UDA encrypted traffic detection method based on LLM enhancement

The LLM-enhanced unsupervised domain adaptive UDA framework addresses the performance degradation of encrypted traffic detection in complex network environments, achieving high-precision cross-domain feature alignment and detection, and improving the adaptability and stability of the detection model.

CN121000413APending Publication Date: 2025-11-21NANJING TECH UNIV
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202511046857.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-28
Publication Date
2025-11-21

AI Technical Summary

Technical Problem

Existing encrypted traffic detection methods suffer from significantly reduced detection performance when faced with complex real-world network environments. In particular, traditional methods struggle to adapt to situations such as changes in packet order caused by dynamic routing and fluctuations in latency and packet loss during long-distance transmission. Furthermore, UDA methods that rely on target domain labeled data suffer from semantic drift and noise pollution issues during feature alignment.

Method used

We adopt an unsupervised domain adaptive UDA framework based on LLM enhancement. By combining source domain labeled data and target domain unlabeled data with a cross-domain translator, cross-domain alignment network and LLM iterative optimizer, we construct a joint training framework. We utilize the deep semantic understanding capability of LLM and the feedback signal of UDA to achieve cross-domain feature alignment and optimization of the detection model.

Benefits of technology

High-precision encrypted traffic detection was achieved in real network environments with multiple offsets, improving the adaptability and stability of the detection model and significantly enhancing detection performance, especially in terms of accuracy and F1 score in feature offset scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121000413A_ABST
    Figure CN121000413A_ABST
Patent Text Reader

Abstract

A UDA encrypted traffic detection method based on LLM enhancement comprises the following steps: under a UDA framework, using a target domain model as a detection model of TLS encrypted traffic, and extracting network attack features from the encrypted traffic; the UDA framework is an LLM (Large Language Model) enhanced UDA framework, and comprises a Prompt-based cross-domain translator which is used for guiding LLM to carry out domain feature conversion between source domain label data and target domain label-free data; according to the cross-domain alignment network, original data and a cross-domain translation result serve as input, and a UDA detection model is trained based on task classification loss and cross-domain consistency loss; the UDA detection model comprises a source domain model and a target domain model; and the LLM iterative optimizer is used for pushing the LLM translation capability to be aligned to a training target of the UDA detection model under the guidance of the loss value. Experiments on a real encrypted traffic data set show that the accuracy and the F1 score of the method in a feature offset scene are improved by 2.45% compared with those of an advanced reference method.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of network security, and specifically relates to an unsupervised domain adaptation (UDA) encrypted traffic detection method based on LLM (Large Language Model) enhancement. BACKGROUND

[0002] With the wide application of traffic encryption means in Internet communication, the traditional malicious traffic detection method based on plaintext analysis is invalid because it cannot analyze the encrypted payload [1] . The existing encrypted traffic detection research is limited to idealized training scenarios, and when facing complex real environments (such as changes in packet order caused by dynamic routing, time delay and packet loss fluctuations in long-distance transmission, etc.), the detection performance is significantly reduced [2] . DL (Deep Learning) technology has shown significant advantages in encrypted traffic detection, but its model generalization ability is still restricted by the heterogeneity of network environments. Many semi-supervised learning [28,29] , transfer learning

[30] and other methods have been proposed to enhance the environmental adaptability of the detection model. However, empirical research has shown that when different degrees of feature distribution shift are superimposed on the time-varying detection environment, the detection accuracy of such traditional methods will still decrease significantly [2,31] . The root problem is that the feature representation system of the DL model has a mapping deviation between the training environment and the real scene. When the detection model encounters unknown network environments with heterogeneous traffic patterns or topological structures, the feature space constructed in the training phase is difficult to be effectively transferred. On the other hand, the existing encrypted traffic dataset contains relatively homogeneous environments, which is difficult to restore the complexity (such as multi-layer protocol encapsulation and payload encryption caused by VPN) and volatility (such as communication path switching caused by dynamic routing) of real network environments, making it difficult for the model to learn discriminative features with strong generalization ability, further exacerbating the detection performance degradation problem.

[0003] For the above problems, the traditional solution [6][7][8] usually fine-tunes the model in a targeted manner based on the labeled data of the target domain to improve its adaptability. However, the large-scale collection of target domain data involves privacy issues, and the annotation of the corresponding encrypted traffic samples also requires a large amount of human cost. To train a target domain detection model at low cost, a natural step is to introduce the UDA method. Based on the feature space distribution alignment strategy, UDA trains a high-performance model that meets the target domain environment by overcoming the feature shift between the source domain (training environment) and the target domain (actual deployment environment)

[14] The advantage is that it can transfer the knowledge contained in the source domain data without the need for target domain labeled data, especially for encrypted network traffic with high labeling costs. However, traditional UDA methods

[15]

[16]

[17]

[20] only rely on shallow feature alignment, and in the case of significant feature shifts between the source domain and the real network environment of the target domain, it is difficult to decouple the coupled representation of deep semantic information, surface statistical features, and domain noise in encrypted traffic.

[0004] The potential of LLM in cross-domain feature decoupling can make up for the data scarcity problem of UDA. Numerous studies

[11]

[12]

[13] have proven the feasibility of LLM generation from the perspective of cross-domain learning. This potential can continue to empower UDA. On the one hand, LLMs, after pre-training with hundreds of billions of parameters, exhibit strong semantic decoupling and contextual awareness, which can make up for the shortcomings of traditional UDA methods in deep semantic modeling. On the other hand, based on the deep understanding of data semantics, LLMs can generate high-quality cross-domain translation samples, not only enriching the pseudo-label samples of the target domain, but also optimizing the decision boundary through cross-domain features, effectively alleviating the limitations of the scarcity of target domain labeled data.

[0005] The deep semantic understanding ability of LLM obtained through pre-training can deeply decouple the coupled representation of protocol specifications, interaction behaviors, and network noise in encrypted traffic, thereby alleviating the "semantic drift" in the feature alignment process of traditional UDA methods. On the other hand, the prediction results of UDA are constrained by stable probability distributions, which helps to improve the stability of LLM output. Although LLM-enhanced UDA has great potential, due to the complexity of cross-domain features and the fluctuating nature of real network environments, there are many challenges in the design of the scheme, mainly:

[0006] 1) Deep cross-domain feature mapping of encrypted traffic. Traditional data cross-domain feature conversion methods [32,33] mainly rely on feature extraction and specific domain alignment strategies. However, the generated semantic information in encrypted traffic is difficult to capture, indirectly leading to the inability to align features. Traditional methods are also sensitive to domain changes, which often leads to a decrease in model performance [2] . Some researchers use LLM as a tool for deep cross-domain feature conversion. For example, CDTrans

[32] is a cross-domain classification method based on Transformer, which achieves feature alignment between the source domain and the target domain through the Cross-Attention mechanism and avoids the influence of noise. In the cross-domain communication network CoCosNet

[33] In the prior art, different domain inputs are mapped to a shared domain to establish a reliable dense correspondence relationship, which is then used to guide image translation. However, the application of LLM in vertical fields still has obvious limitations, mainly manifested as insufficient generalization ability and unstable output results. LLM may generate text with semantic deviation from the original data, or produce output characteristics that do not meet the requirements of the target domain, making it difficult to be directly used in professional scenarios.

[0007] 2) Consistency coordination of distribution alignment and classification. In the absence of target domain labels, UDA methods have difficulty in balancing feature distribution alignment and classification reliability, especially for sensitive features with overlapping benign and malicious traffic. Traditional UDA methods such as DANN

[34] and ADDA

[35] try to make the feature distributions of the source and target domains as close as possible, but have limitations in improving the reliability of classification decisions. When the difference between the feature distributions of the domains is too large, forced alignment can pollute the feature space, causing the performance of the classifier on the target domain to decline. Other methods such as SHOT

[36] and BAIT

[37] optimize the performance of the classifier through pseudo-label generation, etc. Although there is some improvement in classification consistency, the accuracy and reliability of the classifier are weakened due to the noise injected during the feature distribution alignment process.

