MACL: A Masked Autoencoder Framework with Contrastive Learning for Efficient Encrypted Malicious Traffic Detection
摘要
Encrypted malicious traffic detection remains challenging, particularly under label-scarce conditions where traditional models struggle to extract discriminative patterns. Although pre-training methods have seen some exploration, their adaptation to network traffic analysis remains limited. In this paper, we propose MACL, a novel Masked Autoencoder-based traffic Transformer with Contrastive Learning, to detect encrypted malicious traffic efficiently. Specifically, MACL employs a Multi-Burst Temporal Matrix (MBTM) representation to effectively capture critical traffic transmission patterns from packet bursts within flows. Our framework first leverages self-supervised pre-training by reconstructing masked MBTM and subsequently enhancing feature discriminability through dual-stage fine-tuning, including intra-flow attention, supervised contrastive learning, and attention-guided pooling. Experiments on two public malicious traffic datasets demonstrate that MACL consistently outperforms current state-of-the-art methods in regular and few-shot scenarios, highlighting its strong capability for knowledge transfer from limited labeled data.