Encrypted traffic classification model training method suitable for dynamic network conditions

By employing feature space alignment and adaptive optimization mechanisms, a training method for encrypted traffic classification models suitable for dynamic network conditions is constructed. This method addresses the generalization ability and stability issues of existing models under dynamic network conditions, achieving more efficient encrypted traffic classification.

CN120979762APending Publication Date: 2025-11-18TSINGHUA UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511244050.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-02
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

Existing encrypted traffic classification methods fail to effectively address traffic characteristic drift caused by changes in network conditions when faced with dynamic network conditions, affecting the model's generalization ability and classification stability in real deployment environments.

Method used

By employing feature space alignment and adaptive optimization mechanisms, a training method for encrypted traffic classification models suitable for dynamic network conditions is constructed. This method includes partitioning subsets based on network conditions, adding Gaussian noise, using the DP-Means clustering algorithm and an adaptive Softmax function to adjust weights, thereby improving the model's generalization ability under dynamic network conditions.

Benefits of technology

It significantly improves the generalization ability and classification accuracy of the encrypted traffic classification model under dynamic network conditions, enhances the robustness of the model to unknown interference, and reduces the representation differences caused by changes in network conditions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979762A_ABST
    Figure CN120979762A_ABST
Patent Text Reader

Abstract

According to the encrypted traffic classification model training method suitable for the dynamic network condition, the generalization ability and the classification accuracy of the encrypted traffic classification model under the dynamic network condition are effectively improved, and through feature space alignment and a self-adaptive optimization mechanism, representation differences caused by network condition changes are remarkably reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of encrypted traffic classification, and more particularly to a method for training an encrypted traffic classification model suitable for dynamic network conditions. Background Technology

[0002] Encrypted traffic classification, a core technology in network security protection systems, is widely used in intrusion detection, behavior recognition, and network management. With the widespread adoption of new encryption protocols such as TLS 1.3, the encryption level of network traffic has significantly increased, posing unprecedented challenges to traditional deep learning-based classification methods. Related technologies typically construct encrypted traffic identification systems through the collaborative operation of data collection, feature extraction, and classification model training. Specifically, this technology system covers the entire process from traffic preprocessing to model deployment, including key stages such as traffic feature modeling, model training and optimization, and testing and evaluation. In practical applications, encrypted traffic classification relies on the model's accurate representation of traffic behavior patterns. Especially in dynamic network environments, its adaptability to changes in network conditions becomes a key factor determining classification performance.

[0003] However, existing encrypted traffic classification methods directly use static training data to build models, failing to adequately consider the impact of dynamic network conditions on traffic characteristics. This can lead to significant performance degradation in real-world deployment environments. Specifically, dynamic network conditions include various forms such as host differences, transmission path variations, and traffic obfuscation strategies. These factors significantly alter the characteristic distribution of encrypted traffic, causing the representations learned during training to become invalid during testing. Furthermore, since the drift of traffic characteristics under different network environments is difficult to predict, existing techniques typically perform data augmentation training based on specific known conditions. However, these augmentation methods are limited by known interference patterns and cannot effectively cope with unknown or complex combinations of dynamic changes, thus affecting the model's generalization ability and classification stability in real-world networks. Summary of the Invention

[0004] The present invention aims to at least partially solve one of the technical problems in the related art.

[0005] This invention proposes a training method for encrypted traffic classification models suitable for dynamic network conditions, which effectively improves the generalization ability and classification accuracy of encrypted traffic classification models under dynamic network conditions. Through feature space alignment and adaptive optimization mechanisms, it significantly reduces the representation differences caused by changes in network conditions.

[0006] Another objective of this invention is to provide a training device for an encrypted traffic classification model suitable for dynamic network conditions.

[0007] To achieve the above objectives, this invention proposes a method for training an encrypted traffic classification model suitable for dynamic network conditions, comprising:

[0008] S1. Based on existing encrypted traffic data, divide it into multiple subsets according to the network conditions in which it is located, and enumerate all possible division methods to construct multiple classification tasks. Each classification task includes a training set and a test set, and the network conditions of the training set and the test set are different.

[0009] S2, train the training set in each classification task to generate the corresponding temporary model. During the training process, add two types of Gaussian noise to the representation vector of each encrypted traffic sample: one is Gaussian noise with a fixed distribution, and the other is class-related Gaussian noise with a variance equal to the variance of samples of the same class.

[0010] S3. For the temporary model in each classification task, the DP-Means clustering algorithm is used to cluster the encrypted traffic representation vectors of the training set and the test set respectively. Euclidean distance and KL divergence are calculated based on the cluster centers to measure the difference in encrypted traffic representation under different network conditions from two perspectives, which serves as the loss index for this task.

[0011] S4, based on the loss metrics of all classification tasks, adaptively allocates the weights of each task during the optimization process through a coefficientd Softmax function. The Softmax coefficient is dynamically adjusted according to the training phase to accelerate model convergence in the early stage of optimization and balance task weights in the later stage of optimization.

[0012] The encrypted traffic classification model training method for dynamic network conditions according to embodiments of the present invention may also have the following additional technical features:

[0013] In one embodiment of the present invention, S1 includes:

[0014] S11 divides network conditions into three categories: hardware and protocol configuration of the host from which the encrypted traffic originates, network layer and transport layer parameter settings in the transmission path, and type and parameters of the traffic obfuscation strategy.

[0015] S12, for each combination of network conditions, generate at least one training set and test set pair, and ensure that the network conditions of the training set and test set are significantly different in at least one dimension.

[0016] In one embodiment of the present invention, S2 includes:

[0017] S21, the fixed-distribution Gaussian noise is divided into coefficients and deviation values, the mean of the coefficients is 1, the mean of the deviation values ​​is 0, and the variance of the two is a preset global noise parameter.

[0018] S22, the mean of the category-related Gaussian noise is 0, and the variance is the variance of the representation vectors of all samples of the current category in the corresponding dimension, and is dynamically calculated in each training task.

[0019] In one embodiment of the present invention, S3 includes:

[0020] S31, the DP-Means clustering algorithm automatically determines the number of clusters during the clustering process and ensures that the representation vectors in each cluster belong to the same category;

[0021] S32, When calculating the Euclidean distance, the logarithmic mean of the distance is used as a metric. This ensures that when optimizing based on this metric, each cluster only approaches a single target cluster. When approaching a single target cluster, the logarithmic mean of the distance approaches negative infinity, thereby finding the correspondence between traffic behavior patterns under two conditions. The traffic behavior patterns are reflected by different clusters.

[0022] In one embodiment of the present invention, it further includes:

[0023] S5 involves iteratively training the optimized original model in multiple rounds. In each round of iteration, steps S2 to S4 are repeated, and the coefficients in the Softmax function are updated after each round to gradually improve the consistency of the model's representation under different network conditions.

[0024] To achieve the above objectives, another aspect of the present invention proposes a training device for an encrypted traffic classification model suitable for dynamic network conditions, comprising:

[0025] The heterogeneous classification task partitioning module is used to divide existing encrypted traffic data into multiple subsets according to the network conditions in which it is located, and enumerate all possible partitioning methods to construct multiple classification tasks. Each classification task includes a training set and a test set, and the network conditions of the training set and the test set are different.

[0026] The noise-enhanced temporary model training module is used to train the training set in each classification task to generate the corresponding temporary model. During the training process, two types of Gaussian noise are added to the representation vector of each encrypted traffic sample: one is Gaussian noise with a fixed distribution, and the other is class-related Gaussian noise with a variance equal to the variance of samples of the same class.

[0027] The clustering-based difference measurement module is used to cluster the encrypted traffic representation vectors of the training set and the test set respectively using the DP-Means clustering algorithm for the temporary model in each classification task. Based on the cluster centers, Euclidean distance and KL divergence are calculated to measure the difference of encrypted traffic representation under different network conditions from two perspectives, which serves as the loss index for the task.

