Search papers, labs, and topics across Lattice.
This paper introduces Mean Masked Autoencoder (MMAE), a teacher-student MAE framework with a flow mixing strategy, to improve encrypted traffic classification. MMAE uses self-distillation for teacher-student interaction, enabling multi-granularity comprehension beyond byte-level reconstruction, and employs a dynamic Flow Mixing (FlowMix) strategy to create challenging cross-flow mixed samples. The method also incorporates a Packet-importance aware Mask Predictor (PMP) that uses packet-level side-channel statistics to dynamically mask tokens, achieving state-of-the-art performance across various encrypted traffic datasets.
By mixing flows and using a teacher-student approach, MMAE learns to classify encrypted traffic more accurately than previous masked autoencoders.
Network traffic classification using self-supervised pre-training models based on Masked Autoencoders (MAE) has demonstrated a huge potential. However, existing methods are confined to isolated byte-level reconstruction of individual flows, lacking adequate perception of the multi-granularity contextual relationship in traffic. To address this limitation, we propose Mean MAE (MMAE), a teacher-student MAE paradigm with flow mixing strategy for building encrypted traffic pre-training model. MMAE employs a self-distillation mechanism for teacher-student interaction, where the teacher provides unmasked flow-level semantic supervision to advance the student from local byte reconstruction to multi-granularity comprehension. To break the information bottleneck in individual flows, we introduce a dynamic Flow Mixing (FlowMix) strategy to replace traditional random masking mechanism. By constructing challenging cross-flow mixed samples with interferences, it compels the model to learn discriminative representations from distorted tokens. Furthermore, we design a Packet-importance aware Mask Predictor (PMP) equipped with an attention bias mechanism that leverages packet-level side-channel statistics to dynamically mask tokens with high semantic density. Numerous experiments on a number of datasets covering encrypted applications, malware, and attack traffic demonstrate that MMAE achieves state-of-the-art performance. The code is available at https://github.com/lx6c78/MMAE