TempoNet: Learning Realistic Communication and Timing Patterns for Network Traffic Simulation

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Moore, Kristen, Goel, Diksha, Christopher, Cody James, Wang, Zhen, Kim, Minjune, Ibrahim, Ahmed, Mohsin, Ahmad, Camtepe, Seyit
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917217087520768
author Moore, Kristen
Goel, Diksha
Christopher, Cody James
Wang, Zhen
Kim, Minjune
Ibrahim, Ahmed
Mohsin, Ahmad
Camtepe, Seyit
author_facet Moore, Kristen
Goel, Diksha
Christopher, Cody James
Wang, Zhen
Kim, Minjune
Ibrahim, Ahmed
Mohsin, Ahmad
Camtepe, Seyit
contents Realistic network traffic simulation is critical for evaluating intrusion detection systems, stress-testing network protocols, and constructing high-fidelity environments for cybersecurity training. While attack traffic can often be layered into training environments using red-teaming or replay methods, generating authentic benign background traffic remains a core challenge -- particularly in simulating the complex temporal and communication dynamics of real-world networks. This paper introduces TempoNet, a novel generative model that combines multi-task learning with multi-mark temporal point processes to jointly model inter-arrival times and all packet- and flow-header fields. TempoNet captures fine-grained timing patterns and higher-order correlations such as host-pair behavior and seasonal trends, addressing key limitations of GAN-, LLM-, and Bayesian-based methods that fail to reproduce structured temporal variation. TempoNet produces temporally consistent, high-fidelity traces, validated on real-world datasets. Furthermore, we show that intrusion detection models trained on TempoNet-generated background traffic perform comparably to those trained on real data, validating its utility for real-world security applications.
format Preprint
id arxiv_https___arxiv_org_abs_2601_15663
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle TempoNet: Learning Realistic Communication and Timing Patterns for Network Traffic Simulation
Moore, Kristen
Goel, Diksha
Christopher, Cody James
Wang, Zhen
Kim, Minjune
Ibrahim, Ahmed
Mohsin, Ahmad
Camtepe, Seyit
Cryptography and Security
Artificial Intelligence
Machine Learning
Realistic network traffic simulation is critical for evaluating intrusion detection systems, stress-testing network protocols, and constructing high-fidelity environments for cybersecurity training. While attack traffic can often be layered into training environments using red-teaming or replay methods, generating authentic benign background traffic remains a core challenge -- particularly in simulating the complex temporal and communication dynamics of real-world networks. This paper introduces TempoNet, a novel generative model that combines multi-task learning with multi-mark temporal point processes to jointly model inter-arrival times and all packet- and flow-header fields. TempoNet captures fine-grained timing patterns and higher-order correlations such as host-pair behavior and seasonal trends, addressing key limitations of GAN-, LLM-, and Bayesian-based methods that fail to reproduce structured temporal variation. TempoNet produces temporally consistent, high-fidelity traces, validated on real-world datasets. Furthermore, we show that intrusion detection models trained on TempoNet-generated background traffic perform comparably to those trained on real data, validating its utility for real-world security applications.
title TempoNet: Learning Realistic Communication and Timing Patterns for Network Traffic Simulation
topic Cryptography and Security
Artificial Intelligence
Machine Learning
url https://arxiv.org/abs/2601.15663