The Sweet Danger of Sugar: Debunking Representation Learning for Encrypted Traffic Classification

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhao, Yuqi, Dettori, Giovanni, Boffa, Matteo, Vassio, Luca, Mellia, Marco
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915404515901440
author Zhao, Yuqi
Dettori, Giovanni
Boffa, Matteo
Vassio, Luca
Mellia, Marco
author_facet Zhao, Yuqi
Dettori, Giovanni
Boffa, Matteo
Vassio, Luca
Mellia, Marco
contents Recently we have witnessed the explosion of proposals that, inspired by Language Models like BERT, exploit Representation Learning models to create traffic representations. All of them promise astonishing performance in encrypted traffic classification (up to 98% accuracy). In this paper, with a networking expert mindset, we critically reassess their performance. Through extensive analysis, we demonstrate that the reported successes are heavily influenced by data preparation problems, which allow these models to find easy shortcuts - spurious correlation between features and labels - during fine-tuning that unrealistically boost their performance. When such shortcuts are not present - as in real scenarios - these models perform poorly. We also introduce Pcap-Encoder, an LM-based representation learning model that we specifically design to extract features from protocol headers. Pcap-Encoder appears to be the only model that provides an instrumental representation for traffic classification. Yet, its complexity questions its applicability in practical settings. Our findings reveal flaws in dataset preparation and model training, calling for a better and more conscious test design. We propose a correct evaluation methodology and stress the need for rigorous benchmarking.
format Preprint
id arxiv_https___arxiv_org_abs_2507_16438
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle The Sweet Danger of Sugar: Debunking Representation Learning for Encrypted Traffic Classification
Zhao, Yuqi
Dettori, Giovanni
Boffa, Matteo
Vassio, Luca
Mellia, Marco
Networking and Internet Architecture
Machine Learning
Recently we have witnessed the explosion of proposals that, inspired by Language Models like BERT, exploit Representation Learning models to create traffic representations. All of them promise astonishing performance in encrypted traffic classification (up to 98% accuracy). In this paper, with a networking expert mindset, we critically reassess their performance. Through extensive analysis, we demonstrate that the reported successes are heavily influenced by data preparation problems, which allow these models to find easy shortcuts - spurious correlation between features and labels - during fine-tuning that unrealistically boost their performance. When such shortcuts are not present - as in real scenarios - these models perform poorly. We also introduce Pcap-Encoder, an LM-based representation learning model that we specifically design to extract features from protocol headers. Pcap-Encoder appears to be the only model that provides an instrumental representation for traffic classification. Yet, its complexity questions its applicability in practical settings. Our findings reveal flaws in dataset preparation and model training, calling for a better and more conscious test design. We propose a correct evaluation methodology and stress the need for rigorous benchmarking.
title The Sweet Danger of Sugar: Debunking Representation Learning for Encrypted Traffic Classification
topic Networking and Internet Architecture
Machine Learning
url https://arxiv.org/abs/2507.16438