[0028] The adaptive weighted model optimization module is used to adaptively allocate the weights of each task in the optimization process based on the loss metrics of all classification tasks through the coefficientd Softmax function. The Softmax coefficient is dynamically adjusted according to the training phase to accelerate model convergence in the early stage of optimization and balance task weights in the later stage of optimization to prevent the model from overfitting to a single task.

[0029] The encrypted traffic classification model training method and apparatus applicable to dynamic network conditions in this invention improve the generalization ability and classification accuracy of the encrypted traffic classification model under dynamic network conditions, effectively reduce the differences in traffic representation under different network conditions, and enhance the robustness of the model to unknown interference.

[0030] Additional aspects and advantages of the invention will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of the invention. Attached Figure Description

[0031] The above and / or additional aspects and advantages of the present invention will become apparent and readily understood from the following description of the embodiments taken in conjunction with the accompanying drawings, wherein:

[0032] Figure 1 This is a flowchart of a method for training an encrypted traffic classification model for dynamic network conditions according to an embodiment of the present invention.

[0033] Figure 2 This is an architecture diagram of a training method for an encrypted traffic classification model applicable to dynamic network conditions according to an embodiment of the present invention;

[0034] Figure 3 This is a structural diagram of a training device for an encrypted traffic classification model suitable for dynamic network conditions according to an embodiment of the present invention. Detailed Implementation

[0035] It should be noted that, unless otherwise specified, the embodiments and features described in the present invention can be combined with each other. The present invention will now be described in detail with reference to the accompanying drawings and embodiments.

[0036] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0037] The following describes, with reference to the accompanying drawings, a method and apparatus for training an encrypted traffic classification model suitable for dynamic network conditions, according to an embodiment of the present invention.

[0038] Example 1

[0039] Figure 1 This is a flowchart of a method for training an encrypted traffic classification model for dynamic network conditions according to an embodiment of the present invention, as shown below. Figure 1 As shown, it includes:

[0040] S1: Based on existing encrypted traffic data, divide it into multiple subsets according to the network conditions in which it is located, and enumerate all possible division methods to construct multiple classification tasks. Each classification task includes a training set and a test set, and the network conditions of the training set and the test set are different.

[0041] Specifically, the step of "dividing existing encrypted traffic data into multiple subsets according to the network conditions in which it exists, and enumerating all possible partitioning methods to construct multiple classification tasks, each classification task containing a training set and a test set, and the network conditions of the training set and the test set being different" is the core implementation method of the classification task construction module (M1) in this invention. Its technical principle is based on the idea of ​​model-independent meta-learning (MAML) in meta-learning, which aims to improve the generalization ability of the model under dynamic network conditions by constructing diverse training-test task pairs.

[0042] At the technical implementation level, this step first extracts and labels network condition features from existing encrypted traffic data. Network conditions may include, but are not limited to, host type (e.g., Windows, Linux, iOS), MTU settings of the transmission path, network topology, encryption protocol version (e.g., TLS 1.2 vs. TLS 1.3), traffic obfuscation strategies (e.g., Dummy Packets, Packet Padding), and their parameter configurations. Using these network conditions as the basis for partitioning, the original dataset is divided into several subsets, each corresponding to a specific combination of network conditions. Subsequently, module M1 enumerates all possible partitioning methods, combining all subsets and selecting one set as the training set and the other as the test set to construct T classification tasks. Each task satisfies that the network conditions of the training and test sets are different, thus simulating the unknown network environments that the model may encounter in real-world deployments.

[0043] At the application level, this step is suitable for the pre-training stage of encrypted traffic classification models, especially in scenarios with diverse training data sources, complex network environments, and traffic obfuscation strategies. For example, in a network intrusion detection system deployed across regions, the network infrastructure, host configurations, and encryption strategies differ across regions. The diverse tasks constructed through this step enable the model to adapt to these differences before deployment.

[0044] From a technical perspective, this step significantly improves the model's robustness in unknown network environments by enumerating training-test task combinations under different network conditions. By forcing the model to face different network features during training and testing, it compels the model to learn a more generalizable representation of encrypted traffic, rather than relying on local features under specific network conditions. This design forms the basis for subsequent modules (such as M2, M3, and M4) to achieve model optimization and adaptive weight adjustment, providing diverse task inputs for the entire training process, thereby enhancing the model's adaptability and stability.

[0045] Furthermore, S1 includes.

[0046] S11 categorizes network conditions into three types: the hardware and protocol configuration of the host from which the encrypted traffic originates, the network layer and transport layer parameter settings in the transmission path, and the type and parameters of the traffic obfuscation strategy.

[0047] Specifically, this step involves classifying network conditions into three categories: the hardware and protocol configuration of the host from which the encrypted traffic originates, the network layer and transport layer parameter settings in the transmission path, and the type and parameters of the traffic obfuscation strategy. The underlying principle is to systematically identify and model the dynamic factors affecting the characteristics of encrypted traffic, thereby providing a representative basis for task division in subsequent model training and improving the model's generalization ability in real network environments.

[0048] In practice, this step first extracts metadata from the collected encrypted traffic data, including the host's hardware fingerprint (such as CPU architecture, memory size, network card model), operating system version, encryption protocol version used (such as TLS 1.2, TLS 1.3, QUIC, etc.) and its configuration parameters (such as handshake round count, key exchange method). Secondly, for network and transport layer parameters in the transmission path, metrics such as Maximum Transmission Unit (MTU), IP fragmentation strategy, TCP window size, RTT (Round Trip Time), and packet interval are extracted. These parameters are typically determined by the configuration of network intermediate devices (such as routers, firewalls) or the transport protocol stack, directly affecting the timing and structural characteristics of the traffic. Finally, for the traffic obfuscation strategy, the type of obfuscation used (such as Dummy Packets, Padding, Rate Shaping, etc.) and its parameters (such as injection frequency, packet size distribution, and time interval perturbation amplitude) are identified. These parameters determine the degree of change in traffic behavior patterns.

[0049] At the parameter level, this step requires a quantitative description of each type of network condition. For example, hardware and protocol configurations can be divided based on protocol version differences (e.g., TLS 1.2 vs TLS 1.3) and handshake packet sizes (e.g., average handshake packet count of 3 vs 1); network layer parameters can be set to MTU ranges (e.g., 1500 bytes vs 9000 bytes), TCP window sizes (e.g., 65535 bytes vs 1024 bytes), etc.; obfuscation policy parameters can be set to the injection frequency of dummy packets (e.g., 10 per second vs 50 per second) or the distribution of padding length (e.g., mean of 128 bytes, standard deviation of 32 bytes).

[0050] In practical applications, this step is suitable for scenarios with complex network environments, diverse sources of encrypted traffic, and active obfuscation behaviors, such as enterprise network intrusion detection, mobile device traffic identification, and IoT device behavior analysis. By classifying network conditions into three categories, multiple classification tasks with different feature distributions can be constructed, thereby simulating dynamic changes in real networks and providing diverse training samples for the model.

[0051] From a technical perspective, this step provides a clear basis for subsequent modules (such as the M1 classification task construction module), ensuring that the training and testing data for each task come from different network conditions, thereby improving the model's adaptability to unknown network environments. Furthermore, this partitioning method helps reveal the characteristic variation patterns of encrypted traffic under different conditions, providing key inputs for model optimization and serving as a fundamental step in achieving robust training of encrypted traffic classification models under dynamic network conditions.

[0052] S12, for each combination of network conditions, generate at least one training set and test set pair, and ensure that the network conditions of the training set and test set are significantly different in at least one dimension.

[0053] Specifically, for each combination of network conditions, generating at least one training and test set pair, and ensuring that the network conditions of the training and test sets are significantly different in at least one dimension, is one of the core steps of the classification task construction module (M1) in this invention. This step aims to simulate the dynamically changing environment in real networks, thereby improving the model's generalization ability under unknown network conditions.

