

浏览全部资源
扫码关注微信
1.成都信息工程大学网络空间安全学院(芯谷产业学院),四川成都 610225
2.先进密码技术与系统安全四川省重点实验室,四川成都 610225
3.先进微处理器技术国家工程研究中心(工业控制与安全分中心),四川成都 610225
4.成都信息工程大学人工智能学院,四川成都 610225
5.国家工程物理交叉科学研究中心,四川绵阳 621000
6.电子科技大学信息与软件工程学院,四川成都 611731
Received:28 December 2025,
Accepted:09 February 2026,
Published:25 February 2026
移动端阅览
卢嘉中, 余坤, 刘小垒, 等. 基于梯度协同与特征融合的加密流量检测[J]. 电子学报, 2026, 54(02): 532-543.
LU Jiazhong, YU Kun, LIU Xiaolei, et al. Encrypted Traffic Detection Based on Gradient Collaboration and Feature Fusion[J]. Acta Electronica Sinica, 2026, 54(02): 532-543.
卢嘉中, 余坤, 刘小垒, 等. 基于梯度协同与特征融合的加密流量检测[J]. 电子学报, 2026, 54(02): 532-543. DOI:10.12263/DZXB.20251021
LU Jiazhong, YU Kun, LIU Xiaolei, et al. Encrypted Traffic Detection Based on Gradient Collaboration and Feature Fusion[J]. Acta Electronica Sinica, 2026, 54(02): 532-543. DOI:10.12263/DZXB.20251021
随着物联网(Internet of Things,IoT)设备的广泛部署和网络通信的快速发展,加密流量已成为主流传输形式,但同时也为后门攻击和针对性投毒攻击等高级威胁提供了隐蔽通道。为应对加密恶意流量检测这一关键安全挑战,本文提出基于梯度协同与特征融合网络的加密流量检测模型,专用于提升网络中加密恶意流量的检测能力。该模型包含两大核心模块:特征融合模块与梯度协同模块,显著增强模型对复杂加密流量模式的表征学习能力。在特征融合模块中,该模型充分利用卷积神经网络(Convolutional Neural Network,CNN)的局部特征提取优势以及知识增强网络(Kolmogorov-Arnold Networks,KAN)的全局特征建模能力,实现局部与全局特征的高效深度融合。为进一步提升子模型间的协同性与鲁棒性,梯度协同机制使多个子模型能够实时动态共享梯度并联合优化损失函数,从而在训练过程中相互引导、纠错,强化对多样化加密恶意流量模式的捕获。该机制不仅缓解了局部与全局特征学习间的冲突,还显著提升了模型对隐蔽加密攻击流量的敏感性。在多个公开加密流量数据集上的实验结果表明,本文所提出的模型相较现有方法在F1分数上提升约7%,实现了对加密恶意流量的高精度分类。
With the widespread deployment of Internet of Things (IoT) devices and the rapid development of network communications
encrypted traffic has become the mainstream transmission form. However
it also provides covert channels for advanced threats such as backdoor attacks and targeted poisoning attacks. To address the critical security challenge of encrypted malicious traffic detection
this paper proposes an encrypted traffic detection model based on gradient collaboration and feature fusion networks
specifically designed to enhance the detection capability of encrypted malicious traffic in networks. The model consists of two core modules: the feature fusion module and the gradient collaboration module
which significantly improve the model’s ability to learn representations of complex encrypted traffic patterns. In the feature fusion module
the model fully leverages the local feature extraction advantages of convolutional neural networks (CNN) and the global feature modeling capabilities of knowledge-augmented networks (KAN) to achieve efficient deep fusion of local and global features. To further enhance the collaboration and robustness among sub-models
the gradient collaboration mechanism enables multiple sub-models to dynamically share gradients in real-time and jointly optimize the loss function
thereby guiding and correcting each other during training
and strengthening the capture of diverse encrypted malicious traffic patterns. This mechanism not only alleviates conflicts between local and global feature learning but also significantly improves the model’s sensitivity to covert encrypted attack traffic. Experimental results on multiple public encrypted traffic datasets show that the proposed model achieves an improvement of approximately 7% in F1 score compared to existing methods
enabling high-precision classification of encrypted malicious traffic.
