计算机科学
加密
图形
计算机网络
理论计算机科学
异构网络
数据挖掘
蒸馏
密码学
人工智能
图论
注意力网络
分布式计算
交通分类
算法设计
钥匙(锁)
计算复杂性理论
机器学习
任务分析
网络拓扑
公钥密码术
数据建模
电子邮件
作者
Jiazhong Lu,Kun Yu,YuanYuan Huang,Zhitan Wei,Jiali Yin,Xiaolei Liu
标识
DOI:10.1109/jiot.2026.3670664
摘要
With the increasing severity of network security threats, encrypted traffic identification has become a core challenge in the field of network security. Graph Neural Networks (GNNs) have demonstrated significant potential in capturing the complex association patterns among encrypted traffic byte units, owing to their powerful structural modeling capabilities. However, traditional homogeneous graph modeling methods struggle to fully characterize the multidimensional heterogeneous relationships between headers and payloads in encrypted traffic. Although Heterogeneous Graph Neural Networks (HGNNs) can address such complexity, they suffer from parameter redundancy and a sharp increase in training overhead due to independent edge-type modeling, while lacking a mechanism for collaborative knowledge transfer across edge types. To address this, this paper proposes a Cross-Type Distillation mechanism, which constructs a unified structural representation path to enable bidirectional knowledge transfer between heterogeneous edge types. This approach enhancing the feature expression capability of weak semantic edges. Building on this foundation, we introduce the malicious traffic detection model SEADGAT, which employs an edge-type weight-sharing mechanism to compress the propagation weights of multiple edge types into a unified representation space and integrates them into graph attention computation. This substantially reduces training time while preserving the ability to perceive structural differences. Based on a heterogeneous graph framework, SEADGAT accurately characterizes the complex dependencies between byte units and between headers and payloads, combined with a dynamic fusion mechanism to generate comprehensive traffic representations. DFUSE is enhanced with gated cross-interactions for adaptive multimodal fusion. Experiments on packet-level and flow-level classification across multiple encrypted traffic datasets demonstrate that SEADGAT outperforms existing methods in classification accuracy, training efficiency, and model parameter scale.
科研通智能强力驱动
Strongly Powered by AbleSci AI