Leo: Online ML-based Traffic Classification at Multi-Terabit Line Rate
Syed Usman Jafri, Sanjay G. Rao, Vishal Shrivastav, Mohit Tawarmalani
Abstract
Online traffic classification enables critical applications such as network intrusion detection and prevention, providing Quality-of-Service, and real-time IoT analytics. However, with increasing network speeds, it has become extremely challenging to analyze and classify traffic online. In this paper, we present Leo, a system for online traffic classification at multi-terabit line rates. At its core, Leo implements an online machine learning (ML) model for traffic classification, namely the decision tree, in the network switch's data plane.
Leo's design is fast (can classify packets at switch's line rate), scalable (can automatically select a resource-efficient design for the class of decision tree models a user wants to support), and runtime programmable (the model can be updated on-thefly without switch downtime), while achieving high model accuracy. We implement Leo on top of Intel Tofino switches. Our evaluations show that Leo is able to classify traffic at line rate with nominal latency overhead, can scale to model sizes more than twice as large as state-of-the-art data plane ML classification systems, while achieving classification accuracy on-par with an offline traffic classifier.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext cbd7c371-8263-4ee4-b9bb-ce5f04dd7de2Builds on11
- ATP: In-network Aggregation for Multi-tenant LearningChonLam Lao, Yanfang Le, Kshiteej Mahajan, Yixi Chen et al.NSDI 2021 · 359 citations
- Re-architecting Traffic Analysis with Neural Network Interface CardsGiuseppe Siracusano, Salvator Galea, Davide Sanvito, Mohammad Malekzadeh et al.NSDI 2022 · 99 citations
- Taurus: a data plane architecture for per-packet MLTushar Swamy, Alexander Rucker, Muhammad Shahbaz, Ishan Gaur et al.ASPLOS 2022 · 94 citations
- Programmable Switches for in-Networking ClassificationBruno Missi Xavier, Rafael Silva Guimarães, Giovanni Comarela, Magnos MartinelloINFOCOM 2021 · 79 citations
- Unlocking the Power of Inline Floating-Point Operations on Programmable SwitchesYifan Yuan, Omar Alama, Jiawei Fei, Jacob Nelson et al.NSDI 2022 · 33 citations
Related papers
- An Efficient Design of Intelligent Network Data PlaneGuangmeng Zhou, Zhuotao Liu, Chuanpu Fu, Qi Li et al.USENIX Security 2023
- Proteus: Towards Accurate and Low-overhead In-Network Malicious Traffic DetectionLonglong Zhu, Linying Zheng, Qing Shu, Zedi Chen et al.WWW 2026
- Jewel: Resource-Efficient Joint Packet and Flow Level Inference in Programmable SwitchesAristide Tanyi-Jong Akem, Beyza Bütün, Michele Gucciardo, Marco FioreINFOCOM 2024 · 27 citations
- FENIX: Enabling In-Network DNN Inference with FPGA-Enhanced Programmable SwitchesXiangyu Gao, Tong Li, Yinchao Zhang, Ziqiang Wang et al.NSDI 2026 · 12 citations
- SPLIDT: Partitioned Decision Trees for Scalable Stateful Inference at Line RateMurayyiam Parvez, Annus Zulfiqar, Roman Beltiukov, Shir Landau Feibish et al.NSDI 2026 · 1 citation