[0008] 3) Persistence compensation for cross-domain feature mapping. Although LLMs exhibit excellent cross-domain generation capabilities, they still need to establish an integrated collaboration mechanism with UDA to align the optimization objectives of cross-domain translation strategies with UDA. However, existing joint designs of LLM and UDA are mostly "simple combinations" and do not form a persistent closed-loop effect. In the DAMP

[38] scheme, the knowledge of the pre-trained model is activated through mutual prompting, and visual and text embeddings are associated through feature alignment to achieve cross-domain knowledge transfer. In the PDA method proposed by Bai et al.

[39] , the prompts of the base branch are adjusted to enhance the model's discrimination ability, and the images in the alignment branch are used to guide feature adjustment, thereby reducing the feature distribution difference between the source and target domains. However, these methods are highly dependent on the quality and diversity of pre-training data and do not have a self-adjusting mechanism. SUMMARY

[0009] To address the above challenges, the present application proposes an LLM-enhanced UDA method for encrypted traffic detection to achieve high-precision encrypted traffic detection in real network environments with multiple offsets coexisting.

[0010] The application is based on source domain labeled data and target domain unlabeled data, and a joint training framework is constructed by combining the cross-domain translation data generated by LLM. In this way, the endogenous knowledge of LLM is used to make up for the shortcomings of UDA method in deep feature alignment, and the feedback signal of UDA is used to improve the stability and availability of LLM output. Under the guidance of cross-domain loss, the translation strategy of LLM gradually aligns with the cross-domain learning needs of UDA.

[0011] An UDA encrypted traffic detection method based on LLM enhancement, under the framework of unsupervised domain adaptation UDA, uses a target domain model as a detection model for TLS encrypted traffic to extract features of network attacks from encrypted traffic.

[0012] The UDA framework is a large language model LLM enhanced UDA framework, including the following modules:

[0013] Module one, cross-domain translator based on Prompt: used to guide LLM to convert domain features of source domain labeled data and target domain unlabeled data;

[0014] Module two, cross-domain alignment network: taking original data and cross-domain translation results as input, training UDA detection model based on task classification loss and cross-domain consistency loss; the UDA detection model includes a source domain model and a target domain model;

[0015] Module three, LLM iterative optimizer: under the guidance of loss value, promote the translation ability of LLM to align with the training target of UDA detection model.

[0016] The main contributions of the application are as follows:

[0017] 1) Source domain-target domain deep feature conversion strategy of encrypted traffic.

[0018] The unlabeled replay traffic in the target domain is used for pre-fine-tuning of LLM to learn the basic features of source domain and target domain data. The adaptive arrangement mechanism of Prompt is responsible for ensuring the semantic consistency, spatial matching degree and output specification of cross-domain mapping, avoiding the negative transfer effect and feature space mismatch problem in the traditional mapping process.

[0019] 2) Double-branch cross-domain parallel training strategy.

[0020] This strategy aims to coordinate the alignment of encrypted feature distribution and classification consistency under unsupervised training. Among them, the training of source domain (and target domain) detection model depends on source domain labeled (target domain unlabeled) traffic data and its cross-domain translation results. In addition to task loss, cross-domain consistency loss is introduced, and the joint optimization of double supervision signals is used to synchronize the constraints of distribution alignment and classification boundary.

[0021] 3) LLM fine-tuning driven adaptive closed-loop optimization method.

[0022] Under the guidance of UDA training loss, the LLM adaptively adjusts the generation strategy, thereby progressively aligning the optimization objectives of the UDA detection model. By controlling the number of cycles, a closed-loop iterative mechanism of "LLM cross-domain translation-model evaluation-LLM optimization" is formed.

[0023] In the experimental data set, the authoritative data set and its replay results in various real network environments are used as source domain data and target domain data. Experimental results verify the adaptability, effectiveness and superiority of the proposed method. At the same time, it is proved that the progressive alignment of LLM translation strategy to UDA model can continuously improve the detection performance, and can effectively adapt to various real-world network environments with multiple offsets. BRIEF DESCRIPTION OF DRAWINGS

[0024] Figure 1 An LLM-enhanced UDA framework is shown.

[0025] Figure 2 A bidirectional adaptive Prompt design for cross-domain translation is shown.

[0026] Figure 3 A cross-domain alignment network is shown.

[0027] Figure 4 An LLM-enabled unsupervised cross-domain joint training workflow is shown.

[0028] Figure 5 Cross-domain translation examples of packet length sequences are shown.

[0029] Figures 6(a) to 6(e) The accuracy of the proposed method using CNN in different test environments is shown, respectively, wherein: Fig. 6(a) corresponds to Test-Env-1, Fig. 6(b) corresponds to Test-Env-2, Fig. 6(c) corresponds to Test-Env-3, Fig. 6(d) corresponds to Test-Env-4, and Fig. 6(e) corresponds to Test-Env-3.

[0030] Figures 7(a) to 7(e) The accuracy of the proposed method using DF in different test environments is shown, respectively, wherein: Fig. 7(a) corresponds to Test-Env-1, Fig. 7(b) corresponds to Test-Env-2, Fig. 7(c) corresponds to Test-Env-3, Fig. 7(d) corresponds to Test-Env-4, and Fig. 7(e) corresponds to Test-Env-3.

[0031] Figures 8(a) to 8(e)Accuracy of the proposed method using Transformer in differentiated test environments, respectively, wherein: Fig. 8(a) corresponds to Test-Env-1, Fig. 8(b) corresponds to Test-Env-2, Fig. 8(c) corresponds to Test-Env-3, Fig. 8(d) corresponds to Test-Env-4, and Fig. 8(e) corresponds to Test-Env-3. DETAILED DESCRIPTION

[0032] 1. SUMMARY

[0033] In real network environments, network traffic feature distributions are susceptible to multi-factor interference. In addition to problems such as packet loss, latency, dynamic routing, and TCP (Transmission Control Protocol) cross-network transmission, factors such as VPN (Virtual Private Network) technology and network device configuration also cause different degrees of distribution disturbance in the feature space. Many detection models degrade in performance in such scenarios, and the detection accuracy is negatively correlated with the degree of feature shift. To address the case of significant feature distribution shift in real network environments,

[0034] The present application proposes an LLM (Large Language Model) enhanced unsupervised domain adaptation (UDA) framework that improves detection model accuracy through a semantic-driven cross-domain alignment mechanism. First, a source-target cross-domain translator is constructed. To this end, a real replay traffic pre-fine-tuned LLM is used to learn the basic representation of cross-domain feature conversion. Subsequently, the Prompt engineering guides the LLM to convert data features between the source domain and the target domain while preserving their core semantics. Second, to alleviate the conflict between traditional domain adaptation in feature alignment and classification consistency, a multi-loss constraint parallel cross-domain alignment network is designed. In this network, task loss and cross-domain consistency loss are used to train the detection model to achieve a balance between distribution alignment and classification boundary. The UDA loss is used to analyze the distribution matching degree of the LLM bidirectional translation data, and the LLM generation strategy is dynamically adjusted based on the results. The optimized LLM generation strategy further improves the detection capability of the UDA model. This mutual promotion process is connected at the beginning and end to form a closed loop optimization. Experiments on real encrypted traffic data sets show that the proposed framework improves the accuracy and F1 score by 2.45% compared with the advanced baseline method in the feature shift scenario.

