Abstract
The increase in the number of encryption schemes for communication networks has resulted in a persistent challenge for network security, as malicious activities can be concealed within otherwise legitimate encrypted communication flows. Current methods using graph theory do not consider semantic behavior while creating links and assuming that all neighbors contribute equally to message transmission regardless of their importance to discriminatory power for fine-grained categories. The current work introduces a model for edge weight calculation with multi-source feature fusion named EW-GAT. A semantic similarity graph is constructed via cosine similarity and Top-K sparsification, with similarity values directly embedded as edge weights to quantitatively encode behavioral closeness between flows. A multi-source fusion scheme integrates flow-level statistical features, KNN-based neighborhood representations, and class-prior signals from a gradient boosting model to enrich node representations. An edge-weighted attention mechanism further modulates attention coefficients with the pre-computed edge weights, enabling behavior-aware neighbor aggregation. Experiments on two benchmark datasets, CIC-IDS2017 and CSE-CIC-IDS2018, show that the proposed approach attains 99.59% and 99.53% Accuracy on the respective binary tasks, and 94.07% Accuracy with 94.20% Macro-F1 on the CIC-IDS2017 15-class task and 93.33% Accuracy with 93.14% Macro-F1 on the CSE-CIC-IDS2018 15-class task, consistently outperforming all baselines across both datasets. Ablation analysis reveals Macro-F1 drops of 9.29% and 9.73% on the two datasets when the similarity graph is replaced by a random graph, confirming the robustness of the three innovations across different network environments.
References
Anderson, B., Paul, S., and McGrew, D. (2018). Deciphering malware’s use of TLS (without decryption). Journal of Computer Virology and Hacking Techniques, 14(3), 195–211.
Bai, X., and Bai, Y. (2025). Equilibrium strategy of attack and defense in computer networks based on Markov signal game theory. Journal of Cyber Security and Mobility, 14(1), 127–154.
Cai, S., Tang, H., Chen, J., Lv, T., Zhao, W., and Huang, C. (2025). GSA-DT: A malicious traffic detection model based on graph self-attention network and decision tree. IEEE Transactions on Network and Service Management, 22(2), 2059–2073.
Chen, E. (2025). Analysis of e-commerce security protection technology based on YOLO algorithm optimized by lightweight neural network. Journal of Cyber Security and Mobility, 14(4), 849–876.
Chen, J., Song, L., Cai, S., Xie, H., Yin, S., and Ahmad, B. (2023). TLS-MHSA: An efficient detection model for encrypted malicious traffic based on multi-head self-attention mechanism. ACM Transactions on Privacy and Security, 26(4), 1–21.
Cui, S., Dong, C., Shen, M., Liu, Y., Jiang, B., and Lu, Z. (2023). CBSeq: A channel-level behavior sequence for encrypted malware traffic detection. IEEE Transactions on Information Forensics and Security, 18, 5011–5025.
Deng, X., Zhu, J., Pei, X., Zhang, L., Ling, Z., and Xue, K. (2023). Flow topology-based graph convolutional network for intrusion detection in label-limited IoT networks. IEEE Transactions on Network and Service Management, 20(1), 684–696.
Diao, Z., Xie, G., Wang, X., Ren, R., Meng, X., Zhang, G., Xie, K., and Qiao, M. (2023). EC-GCN: A encrypted traffic classification framework based on multi-scale graph convolution networks. Computer Networks, 224, 109614.
Fu, C., Li, Q., Shen, M., and Xu, K. (2023). Frequency domain feature based robust malicious traffic detection. IEEE/ACM Transactions on Networking, 31(1), 452–467.
Fu, C., Li, Q., and Xu, K. (2023). Detecting unknown encrypted malicious traffic in real time via flow interaction graph analysis. In Proceedings of the 30th Network and Distributed System Security Symposium (NDSS 2023). Internet Society.
Gilmer, J., Schoenholz, S. S., Riley, P. F., Vinyals, O., and Dahl, G. E. (2017). Neural message passing for quantum chemistry. In Proceedings of the 34th International Conference on Machine Learning (ICML 2017) (pp. 1263–1272). PMLR.
Han, X., Xu, G., Zhang, M., Yang, Z., Yu, Z., Huang, W., and Meng, C. (2024). DE-GNN: Dual embedding with graph neural network for fine-grained encrypted traffic classification. Computer Networks, 245, 110372.
Hong, Y., Li, Q., Yang, Y., and Shen, M. (2023). Graph based encrypted malicious traffic detection with hybrid analysis of multi-view features. Information Sciences, 644, 119229.
Hu, G., Xiao, X., Shen, M., Zhang, B., Yan, X., and Liu, Y. (2023). TCGNN: Packet-grained network traffic classification via graph neural networks. Engineering Applications of Artificial Intelligence, 123, 106531.
Huoh, T.-L., Luo, Y., Li, P., and Zhang, T. (2023). Flow-based encrypted network traffic classification with graph neural networks. IEEE Transactions on Network and Service Management, 20(2), 1224–1237.
Kipf, T. N., and Welling, M. (2017). Semi-supervised classification with graph convolutional networks. In Proceedings of the 5th International Conference on Learning Representations (ICLR 2017).
