Secure Federated Distillation Framework for Encrypted Traffic Classification
摘要
Encrypted traffic classification is essential for cyberspace governance. However, due to the privacy issues associated with network traffic, most organizations, such as hospitals, government agencies, and universities, are reluctant to disclose their network traffic. Malicious users can spread illegal information or commit cybercrime on the intranet via VPN or TOR. In this paper, we adopt federated learning to provide a new solution for encrypted traffic classification in darknet. Meanwhile, we introduce federated distillation to solve the problems of excessive communication overhead and Non-IID data. In addition, secret sharing is used for privacy federated distillation. By introducing sharpening coefficients, we effectively improve the robustness of the framework against data poisoning attacks and Byzantine attacks under an honest majority. We conduct extensive experiments on public dataset ISCX CICDarknet2020 and real dataset DarkCSE2023 containing popular application traffic, including VPN and Tor. Experiments show that our proposed framework achieves precision of 96.63% and recall of 96.76% in centralized setting, precision of 90.02%, and recall of 89.60% in federated setting, which is superior to other state-of-the-art methods.