[0035] 2. LLM-enhanced UDA architecture

[0036] The proposed framework, as shown in Figure 1 includes the following functional modules:

[0037] 1) Prompt-based cross-domain translator: responsible for guiding the LLM to realize the domain feature conversion of source domain labeled data and target domain unlabeled data;

[0038] 2) Cross-domain alignment network: taking the original data and cross-domain translation results as input, training the detection model based on task classification loss and cross-domain consistency loss;

[0039] 3) LLM iterative optimizer: constantly promotes the translation ability of LLM to align with the training target of UDA model under the guidance of loss value.

[0040] 2.1 Prompt-based cross-domain translator

[0041] Under the driving of LLM, the cross-domain translator is responsible for bidirectional conversion of traffic features between the source domain and the target domain, and comprehensively considers the training efficiency, computing resources and model performance boundaries. Since LLM completes the specified task of the user in the form of text interaction, the structured Prompt engineering framework is used to process the input data packet length sequence. In addition to adhering to general rules such as accuracy, simplicity and strong guidance, the Prompt design must also distinguish between the feature domain of the input data and the direction of the translation task, avoiding confusion between the source domain and the target domain.

[0042] Following the above rules, the present application arranges two types of Prompt in Figure 2 to guide the LLM to output high-fidelity cross-domain translation results. This design aims to build a bidirectional adaptive Prompt mechanism, guiding the LLM to recognize the domain features and migration direction of the input data through forward Prompt (source domain to target domain) and backward Prompt (target domain to source domain), thereby establishing the LLM's cognitive framework for inter-domain feature mapping. The highlighted part is the key guiding word. When LLM needs to perform a translation task, the dynamic routing mechanism automatically selects the translation path according to the input data packet length sequence. If the input data belongs to the source domain (target domain), the DATA in the forward (backward) Prompt is replaced with the corresponding data, which is then input into the LLM. This not only avoids the direction confusion problem that may be caused by traditional fixed Prompt mechanism, but also enhances the robustness of LLM output through double-channel information complementation.

[0043] 2.2 Cross-domain alignment network

[0044] In the proposed framework, the input data is divided into source domain and target domain. To utilize the knowledge contained in the cross-domain translator, the loss of the TLS traffic detection model on labeled data and unlabeled data is calculated by the data of the two domains. Although the original traffic and translated traffic in the two different domains have different styles, the prediction results obtained from the respective detection models are consistent

[18]

[19]

[21] To ensure consistent predictions from detection models across different domains, both task classification loss and cross-domain consistency loss are introduced.

[0045] like Figure 3 As shown, during training, both the input labeled source domain dataset and the unlabeled target domain dataset are divided into M batches, each batch containing I data points. The i-th data point in the m-th batch of the labeled source domain dataset and its label are represented as (S... m,i ,y m,i The i-th data point in the m-th batch of the unlabeled dataset in the target domain is represented as T. m,i Let G(x,f) be the translation result generated by the cross-domain translator for the input data x and the domain label f ​​(0 and 1 represent forward and backward directions). m,i With T m,i The translation output is represented as S′ m,i =G(S m,i ,0) and T m ′ ,i =G(T) m,i 1). Source and target domain data are used to train their respective encrypted traffic detection models. Let P1(y|x) and P2(y|x) be the predicted class distributions generated by the source and target domain detection models for input x, respectively. The cross-entropy between the two probability distributions is denoted as H(·,·). The cross-entropy loss of the m-th batch in the source domain labeled dataset is calculated as...

[0046]

[0047] Considering the target domain data is unlabeled, we introduce cross-domain consistency loss to align the feature distributions of the two models, thereby encouraging the target domain model to generate accurate predictions. The bidirectional Kullback-Leibler divergence loss for the m-th batch in the unlabeled target domain dataset is calculated as follows:

[0048]

[0049] The training objective of the source and target domain detection model is to minimize Where λ is the weight hyperparameter.

[0050] 2.3 LLM Iterative Optimizer

[0051] There is an essential difference between forward and backward translation in cross-domain translation tasks. Both rely on the same LLM, but forward and backward translation not only have different input and output characteristics, but their application scenarios also have significant differences in translation strategy requirements. This difference in functional positioning means that there are different needs for LLM adjustment direction and optimization amplitude. Therefore, it is necessary to design a separate fine-tuning framework to decouple the forward and backward translation modules and provide differentiated translation optimization solutions.

[0052]

[0053] The present application improves the weight distribution strategy of TIES

[23] and develops an LLM iterative optimizer to quantitatively optimize the generation strategy of the same LLM for two different tasks. To reduce the coupling between forward and backward translation tasks, the iterative optimizer involves the combined fine-tuning of three homologous derived LLMs. The specific operation is summarized as Algorithm 1. Taking Figure 1 as an example, assume that LLM 1, LLM2 and LLM 3 are fine-tuned from the same original LLM, and the corresponding trainable parameters are θ1, θ2, θ3 and θ0. Among them, θ1 and θ2 are the results of targeted fine-tuning for different generation tasks, and the optimization result produced by the previous iteration is represented as θ3. The task update vectors corresponding to the three derived LLMs are represented as

[0054]

[0055] By performing pruning and decomposition operations (see lines 2-4), the task vector and the corresponding sign vectors γ1, γ2, γ3 and amplitude vectors η1, η2, η3 can be obtained. Let and The combined task vector is φ, and the corresponding sign vector is γ. The vth element of γ is calculated as

[0056] σ=max(E (h) ,1). The hth element of φ is calculated as

[0057]

[0058] where λ1, λ2, λ3 are the weights of θ1, θ2, θ3, respectively, determined by the minimum loss values defined in equations (1) and (2). The trainable parameters of the combined LLM are represented as θ=θ0+αφ, where α is the scaling hyperparameter.

[0059] 3. Unsupervised cross-domain joint training enabled by LLM

[0060] Based on the proposed architecture, a joint training procedure is designed in this subsection. In Figure 4 Under the joint design framework of LLM and UDA, the training loss guided joint training is used to promote the LLM generation strategy to gradually align with the UDA optimization goal. The joint training procedure of the detection model and the LLM mainly includes:

[0061] 1) Translator pre-fine-tuning: The knowledge reserve of the general LLM on encrypted traffic cannot meet the actual application requirements. The fine-tuning data of forward and backward translation comes from encrypted traffic data and its retransmission results. These data are used to fine-tune the original LLM, so that it has the initial ability of cross-domain translation.

[0062] 2) Consistency learning for cross-domain feature reconstruction: Through the cross-domain translator, the source domain label data and the target domain unlabel data are mapped to the feature space of another domain. The original data and the translation results are then input into the cross-domain alignment network. Task loss and cross-domain consistency loss are introduced into the training of the source domain and target domain detection model, thereby synchronously constraining the distribution alignment and classification boundary.

[0063] 3) Fine-tuning driven UDA closed-loop optimization: The pre-fine-tuned LLM is used for cross-domain translation to ensure the authenticity and feature consistency of the training data; the task classification loss and cross-domain consistency loss of the cross-domain alignment network reversely guide the weighted combination and fine-tuning of the LLM parameters, thereby updating its translation strategy. Through multiple iterations, the cross-domain translation results of the LLM gradually align with the optimization goal of the UDA model.

