{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,10]],"date-time":"2026-08-10T08:28:13Z","timestamp":1786350493960,"version":"build-2736575974"},"reference-count":42,"publisher":"Springer Science and Business Media LLC","issue":"6","license":[{"start":{"date-parts":[[2026,6,23]],"date-time":"2026-06-23T00:00:00Z","timestamp":1782172800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"},{"start":{"date-parts":[[2026,8,10]],"date-time":"2026-08-10T00:00:00Z","timestamp":1786320000000},"content-version":"vor","delay-in-days":48,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"}],"funder":[{"DOI":"10.13039\/501100012165","name":"Key Technologies Research and Development Program","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100012165","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Jiangsu Key Development Planning Project"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J. King Saud Univ. Comput. Inf. Sci."],"published-print":{"date-parts":[[2026,8]]},"DOI":"10.1007\/s44443-026-00949-3","type":"journal-article","created":{"date-parts":[[2026,6,23]],"date-time":"2026-06-23T12:25:10Z","timestamp":1782217510000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Adaptive encrypted traffic classification via online hash center evolution"],"prefix":"10.1007","volume":"38","author":[{"given":"Qian","family":"Yang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Minghao","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Biwen","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hongxin","family":"Han","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wenxun","family":"He","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fei","family":"Wu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yimu","family":"Ji","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,6,23]]},"reference":[{"issue":"1","key":"949_CR1","doi-asserted-by":"publisher","first-page":"243","DOI":"10.1016\/j.patcog.2012.07.021","volume":"46","author":"O Arbelaitz","year":"2013","unstructured":"Arbelaitz O, Gurrutxaga I, Muguerza J et al (2013) An extensive comparative study of cluster validity indices. Pattern Recognit 46(1):243\u2013256","journal-title":"Pattern Recognit"},{"key":"949_CR2","doi-asserted-by":"crossref","unstructured":"Bendale A, Boult TE (2016) Towards open set deep networks. In: Proc IEEE Conf Comput Vis Pattern Recognit, pp 1563\u20131572","DOI":"10.1109\/CVPR.2016.173"},{"key":"949_CR3","unstructured":"Canadian Institute for Cybersecurity (2018) CSE-CIC-IDS2018 on AWS. Online: https:\/\/www.unb.ca\/cic\/datasets\/ids-2018.html. Accessed: 27 Nov 2020"},{"key":"949_CR4","doi-asserted-by":"crossref","unstructured":"Charyyev B, Gunes MH (2020) Detecting anomalous IoT traffic flow with locality sensitive hashes. In: Proc IEEE GLOBECOM, pp 1\u20136","DOI":"10.1109\/GLOBECOM42002.2020.9322559"},{"key":"949_CR5","doi-asserted-by":"crossref","unstructured":"Doroud H, Aceto G, De\u00a0Donato W, et al (2018) Speeding-up DPI traffic classification with chaining. In: Proc IEEE GLOBECOM, pp 1\u20136","DOI":"10.1109\/GLOCOM.2018.8648137"},{"key":"949_CR6","unstructured":"Graves A, Bellemare MG, Menick J et al (2017) Automated curriculum learning for neural networks. In: Proc Int Conf Mach Learn, pp 1311\u20131320"},{"key":"949_CR7","unstructured":"Hacohen G, Weinshall D (2019) On the power of curriculum learning in training deep networks. In: Proc int conf mach learn, pp 2535\u20132544"},{"issue":"10","key":"949_CR8","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3659575","volume":"56","author":"J Halvorsen","year":"2024","unstructured":"Halvorsen J, Izurieta C, Cai H et al (2024) Applying generative machine learning to intrusion detection: a systematic mapping study and review. ACM Comput Surv 56(10):1\u201333","journal-title":"ACM Comput Surv"},{"key":"949_CR9","volume-title":"Ecnet: robust malicious network traffic detection with multi-view feature and confidence