[0054] At the technical implementation level, this step first categorizes existing encrypted traffic data based on multi-dimensional features according to the network conditions in which it was generated. These network conditions include, but are not limited to, host type (e.g., different operating systems, hardware configurations), transmission path (e.g., different MTU settings, network topology), and traffic obfuscation strategies (e.g., whether fake data packets are injected, obfuscation strength, etc.). By enumerating all possible combinations of network conditions, the M1 module constructs multiple classification tasks, each consisting of a training set and a test set. The network conditions of the training set and the test set must differ significantly in at least one dimension; for example, the training set uses the TLS 1.2 protocol while the test set uses the TLS 1.3 protocol, or the training set traffic is unobfuscated while the test set traffic has undergone fake data packet injection.

[0055] At the parameter level, the criterion for determining significant differences can be set as a statistical significance test of the feature distribution, such as using the Kolmogorov-Smirnov test (KS test) or t-test, to ensure that the difference in feature distribution between training and test data in at least one dimension reaches a preset threshold (e.g., p-value less than 0.05). Furthermore, the training and test sets for each task should maintain a balance in sample size, typically with the training set having 2 to 5 times the number of samples in the test set, to ensure sufficient model training and representative testing.

[0056] At the application level, this step is widely applicable to the pre-training stage of encrypted traffic classification models, especially in scenarios with complex network environments, heterogeneous hosts, and multiple obfuscation strategies. By constructing diverse task pairs, the model can learn consistent traffic representations under different network conditions during training, thereby enhancing its robustness in real-world deployment environments.

[0057] The technical advantage of this step lies in introducing task pairs with significant differences in network conditions, forcing the model to learn more generalizable feature representations during training, rather than relying on local features specific to a particular network environment. This not only improves the model's classification performance under dynamic network conditions but also provides a diverse training task foundation for subsequent modules (such as M2, M3, and M4), serving as a key prerequisite for achieving model meta-learning and adaptive optimization.

[0058] S2 trains the training set for each classification task to generate the corresponding temporary model. During the training process, two types of Gaussian noise are added to the representation vector of each encrypted traffic sample: one is Gaussian noise with a fixed distribution, and the other is class-related Gaussian noise with a variance equal to the variance of samples of the same class.

[0059] Specifically, in the temporary model training module, the present invention directs the representation of encrypted traffic samples during the training process of each classification task.

[0060] From an application perspective, this step is suitable for sample processing of each classification task during the training phase. It is particularly effective in mitigating model performance degradation caused by feature drift when dealing with encrypted traffic from different hosts, network environments, or under different obfuscation strategies. By introducing class-related noise, the model can still perceive the structural differences between classes during the learning process, avoiding the loss of key classification information due to noise interference.

[0061] This technique has a significant effect on improving the generalization ability of the model. Experiments show that, compared with training methods that use only fixed noise or no noise enhancement, the dual-noise mechanism of this invention can improve the classification accuracy of the model in cross-network conditional tests by 5% to 12%, while reducing the class confusion rate and enhancing the robustness of the model to dynamic feature perturbations.

[0062] Furthermore, S2 includes:

[0063] S21, the fixed-distribution Gaussian noise is divided into coefficients and deviation values. The mean of the coefficients is 1, the mean of the deviation values ​​is 0, and the variance of the two is the preset global noise parameter.

[0064] Specifically, in the M2 temporary model training module of this invention, to enhance the model's generalization ability under dynamic network conditions, Gaussian noise is injected into the representation vector of encrypted traffic samples to improve the diversity of training data and avoid model overfitting. The fixed-distribution Gaussian noise consists of coefficients and bias values. The mean of the coefficients is 1, the mean of the bias values ​​is 0, and their variance is a preset global noise parameter. This step is a core component of the class-aware representation enhancement mechanism. Specifically, this noise is x' = alpha*x + beta, where the mean of alpha is 1, the mean of beta is 0, and their variance is a fixed value.

[0065] At the application level, this step is applicable to the training process of encrypted traffic classification models when facing different hosts, network environments, or obfuscation strategies. By injecting Gaussian noise with a fixed distribution into the representation layer, the interference of network condition changes on traffic features can be simulated, enabling the model to learn feature representations that are robust to noise during the training phase, thereby improving its classification stability in real dynamic network environments.

[0066] From a technical perspective, this step effectively increases the representation space complexity of training samples by introducing Gaussian noise with a fixed distribution, preventing the model from becoming dependent on features under specific network conditions. Simultaneously, since the noise has a mean of 0, it does not alter the overall distribution trend of the representation, thus maintaining the distributional correlation between categories while improving generalization ability. This technique further enhances the robustness of meta-learning within the MAML framework and is one of the key innovations of this invention in achieving stable training of the encrypted traffic classification model under dynamic network conditions.

[0067] S22, the mean of the category-related Gaussian noise is 0, and the variance is the variance of the representation vectors of all samples of the current category in the corresponding dimension, and is dynamically calculated in each training task.

[0068] Specifically, in the M2 temporary model training module of this invention, to enhance the robustness of the model under dynamic network conditions, class-dependent Gaussian noise is introduced to perturb the representation vectors of the samples. This noise has a mean of 0 and a variance of σ², which is the variance of the representation vectors of all samples in the current class along the corresponding dimension. 2 The algorithm is dynamically computed in each training task. The core principle of this design is to improve the model's tolerance to feature perturbations by introducing noise consistent with the distribution of class features to simulate feature drift caused by different hosts, network environments, or obfuscation strategies in real networks.

[0069] In practical applications, this step is particularly suitable for scenarios where encrypted traffic characteristics are easily affected by network conditions, such as cross-host communication, multi-path transmission, or network environments with traffic obfuscation attacks. Through dynamic perturbation, the model can learn a representation method that maintains stable classification ability under different feature distributions during the training phase, thereby significantly improving its generalization performance under real dynamic network conditions.

[0070] From a technical perspective, this step effectively alleviates the overfitting problem caused by training the model under single-network conditions and enhances the model's robustness to unknown disturbances. Simultaneously, since the noise variance is consistent with the distribution of class features, the model can still maintain the discriminative power between classes after perturbation, avoiding the degradation of classification performance caused by noise introduction. This design improves the model's generalization ability while ensuring the stability and convergence efficiency of the training process, and is one of the key technical means of this invention to achieve stable classification of encrypted traffic under dynamic network conditions.

[0071] S3. For the temporary model in each classification task, the DP-Means clustering algorithm is used to cluster the encrypted traffic representation vectors of the training set and the test set respectively. Euclidean distance and KL divergence are calculated based on the cluster centers to measure the difference in encrypted traffic representation under different network conditions from two perspectives, which serves as the loss index for this task.

[0072] Specifically, in the M3 temporary model testing module of this invention, for the training and test sets in each classification task, the DP-Means clustering algorithm is used to cluster the representation vectors of encrypted traffic. Euclidean distance and KL divergence are calculated based on the cluster centers to measure the differences in encrypted traffic representations under different network conditions from two perspectives, serving as the loss metric for that task. The core of this step lies in extracting representative cluster centers through clustering, thereby achieving efficient evaluation of the model representation stability without relying on category labels.

[0073] At the technical implementation level, the DP-Means algorithm is a parameter-free clustering method that adaptively determines the number of clusters based on the prior assumption of the Dirichlet Process. Specifically, the algorithm iteratively assigns data points to the nearest cluster centers and decides whether to add new cluster centers based on the Euclidean distance between the data points and the cluster centers and a preset cluster tolerance (i.e., distance threshold). In this invention, DP-Means clusters the encrypted traffic representation vectors of the training and test sets respectively, ensuring that the samples within each cluster belong to the same category, thereby extracting multiple cluster centers as representative representations of that category.