[0064] 3.1 Translator pre-fine-tuning

[0065] To strengthen the cross-domain translation ability, the bidirectional replay results of the encrypted traffic data in the source domain and target domain network environment become the pre-fine-tuning corpus of the LLM. Before replay, the traffic data is preprocessed, that is, reordered according to the timestamp and repeated data packets are deleted. The replay process considers the changes in the geographical location and access network type of the sender and receiver to obtain samples under complex environments (which can reflect the behaviors of packet recombination, segmentation, repetition, out-of-order, etc.) to ensure that the data retains valid information, especially to reflect the real network behavior. The replay trajectory of each network stream in the dual-domain environment is processed as a data packet length sequence, which is finally converted into Figure 5 The structured Question&Answer data pair shown in the figure. The fine-tuning method adopts LoRA

[10] .

[0066] Considering the bidirectionality and knowledge-intensive nature of the translation task, the pre-fine-tuning data is differentiated. To meet the translation needs from the source domain to the target domain, the Question field carries the packet length sequence generated in the source domain network environment, and the Answer field corresponds to the replay result in the target domain environment; conversely, in the translation task from the target domain to the source domain, the position of the packet length sequence is reversed. Under the directional translation mechanism, the requirement description in the pre-fine-tuning data is strictly distinguished, guiding the LLM to establish the mapping relationship between the environmental characteristics and the translation direction.

[0067] To ensure the normativity of data generation, all expression templates of Question follow the Prompt framework defined in Section 2.1, which constrains the output structure of the model through standardized input format, ensuring that the pre-fine-tuned LLM can consistently generate standard format Answer output when receiving standardized Question input.3.2 Consistency learning for cross-domain feature reconstruction

[0068] As shown in Figure 4 , the labeled source domain data and unlabeled target domain data are respectively embedded in the translation guide Prompt of a specific direction to construct the complete cross-domain conversion request of encrypted network traffic. The corresponding request is input into the cross-domain translator to generate encrypted traffic samples with another domain feature. The source domain (target domain) traffic presents the target domain (source domain) feature after forward (backward) translation. The generated traffic is input into the cross-domain alignment network. In the source domain branch, the original labeled source domain data and its backward translation result are used to train the source domain detection model. On the contrary, in the target domain branch, the original unlabeled target domain data and its forward translation result are used to train the target domain detection model.

[0069] The loss function of the training process considers consistency constraints (1) and (2). Cross-domain translation changes the feature distribution of encrypted traffic, but the discriminative features that carry semantics should remain unchanged. This invariance assumption helps to alleviate the prediction distribution shift caused by the unlabeled target domain.

[0070] Considering the high time cost brought by more training rounds and training data, we introduce a dynamic translation frequency strategy. Let B be the total number of training rounds, and the number of retranslations is represented as

[0071]

[0072] k is configurable. Between every two translation tasks, the training of the detection model always uses the same translation data. For a fixed B, when k = 1 (i.e., retranslate the data every round of training) the data set quality is the highest, but it is accompanied by high time cost. Appropriately increasing the value of k can reduce the number of translations T, thereby balancing the detection effect and training efficiency.3.3 Fine-tuning driven closed-loop domain adaptation

[0073] This subsection designs a LLM fine-tuning mechanism for cross-domain translation, which contains a loss-aware dynamic weight strategy. Based on equation (1) and equation (2), it is assumed that (S m,i ,y m,i ) and T m,i correspond to the losses respectively and The original dataset and the loss value set are denoted as

[0074]

[0075] Let f (initial value is 0) be the current completed joint fine-tuning round, and T be the preset fine-tuning round. The system will perform a conditional judgment every time a new fine-tuning is performed. When f < T, a new round of LLM fine-tuning process is triggered, otherwise, the training is terminated. The purpose of this joint fine-tuning strategy is to promote the coordination of LLM and cross-domain alignment network. In this process, through loss-guided LLM fine-tuning, the generation strategy of cross-domain translation LLM gradually approaches the optimization goal of UDA model, and finally realizes the closed-loop optimization of the two. The specific implementation details are summarized as algorithm 2, which contains the following three key steps:

[0076] 1) Forward and backward separated targeted fine-tuning. This step fine-tunes the forward and backward translation capabilities of the pre-trained LLM in the cross-domain translator. Due to training needs, every k training rounds, the forward and backward translation results of the original dataset are automatically generated by the training framework. These data are also used to construct the fine-tuning dataset, which is divided into two groups according to the translation direction, as shown in the format Figure 5 . Among them, Question fills in the original data, and Answer fills in the corresponding translation results (see line 6) within each k training. The fine-tuning method uses LoRA

[10] . The fine-tuning dataset for forward and backward translation is denoted as and θ0 is fine-tuned to θ1 and θ2 (see line 10).

[0077] 2) Weighted merging of LLM features. which can reflect the accuracy of cross-domain translation, is used to evaluate the quality of the fine-tuning dataset, and determine the merging weights of θ1, θ2 and θ3. LLMs with low values are given high weights to retain high available translation strategies. LLMs with high values are also assigned appropriate weights to stimulate new translation patterns. In each k training, the of the last round is used to measure the performance index of θ1 and θ2, which are calculated as

[0078]

[0079] w3 is the performance index corresponding to θ3. θ3 was not initialized during the first round of joint fine-tuning, therefore w3 was set to 0. λ1, λ2, and λ3 were normalized to... and (See line 11). Algorithm 1 is called, and θ1, θ2, and θ3 are merged into θ (see line 12). At this point, the LLM completes the (f+1)th iteration alignment with the UDA model.

[0080] 3) Continuous iteration of the LLM and UDA models. After each iteration, θ3 is updated to θ, and w3 is updated to λ1w1+λ2w2+λ3w3 (see lines 13-14). The translation operation of LLM 3 is represented as G2(x,f), which is used to update the training set for the next k rounds of training (see lines 16-21). When the kth round of training is completed, the joint fine-tuning process is restarted (see lines 22-23). ​​This continuous fine-tuning mechanism applies throughout the training cycle, ensuring that the cross-domain translator and the UDA objective always evolve in sync, ultimately forming a self-reinforcing and sustainable closed loop.

[0081]

[0082]

[0083] 4. Experimental Preparation

[0084] 4.1 Selection of Experimental Data

[0085] Table 1 TLS Encrypted Traffic Test Environment

[0086]

[0087] Table 2 TLS Encrypted Traffic Replay Environment

[0088]

[0089] Let's assume the CIRA-CIC-DoHBrw-2020 dataset is used.

[24] The data collection environment was the source domain, from which 5,000 class-balanced (1:1 ratio) label data were randomly extracted and used as training data. Test-Env-1 to -5 were set as the target domain environment, and the environment configuration is shown in Table 1. We used the replay CIRA-CIC-DoHBrw-2020...

[24] This method aims to obtain data within the target domain's network environment. It references existing research. [3,4,5,25]The length of the first 100 packets of each network flow is extracted as the data sequence in the experimental setup, and sequences with less than 100 packets are padded with zeros. The sender host uses different network access methods such as Ethernet, Wi-Fi, and 5G. TCP socket (https: / / docs.python.org / 3 / library / socket.html) is used to establish connections in multiple real network environments, and tcpdump (https: / / www.tcpdump.org / ) is used to capture the retransmitted flow. The experimental platform covers local area networks and remote cross-country environments. This configuration helps to evaluate the performance of the model in real networks. Each target domain contains 20,000 unlabeled training data and two independent validation and test sets (2,000 each with a 1:1 class ratio), and each target domain dataset is derived from the same batch of original traffic. It should be noted that there is no intersection between the original traffic corresponding to the source and target domain datasets to avoid early access to the answer.