mechanism","author":"X Han","year":"2024","unstructured":"Han X, Liu S, Liu J et al (2024) Ecnet: robust malicious network traffic detection with multi-view feature and confidence mechanism. IEEE Trans. Inf, Forensics Security"},{"key":"949_CR10","doi-asserted-by":"crossref","unstructured":"Hang Z, Lu Y, Wang Y et al (2023) Flow-MAE: leveraging masked autoencoder for accurate, efficient and robust malicious traffic classification. In: Proc int symp research in attacks, intrusions and defenses, pp 297\u2013314","DOI":"10.1145\/3607199.3607206"},{"key":"949_CR11","unstructured":"Hendrycks D, Gimpel K (2017) A baseline for detecting misclassified and out-of-distribution examples in neural networks. In: Proc int conf learn represent"},{"key":"949_CR12","doi-asserted-by":"publisher","first-page":"5817","DOI":"10.1109\/TIFS.2023.3318960","volume":"18","author":"X Hu","year":"2023","unstructured":"Hu X, Gao W, Cheng G et al (2023) Toward early and accurate network intrusion detection using graph embedding. IEEE Trans Inf Forensics Secur 18:5817\u20135831","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"949_CR13","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2024.110656","volume":"252","author":"Y Hu","year":"2024","unstructured":"Hu Y, Zeng Z, Song J, Xu L, Zhou X (2024) Online network traffic classification based on external attention and convolution by ip packet header. Comput Netw 252:110656","journal-title":"Comput Netw"},{"key":"949_CR14","unstructured":"Jiang H, Kim B, Guan M, et al (2018) To trust or not to trust a classifier. Advances in Neural Information Processing Systems 31"},{"key":"949_CR15","doi-asserted-by":"publisher","first-page":"107974","DOI":"10.1016\/j.comnet.2021.107974","volume":"190","author":"K Lin","year":"2021","unstructured":"Lin K, Xu X, Gao H (2021) Tscrnn: a novel classification scheme of encrypted traffic based on flow spatiotemporal features for efficient management of iiot. Comput Netw 190:107974","journal-title":"Comput Netw"},{"key":"949_CR16","doi-asserted-by":"crossref","unstructured":"Lin X, Xiong G, Gou G, Li Z, Shi J, Yu J (2022) Et-bert: a contextualized datagram representation with pre-training transformers for encrypted traffic classification. In: Proc. ACM web conf, pp 633\u2013642","DOI":"10.1145\/3485447.3512217"},{"key":"949_CR17","doi-asserted-by":"crossref","unstructured":"Liu C, He L, Xiong G et al (2019) FS-Net: a flow sequence network for encrypted traffic classification. In: Proc IEEE INFOCOM, pp 1171\u20131179","DOI":"10.1109\/INFOCOM.2019.8737507"},{"key":"949_CR18","doi-asserted-by":"crossref","unstructured":"Lotfollahi M, Jafari\u00a0Siavoshani M, Shirali Hossein\u00a0Zade R, Safari M (2020) Deep packet: a novel approach for encrypted traffic classification using deep learning. Soft Comput 24(3):1999\u20132012","DOI":"10.1007\/s00500-019-04030-2"},{"issue":"4","key":"949_CR19","doi-asserted-by":"publisher","first-page":"2451","DOI":"10.1109\/TNSM.2020.3016246","volume":"17","author":"B Molina-Coronado","year":"2020","unstructured":"Molina-Coronado B, Mori U, Mendiburu A et al (2020) Survey of network intrusion detection methods from the perspective of the knowledge discovery in databases process. IEEE Trans Netw Serv Manag 17(4):2451\u20132479","journal-title":"IEEE Trans Netw Serv Manag"},{"issue":"2","key":"949_CR20","doi-asserted-by":"publisher","first-page":"1145","DOI":"10.1109\/COMST.2016.2636078","volume":"19","author":"EM Rudd","year":"2016","unstructured":"Rudd EM, Rozsa A, G\u00fcnther M, Boult TE (2016) A survey of stealth malware attacks, mitigation measures, and steps toward autonomous open world solutions. IEEE Commun Surv Tutorials 19(2):1145\u20131172","journal-title":"IEEE Commun Surv Tutorials"},{"issue":"2","key":"949_CR21","doi-asserted-by":"publisher","first-page":"1218","DOI":"10.1109\/TNSM.2021.3071441","volume":"18","author":"T Shapira","year":"2021","unstructured":"Shapira T, Shavitt Y (2021) Flowpic: a generic