[0074] In application scenarios, this step is suitable for the training process of encrypted traffic classification models under dynamic network conditions. For example, encrypted traffic data collected under different hosts, different MTU configurations, or different obfuscation strategies may have significantly different representation vectors. By extracting cluster centers through DP-Means clustering and combining Euclidean distance and KL divergence for dual-angle measurement, these differences can be effectively captured, providing a quantitative basis for subsequent model optimization.

[0075] The technical advantage of this step lies in its ability to more comprehensively and efficiently evaluate the model's representational stability under different network conditions through a two-dimensional difference metric of cluster centers. Compared to traditional prototype alignment methods, the cluster alignment strategy of this invention improves adaptability to complex distribution patterns while maintaining computational efficiency, thereby enhancing the model's generalization performance and robustness in dynamic network environments.

[0076] Furthermore, S3 includes:

[0077] S31, the DP-Means clustering algorithm automatically determines the number of clusters during the clustering process and ensures that the representation vectors in each cluster belong to the same category.

[0078] Specifically, in the M3 temporary model testing module of this invention, the DP-Means clustering algorithm is used to automatically determine the number of clusters and ensure that the representation vectors in each cluster belong to the same category. The core objective of this step is to efficiently and accurately measure the differences in encrypted traffic representations under different network conditions, thereby providing a reliable evaluation metric for the subsequent optimization of the original model.

[0079] From a technical implementation perspective, DP-Means is a parameter-free clustering method based on the Dirichlet Process (DP). Its core idea is to iteratively update cluster centers and dynamically determine whether to form new clusters based on the distance between data points and the centers. Specifically, the algorithm initializes by setting a cluster center, and then sequentially assigns each representation vector to the nearest cluster. If the distance between the vector and the current nearest cluster center is greater than a preset threshold, a new cluster is created. This threshold is determined by the average distance of the current clusters and a hyperparameter. In this invention, DP-Means clusters encrypted traffic representation vectors in both the training and test subsets to extract representative cluster centers for each category under different network conditions.

[0080] In terms of application scenarios, this step is mainly used in the robustness training phase of encrypted traffic classification models. When faced with feature drift caused by different hosts, network environments, or traffic obfuscation strategies, DP-Means can automatically identify the substructures within a category due to changes in network conditions, thereby avoiding the bias caused by using a single prototype sample. For example, in the test set, encrypted traffic of the same category may exhibit multiple feature patterns due to different MTU settings. DP-Means can divide them into multiple clusters, each cluster representing a specific behavioral pattern.

[0081] From a technical perspective, the introduction of DP-Means effectively improves the accuracy and efficiency of representing differences. By using cluster centers generated through clustering, combined with a dual-angle measure of Euclidean distance and KL divergence, it can more comprehensively reflect the differences in encrypted traffic representation under different network conditions. This step not only reduces computational complexity (avoiding the O(n) time complexity of pairwise comparisons), but also... 2 This not only reduces complexity but also enhances the model's adaptability to diversity within categories, providing a more representative loss signal for optimizing the original model, thereby improving the model's generalization performance under dynamic network conditions.

[0082] S32, when calculating the Euclidean distance between clusters, the logarithmic mean of the distance is used as a metric, so that when optimizing based on this metric, each cluster only moves closer to a single target cluster, and when moving closer to a single target cluster, the logarithmic mean of the distance will approach negative infinity, thereby finding the correspondence between traffic behavior patterns under two conditions, and the traffic behavior patterns are reflected by different clusters.

[0083] Specifically, in the M3 temporary model testing module of this invention, the logarithmic average of the Euclidean distances between the centers of all clusters of the same category is used when calculating the loss metric. The core technical principle of this step is that, during the optimization process, the loss metric based on the logarithmic average can ensure that each cluster is only close to a single target cluster, guaranteeing an accurate correspondence of the same traffic behavior pattern under different network conditions, and enabling subsequent steps to optimize the model more accurately.

[0084] Understandably, using the logarithmic mean as a metric in cluster analysis is a unique calculation method. The core purpose of this method is to guide each cluster to move closer to a single target cluster during the optimization process. Specifically, when the logarithmic mean of the distances between a cluster and a single target cluster approaches negative infinity, it indicates that the similarity between the two clusters is extremely high, thus prompting clusters to move closer to the target cluster. This mechanism not only effectively avoids clusters moving in multiple directions during optimization but also significantly improves the accuracy and efficiency of clustering.

[0085] Furthermore, this method can reveal the correspondence between traffic behavior patterns under two different conditions. Traffic behavior patterns are typically reflected in clusters during cluster analysis. By using the logarithmic mean as a metric, the similarity between clusters under different conditions can be more clearly identified and matched, thereby finding the intrinsic connections between these traffic behavior patterns. This has significant practical implications for understanding changes in behavior patterns in complex systems, predicting future trends, and developing corresponding strategies.

[0086] In practical applications, this step is suitable for evaluating the performance of encrypted traffic classification models under different network conditions, especially when there are significant differences in the feature distributions of training and test data. By calculating the weighted Euclidean distance, the consistency of the model's representation under different network environments can be more realistically reflected, thus providing a reliable basis for subsequent model optimization.

[0087] The technical advantage of this step is that, compared to the traditional average Euclidean distance calculation method, the weighted average method can highlight the impact of clusters with a larger number of samples on model performance, thus improving the accuracy of evaluating the model's generalization ability. At the same time, this method is significantly superior to pairwise distance calculation in terms of time complexity, making the entire training process more efficient and helping to improve the model's robustness and classification accuracy under dynamic network conditions.

[0088] S4, based on the loss metrics of all classification tasks, adaptively allocates the weights of each task during the optimization process through a coefficientd Softmax function. The Softmax coefficient is dynamically adjusted according to the training phase to accelerate model convergence in the early stage of optimization and balance task weights in the later stage of optimization, preventing the model from overfitting to a single task.

[0089] Specifically, in the original model optimization module (M4), this invention employs a coefficientd Softmax function to adaptively assign weights to the loss metrics of multiple classification tasks, thereby dynamically adjusting the task weights at different training stages to balance model convergence speed and generalization ability. This step is technically based on the Model-Independent Meta-Learning (MAML) concept, which introduces an adjustable Softmax temperature coefficient to achieve adaptive evolution of task weights.

[0090] In application scenarios, this step is suitable for robust training of encrypted traffic classification models in the face of changing network environments (such as different hosts, transmission paths, or obfuscation strategies). Through dynamic task weight allocation, the model can quickly adapt to feature differences in the initial training tasks and maintain stable representation capabilities for various tasks in later stages, thereby improving its classification performance in real network deployments.

[0091] The technical advantage of this step lies in the adaptive evolution of task weights achieved by introducing an adjustable Softmax temperature coefficient, effectively balancing the model's convergence speed and generalization ability. In the early stages of optimization, the model focuses on tasks with higher losses, accelerating the learning process; in the later stages of optimization, the weights tend to be balanced, preventing the model from becoming overly dependent on specific tasks, thereby improving its robustness and classification accuracy under dynamic network conditions.

[0092] The encrypted traffic classification model training method applicable to dynamic network conditions in this invention improves the generalization ability and classification accuracy of the encrypted traffic classification model under dynamic network conditions, effectively reduces the differences in traffic representation under different network conditions, and enhances the robustness of the model to unknown interference.

[0093] Furthermore, it also includes:

[0094] S5 involves iteratively training the optimized original model in multiple rounds. In each round of iteration, steps S2 to S4 are repeated, and the coefficients in the Softmax function are updated after each round to gradually improve the consistency of the model's representation under different network conditions.

[0095] Specifically, the steps are as follows: the optimized original model is trained through multiple rounds of iteration. In each round of iteration, steps S2 to S4 are repeated, and the coefficients in the Softmax function are updated after each round to gradually improve the consistency of the model's representation under different network conditions.