[0090] The pre-fine-tuning dataset of the LLM in the cross-domain translator is collected from the environments listed in Table 2. First, 100,000 client access traffic as source domain data is captured, and then replayed across environments 1-5 to generate paired data with domain migration characteristics. Each set of paired data is combined with the forward or backward prompt shown in Table 2 to generate pre-fine-tuning data. To form a balanced pre-fine-tuning dataset, the forward prompt and the reverse prompt process data at a 50% ratio. It should be emphasized that the pre-fine-tuning dataset is completely independent of the training and testing environment, and is designed to eliminate prior knowledge that may exist in cross-domain translation data, thereby fairly evaluating the adaptability of the proposed method in the specified network environment. Figure 5

[0091] 4.2 Training and testing environment setup

[0092] The proposed method is implemented based on the PyTorch library and uses the Stochastic Gradient Descent (SGD) algorithm to update model parameters. The server used for model training is equipped with an Intel Core i9-14900K processor, 64GB DDR5 5200MHz memory, a 4TB PCIe 4.0 solid state drive, a ASUS PRIME Z790-P WIFID5 motherboard, and two Gigabyte RTX 4090 24GB WindForce graphics cards. The training server serves as the sender host, and the receiver host is a rented Vultr server with 2 vCPUs (3GHz + Intel Xeon CPU), 2GB of memory, and 80GB of NVMe SSD. ​

[0093] Qwen-7B

[26] The initial LLM selected as the pre-fine-tuning stage. Data augmentation is accelerated using the official open-source batch inference scheme. Both LLM pre-fine-tuning and fine-tuning contain 5 training rounds, with a learning rate of 0.0003, and gradients accumulated for 8 mini-batches before each parameter update. LLaMA Factory

[27] The toolkit is used to implement LLM fine-tuning based on LoRA

[10] .

[0094] To support domain adaptation tasks, the LLM fine-tuning environment is configured specifically. In the special fine-tuning stage before model merging (corresponding to process one in section 3.3), the proposed method needs to optimize the forward and backward translation capabilities of the pre-fine-tuned LLM respectively. This process must ensure that the fine-tuning hyperparameters of the two models (such as learning rate, training batch size, etc.) are strictly consistent. Since the replacement of the backbone detection model directly affects the training requirements, the total training rounds B need to be adjusted synchronously. k is set to Bring this value into equation (5), we can get T = 5. The detailed training parameter settings are shown in Table 3.

[0095] Table 3 Default parameter settings

[0096]

[0097] 4.3 Evaluation indicators and baseline models

[0098] The accuracy (Accuracy) and F1 value (F1-Score) double-index evaluation system is used for quantitative analysis and evaluation of the performance of the TLS malicious encrypted traffic detection method, that is,

[0099]

[0100] and

[0101]

[0102] The former represents the basic measure of the correct detection ratio. The latter balances precision and recall by True Positives (TP), True Negatives (TN), False Positives (FP), and False Negatives (FN), providing a more comprehensive evaluation.

[0103] According to the characteristics of the domain adaptation detection task, in the cross-domain alignment network, the source domain detection model is fixedly used CNN [3 ,4] and the training parameters remain unchanged, and the target domain detection model is replaced with CNN [3,4] , DF[5] and Transformer [9] Three backbone networks were used to verify the universality of the proposed method under different detection architectures.

[0104] The proposed method possesses a degree of openness and customizability. Based on different target domain backbone networks, fine-tuning, and training strategies, we combined them into six schemes as shown in Table 4 to observe the effectiveness of each module. Proposed-1, -2, and -3 employ cross-domain alignment networks and cross-domain translators, while Proposed-4, -5, and -6 apply a complete LLM-enhanced UDA framework. This hierarchical comparative design clearly demonstrates the performance gain effect of multi-round joint fine-tuning on detection performance.

[0105] Classification of the methods proposed in Table 4

[0106]

[0107] The benchmark methods are shown in Table 5, comprising 15 methods across three main categories, covering the mainstream technical paradigms in the field of encrypted traffic detection. Baselines -1, -6, and -11 serve as basic reference groups, employing traditional supervised learning strategies to train detection models, visually demonstrating the performance improvements of each method. Baselines -2, -7, and -12 rely on FixMatch.

[22] The framework implements SSL. Baseline-3, -8, and -13 introduce Rosetta. [2] To compare the proposed method with advanced encrypted traffic generalization detection methods. Baseline-4, -9, and -14 employ KTDA-based methods.

[40] A semi-supervised domain adaptation method. This is a state-of-the-art DA method in the field of traffic detection, where the proportion of target domain labeled data during the training phase is set to 1%. Baselines -5, -10, and -15 employ DAN-pInverse.

[41] A UDA traffic detection method is implemented to compare the proposed method with state-of-the-art methods using the same training modulus. All benchmark experiments adhere to the principle of consistent source domain detection network parameters. Depending on experimental requirements, the target domain detection network can be optionally configured as a CNN. [3,4] DF [5] or Transformer [9] These differentiated configuration schemes were used to evaluate the validity of the conclusions and the compatibility of the proposed framework with different components.

[0108] Table 5 Classification of Benchmark Methods

[0109]

[0110] Table 6 shows the detection results of various methods using CNN.

[0111]

[0112] Table 7. Detection results of various methods using DF.

[0113]

[0114] Table 8 shows the detection results of various methods using Transformer.

[0115]

[0116] Performance Evaluation

[0117] 5.1 The effectiveness of multi-round sustainable iteration

[0118] To investigate the impact of the joint fine-tuning strategy on the model's cross-domain adaptability, the target domains for the iterative comparative experiments were set to Test-Env-1 to -5 as shown in Table 1, and the comparison methods are shown in Table 5. The test results after each iteration are as follows: Figures 6(a) to 8(e) As shown, the joint fine-tuning strategy clearly enhances the performance of the target domain detection model. In Test-Env-1 and Test-Env-2, the final performance of joint fine-tuning (Proposed-4, -5, -6) is similar to that of non-joint fine-tuning (Proposed-1, -2, -3). However, in the target domain environments Test-Env-3, -4, and -5, where feature shifts are more significant, the joint fine-tuning strategy demonstrates a clear advantage. Using average accuracy as the evaluation metric, Proposed-4, -5, and -6 achieve improvements of 3.11%, 3.92%, and 3.19% compared to Proposed-1, -2, and -3, respectively. The F1 score also shows a consistent trend.

[0119] By analyzing the change trend of detection performance (Fig. 7(c), (e) and Fig. 8(e)), we find that the strategies without joint fine-tuning (Proposed-1, -2, -3) show a non-monotonic phenomenon of first decline and then rebound (or temporary stagnation) in the iteration process. This fluctuation is due to the target mismatch between LLM and UDA model. Especially in the absence of alignment constraints in cross-domain translation, the feature distribution of generated data presents strong randomness, making it difficult for the detection model to extract effective information from it. In contrast, Proposed-4, -5, -6 with progressive joint fine-tuning always maintain a monotonic upward trend during training, significantly accelerating the convergence speed, and breaking through the performance upper limit of Proposed-1, -2, -3. A notable detail is that in the absence of joint fine-tuning, performance decay occurs in the later training period (see Fig. 6(b), Fig. 7(a), (b), (c), (d) and Fig. 8(b)). An important reason is that unaligned cross-domain translation may induce UDA model to overfit to pseudo features. Under the proposed scheme, joint fine-tuning prompts LLM to update the translation strategy, so that the feature complexity of generated data dynamically adapts to the current knowledge absorption capacity of UDA model, preventing the reduction of training effect due to the mismatch between data and learning ability.

[0120] By perceiving the training state of UDA model, the proposed coordination can adaptively adjust the feature complexity of LLM cross-domain translation data. Test results in different target domain environments (see Figures 6(a) to 6(e) 、 Figures 7(a) to 7(e) 、 Figures 8(a) to 8(e) ) show that this joint fine-tuning strategy has a significant effect in suppressing overfitting and underfitting, and promotes the rapid convergence of UDA detection model in the target domain network environment. When using F1 score as the evaluation indicator, the change trend is basically consistent with the above findings.

