Organizations: School of Cyberspace Security, Beijing University of Posts and Telecommunications, Beijing, China · Zhongguancun Laboratory, Beijing, China
Identifying the set of monitored websites in mixed encrypted traffic is challenging because an individual flow often provides only partial evidence of website identity. To address this challenge, we propose FlowAtom, which constructs shared prototypes, called Atoms, from flow representations without website labels. Specifically, FlowAtom pretrains a flow encoder on external unlabeled traffic and aggregates Atom responses across flows within each observation window into a fixed-dimensional, permutation-invariant representation for monitored website-set prediction. Across Direct HTTPS, Trojan, and VMess, FlowAtom achieves micro-F1 scores of 97.82%, 94.43%, and 93.92% in closed-world evaluation, respectively, and consistently outperforms the evaluated baselines in open-world evaluation on windows containing monitored visits. The code is available at https://github.com/aimafan123/FlowAtom.
Figures & tables
Figure 1: Different websites can generate similar flows; aggregating complementary evidence across flows in an observation window supports prediction of the monitored website set.
Figure 2: Overview of FlowAtom: flow representation pretraining, Atom construction, and window-level multi-label prediction.
Direct HTTPS
Trojan
VMess
Method
1
2
3
4
5
1
2
3
4
5
1
2
3
4
5
ARES
67.91
57.14
40.49
37.41
35.77
88.20
73.37
62.42
57.07
53.73
89.89
74.74
63.73
61.79
53.82
BAPM
57.57
34.21
25.30
21.05
15.66
64.17
34.33
33.61
32.39
23.73
65.26
37.11
31.71
30.95
24.12
TMWF
68.85
35.72
29.39
25.45
20.22
79.42
42.38
36.84
36.55
30.00
82.83
46.91
39.67
39.98
32.53
Flow-DF
75.92
80.20
78.82
78.66
81.72
82.29
79.62
77.05
81.30
82.07
82.56
82.49
82.21
84.23
80.10
CAWF
84.72
86.59
86.06
81.00
84.19
82.41
84.75
81.87
80.80
80.52
80.85
79.85
77.39
81.79
73.62
Table 1: Closed-world micro-F1 (%) in three traffic scenarios, with m∈{1,2,3,4,5} distinct monitored websites per observation window. Bold and underlined values indicate the best and second-best results in each column, respectively.
Deep learning-based website fingerprinting has emerged as an effective technique for inferring the websites users visit. Although existing methods achieve strong performance on closed-world datasets, they often fail to generalize to real-world environments, especially under geographic and temporal shifts. This limitation fundamentally stems from the coupled effects of two key challenges: application-layer resource composition variability and observable feature instability induced by cross-layer encapsulation. Intertwined, these factors induce systematic shifts between underlying application semantics and observable traffic features. To address the above challenges, we propose SATA , a semantics-aware traffic augmentation framework. Specifically, SATA first performs application-layer semantic augmentation based on protocol rules, expanding the resource composition patterns within each flow and frame sequence patterns under protocol constraints. Based on these augmented frame sequences, we further introduce a cross-layer feature alignment mechanism via knowledge distillation. It aligns frame sequence with packet-length sequence features, enabling cross-layer feature alignment between enhanced semantics and observable sequences. Extensive experiments show that SATA successfully generates traffic patterns that are absent from the training set but genuinely exist in the test set, and significantly improves the performance of mainstream models across diverse and complex scenarios. In particular, in open-world settings, SATA improves ACC by 90.81% and AUROC by 48.37%. The source code of the prototype system is available at https://anonymous.4open.science/r/SATA-B6C2/.
Youquan Xian, Xueying Zeng, Lingjia Meng +6
School of Cyberspace Security, Beijing University of Posts and Telecommunications, Beijing, China · School of Computer Science and Engineering, Beihang University, Beijing, China · Zhongguancun Laboratory, Beijing, China +2
Traditional traffic analysis is being fundamentally challenged by the rapid adoption of encryption, tunnelling, and privacy-preserving protocols, which increasingly obscure packet payloads and limit the usefulness of Deep Packet Inspection (DPI). Although machine learning has advanced encrypted traffic analysis, existing approaches often remain tied to protocol-specific header features, depend on large labelled datasets, and degrade when deployed across heterogeneous network environments. We present GETA, a protocol-agnostic framework for encrypted traffic analysis that models network flows as multivariate time series using only traffic metadata, thereby avoiding reliance on packet payloads or header semantics. GETA combines meta-learning, embedding refinement, and self-attention to support few-shot adaptation to previously unseen domains with minimal labelled data. Across nine public datasets spanning application identification, VPN traffic classification, IoT device fingerprinting, and attack detection, GETA consistently outperforms state-of-the-art baselines. These results show that GETA offers a practical and generalisable foundation for robust traffic analysis in modern encrypted networks.
While Website Fingerprinting (WF) attacks achieve high accuracy in controlled laboratory settings, they often degrade substantially in real-world environments due to spatio-temporal drift, browser heterogeneity, proxy obfuscation and etc. This limitation stems from their sole reliance on low-level traffic features that are noisy and highly sensitive to environmental perturbations. To address this problem, we propose \textbf{ResAware}, a cross-environment resource-aware distillation framework under a \textit{training-rich/inference-poor} asymmetric setting. Specifically, ResAware trains a teacher model on resource-level features, and then distills the resulting privileged knowledge into a student model through heterogeneous knowledge distillation. At deployment time, the student model performs inference using only encrypted traffic, incurring zero additional cost. We evaluate ResAware on a large-scale dataset collected over five months from six globally distributed vantage points, comprising more than 160,000 paired samples. The results show that ResAware significantly enhances the cross-environment robustness of diverse WF baselines. Under a 150-day temporal drift, for example, ResAware improves the F1-score of Var-CNN from 72.77% to 81.49% and the open-world TPR@1%FPR from 22.40% to 27.20%. Our results demonstrate that resource-level supervision improves WF robustness without expanding online observation capabilities.
Chongru Fan, Wei Wang, Wentao Huang +5
Beijing University of Posts and Telecommunications Beijing, China · Zhongguancun Laboratory Beijing, China