[0096] This step is the core iterative optimization stage in the training process of this invention. It aims to continuously improve the model's generalization ability under dynamic network conditions by repeatedly executing the temporary model training (S2), testing (S3), and original model optimization (S4) processes. In each iteration, the original model updates its parameters based on the representational difference loss of the current task, thereby gradually reducing the inconsistency in the model's feature extraction of encrypted traffic under different network conditions. After each iteration, the system adaptively adjusts the temperature coefficient in the Softmax function according to the current optimization state of the model to dynamically control the task weight allocation strategy. This coefficient adjustment mechanism incorporates the loss change trend of the model on different tasks, ensuring rapid convergence in the early stages of training and avoiding overfitting to specific tasks in the later stages.

[0097] This step applies to the robust training phase of the encrypted traffic classification model before deployment in a real network environment. In practice, the model needs to handle encrypted traffic from different hosts, transmitted through different network environments, or processed by different obfuscation strategies. Through multiple rounds of iterative training, the model can learn to maintain consistent feature representations under these dynamic conditions, thereby improving its classification accuracy in unknown network environments. For example, in encrypted traffic detection systems deployed in enterprise or mobile networks, this training method can effectively address performance degradation caused by network topology changes or traffic obfuscation attacks.

[0098] This step introduces an adaptive Softmax coefficient adjustment mechanism to dynamically allocate task weights, thus balancing convergence speed and generalization ability during model optimization. In the early stages of training, a larger temperature coefficient prioritizes tasks with high disparity, accelerating the learning process; in the later stages, a smaller temperature coefficient balances task weights, preventing overfitting to specific tasks. Experiments show that this method significantly improves classification consistency across network conditions on multiple encrypted traffic datasets (such as CIC-DoHBrw-2020 and NUDT-MobileTraffic), with an average improvement of 8%–16%. Its robustness against unknown obfuscation strategies is also superior to existing methods.

[0099] The encrypted traffic classification model training method applicable to dynamic network conditions in this invention improves the representation consistency and convergence stability of the encrypted traffic classification model under different network conditions by conducting multiple rounds of iterative training and dynamically updating the coefficients in the Softmax function, thereby achieving more efficient and robust classification performance in complex dynamic environments.

[0100] Example 2

[0101] This invention proposes a training method for an encrypted traffic classification model suitable for dynamic network conditions, the architecture of which is as follows: Figure 2 As shown, the specific components include the following modules: M1 Classification Task Construction Module, which constructs classification tasks for training and testing encrypted traffic under different network conditions based on existing traffic data; M2 Temporary Model Training Module, which trains a temporary model using the training dataset from a single task, avoiding overfitting due to the single characteristic of the training data; M3 Temporary Model Testing Module, which efficiently and accurately measures the differences in encrypted traffic representations under different network conditions obtained by the temporary model, serving as an evaluation metric for the original model in different classification tasks; M4 Original Model Optimization Module, which iteratively optimizes the original model based on the metrics of all classification tasks obtained in M3, reducing the differences in encrypted traffic representations under different network conditions, and adaptively adjusting the weight ratio of each classification task loss when updating the original model, balancing model convergence speed and model generalization; and M5 Fine-tuning Module, which fine-tunes the original model optimized in M4 using all training data, resulting in a final model that can correctly classify encrypted traffic under dynamic network conditions.

[0102] The M1 classification task construction module of this training method can construct classification tasks for training and testing encrypted traffic under different network conditions based on existing encrypted traffic data. M1 divides the existing encrypted traffic data into several subsets according to the network conditions, then selects one subset as the training set and another subset as the test set to construct each classification task. In particular, M1 enumerates all construction methods to obtain the maximum number of classification tasks.

[0103] The M2 temporary model training module of this training method avoids overfitting caused by the homogeneity of training data. During the training of a single temporary model using training data for each task, M2 adds two types of Gaussian noise to the representation vector of each encrypted traffic sample: one is Gaussian noise following a fixed distribution, and the other is Gaussian noise with a distribution variance equal to the variance of all samples in the same class. The addition of these two types of Gaussian noise increases the diversity of the training data to avoid overfitting, while also maintaining the distributional correlation between different classes of data, preventing misclassification by the temporary model.

[0104] The M3 temporary model testing module of this training method can efficiently and accurately measure the differences in encrypted traffic representations extracted by the temporary model under different network conditions, given that encrypted traffic data has multiple typical distribution characteristics. M3 uses the DP-Means parameterless clustering algorithm to cluster the encrypted traffic representation vectors under different network conditions, and then performs a two-dimensional difference measurement based on the obtained cluster centers. The first is the Euclidean distance of the cluster centers, and the second is the KL divergence of the class probability vectors obtained by the classification network through the cluster centers. The two together constitute the index representing the difference.

[0105] The M4 original model optimization module of this training method can adaptively allocate weights for different classification tasks during the original model update process, balancing the convergence speed and generalization performance of the original model. M4 includes a Softmax function with coefficients, which receives the representational differences of all tasks (from M3) and outputs the weight of each task in the optimization process. M4 continuously evaluates the model's optimization progress and adjusts the coefficients carried by Softmax at different optimization stages. Specifically, in the early stages of optimization, the coefficients are larger, allowing classification tasks with greater representational differences to receive larger weights, accelerating model convergence; in the later stages of optimization, the coefficients decrease, allowing different tasks to receive similar weights, avoiding overfitting to a single task.

[0106] The M5 fine-tuning module of this training method can obtain a classification model applicable to dynamic network conditions. M5 fine-tunes the original model optimized by M4 using all existing encrypted traffic data to obtain the final encrypted traffic classification model.

[0107] The training method consists of the following steps: T1, module M1 constructs several classification tasks with different training and testing network conditions using existing traffic data, each task containing a training set and a test set; T2, for each classification task, module M2 trains the corresponding temporary model; T3, for each temporary model obtained from the classification task, module M3 measures the difference in the model's representation of encrypted traffic under different network conditions; T4, module M4 optimizes the original model based on the representation differences corresponding to all tasks; T5, for the optimized original model, steps T2-T4 are repeated a specified number of times; T6, module M5 fine-tunes the original model obtained in T5 to obtain the final encrypted traffic classification model.

[0108] Specifically, such as Figure 2 As shown, the modules are: a classification task construction module, a temporary model training module, a temporary model testing module, an original model optimization module, and a fine-tuning module. The classification task construction module is responsible for constructing multiple classification tasks that include training and testing encrypted traffic under different network conditions; the temporary model training module is responsible for training the original model to obtain a temporary model; the temporary model testing module is responsible for measuring the representation differences of the model in each task; the original model optimization module is responsible for optimizing the original model based on the representation differences under all tasks; and the fine-tuning module is responsible for fine-tuning the optimized original model.

[0109] The workflow of the training method is as follows: Figure 2 As shown by the solid line, the existing encrypted traffic data is first divided according to network conditions, and all division schemes are enumerated to obtain T classification tasks with different training and testing network conditions. Then, for each task, the original model is trained using the training dataset from that task, resulting in a total of T temporary models. The representational differences of each temporary model are then measured and used as the loss function of the original model on the T tasks. Finally, the original model is optimized based on the loss function of all tasks. The final original model, when deployed on a real network, is shown by the dashed line. The model is trained using all existing encrypted traffic, ultimately resulting in an encrypted traffic classification model that can stably represent and correctly classify traffic under dynamic network conditions.

[0110] First, a description of several concepts and key technologies used in the specific implementation method of this invention is given:

[0111] Model-Agnostic Meta-Learning (MAML) is a training method that enables any deep learning model to generalize well across a variety of learning tasks. Specifically, MAML takes an untrained deep learning model as input and multiple datasets, each treated as a specific learning task. In each iteration, several tasks are selected, and an independent temporary model is built for each task by training on the training set. The original model is then optimized based on the performance of each temporary model on the test set. Once converged, the model will perform well across different tasks. Furthermore, because meta-learning does not directly use all known data to train the model, it prevents overfitting to existing data, thus improving its generalization ability to unknown data.