[0121] 5.2 Adaptability analysis for different target domains

[0122] This subsection investigates the adaptability of each scheme under different target domains (real network environment switching). The results of training under five types of heterogeneous network environments, Test-Env-1 to Test-Env-5, are summarized in Tables 6, 7, and 8. The average detection accuracy of the Rosetta method enhanced based on TCP awareness in the five unknown environments is 75.35%. The DAN-pInverse strategy improves this index by 14.58%. However, in Test-Env-4, an environment where multiple significant feature shifts coexist, due to factors such as unstable network access (high packet loss rate, delay fluctuation), complex communication path (multi-level network spanning, frequent route changes), etc., although the average detection accuracy of DAN-pInverse is much higher than Rosetta's 63.13%, reaching 85.38%, it still needs further optimization. The proposed method not only improves accuracy but also exhibits satisfactory stability, with an average accuracy and F1 score of 92.38% and 92.34% in the five environments, and an average accuracy of 90.99% in Test-Env-4, significantly better than traditional supervised learning, semi-supervised learning, and current mainstream methods such as Rosetta, KTDA, and DAN-pInverse benchmark schemes.

[0123] Specifically, the performance improvement of the proposed method (Proposed-4, -5, -6) compared to different benchmark schemes shows three levels of large, medium, and small. More than 20% is the large level, between 10% and 20% is the medium level, and less than 10% is the small level. The large level includes traditional supervised learning (Baseline-1, -6, -11) and semi-supervised FixMatch method (Baseline-2, -7, -12), compared to these two types of methods, the average accuracy of the proposed scheme is improved by 26.5% and 25.15%, and the average F1 score is also improved by 35.35% and 31.89%, respectively; Rosetta method (Baseline-3, -8, -13) is in the medium level, and the average accuracy and F1 score of the proposed method are improved by 17.02% and 17.72% compared to it; the small level includes KTDA-based schemes (corresponding to Baseline-4, -9, -14) and DAN-pInverse-based schemes (corresponding to Baseline-5, -10, -15), compared to these two types of methods, the average accuracy is improved by 0.88% and 2.45%, and the average F1 score is improved by 0.89% and 2.46%, respectively.

[0124] Notably, in Test-Env-1 and Test-Env-2, the average accuracy of the proposed method is 94.74%, slightly lower than KTDA's 96.13% and DAN-pInverse's 94.78%. But in the complex scenarios of Test-Env-3, -4, -5, the proposed method leads overall except for a slight 0.09% gap in Test-Env-4 compared to Baseline-14. This differential performance confirms the effective environment adaptation mechanism of the proposed method. Compared with other methods, the performance fluctuation of the proposed method between Test-Env-1, -2 and Test-Env-3, -4, -5 is significantly reduced, with the lowest detection accuracy of 89.73% in five network environments, an increase of 5.37% and 7.56% compared with the best KTDA (84.36%) and DAN-pInverse (82.17%) respectively. In the verification experiment of feature offset network environment, the proposed method shows reliable encrypted traffic detection stability and potential for real-time accurate detection in real network environment.

[0125] 6. Summary

[0126] This paper proposes an LLM enhanced UDA method, aiming to achieve low-cost and reliable encrypted traffic detection in real network environments with significant feature distribution shifts. The method guides LLM to perform deep semantic conversion on source and target domain traffic data by designing Prompt engineering, generating translated data with consistent cross-domain features. On this basis, a parallel cross-domain alignment network driven by original data and translated data is constructed, which can achieve simultaneous improvement of feature alignment and classification consistency by jointly optimizing classification task loss and cross-domain consistency loss. In addition, through the introduction of dynamic feedback mechanism, a closed-loop domain adaptation driven by fine-tuning is formed. The iterative optimizer uses model training loss to guide LLM to adjust the translation strategy, promoting the closed-loop iterative optimization of LLM and UDA model. The experiment uses encrypted traffic data sets in real network environments, and the results show that the proposed method has obvious performance improvement compared with traditional supervised learning, semi-supervised learning and current mainstream Rosetta, KTDA and DAN-pInverse methods, which can effectively make up for the short board of encrypted traffic detection in multiple feature offset coexisting scenarios.

[0127] 7. References

[0128] [1] Lin X, Xiong G, Gou G, et al. Et-bert: A contextualized datagram representation with pre-training transformers for encrypted traffic classification [C] / / Proceedings of the ACM Web Conference 2022. 2022: 633-642.

[0129] [2] Xie R, Wang Y, Cao J, et al. Rosetta: Enabling robust tls encrypted traffic classification in diverse network environments with tcp-aware traffic augmentation [C] / / Proceedings of the ACM Turing Award Celebration Conference-China 2023. 2023: 131-132.

[0130] [3] Rimmer V, Preuveneers D, Juarez M, et al. Automated website fingerprinting through deep learning [J]. arXiv preprint arXiv: 1708.06376, 2017.

[0131] [4] Shen M, Liu Y, Zhu L, et al. Fine-grained webpage fingerprinting using only packet length information of encrypted traffic [J]. IEEE Transactions on Information Forensics and Security, 2020, 16: 2046-2059.

[0133] [5] Sirinam P, Imani M, Juarez M, et al. Deep fingerprinting: Undermining website fingerprinting defenses with deep learning [C] / / Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security. 2018: 1928-1943.

[0134] [6] Bazuhair W, Lee W. Detecting malign encrypted network traffic using perlin noise and convolutional neural network [C] / / Proceedings of the 2020 10th Annual Computing and Communication Workshop and Conference (CCWC). IEEE, 2020: 0200-0206.

[0135] [7] Yao H, Liu C, Zhang P, et al. Identification of encrypted traffic through attention mechanism based long short term memory [J]. IEEE Transactions on Big Data, 2019, 8(1): 241-252.

[0136] [8] Aceto G, Ciuonzo D, Montieri A, et al. DISTILLER: Encrypted traffic classification via multimodal multitask deep learning [J]. Journal of Network and Computer Applications, 2021, 183: 102985.

[0138] [9] Vaswani A, Shazeer N, Parmar N, et al. Attention is all you need[J]. Advances in Neural Information Processing Systems, 2017, 30.

[0139]

[10] Hu E J, Shen Y, Wallis P, et al. Lora: Low-rank adaptation of large language models[J].

[0140] ICLR, 2022, 1(2): 3.

[0141]

[11] Alayrac J B, Donahue J, Luc P, et al. Flamingo: a visual language model for few-shot learning[J]. Advances in Neural Information Processing Systems, 2022, 35: 23716-23736.

[0142]

[12] Radford A, Kim J W, Xu T, et al. Robust speech recognition via large-scale weak supervision[C] / / Proceedings of the International Conference on Machine Learning. PMLR, 2023: 28492-28518.

[0144]

[13] Team G, Anil R, Borgeaud S, et al. Gemini: a family of highly capable multimodal models[J].

[0145] arXiv preprint arXiv:2312.11805, 2023.

[0146]

[14] Ben-David S, Blitzer J, Crammer K, et al. A theory of learning from different domains[J].

[0147] Machine Learning, 2010, 79: 151-175.

[0148]

[15] Chang W G, You T, Seo S, et al. Domain-specific batch normalization for unsupervised domain adaptation [C] / / Proceedings of the IEEE / CVF Conference on Computer Vision and Pattern Recognition. 2019: 7354-7362.

[0149]

[16] Ganin Y, Lempitsky V. Unsupervised domain adaptation by backpropagation [C] / / Proceedings of the International Conference on Machine Learning. PMLR, 2015: 1180-1189.