representation for encrypted traffic classification and applications identification. IEEE Trans Netw Serv Manag 18(2):1218\u20131232","journal-title":"IEEE Trans Netw Serv Manag"},{"key":"949_CR22","doi-asserted-by":"publisher","first-page":"2046","DOI":"10.1109\/TIFS.2020.3046876","volume":"16","author":"M Shen","year":"2020","unstructured":"Shen M, Liu Y, Zhu L et al (2020) Fine-grained webpage fingerprinting using only packet length information of encrypted traffic. IEEE Trans Inf Forensics Secur 16:2046\u20132059","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"949_CR23","doi-asserted-by":"publisher","first-page":"2367","DOI":"10.1109\/TIFS.2021.3050608","volume":"16","author":"M Shen","year":"2021","unstructured":"Shen M, Zhang J, Zhu L et al (2021) Accurate decentralized application identification via encrypted traffic analysis using graph neural networks. IEEE Trans Inf Forensics Secur 16:2367\u20132380","journal-title":"IEEE Trans Inf Forensics Secur"},{"issue":"5","key":"949_CR24","doi-asserted-by":"publisher","first-page":"3541","DOI":"10.1109\/TII.2025.3534441","volume":"21","author":"C Sheng","year":"2025","unstructured":"Sheng C, Zhou W, Han Q-L et al (2025) Network traffic fingerprinting for iiot device identification: a survey. IEEE Trans Ind Inf 21(5):3541\u20133554","journal-title":"IEEE Trans Ind Inf"},{"key":"949_CR25","first-page":"739","volume":"117","author":"RR Varshamov","year":"1957","unstructured":"Varshamov RR (1957) Estimate of the number of signals in error correcting codes. Docklady Akad Nauk SSSR 117:739\u2013741","journal-title":"Docklady Akad Nauk SSSR"},{"key":"949_CR26","doi-asserted-by":"crossref","unstructured":"Wang W, Zhu M, Zeng X, Ye X (2017) Malware traffic classification using convolutional neural network for representation learning. In: Proc int conf information networking (ICOIN), pp 712\u2013717","DOI":"10.1109\/ICOIN.2017.7899588"},{"key":"949_CR27","doi-asserted-by":"crossref","unstructured":"Wang X, Chen S, Su J (2020) App-Net: a hybrid neural network for encrypted mobile traffic classification. In: Proc. IEEE INFOCOM workshops, pp 424\u2013429","DOI":"10.1109\/INFOCOMWKSHPS50562.2020.9162891"},{"key":"949_CR28","unstructured":"Wang D, Shelhamer E, Liu S, et al (2021) Tent: fully test-time adaptation by entropy minimization. In: Proc int conf learn represent"},{"key":"949_CR29","doi-asserted-by":"crossref","unstructured":"Wu J, Niu W, Wei F, Li S, Huang S, Gong J, Zhang X (2025) Dlet-classifier: a dynamic and lightweight method for encrypted traffic classification. IEEE Internet Things Journal","DOI":"10.1109\/JIOT.2025.3593143"},{"key":"949_CR30","doi-asserted-by":"publisher","first-page":"3538","DOI":"10.1109\/TIFS.2021.3083422","volume":"16","author":"J Yang","year":"2021","unstructured":"Yang J, Chen X, Chen S et al (2021) Conditional variational auto-encoder and extreme value theory aided two-stage learning approach for intelligent fine-grained known\/unknown intrusion detection. IEEE Trans Inf Forensics Secur 16:3538\u20133553","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"949_CR31","unstructured":"Yang L, Guo W, Hao Q et al (2021) CADE: detecting and explaining concept drift samples for security applications. In: Proc USENIX security symp, pp 2327\u20132344"},{"key":"949_CR32","doi-asserted-by":"crossref","unstructured":"Yu S, Zhai R, Shen Y, et al (2023) Deep q-network-based open-set intrusion detection solution for industrial internet of things. IEEE Internet Things Journal 11(7)","DOI":"10.1109\/JIOT.2023.3333903"},{"key":"949_CR33","doi-asserted-by":"publisher","first-page":"133","DOI":"10.1109\/TIFS.2023.3318962","volume":"19","author":"Q Yuan","year":"2023","unstructured":"Yuan Q, Gou G, Zhu Y et al (2023) Mcre: a unified framework for handling malicious traffic with noise labels based on multidimensional constraint representation. IEEE Trans Inf Forensics Secur 