MalMoE: Mixture-of-Experts Enhanced Encrypted Malicious Traffic Detection Under Graph Drift
Yunpeng Tan, Qingyang Li, Mingxin Yang, Yannan Hu, Lei Zhang, Xinggong Zhang
摘要
Encryption has been commonly used in network traffic to secure transmission, but it also brings challenges for malicious traffic detection, due to the invisibility of the packet payload. Graph-based methods are emerging as promising solutions by leveraging multi-host interactions to promote detection accuracy. But most of them face a critical problem: Graph Drift, where the flow statistics or topological information of a graph change over time.
To overcome these drawbacks, we propose a graph-assisted encrypted traffic detection system, MalMoE, which applies Mixture of Experts (MoE) to select the best expert model for drift-aware classification. Particularly, we design 1-hop-GNN-like expert models that handle different graph drifts by analyzing graphs with different features. Then, the redesigned gate model conducts expert selection according to the actual drift. MalMoE is trained with a stable two-stage training strategy with data augmentation, which effectively guides the gate on how to perform routing. Experiments on open-source, synthetic, and real-world datasets show that MalMoE can perform precise and real-time detection.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper9
- Realtime Robust Malicious Traffic Detection via Frequency Domain AnalysisChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2021 · 被引用 194 次
- IXP scrubber: learning from blackholing traffic for ML-driven DDoS detection at scaleMatthias Wichtlhuber, Eric Strehle, Daniel Kopp, Lars Prepens 等SIGCOMM 2022 · 被引用 35 次
- GraphMETRO: Mitigating Complex Graph Distribution Shifts via Mixture of Aligned ExpertsShirley Wu, Kaidi Cao, Bruno Ribeiro, James Y. Zou 等NeurIPS 2024 · 被引用 27 次
- Robust and Reliable Early-Stage Website Fingerprinting Attacks via Spatial-Temporal Distribution AnalysisXinhao Deng, Qi Li, Ke XuCCS 2024 · 被引用 22 次
- NetVigil: Robust and Low-Cost Anomaly Detection for East-West Data Center SecurityKevin Hsieh, Mike Wong, Santiago Segarra, Sathiya Kumaran Mani 等NSDI 2024 · 被引用 17 次
相关 Paper
- Revolutionizing Encrypted Traffic Classification with MH-Net: A Multi-View Heterogeneous Graph ModelHaozhen Zhang, Haodong Yue, Xi Xiao, Le Yu 等AAAI 2025 · 被引用 16 次
- Detecting Unknown Encrypted Malicious Traffic in Real Time via Flow Interaction Graph AnalysisChuanpu Fu, Qi Li, Ke XuNDSS 2023
- Graph Mixture of Experts and Memory-augmented Routers for Multivariate Time Series Anomaly DetectionXiaoyu Huang, Weidong Chen, Bo Hu, Zhendong MaoAAAI 2025 · 被引用 22 次
- FlowMiner: A Powerful Model Based on Flow Correlation Mining for Encrypted Traffic ClassificationHongbo Xu, Chengxiang Si, Shuhao Li, Zhenyu Cheng 等INFOCOM 2025 · 被引用 4 次
- TDDM-Melatt: A Decoupled Memory and Diffusion Framework for Generalizable Encrypted Traffic ClassificationZe Chen, Qiming Yu, Zijia Song, Guozheng Yang 等CCS 2026