[0150]

[17] Zhuang F, Cheng X, Luo P, et al. Supervised representation learning: Transfer learning with deep autoencoders [C] / / Proceedings of the IJCAI. 2015, 15: 4119-4125.

[0151]

[18] Liu M Y, Tuzel O. Coupled generative adversarial networks [J]. Advances in Neural Information Processing Systems, 2016, 29.

[0152]

[19] He D, Xia Y, Qin T, et al. Dual learning for machine translation [J]. Advances in Neural Information Processing Systems, 2016, 29.

[0153]

[20] Zhu J Y, Park T, Isola P, et al. Unpaired image-to-image translation using cycle-consistent adversarial networks [C] / / Proceedings of the IEEE International Conference on Computer Vision. 2017: 2223-2232.

[0154]

[21] Chen Y C, Lin Y Y, Yang M H, et al. Crdoco: Pixel-level domain transfer with cross-domain consistency [C] / / Proceedings of the IEEE / CVF Conference on Computer Vision and Pattern Recognition. 2019: 1791-1800.

[0155]

[22] Sohn K, Berthelot D, Carlini N, et al. Fixmatch: Simplifying semi-supervised learning with consistency and confidence [J]. Advances in Neural Information Processing Systems, 2020, 33: 596-608.

[0157]

[23] Yadav P, Tam D, Choshen L, et al. Ties-merging: Resolving interference when merging models [J]. Advances in Neural Information Processing Systems, 2023, 36: 7093-7115.

[0158]

[24] Montazeri Shatoori M, Davidson L, Kaur G, et al. Detection of doh tunnels using time-series classification of encrypted traffic [C] / / Proceedings of the 2020 IEEE Intl Conf on Dependable, Autonomic and Secure Computing, Intl Conf on Pervasive Intelligence and Computing, Intl Conf on Cloud and Big Data Computing, Intl Conf on Cyber Science and Technology Congress (DASC / PiCom / CBDCom / CyberSciTech). IEEE, 2020:63-70.

[0159]

[25] Wang X, Chen S, Su J. App-net: A hybrid neural network for encrypted mobile traffic classification [C] / / Proceedings of the IEEE INFOCOM 2020-IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS). IEEE, 2020:424-429.

[0160]

[26] Bai J, Bai S, Chu Y, et al. Qwen technical report [J]. arXiv preprint arXiv:2309.16609, 2023.

[0161]

[27] Zheng Y, Zhang R, Zhang J, et al. Llama factory: Unified efficient fine-tuning of 100+ language models [J]. arXiv preprint arXiv:2403.13372, 2024.

[0163]

[28] Zhao R, Deng X, Yan Z, et al. Mt-flowformer: A semi-supervised flow transformer for encrypted traffic classification [C] / / Proceedings of the 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining. 2022:2576-2584.

[0164]

[29] Wang P, Wang Z, Ye F, et al. Bytesgan: A semi-supervised generative adversarial network for encrypted traffic classification in SDN edge gateway [J]. Computer Networks, 2021, 200:108535.

[0166]

[30] Singh A, Mushtaq Z, Abosaq H A, et al. Enhancing ransomware attack detection using transfer learning and deep learning ensemble models on cloud-encrypted data [J]. Electronics, 2023, 12(18):3899.

[0168]

[31] Papadogiannaki E, Ioannidis S. A survey on encrypted network traffic analysis applications,

[0169]

[32] Xu T, Chen W, Wang P, et al. Cdtrans: Cross-domain transformer for unsupervised domain adaptation[J]. arXiv preprint arXiv:2109.06165, 2021.

[0170]

[33] Zhang P, Zhang B, Chen D, et al. Cross-domain correspondence learning for exemplar-based image translation[C] / / Proceedings of the IEEE / CVF Conference on Computer Vision and Pattern Recognition. 2020: 5143-5153.

[0171]

[34] Ajakan H, Germain P, Larochelle H, et al. Domain-adversarial neural networks[J]. arXiv preprint arXiv:1412.4446, 2014.

[0172]

[35] Tzeng E, Hoffman J, Saenko K, et al. Adversarial discriminative domain adaptation[C] / / Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition. 2017: 7167-7176.

[0173]

[36] Liang J, Hu D, Feng J. Do we really need to access the source data? source hypothesis transfer for unsupervised domain adaptation [C] / / Proceedings of the International Conference on Machine Learning. PMLR, 2020:6028-6039.

[0174]

[37] Yang S, Wang Y, Van De Weijer J, et al. Unsupervised domain adaptation without source data by casting a bait [J]. arXiv preprint arXiv:2010.12427, 2020, 1(2):5.

[0175]

[38] Du Z, Li X, Li F, et al. Domain-agnostic mutual prompting for unsupervised domain adaptation [C] / / Proceedings of the IEEE / CVF Conference on Computer Vision and Pattern Recognition. 2024:23375-23384.

[0176]

[39] Bai S, Zhang M, Zhou W, et al. Prompt-based distribution alignment for unsupervised domain adaptation [C] / / Proceedings of the AAAI Conference on Artificial Intelligence. 2024, 38(2):729-737.

[0178]

[40] Ning J, Gui G, Wang Y, et al. Malware traffic classification using domain adaptation and ladder network for secure industrial internet of things [J]. IEEE Internet of Things Journal, 2021, 9(18): 17058-17069.

[0180]

[41] Tong V, Dao C, Tran H A, et al. Encrypted Traffic Classification Through Deep Domain Adaptation Network With Smooth Characteristic Function [J]. IEEE Transactions on Network and Service Management, 2025.

Claims

1. A method for detecting encrypted traffic based on LLM enhancement, which uses the target domain model as the detection model for TLS encrypted traffic under the unsupervised domain adaptive UDA framework, and extracts network attack features from the encrypted traffic; Its characteristics are The UDA framework is a UDA framework enhanced with a large language model LLM, and includes the following modules: Module 1, Prompt-based cross-domain translator: used to guide LLM in performing domain feature conversion between source domain labeled data and target domain unlabeled data; Module 2, Cross-Domain Alignment Network: Taking the original data and cross-domain translation results as input, a UDA detection model is trained based on task classification loss and cross-domain consistency loss; the UDA detection model includes a source domain model and a target domain model; Module 3, LLM Iterative Optimizer: Guided by the loss value, it aligns the LLM translation capabilities with the training objectives of the UDA detection model; The cross-domain translator in Module 1 includes a forward Prompt from the source domain to the target domain and a backward Prompt from the target domain to the source domain. When LLM is used to perform the translation task, the dynamic routing mechanism selects the translation path based on the length sequence of the input data packets: if the input data belongs to the source domain, the DATA in the forward Prompt is replaced with the corresponding data, and then it is input into the LLM; if the input data belongs to the destination domain, the DATA in the backward Prompt is replaced with the corresponding data, and then it is input into the LLM. The input data for the cross-domain alignment network in Module 2 includes labeled data from the source domain and unlabeled data from the target domain; During the training of the cross-domain alignment network, the input source domain labeled dataset and target domain unlabeled dataset are both divided into M batches, and each batch contains I data points. The i-th data point in the m-th batch of the source domain labeled dataset and its label are represented as (S m,i ,y m,i ); The i-th data point in the m-th batch of the unlabeled dataset in the target domain is represented as T. m,i ; Let G(x,f) be the translation result generated by the cross-domain translator for the input data x and the domain label f, where f is 0 or 1, representing the forward direction from the source domain to the target domain or the backward direction from the target domain to the source domain, respectively; S m,i With T m,i The translation outputs are represented as S′ m,i =G(S m,i ,0) and T′ m,i =G(T) m,i ,1); Labeled data from the source domain and unlabeled data from the target domain were used to train the source domain model and the target domain model, respectively. Let P1(y|x) and P2(y|x) be the predicted class distributions generated by the source domain model and the target domain model for the input x, respectively; the cross-entropy between the two probability distributions is represented as H(·,·). The cross-entropy loss for the m-th batch of training in the source domain labeled dataset is calculated as follows: The bidirectional KL divergence loss for the m-th batch training in the unlabeled dataset of the target domain is calculated as follows: The training objective of the source domain model and the target domain model is to minimize Where λ is the weight hyperparameter; The LLM iterative optimizer in Module 3 involves merging and fine-tuning three homologous derived LLMs; Suppose that LLM 1, LLM 2 and LLM 3 are fine-tuned from the same native LLM, and the corresponding trainable parameters are θ1, θ2, θ3 and θ0 respectively; where θ1 and θ2 represent the targeted fine-tuning results for two different generation tasks, forward and backward translation, respectively, and θ3 represents the optimization result generated in the previous iteration; The task update vectors corresponding to the three derived LLMs are represented as follows: The task vector is obtained by performing pruning and decomposition operations. And the corresponding symbol vectors γ1, γ2, γ3 and amplitude vectors η1, η2, η3; set up and The merged task vector is φ, and the corresponding symbol vector is γ; the v-th element of γ is calculated as The h-th element of φ ∈ {1,2,...,dim(θ0)} is calculated as Where λ1, λ2, and λ3 are the weights of θ1, θ2, and θ3, respectively, and are determined by the minimum loss values ​​defined in equations (1) and (2); σ=max(E (h) ,1); E (h) Equivalent to |ε (h) | represents ε (h) The number of elements in the middle; The trainable parameters of the merged LLM are represented as θ = θ0 + αφ, where α is the scaling hyperparameter.