[0112] Gaussian noise: A statistically significant random process in which each sampled value is a random variable independently drawn from a Gaussian distribution (i.e., a normal distribution). Gaussian distribution N(μ,σ) 2 It is determined by two parameters: mean μ and variance σ. 2 The mean determines the central location of the distribution, while the variance controls the dispersion of the data. The mathematical expression for its probability density function is:

[0113]

[0114] DP-Means (Dirichlet Process Means) is an adaptive clustering algorithm that fits all input data into a mixture of multiple Gaussian distributions and calculates the lower bound of the distance between two data points belonging to different Gaussian distributions. This lower bound is used as the distance threshold to determine whether a single data point belongs to a particular cluster. The DP-Means method can automatically identify the smallest compact set of clusters containing all input data, even without prior knowledge of the number of clusters. Each cluster corresponds to an independent Gaussian distribution, and its center represents all data within the cluster.

[0115] The Softmax function is a function that transforms any real-valued vector into a probability distribution, with non-negative outputs that sum to 1. It is typically used in the last layer of a multi-class classification model to normalize the model's raw output into class probabilities. Let the input be a vector: z = [z1, z2, ..., z...]. K The output of the Softmax function for each dimension is:

[0116] Furthermore, the implementation and operation of the five modules specifically implemented in this invention will be described:

[0117] In one embodiment of the present invention, the classification task construction module is designed as follows:

[0118] To enable encrypted traffic classification models to correctly perform classification tasks under dynamic network conditions in the real world, this invention aims to improve the generalization performance of the classification model by drawing on the ideas of MAML. Following the MAML workflow, this invention first constructs diverse classification tasks to mimic dynamic network conditions, allowing the classification model to be trained to correctly classify traffic even when network conditions change dynamically. This module divides the existing encrypted traffic data into several subsets based on the network conditions they fall under. Then, it selects one subset as the training set and another as the test set to construct each classification task. This ensures that the encrypted traffic used for training and testing in each classification task belongs to different network conditions. Specifically, this module enumerates all construction methods to obtain the maximum number of classification tasks, thereby improving the generalization performance of the classification model. Let's assume that T classification tasks can be constructed.

[0119] In one embodiment of the present invention, the temporary model training module is designed as follows:

[0120] Drawing inspiration from the MAML workflow, this invention trains a total of T temporary models using the training set for each classification task. For a single model parameter φ, the traditional training process is as follows:

[0121]

[0122] Where Z and C are the representation layer and classification layer of the model, respectively. Let η1 be the learning rate of the temporary model, and η1 be the loss function. However, this training method has a serious drawback: simple samples can limit the representational ability of the temporary model. Simple samples refer to samples with features that can be directly inferred as class labels, such as specific handshake metadata that is rarely seen in normal traffic within malicious encrypted traffic. Such samples cause the temporary model to rely solely on specific features that can be directly inferred as class labels, rather than exploring the intrinsic relationships between all features to generate representations. This limits its representational ability, and consequently, it fails to generate correctly classified representations when all features change significantly due to dynamic network conditions. Furthermore, since the original model is optimized based on the performance of the temporary model on the test set, the representational ability of the optimized original model is also limited. To overcome these problems, we designed a class-aware representation enhancement module that directly adds noise to the representations generated by the temporary model during the training phase to improve the diversity of the temporary model's representations. The specific implementation is as follows:

[0123] Let (x, y) be a training encrypted traffic sample, where x is the encrypted traffic data, y is its corresponding class label, and z is the representation vector of the sample extracted by the model. To calculate the variance of all samples in category y, this module adds random Gaussian noise and category-correlated Gaussian noise to z, resulting in a new representation vector. The formula is: in Represents random Gaussian noise, λ 1,2 All are hyperparameters; The noise is class-related Gaussian, and its variance is equal to the variance of samples of the same class. The temporary model is trained using the new representation vector. The training process is as follows:

[0124]

[0125] The temporary model training module of the training method of the present invention differs from the traditional training process by innovatively adding Gaussian noise to the representation vector of the training samples, which can enhance the representation ability of the temporary model and promote the overall training method effect.

[0126] In one embodiment of the present invention, the temporary model testing module is as follows:

[0127] After obtaining the temporary model trained for each classification task, this invention needs to evaluate the performance of the corresponding temporary model on the test set of each task for subsequent optimization of the original model. We observed that even under different network conditions, encrypted traffic still has some stable representations that can be used for classification. This invention aims to train the classification model to learn these stable representations in order to achieve correct classification under dynamic network conditions. Therefore, the temporary model testing module measures the difference in the temporary model's representation of encrypted traffic under different network conditions as a loss function. The optimization module in subsequent steps of this invention will train the model based on this loss function to minimize the representation difference, ultimately obtaining a classification model that can generate stable representations.

[0128] A straightforward loss function design calculates the sum of distances between every pair of representations belonging to the same class in both the training and test subsets. However, its time complexity is quadratic, significantly increasing training overhead. A widely used alternative design is to obtain the average representation vector of each class as a prototype sample and calculate the sum of distances between prototype samples from each class. However, in some encrypted traffic classification tasks, traffic samples exhibiting different behaviors may be labeled as belonging to the same class. For example, traffic visiting different types of websites may all be labeled as normal traffic. This leads to significant differences in representations within the same class. A coarse-grained single prototype sample is insufficient to represent these different representations, causing a single prototype-based loss function design to fail to accurately calculate the differences between representations. To overcome these limitations, this module designs a clustering-based representation alignment method. This module utilizes DP-Means to automatically calculate a small number of highly representative representation vectors for samples exhibiting different behavioral patterns in each class, thereby achieving accurate and efficient representation difference calculation with a time complexity far below quadratic levels. The specific implementation method is as follows: This module uses DP-Means to cluster the representation vectors of all traffic samples in the training and test subsets, while ensuring that the representation vectors in each cluster belong to the same category, and calculates the Gaussian center of each cluster as the prototype sample of the corresponding category. For each category c, we denote the category prototype sets obtained from the training and test subsets as follows: The differences between these prototypes are calculated from two different perspectives and used as the loss function for this classification task.

[0129]

[0130] Where KL(p / / q)=plog(p / q) is the KL divergence between p and q, ω 1,2 These are the weight parameters. The content differences between prototypes were quantified, and This captures the semantic differences between prototypes, i.e., whether they can be classified into the same category by the temporary model. The loss function design ensures that the classification model, after optimization, generates stable representations of encrypted traffic under different network conditions that are both content- and semantically similar.

[0131] The temporary model testing module of the training method of this invention innovatively uses DP-Means adaptive clustering to simplify the calculation of differences between representation vectors, while ensuring the composite nature of the behavior patterns of encrypted traffic. It efficiently and accurately measures the differences in the representation of encrypted traffic under different network conditions by the temporary model, thereby improving the efficiency and effectiveness of the entire training method.

[0132] In one embodiment of the present invention, the original model optimization module is as follows:

[0133] This invention requires the loss of all classification tasks. Joint optimization of the original model ensures that it learns stable representations in response to any dynamic changes in network conditions. A direct approach to joint optimization is to calculate the sum of the gradients of the loss for each task relative to the parameters of the original model and use this sum as the optimization gradient. However, this method overlooks the fact that each task may contribute differently to the classification model's representational ability due to the different training and testing samples. To accelerate the optimization process, larger weights can be assigned to tasks with higher losses. However, this strategy may lead to overfitting the model to high-loss tasks, thus affecting its generalization ability on other tasks.