Lin, X., Xiong, G., Gou, G., Li, Z., Shi, J., and Yu, J. (2022). ET-BERT: A contextualized datagram representation with pre-training transformers for encrypted traffic classification. In Proceedings of the ACM Web Conference 2022 (WWW’22) (pp. 633–642). ACM.
Lo, W. W., Layeghy, S., Sarhan, M., Gallagher, M., and Portmann, M. (2022). E-GraphSAGE: A graph neural network based intrusion detection system for IoT. In NOMS 2022–2022 IEEE/IFIP Network Operations and Management Symposium (pp. 1–9). IEEE.
Malekghaini, N., Akbari, E., Salahuddin, M. A., Limam, N., Boutaba, R., Mathieu, B., Moteau, S., and Tuffin, S. (2023). Deep learning for encrypted traffic classification in the face of data drift: An empirical study. Computer Networks, 225, 109648.
Papadogiannaki, E., and Ioannidis, S. (2021). A survey on encrypted network traffic analysis applications, techniques, and countermeasures. ACM Computing Surveys, 54(6), 1–35.
Qing, Y., Yin, Q., Deng, X., Chen, Y., Liu, Z., Sun, K., Xu, K., Zhang, J., and Li, Q. (2024). Low-quality training data only? A robust framework for detecting encrypted malicious network traffic. In Proceedings of the 31st Network and Distributed System Security Symposium (NDSS 2024).
Rezaei, S., and Liu, X. (2019). Deep learning for encrypted traffic classification: An overview. IEEE Communications Magazine, 57(5), 76–81.
Sharafaldin, I., Lashkari, A. H., and Ghorbani, A. A. (2018). Toward generating a new intrusion detection dataset and intrusion traffic characterization. In Proceedings of the 4th International Conference on Information Systems Security and Privacy (ICISSP 2018) (pp. 108–116). SciTePress.
Shen, M., Ye, K., Liu, X., Zhu, L., Kang, J., Yu, S., Li, Q., and Xu, K. (2023). Machine learning-powered encrypted network traffic analysis: A comprehensive survey. IEEE Communications Surveys & Tutorials, 25(1), 791–824.
Shen, M., Zhang, J., Zhu, L., Xu, K., and Du, X. (2021). Accurate decentralized application identification via encrypted traffic analysis using graph neural networks. IEEE Transactions on Information Forensics and Security, 16, 2367–2380.
Velièkoviæ, P., Cucurull, G., Casanova, A., Romero, A., Liò, P., and Bengio, Y. (2018). Graph attention networks. In Proceedings of the 6th International Conference on Learning Representations (ICLR 2018).
Wang, L., Ma, X., Li, N., Lv, Q., Wang, Y., Huang, W., and Chen, H. (2023). TGPrint: Attack fingerprint classification on encrypted network traffic based graph convolution attention networks. Computers & Security, 135, 103466.
Wang, W., Zhu, M., Zeng, X., Ye, X., and Sheng, Y. (2017). Malware traffic classification using convolutional neural network for representation learning. In 2017 International Conference on Information Networking (ICOIN) (pp. 712–717). IEEE.
Wang, Z., Fok, K. W., and Thing, V. L. L. (2022). Machine learning for encrypted malicious traffic detection: Approaches, datasets and comparative study. Computers & Security, 113, 102542.
Yang, J., Jiang, X., Lei, Y., Liang, W., Ma, Z., and Li, S. (2024). MTSecurity: Privacy-preserving malicious traffic classification using graph neural network and transformer. IEEE Transactions on Network and Service Management, 21(4), 4678–4692.
Zang, X., Wang, T., Zhang, X., Gong, J., Gao, P., and Zhang, G. (2024). Encrypted malicious traffic detection based on natural language processing and deep learning. Computer Networks, 250, 110598.
Zhang, H., Meng, F., and Wang, Q. (2025). Computer network security system optimization based on improved neural network algorithm and data search. Journal of Cyber Security and Mobility, 14(1), 75–100.
Zhang, H., Yu, L., Xiao, X., Li, Q., Mercaldo, F., Luo, X., and Liu, Q. (2023). TFE-GNN: A temporal fusion encoder using graph neural networks for fine-grained encrypted traffic classification. In Proceedings of the ACM Web Conference 2023 (WWW’23) (pp. 2066–2075). ACM.
Zhong, M., Lin, M., Zhang, C., and Xu, Z. (2024). A survey on graph neural networks for intrusion detection systems: Methods, trends and challenges. Computers & Security, 141, 103821.
Zhu, S., Xu, X., Gao, H., and Xiao, F. (2023). CMTSNN: A deep learning model for multiclassification of abnormal and encrypted traffic of Internet of Things. IEEE Internet of Things Journal, 10(13), 11773–11791.
Zhu, Y., Tao, J., Wang, H., Yu, L., Luo, Y., Qi, T., … Xu, Y. (2023). DGNN: Accurate darknet application classification adopting attention graph neural network. IEEE Transactions on Network and Service Management, 21(2), 1660–1671.

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
Copyright (c) 2026 Journal of Cyber Security and Mobility