2. The UDA encrypted traffic detection method based on LLM enhancement according to claim 1, characterized in that... Under the LLM-enhanced UDA framework, the joint training process of the UDA detection model and LLM is as follows: 1) Pre-fine-tuned cross-domain translator: The fine-tuning data for forward and backward translation comes from encrypted traffic data and its retransmission results. This data is used to fine-tune the native LLM, giving it preliminary cross-domain translation capabilities; 2) Consistent learning for cross-domain feature reconstruction: Through a cross-domain translator, source domain labeled data and target domain unlabeled data are first mapped to the feature space of another domain; The original data and translation results were then input into the cross-domain alignment network; Task loss and cross-domain consistency loss are introduced into the training of the source domain model and the target domain model, thereby simultaneously constraining distribution alignment and classification boundaries; 3) Fine-tuning-driven UDA closed-loop optimization: The pre-fine-tuned LLM is used for cross-domain translation to ensure the authenticity of the training data and the consistency of features; The task classification loss and cross-domain consistency loss of the cross-domain alignment network guide the weighted merging fine-tuning of LLM parameters, thereby updating the LLM translation strategy; Through multiple iterations, the cross-domain translation results of LLM gradually align with the optimization target of the UDA detection model.

3. The UDA encrypted traffic detection method based on LLM enhancement according to claim 2, characterized in that... In step 1), the bidirectional replay results of encrypted traffic data in the source and target domain network environments become the pre-fine-tuned corpus of LLM; Before replay, the traffic data is preprocessed, namely, reordered according to timestamps and duplicate data packets are removed; The replay trajectory of each network flow in the source and destination network environments is processed into a sequence of packet lengths, which is then converted into structured Question & Answer data pairs. The pre-fine-tuned data is constructed differentially; the Question field carries the sequence of packet lengths generated in the source domain network environment, and the Answer field corresponds to the replay results in the target domain environment; in the forward and backward translation tasks, the positions of the packet length sequences are reversed; All question responses follow the same Prompt framework.

4. The UDA encrypted traffic detection method based on LLM enhancement according to claim 2, characterized in that... In step 2), the source domain data and the target domain data are respectively embedded in the translation guidance Prompt of the corresponding direction to construct a complete cross-domain conversion request for encrypted traffic; the corresponding request is input into the cross-domain translator to generate an encrypted traffic sample with the characteristics of another domain; the generated traffic is input into the cross-domain alignment network. In the source domain branch, the original source domain data and its backward translation results are used to train the source domain model; In the target domain branch, the original target domain data and its forward translation results are used to train the target domain model; The loss function during training takes into account the consistency constraints (1) and (2); Simultaneously, a dynamic translation frequency strategy is introduced: Let B be the total number of training rounds, and the number of retranslations is represented as... k is configurable; the same translation data is always used for training between each two translation tasks; For a fixed B, when k=1, i.e., the data is re-translated in each training round, the dataset quality is the highest but the cost and time are high; increasing the value of k can reduce the number of translations T, thereby balancing the detection effect and training efficiency.

5. The UDA encrypted traffic detection method based on LLM enhancement according to claim 2, characterized in that: In step 3), an LLM fine-tuning mechanism for cross-domain translation is adopted, along with a loss-aware dynamic weighting strategy: Based on equations (1) and (2), it is assumed that (S) m,i ,y m,i ) and T m,i The corresponding losses are respectively and The original dataset and the loss value set are respectively represented as: Let z, with an initial value of 0, be the number of joint fine-tuning rounds that have been completed so far, and T be the preset number of fine-tuning rounds; Each time a new fine-tuning is performed, a conditional check will be executed; if z < T, a new round of LLM fine-tuning process is triggered; otherwise, training is terminated.

6. The UDA encrypted traffic detection method based on LLM enhancement according to claim 5, characterized in that: Step 3) includes: 3.1) Targeted fine-tuning of forward and backward separation For the pre-trained LLM in the cross-domain translator, the forward and backward translation capabilities of the LLM are fine-tuned separately; Every k training epochs, the forward and backward translation results of the original dataset are automatically generated by the training framework; these data are also used to build the fine-tuning dataset. The fine-tuning dataset is divided into two groups according to the translation direction. The Question dataset is filled with the original data, while the Answer dataset is filled with the corresponding translation results from each k training rounds. The LoRA method is used for fine-tuning. The fine-tuning datasets for forward and backward translation are represented as follows: and θ0 is finely adjusted by both to θ1 and θ2; 3.2) Weighted merging of LLM features Reflecting the accuracy of cross-domain translation, it is used to evaluate the quality of fine-tuning datasets and determine the merging weights of θ1, θ2, and θ3; Low-value LLMs are assigned high weights to preserve highly available translation strategies; High-value LLMs were also assigned appropriate weights to stimulate new translation patterns; In every k rounds of training, the last round The performance indices used to measure θ1 and θ2 are calculated as follows: w3 is the performance index corresponding to θ3; since θ3 is not initialized during the first round of joint fine-tuning, w3 is set to 0; λ1, λ2, and λ3 are normalized to and θ1, θ2, and θ3 are merged into θ; At this point, the LLM has completed its alignment with the UDA model for the (z+1)th iteration. 3.3) Continuous iteration of LLM and UDA detection models; After each iteration, θ3 is updated to θ, and w3 is updated to λ1w1+λ2w2+λ3w3; The translation operation of LLM 3 is represented as G2(x,f), which is used to update the training set for the next k rounds of training; Once the k-th round of training is completed, the joint fine-tuning process is restarted.

7. The UDA encrypted traffic detection method based on LLM enhancement according to claim 1, characterized in that the source domain... The model uses a fixed CNN and keeps the training parameters unchanged. The target domain model is configured as a CNN, DF, or Transformer network.

Citation Information

Cited By

  • Off-line passive domain target detection method, device and equipment based on dual-domain generative network, and medium

    CN121459118A

  • An offline passive domain target detection method and device based on a dual-domain generation network, equipment and medium

    CN121459118B