Ahn S , Yi H , Lee Y , et al . Hawkware: Network intrusion detection based on behavior analysis with ANNs on an IoT device [C ] // 2020 57th ACM/IEEE Design Automation Conference . Piscataway : IEEE , 2020 : 1 - 6 . DOI: 10.1109/dac18072.2020.9218559 http://dx.doi.org/10.1109/dac18072.2020.9218559
Hameed S , Khan F I , Hameed B . Understanding security requirements and challenges in Internet of Things (IoT): A review [J ] . Journal of Computer Networks and Communications , 2019 , 2019 : 9629381 . DOI: 10.1155/2019/9629381 http://dx.doi.org/10.1155/2019/9629381
Hinton G , Vinyals O , Dean J . Distilling the knowledge in a neural network [PP/OL ] . V1.arXiv ( 2015-03-09 )[ 2025-12-28 ] . https://doi.org/10.48550/arXiv.1503.02531 https://doi.org/10.48550/arXiv.1503.02531 .
Liu Ziming , Wang Yixuan , Vaidya S , et al . KAN: Kolmogorov-arnold networks [C/OL ] // International Conference on Learning Representations (ICLR) . Vienna: 2024 . https://proceedings.iclr.cc/paper_files/paper/2025/file/afaed89642ea100935e39d39a4da602c-Paper-Conference.pdf https://proceedings.iclr.cc/paper_files/paper/2025/file/afaed89642ea100935e39d39a4da602c-Paper-Conference.pdf .
Peng Zhiliang , Huang Wei , Gu Shanzhi , et al . Conformer: Local features coupling global representations for visual recognition [C ] // 2021 IEEE/CVF International Conference on Computer Vision . Piscataway : IEEE , 2021 : 357 - 366 . DOI: 10.1109/iccv48922.2021.00042 http://dx.doi.org/10.1109/iccv48922.2021.00042
Ayo F E , Awotunde J B , Folorunso S O , et al . A genomic rule-based KNN model for fast flux botnet detection [J ] . Egyptian Informatics Journal , 2023 , 24 ( 2 ): 313 - 325 . DOI: 10.1016/j.eij.2023.05.002 http://dx.doi.org/10.1016/j.eij.2023.05.002
孙剑文 , 张斌 , 李红宇 , 等 . 自监督学习驱动的注意力增强恶意流量检测方法 [J ] . 网络与信息安全学报 , 2025 , 11 ( 2 ): 136 - 151 .
Sun Jianwen , Zhang Bin , Li Hongyu , et al . Harnessing self-supervised learning to boost malicious traffic detection with enhanced attention [J ] . Chinese Journal of Network and Information Security , 2025 , 11 ( 2 ): 136 - 151 . (in Chinese)
马博文 , 郭渊博 , 马骏 , 等 . 基于后门攻击的恶意流量逃逸方法 [J ] . 通信学报 , 2024 , 45 ( 4 ): 73 - 83 .
