Lune

NSDI2026Top-tier venue

SPLIDT: Partitioned Decision Trees for Scalable Stateful Inference at Line Rate

Murayyiam Parvez, Annus Zulfiqar, Roman Beltiukov, Shir Landau Feibish, Walter Willinger, Arpit Gupta, Muhammad Shahbaz

2026Year
1Citations

Abstract

Machine learning (ML) is increasingly being deployed in programmable data planes (switches and SmartNICs) to enable real-time traffic analysis, security monitoring, and innetwork decision-making. Decision trees (DTs) are particularly well-suited for these tasks due to their interpretability and compatibility with data-plane architectures, i.e., matchaction tables (MATs). However, existing in-network DT implementations are constrained by the need to compute all input features upfront, forcing models to rely on a small, fixed set of features per flow. This significantly limits model accuracy and scalability under stringent hardware resource constraints.

We present SPLIDT, a system that rethinks DT deployment in the data plane by enabling partitioned inference over sliding windows of packets. SPLIDT introduces two key innovations: (1) it groups individual subtrees of a DT into partitions and allows each subtree to have its own feature set, and (2) it leverages an in-band control channel (via recirculation) to reuse data-plane resources (both stateful registers and match keys) across partitions at line rate. These insights allow SPLIDT to scale the number of stateful features a model can use without exceeding hardware limits. To support this architecture, SPLIDT incorporates a custom training and design-space exploration (DSE) framework that jointly optimizes feature allocation, tree partitioning, and DT model depth. Evaluation across multiple real-world datasets shows that SPLIDT achieves higher accuracy while supporting up to 5↔ more stateful features than prior approaches (e.g., NetBeacon and Leo). It maintains the same low time-to-detection (TTD) as these systems, while scaling to millions of flows with minimal recirculation overhead (↗0.05%).

Machine Learning (ML) is rapidly becoming a cornerstone of modern networking, driving increasingly sophisticated applications such as DDoS detection (LUCID [25], Flowlens [5]), intrusion detection [14,15,75], encrypted traffic analysis [4, 74, 80], malware classification [2, 29], IoT botnet detection [24] as well as congestion control [23,39,52,77,86], and variable bitrate (VBR) video streaming [55,85]. These use cases demand real-time, high-throughput inference [71] to keep up with the ever-growing scale and complexity of network traffic [6,[14][15][16][17][18]65].

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext f2dba0ba-5c7d-44ab-b3c8-16a6531b3e71

Builds on11

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines