Decompose to Understand, Fuse to Detect: Frequency-Decoupled Anomaly Detection for Encrypted Network Traffic
Xinglin Lian, Chengtai Cao, Ting Zhong, Yong Wang, Kai Chen, Fan Zhou
Abstract
Network traffic anomaly detection represents a critical cybersecurity task, yet widespread encryption makes this task increasingly challenging. In response, image-based methods that model traffic as visual patterns have emerged as the dominant approach. However, this work pioneers the identification of a pervasive "full-frequency"characteristic and an associated limitation termed "spectral mismatch"within this paradigm. Specifically, while encrypted traffic exhibits prominent high-frequency components, mainstream reconstruction methods demonstrate an inherent bias toward learning low-frequency information. This fundamental mismatch results in incomplete representations that consequently degrade anomaly detection performance. To address this challenge, we propose FreeUp, a novel frequency-decoupled framework designed explicitly for encrypted traffic analysis. FreeUp decomposes traffic data into distinct low- and high-frequency bands, processing them through separate, dedicated branches along with a customized training strategy that ensures stable and independent frequency-specific learning. Furthermore, recognizing that simple reconstruction error proves inadequate for evaluating dual-branch architectures, we introduce an uncertainty-inspired fusion scoring mechanism. This mechanism quantifies the reconstruction uncertainty of the frequency-specific branches and dynamically integrates their outputs, yielding a more comprehensive and reliable anomaly score. Extensive experiments across multiple benchmarks demonstrate that FreeUp consistently outperforms state-of-the-art baselines. The code is available at https://github.com/ikun0124/FreeUp.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c0d230fd-dcac-41d8-af2a-62aaf5480ccdCited by top-tier papers2
- AnchorMoE: Interpretable Time Series Classification via Anchor-Routed MoETao Xie, Zexi Tan, Haoyi Xiao, Mengke Li et al.KDD 2026 · 4 citations
- Disentangling Multi-View Scanning in Mamba for Network Traffic Anomaly DetectionXinglin Lian, Chengtai Cao, Ting Zhong, Fan ZhouKDD 2026 · 2 citations
Builds on13
- Anomaly Transformer: Time Series Anomaly Detection with Association DiscrepancyJiehui Xu, Haixu Wu, Jianmin Wang, Mingsheng LongICLR 2022 · 960 citations
- Deep Evidential RegressionAlexander Amini, Wilko Schwarting, Ava Soleimany, Daniela RusNeurIPS 2020 · 777 citations
- ET-BERT: A Contextualized Datagram Representation with Pre-training Transformers for Encrypted Traffic ClassificationXinjie Lin, Gang Xiong, Gaopeng Gou, Zhen Li et al.WWW 2022 · 490 citations
- TimesNet: Temporal 2D-Variation Modeling for General Time Series AnalysisHaixu Wu, Tengge Hu, Yong Liu, Hang Zhou et al.ICLR 2023 · 423 citations
- Neural Transformation Learning for Deep Anomaly Detection Beyond ImagesChen Qiu, Timo Pfrommer, Marius Kloft, Stephan Mandt et al.ICML 2021 · 171 citations
Related papers
- Facing Anomalies Head-On: Network Traffic Anomaly Detection via Uncertainty-Inspired Inter-Sample DifferencesXinglin Lian, Chengtai Cao, Yan Liu, Xovee Xu et al.WWW 2025 · 11 citations
- TDDM-Melatt: A Decoupled Memory and Diffusion Framework for Generalizable Encrypted Traffic ClassificationZe Chen, Qiming Yu, Zijia Song, Guozheng Yang et al.CCS 2026
- Frequency-Domain Mixing Data Augmentation for Malicious Traffic DetectionYuhao Yan, Bo Lang, Xiangyu LiCCS 2026
- Trident: A Universal Framework for Fine-Grained and Class-Incremental Unknown Traffic DetectionZiming Zhao, Zhaoxuan Li, Zhuoxue Song, Wenhao Li et al.WWW 2024 · 38 citations
- Towards Context-Aware Traffic Classification via Time-Wavelet Fusion NetworkZiming Zhao, Zhuoxue Song, Xiaofei Xie, Zhaoxuan Li et al.KDD 2025 · 5 citations
