Detection via Multi-Scale Convolution-Augmented Transformer: The NetFlowClassifier Approach

Эффективное обнаружение вредоносного зашифрованного трафика с помощью многомасштабного сверточно-усиленного трансформера: подход NetFlowClassifier
Zongbao Wang, Juan Fu, Zhili Ma, Zhiru Li, Mingming Xiang
2026-01-23

NetFlowClassifierimproved Transformer encoderlearnable feature position encodingmalicious encrypted traffic detectionmulti-scale depthwise separable convolution
With the widespread adoption of encryption technologies, an increasing proportion of Internet traffic is encrypted, which fundamentally weakens traditional traffic inspection mechanisms. Existing port-based and payload-based detection methods have become ineffective, while approaches relying on handcrafted features suffer from limited discriminative capability and poor generalization. To address the problem of malicious encrypted traffic identification, this paper proposes a lightweight hybrid model named NetFlowClassifier, together with a targeted data preprocessing pipeline. An encrypted traffic dataset is first constructed from CSE-CIC-IDS2018 for binary classification of benign and malicious flows. The proposed model integrates multi-scale depthwise separable convolution and an improved Transformer encoder to jointly capture local discriminative patterns and long-range dependencies. In addition, learnable feature position encoding and attention-weighted pooling are introduced to enhance feature representation. Experimental results show that NetFlowClassifier achieves an F1-score of 0.9661, outperforming baseline CNN and Transformer models by 1.8%–3.2%. With 11.2 million parameters and a throughput of 128 samples per second, the model effectively balances detection accuracy and computational efficiency. These results demonstrate the effectiveness of the proposed approach for malicious encrypted traffic detection in modern network environments.
1
Constructed an encrypted traffic dataset from CSE-CIC-IDS2018 for binary classification of benign versus malicious flows.
2
Introduced NetFlowClassifier, a lightweight hybrid model combining multi-scale depthwise separable convolution and an improved Transformer encoder for encrypted traffic detection.
3
Model complexity is 11.2 million parameters with a throughput of 128 samples per second, balancing accuracy and computational efficiency.
4
NetFlowClassifier achieves an F1-score of 0.9661, outperforming baseline CNN and Transformer models by 1.8%–3.2%.
5
Proposed learnable feature position encoding and attention-weighted pooling to enhance feature representation.

Malicious encrypted network traffic flows (binary-class dataset of benign vs. malicious NetFlow records)

Detection/classification performance and efficiency of the NetFlowClassifier model in identifying maliciousness in encrypted traffic, including feature representation (multi-scale depthwise separable convolution, Transformer encoder, learnable position encoding, attention-weighted pooling), accuracy (F1-score), model size and throughput

Publication Details
Publication Date
2026-01-23
Journal
Publisher
ISSN
Cited by
0
Access Type
Author Information
Authors
Zongbao Wang
Juan Fu
Zhili Ma
Zhiru Li
Mingming Xiang
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%