Ma Bowen , Guo Yuanbo , Ma Jun , et al . Escape method of malicious traffic based on backdoor attack [J ] . Journal on Communications , 2024 , 45 ( 4 ): 73 - 83 . (in Chinese)
Afzal R , Kumar Murugesan R . Rule-based anomaly detection model with stateful correlation enhancing mobile network security [J ] . Intelligent Automation & Soft Computing , 2022 , 31 ( 3 ): 1825 - 1841 . DOI: 10.32604/iasc.2022.020598 http://dx.doi.org/10.32604/iasc.2022.020598
Uszko K , Kasprzyk M , Natkaniec M , et al . Rule-based system with machine learning support for detecting anomalies in 5G WLANs [J ] . Electronics , 2023 , 12 ( 11 ): 2355 . DOI: 10.3390/electronics12112355 http://dx.doi.org/10.3390/electronics12112355
Berkay Celik Z , Walls R J , McDaniel P , et al . Malware traffic detection using tamper resistant features [C ] // MILCOM 2015 - 2015 IEEE Military Communications Conference . Piscataway : IEEE , 2015 : 330 - 335 . DOI: 10.1109/milcom.2015.7357464 http://dx.doi.org/10.1109/milcom.2015.7357464
Mao Qian , O’Neill C , Bao Ke . A feature-based network traffic classification approach [J ] . International Journal of Network Security , 2023 , 25 ( 5 ): 821 - 828 .
赵荻 , 尹志超 , 崔苏苏 , 等 . 基于图表示的恶意TLS流量检测方法 [J ] . 信息安全研究 , 2024 , 10 ( 3 ): 209 - 215 .
Zhao Di , Yin Zhichao , Cui Susu , et al . Malicious TLS traffic detection based on graph representation [J ] . Journal of Information Security Research , 2024 , 10 ( 3 ): 209 - 215 . (in Chinese)
Fei Chao , Xia Nian , Tsai P W , et al . An effective feature selection algorithm for machine learning-based malicious traffic detection [C ] // 2024 19th Asia Joint Conference on Information Security . Piscataway : IEEE , 2024 : 1 - 8 . DOI: 10.1109/asiajcis64263.2024.00024 http://dx.doi.org/10.1109/asiajcis64263.2024.00024
Ferriyan A , Thamrin A H , Takeda K , et al . Encrypted malicious traffic detection based on Word2Vec [J ] . Electronics , 2022 , 11 ( 5 ): 679 . DOI: 10.3390/electronics11050679 http://dx.doi.org/10.3390/electronics11050679
许小龙 , 方子介 , 齐连永 , 等 . 车联网边缘计算环境下基于深度强化学习的分布式服务卸载方法 [J ] . 计算机学报 , 2021 , 44 ( 12 ): 2382 - 2405 .
Xu Xiaolong , Fang Zijie , Qi Lianyong , et al . A deep reinforcement learning-based distributed service offloading method for edge computing empowered Internet of vehicles [J ] . Chinese Journal of Computers , 2021 , 44 ( 12 ): 2382 - 2405 . (in Chinese)
王承祥 , 黄杰 , 王海明 , 等 . 面向6G的无线通信信道特性分析与建模 [J ] . 物联网学报 , 2020 , 4 ( 1 ): 19 - 32 . DOI: 10.11959/j.issn.2096-3750.2020.00155 http://dx.doi.org/10.11959/j.issn.2096-3750.2020.00155
Wang Chengxiang , Huang Jie , Wang Haiming , et al . 6G oriented wireless communication channel characteristics analysis and modeling [J ] . Chinese Journal on Internet of Things , 2020 , 4 ( 1 ): 19 - 32 . (in Chinese) . DOI: 10.11959/j.issn.2096-3750.2020.00155 http://dx.doi.org/10.11959/j.issn.2096-3750.2020.00155
唐博麟 , 王晨飞 , 江帆 , 等 . 基于网络流时空序列的加密流量分类 [J ] . 计算机应用与软件 , 2024 , 41 ( 3 ): 297 - 302 .