19:133\u2013147","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"949_CR34","doi-asserted-by":"crossref","unstructured":"Zhang J, Li F, Ye F, et al (2020) Autonomous unknown-application filtering and labeling for DL-based traffic classifier update. In: Proc IEEE INFOCOM, pp 397\u2013405","DOI":"10.1109\/INFOCOM41043.2020.9155292"},{"key":"949_CR35","doi-asserted-by":"crossref","unstructured":"Zhang H, Yu L, Xiao X et al (2023) TFE-GNN: a temporal fusion encoder using graph neural networks for fine-grained encrypted traffic classification. In: Proc ACM web conf, pp 2066\u20132075","DOI":"10.1145\/3543507.3583227"},{"key":"949_CR36","volume-title":"Toward open-set intrusion detection in vanets: an efficient meta-recognition approach","author":"J Zhang","year":"2024","unstructured":"Zhang J, Pan Z, Cui J et al (2024) Toward open-set intrusion detection in vanets: an efficient meta-recognition approach. IEEE Trans. Netw. Sci, Eng"},{"key":"949_CR37","doi-asserted-by":"crossref","unstructured":"Zhao L, Cai L, Yu A, et al (2019) Prototype-based Malware Traffic Classification with Novelty Detection. In: Proc int conf inf commun security, pp 3\u201317","DOI":"10.1007\/978-3-030-41579-2_1"},{"key":"949_CR38","doi-asserted-by":"crossref","unstructured":"Zhao R, Zhan M, Deng X et al (2023) Yet another traffic classifier: a masked autoencoder based traffic transformer with multi-level flow Representation. In: Proc AAAI conf artif intell, vol 37, pp 5420\u20135427","DOI":"10.1609\/aaai.v37i4.25674"},{"key":"949_CR39","doi-asserted-by":"crossref","unstructured":"Zhao Z, Li Z, Song Z, et al (2024) Trident: a universal framework for fine-grained and class-incremental unknown traffic detection. In: Proc ACM web conf, pp 1608\u20131619","DOI":"10.1145\/3589334.3645407"},{"key":"949_CR40","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2024.3413789","volume-title":"Towards fine-grained unknown class detection against the open-set attack spectrum with variable legitimate traffic","author":"Z Zhao","year":"2024","unstructured":"Zhao Z, Li Z, Xie X et al (2024) Towards fine-grained unknown class detection against the open-set attack spectrum with variable legitimate traffic. IEEE\/ACM Trans, Netw"},{"key":"949_CR41","doi-asserted-by":"crossref","unstructured":"Zhou G, Guo X, Liu Z, Li T, Li Q, Xu K (2025) Trafficformer: an efficient pre-trained model for traffic data. In: IEEE symp security privacy (SP), pp 1844\u20131860","DOI":"10.1109\/SP61157.2025.00102"},{"key":"949_CR42","doi-asserted-by":"crossref","unstructured":"Zhu H, Long M, Wang J, Cao Y (2016) Deep hashing network for efficient similarity retrieval. In: Proc AAAI conf artif intell, vol 30","DOI":"10.1609\/aaai.v30i1.10235"}],"container-title":["Journal of King Saud University Computer and Information Sciences"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s44443-026-00949-3","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s44443-026-00949-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s44443-026-00949-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,8,10]],"date-time":"2026-08-10T07:35:07Z","timestamp":1786347307000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s44443-026-00949-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,23]]},"references-count":42,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2026,8]]}},"alternative-id":["949"],"URL":"https:\/\/doi.org\/10.1007\/s44443-026-00949-3","relation":{},"ISSN":["1319-1578","2213-1248"],"issn-type":[{"value":"1319-1578","type":"print"},{"value":"2213-1248","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,23]]},"assertion":[{"value":"25 March 2026","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"11 June 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"23 June 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"The authors declare no competing interests.","order":1,"name":"Ethics","label":"Competing interests","group":{"name":"EthicsHeading","label":"Declarations"}}],"article-number":"558"}}