[0134] To accelerate model optimization while preventing overfitting to specific tasks, this invention designs an adaptive task weight allocation module. Its core idea is to continuously evaluate the model's optimization progress and allocate task weights that meet the model's optimization requirements at different optimization stages. Typically, in the early optimization stages, due to the model's limited representational ability, the loss of each task often fluctuates significantly between consecutive training iterations. Therefore, this module allocates higher weights to high-loss tasks to accelerate the optimization process. In the later optimization stages, as the model's representational ability stabilizes, the loss of each task often only changes slightly between training iterations. Therefore, the weights should be distributed more evenly across the tasks to prevent the model from over-focusing on high-loss tasks. Specifically, for all T tasks, we denote the loss of the t-th task in the e-th training iteration as... Then the weight vector W for each task in this iteration e The calculation is as follows:

[0135]

[0136] Here, η3 is the learning rate of the weight coefficient w, which is evaluated based on the change in the loss function of each task between two iterations. This design ensures that in the early optimization stage, when the loss changes significantly, a larger weight coefficient w can be obtained, thus giving larger weights to tasks with larger losses. In the later optimization stage, when the loss changes less, our design reduces the weight coefficient, thereby minimizing the difference between task weights. With the weight vector W, the model update in the e-th training iteration is as follows:

[0137]

[0138] Where η² is the learning rate for optimizing the original model. After multiple rounds of iterative training, the resulting original model can handle a variety of classification tasks, learn stable representations of encrypted traffic under different network conditions, and is suitable for encrypted traffic classification tasks under dynamic network conditions.

[0139] The temporary model testing module of this invention innovatively designs an adaptive weight allocation system that can automatically evaluate training progress and obtain suitable task weights. This accelerates model optimization while avoiding overfitting of the model to a single task, thus promoting overall model training.

[0140] In one embodiment of the present invention, the fine-tuning module is designed as follows:

[0141] The fine-tuning module of this invention uses all training encrypted traffic data to fine-tune the original model after iterative optimization. Specifically, it adopts the classic supervised training method to obtain the final encrypted traffic classification model, which can be directly deployed under dynamic network conditions to correctly classify encrypted traffic.

[0142] Therefore, the M1 classification task construction module constructs classification tasks for training and testing encrypted traffic under different network conditions based on existing traffic data; the M2 temporary model training module trains a temporary model using the training dataset from a single task, avoiding overfitting due to the single characteristic of the training data; the M3 temporary model testing module efficiently and accurately measures the differences in encrypted traffic representations under different network conditions obtained by the temporary model, serving as an evaluation metric for the original model facing different classification tasks; the M4 original model optimization module iteratively optimizes the original model based on the metrics of all classification tasks obtained from M3, reducing the differences in encrypted traffic representations under different network conditions and adaptively adjusting the weight ratio of each classification task loss when updating the original model, balancing model convergence speed and model generalization; the M5 fine-tuning module fine-tunes the original model optimized by M4 using all training data, resulting in a final model that can correctly classify encrypted traffic under dynamic network conditions. The M1 classification task construction module can construct classification tasks for training and testing encrypted traffic under different network conditions based on existing encrypted traffic data. M1 divides the existing encrypted traffic data into several subsets based on the network conditions. Then, it selects one subset as the training set and another as the test set to construct each classification task. Specifically, M1 enumerates all construction methods to obtain the maximum number of classification tasks. The M2 temporary model training module avoids overfitting caused by the homogeneity of the training data. During the training of a single temporary model using the training data for each task, M2 adds two types of Gaussian noise to the representation vector of each encrypted traffic sample: one is Gaussian noise with a fixed distribution, and the other is Gaussian noise with a distribution variance equal to the variance of all samples in the same class. The addition of these two types of Gaussian noise increases the diversity of the training data to avoid overfitting, while also maintaining the distribution correlation between different classes of data, preventing misclassification by the temporary model. The M3 temporary model testing module can efficiently and accurately measure the differences in encrypted traffic representations extracted by the temporary model under different network conditions, even when the encrypted traffic data has multiple typical distribution characteristics. M3 uses the DP-Means parameterless clustering algorithm to cluster the encrypted traffic representation vectors under different network conditions. Then, based on the obtained cluster centers, it performs a two-dimensional difference metric: one is the Euclidean distance between the cluster centers, and the other is the KL divergence of the class probability vectors obtained by the classification network after processing the cluster centers. These two metrics together constitute the representation difference index. The M4 original model optimization module can adaptively allocate the weights of different classification tasks in the process of updating the original model, balancing the convergence speed and generalization ability of the original model. M4 includes a Softmax function with coefficients, which receives the representation differences of all tasks (from M3) and outputs the weight of each task in the optimization. M4 continuously evaluates the model's optimization progress and adjusts the coefficients carried by Softmax at different optimization stages.Specifically, in the early stages of optimization, this coefficient is relatively large, allowing classification tasks with greater representational differences to receive greater weights, thus accelerating model convergence. In the later stages of optimization, this coefficient decreases, allowing different tasks to receive similar weights and avoiding overfitting to a single task. The M5 fine-tuning module can obtain a classification model applicable to dynamic network conditions. M5 uses all existing encrypted traffic data to fine-tune the original model optimized by M4, resulting in the final encrypted traffic classification model.

[0143] In summary, this specific implementation method draws on the idea of ​​MAML (Multi-Instance Classification), constructing diverse classification tasks under different network conditions to minimize the differences in the representation of encrypted traffic learned by the classification model under different network conditions. This enables the classification model to generate stable representations for encrypted traffic under dynamic network conditions, thereby ensuring classification accuracy under dynamic network conditions. This invention designs five modules to implement the above solutions. The temporary model training module, temporary model testing module, and original model optimization module all discuss specific problems in the field of encrypted traffic classification and design innovative solutions, which can further improve the overall training method's effectiveness and efficiency, and enhance the robustness of the encrypted traffic classification model under dynamic network conditions.

[0144] The beneficial effects of this invention are as follows:

[0145] By minimizing the differences in encrypted traffic representations under different network conditions, the classification model can generate stable representations for encrypted traffic under dynamic network conditions, thereby ensuring classification accuracy under dynamic network conditions. The training method proposed in this invention has been tested on public encrypted traffic datasets and real-world encrypted traffic data, and has been verified to effectively improve the classification performance of the model under dynamic network conditions, with a significant improvement over existing work.

[0146] Example 3

[0147] To achieve the above embodiments, such as Figure 3 As shown, this embodiment also provides a training device 10 for an encrypted traffic classification model suitable for dynamic network conditions, including:

[0148] The heterogeneous classification task partitioning module is used to divide existing encrypted traffic data into multiple subsets according to the network conditions in which it is located, and enumerate all possible partitioning methods to construct multiple classification tasks. Each classification task includes a training set and a test set, and the network conditions of the training set and the test set are different.

[0149] The noise-enhanced temporary model training module is used to train the training set in each classification task to generate the corresponding temporary model. During the training process, two types of Gaussian noise are added to the representation vector of each encrypted traffic sample: one is Gaussian noise with a fixed distribution, and the other is class-related Gaussian noise with a variance equal to the variance of samples of the same class.

[0150] The clustering-based difference measurement module is used to cluster the encrypted traffic representation vectors of the training set and the test set respectively using the DP-Means clustering algorithm for the temporary model in each classification task. Based on the cluster centers, Euclidean distance and KL divergence are calculated to measure the difference of encrypted traffic representation under different network conditions from two perspectives, which serves as the loss index for the task.

[0151] The adaptive weighted model optimization module is used to adaptively allocate the weights of each task in the optimization process based on the loss metrics of all classification tasks through the coefficientd Softmax function. The Softmax coefficient is dynamically adjusted according to the training phase to accelerate model convergence in the early stage of optimization and balance task weights in the later stage of optimization to prevent the model from overfitting to a single task.

[0152] Furthermore, the conditionally heterogeneous classification task partitioning module is also used for:

[0153] Network conditions are divided into three categories: the hardware and protocol configuration of the host from which the encrypted traffic originates, the network layer and transport layer parameter settings in the transmission path, and the type and parameters of the traffic obfuscation strategy.

[0154] For each combination of network conditions, generate at least one training set and test set pair, ensuring that the network conditions of the training set and test set are significantly different in at least one dimension.

[0155] Furthermore, the noise-enhanced temporary model training module is also used for:

[0156] The fixed-distribution Gaussian noise is divided into coefficients and deviation values. The mean of the coefficients is 1, the mean of the deviation values ​​is 0, and the variance of the two is a preset global noise parameter.