Tang Bolin , Wang Chenfei , Jiang Fan , et al . Encrypted traffic classification based on network flow time-space series [J ] . Computer Applications and Software , 2024 , 41 ( 3 ): 297 - 302 . (in Chinese)
Han Ying , Wang Xinlei , He Mingshu , et al . Intrusion detection for encrypted flows using single feature based on graph integration theory [J ] . IEEE Internet of Things Journal , 2024 , 11 ( 10 ): 17589 - 17601 . DOI: 10.1109/jiot.2024.3360039 http://dx.doi.org/10.1109/jiot.2024.3360039
Zhu Shizhou , Xu Xiaolong , Zhao Juan , et al . LKD-STNN: A lightweight malicious traffic detection method for Internet of Things based on knowledge distillation [J ] . IEEE Internet of Things Journal , 2024 , 11 ( 4 ): 6438 - 6453 . DOI: 10.1109/jiot.2023.3310794 http://dx.doi.org/10.1109/jiot.2023.3310794
Zhou Xiaokang , Wu Jiayi , Liang Wei , et al . Reconstructed graph neural network with knowledge distillation for lightweight anomaly detection [J ] . IEEE Transactions on Neural Networks and Learning Systems , 2024 , 35 ( 9 ): 11817 - 11828 . DOI: 10.1109/tnnls.2024.3389714 http://dx.doi.org/10.1109/tnnls.2024.3389714
Lu Jiazhong , Wang Chenli , Huang Yuanyuan , et al . An adversarial example defense algorithm for intelligent driving [J ] . IEEE Network , 2024 , 38 ( 6 ): 98 - 105 . DOI: 10.1109/mnet.2024.3392582 http://dx.doi.org/10.1109/mnet.2024.3392582
Huang Tao , You Shan , Wang Fei , et al . Knowledge distillation from a stronger teacher [C ] // Proceedings of the 36th International Conference on Neural Information Processing Systems . New York : ACM , 2022 : 33716 - 33727 . DOI: 10.52202/068431-2443 http://dx.doi.org/10.52202/068431-2443
戚子健 , 柳毅 . 基于双向GRU和CNN的恶意网络流量检测方法 [J ] . 计算机应用与软件 , 2024 , 41 ( 12 ): 334 - 340 .
Qi Zijian , Liu Yi . Malicious network traffic detection method based on bidirectional gru and cnn [J ] . Computer Applications and Software , 2024 , 41 ( 12 ): 334 - 340 . (in Chinese)
Lu Jiazhong , Chen Kai , Zhuo Zhongliu , et al . A temporal correlation and traffic analysis approach for APT attacks detection [J ] . Cluster Computing , 2019 , 22 ( S3 ): 7347 - 7358 . DOI: 10.1007/s10586-017-1256-y http://dx.doi.org/10.1007/s10586-017-1256-y
Niu Ziwei , Yuan Junkun , Ma Xu , et al . Knowledge distillation-based domain-invariant representation learning for domain generalization [J ] . IEEE Transactions on Multimedia , 2024 , 26 : 245 - 255 . DOI: 10.1109/tmm.2023.3263549 http://dx.doi.org/10.1109/tmm.2023.3263549
Yang Chuanguang , An Zhulin , Cai Linhang , et al . Knowledge distillation using hierarchical self-supervision augmented distribution [J ] . IEEE Transactions on Neural Networks and Learning Systems , 2024 , 35 ( 2 ): 2094 - 2108 . DOI: 10.1109/tnnls.2022.3186807 http://dx.doi.org/10.1109/tnnls.2022.3186807
Lu Jiazhong , Lan Jin , Huang Yuanyuan , et al . Anti-attack intrusion detection model based on MPNN and traffic spatiotemporal characteristics [J ] . Journal of Grid Computing , 2023 , 21 ( 4 ): 60 . DOI: 10.1007/s10723-023-09703-9 http://dx.doi.org/10.1007/s10723-023-09703-9
Yang Jing , Zhu Xiatian , Bulat A , et al . Knowledge distillation meets open-set semi-supervised learning [J ] . International Journal of Computer Vision , 2025 , 133 ( 1 ): 315 - 334 . DOI: 10.1007/s11263-024-02192-7 http://dx.doi.org/10.1007/s11263-024-02192-7
Qazi E U H , Faheem M H , Zia T . HDLNIDS: Hybrid deep-learning-based network intrusion detection system [J ] . Applied Sciences , 2023 , 13 ( 8 ): 4921 . DOI: 10.3390/app13084921 http://dx.doi.org/10.3390/app13084921
Long Jing , Liang Wei , Li Kuanching , et al . A regularized cross-layer ladder network for intrusion detection in industrial Internet of Things [J ] . IEEE Transactions on Industrial Informatics , 2023 , 19 ( 2 ): 1747 - 1755 . DOI: 10.1109/tii.2022.3204034 http://dx.doi.org/10.1109/tii.2022.3204034
Ning Jinhui , Gui Guan , Wang Yu , et al . Malware traffic classification using domain adaptation and ladder network for secure industrial Internet of Things [J ] . IEEE Internet of Things Journal , 2022 , 9 ( 18 ): 17058 - 17069 . DOI: 10.1109/jiot.2021.3131981 http://dx.doi.org/10.1109/jiot.2021.3131981
Dai Jianbang , Xu Xiaolong , Xiao Fu . GLADS: A global-local attention data selection model for multimodal multitask encrypted traffic classification of IoT [J ] . Computer Networks , 2023 , 225 : 109652 . DOI: 10.1016/j.comnet.2023.109652 http://dx.doi.org/10.1016/j.comnet.2023.109652
Dai Jianbang , Xu Xiaolong , Gao Honghao , et al . CMFTC: Cross modality fusion efficient multitask encrypt traffic classification for efficient management of IIoT [J ] . IEEE Transactions on Network Science and Engineering , 2023 , 10 ( 6 ): 3989 - 4009 .
Aceto G , Ciuonzo D , Montieri A , et al . DISTILLER: Encrypted traffic classification via multimodal multitask deep learning [J ] . Journal of Network and Computer Applications , 2021 , 183 : 102985 . DOI: 10.1016/j.jnca.2021.102985 http://dx.doi.org/10.1016/j.jnca.2021.102985
Wang Wei , Zhu Ming , Wang Jinlin , et al . End-to-end encrypted traffic classification with one-dimensional convolution neural networks [C ] // 2017 IEEE International Conference on Intelligence and Security Informatics . Piscataway : IEEE , 2017 : 43 - 48 . DOI: 10.1109/isi.2017.8004872 http://dx.doi.org/10.1109/isi.2017.8004872
Huang He , Deng Haojiang , Chen Jun , et al . Automatic multi-task learning system for abnormal network traffic detection [J ] . International Journal of Emerging Technologies in Learning (IJET) , 2018 , 13 ( 4 ): 4 - 20 . DOI: 10.3991/ijet.v13i04.8466 http://dx.doi.org/10.3991/ijet.v13i04.8466
Zhao Ying , Chen Junjun , Wu Di , et al . Multi-task network anomaly detection using federated learning [C ] // Proceedings of the 10th International Symposium on Information and Communication Technology . New York : ACM , 2019 : 273 - 279 . DOI: 10.1145/3368926.3369705 http://dx.doi.org/10.1145/3368926.3369705
Sun Haifeng , Xiao Yunming , Wang Jing , et al . Common knowledge based and one-shot learning enabled multi-task traffic classification [J ] . IEEE Access , 2019 , 7 : 39485 - 39495 . DOI: 10.1109/access.2019.2904039 http://dx.doi.org/10.1109/access.2019.2904039
Lopez-Martin M , Carro B , Sanchez-Esguevillas A , et al . Network traffic classifier with convolutional and recurrent neural networks for Internet of Things [J ] . IEEE Access , 2017 , 5 : 18042 - 18050 . DOI: 10.1109/access.2017.2747560 http://dx.doi.org/10.1109/access.2017.2747560
0
Views
73
下载量
0
CSCD
Publicity Resources
Related Articles
Related Author
Related Institution
京公网安备11010802024621