[0157] The mean of the category-related Gaussian noise is 0, and the variance is the variance of the representation vectors of all samples in the current category in the corresponding dimension, which is dynamically calculated in each training task.

[0158] Furthermore, the cluster-based difference measurement module is also used for:

[0159] The DP-Means clustering algorithm automatically determines the number of clusters during the clustering process and ensures that the representation vectors in each cluster belong to the same category.

[0160] When calculating the Euclidean distance between clusters, the logarithmic mean of the distance is used as a metric. This ensures that when optimizing based on this metric, each cluster only moves closer to a single target cluster. Furthermore, when moving closer to a single target cluster, the logarithmic mean of the distance approaches negative infinity. This allows us to find the correspondence between traffic behavior patterns under two conditions, which are reflected by different clusters.

[0161] Furthermore, it also includes:

[0162] The iterative training module is used to perform multiple rounds of iterative training on the optimized original model. In each round of iteration, the steps of the noise-enhanced temporary model training module, the clustering-based difference measurement module, and the adaptive weighted model optimization module are repeatedly executed. After each round, the coefficients in the Softmax function are updated to gradually improve the consistency of the model's representation under different network conditions.

[0163] The encrypted traffic classification model training device for dynamic network conditions according to embodiments of the present invention further improves the representation consistency and convergence stability of the encrypted traffic classification model under different network conditions by conducting multiple rounds of iterative training and dynamically updating the coefficients in the Softmax function, thereby achieving more efficient and robust classification performance in complex dynamic environments.

[0164] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.

[0165] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this invention, "a plurality of" means at least two, such as two, three, etc., unless otherwise explicitly specified.

Claims

1. A method for training an encrypted traffic classification model suitable for dynamic network conditions, characterized in that, include: S1. Based on existing encrypted traffic data, divide it into multiple subsets according to the network conditions in which it is located, and enumerate all possible division methods to construct multiple classification tasks. Each classification task includes a training set and a test set, and the network conditions of the training set and the test set are different. S2, train the training set in each classification task to generate the corresponding temporary model. During the training process, add two types of Gaussian noise to the representation vector of each encrypted traffic sample: one is Gaussian noise with a fixed distribution, and the other is class-related Gaussian noise with a variance equal to the variance of samples of the same class. S3. For the temporary model in each classification task, the DP-Means clustering algorithm is used to cluster the encrypted traffic representation vectors of the training set and the test set respectively. Euclidean distance and KL divergence are calculated based on the cluster centers to measure the difference in encrypted traffic representation under different network conditions from two perspectives, which serves as the loss index for this task. S4, based on the loss metrics of all classification tasks, adaptively allocates the weights of each task during the optimization process through a coefficientd Softmax function. The Softmax coefficient is dynamically adjusted according to the training phase to accelerate model convergence in the early stage of optimization and balance task weights in the later stage of optimization.

2. The method as described in claim 1, characterized in that, S1 includes: S11 divides network conditions into three categories: hardware and protocol configuration of the host from which the encrypted traffic originates, network layer and transport layer parameter settings in the transmission path, and type and parameters of the traffic obfuscation strategy. S12, for each combination of network conditions, generate at least one training set and test set pair, and ensure that the network conditions of the training set and test set are significantly different in at least one dimension.

3. The method as described in claim 1, characterized in that, The S2 includes: S21, the fixed-distribution Gaussian noise is divided into coefficients and deviation values, the mean of the coefficients is 1, the mean of the deviation values ​​is 0, and the variance of the two is a preset global noise parameter. S22, the mean of the category-related Gaussian noise is 0, and the variance is the variance of the representation vectors of all samples of the current category in the corresponding dimension, and is dynamically calculated in each training task.

4. The method as described in claim 1, characterized in that, The S3 includes: S31, the DP-Means clustering algorithm automatically determines the number of clusters during the clustering process and ensures that the representation vectors in each cluster belong to the same category; S32, when calculating the Euclidean distance between clusters, the logarithmic mean of the distance is used as a metric, so that when optimizing based on this metric, each cluster only moves closer to a single target cluster, and when moving closer to a single target cluster, the logarithmic mean of the distance will approach negative infinity, thereby finding the correspondence between traffic behavior patterns under two conditions, and the traffic behavior patterns are reflected by different clusters.

5. The method as described in claim 1, characterized in that, Also includes: S5 involves iteratively training the optimized original model in multiple rounds. In each round of iteration, steps S2 to S4 are repeated, and the coefficients in the Softmax function are updated after each round to gradually improve the consistency of the model's representation under different network conditions.

6. A training device for an encrypted traffic classification model suitable for dynamic network conditions, characterized in that, include: The heterogeneous classification task partitioning module is used to divide existing encrypted traffic data into multiple subsets according to the network conditions in which it is located, and enumerate all possible partitioning methods to construct multiple classification tasks. Each classification task includes a training set and a test set, and the network conditions of the training set and the test set are different. The noise-enhanced temporary model training module is used to train the training set in each classification task to generate the corresponding temporary model. During the training process, two types of Gaussian noise are added to the representation vector of each encrypted traffic sample: one is Gaussian noise with a fixed distribution, and the other is class-related Gaussian noise with a variance equal to the variance of samples of the same class. The clustering-based difference measurement module is used to cluster the encrypted traffic representation vectors of the training set and the test set respectively using the DP-Means clustering algorithm for the temporary model in each classification task. Based on the cluster centers, Euclidean distance and KL divergence are calculated to measure the difference of encrypted traffic representation under different network conditions from two perspectives, which serves as the loss index for the task. The adaptive weighted model optimization module is used to adaptively allocate the weights of each task in the optimization process based on the loss metrics of all classification tasks through the coefficientd Softmax function. The Softmax coefficient is dynamically adjusted according to the training phase to accelerate model convergence in the early stage of optimization and balance task weights in the later stage of optimization to prevent the model from overfitting to a single task.

7. The apparatus as claimed in claim 6, characterized in that, The conditionally heterogeneous classification task partitioning module is also used for: Network conditions are divided into three categories: the hardware and protocol configuration of the host from which the encrypted traffic originates, the network layer and transport layer parameter settings in the transmission path, and the type and parameters of the traffic obfuscation strategy. For each combination of network conditions, generate at least one training set and test set pair, ensuring that the network conditions of the training set and test set are significantly different in at least one dimension.

8. The apparatus as claimed in claim 6, characterized in that, The temporary model training module for noise enhancement is also used for: The fixed-distribution Gaussian noise is divided into coefficients and deviation values. The mean of the coefficients is 1, the mean of the deviation values ​​is 0, and the variance of the two is a preset global noise parameter. The mean of the category-related Gaussian noise is 0, and the variance is the variance of the representation vectors of all samples in the current category in the corresponding dimension, which is dynamically calculated in each training task.

9. The apparatus as claimed in claim 6, characterized in that, The cluster-based difference measurement module is also used for: The DP-Means clustering algorithm automatically determines the number of clusters during the clustering process and ensures that the representation vectors in each cluster belong to the same category. When calculating the Euclidean distance between clusters, the logarithmic mean of the distance is used as a metric. This ensures that when optimizing based on this metric, each cluster only moves closer to a single target cluster. Furthermore, when moving closer to a single target cluster, the logarithmic mean of the distance approaches negative infinity. This allows us to find the correspondence between traffic behavior patterns under two conditions, which are reflected by different clusters.

10. The apparatus as claimed in claim 6, characterized in that, Also includes: The iterative training module is used to perform multiple rounds of iterative training on the optimized original model. In each round of iteration, the steps of the noise-enhanced temporary model training module, the clustering-based difference measurement module, and the adaptive weighted model optimization module are repeatedly executed. After each round, the coefficients in the Softmax function are updated to gradually improve the consistency of the model's representation under different network conditions.