{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T10:57:08Z","timestamp":1777892228169,"version":"3.51.4"},"reference-count":54,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T00:00:00Z","timestamp":1775001600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T00:00:00Z","timestamp":1775001600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T00:00:00Z","timestamp":1775001600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T00:00:00Z","timestamp":1775001600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T00:00:00Z","timestamp":1775001600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T00:00:00Z","timestamp":1775001600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T00:00:00Z","timestamp":1775001600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100002367","name":"Chinese Academy of Sciences","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100002367","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2023YFC2206402"],"award-info":[{"award-number":["2023YFC2206402"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100002338","name":"Ministry of Education of the People&apos;s Republic of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100002338","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Computer Networks"],"published-print":{"date-parts":[[2026,4]]},"DOI":"10.1016\/j.comnet.2026.112120","type":"journal-article","created":{"date-parts":[[2026,2,20]],"date-time":"2026-02-20T07:50:50Z","timestamp":1771573850000},"page":"112120","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["GranulNet: A unified framework for traffic identification using multi-grained feature fusion"],"prefix":"10.1016","volume":"279","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3992-8087","authenticated-orcid":false,"given":"Jian","family":"Qin","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-2881-9259","authenticated-orcid":false,"given":"Xueying","family":"Han","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5156-889X","authenticated-orcid":false,"given":"Yunpeng","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-9270-5708","authenticated-orcid":false,"given":"Ding","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5249-5699","authenticated-orcid":false,"given":"Susu","family":"Cui","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7185-990X","authenticated-orcid":false,"given":"Bo","family":"Jiang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2552-6231","authenticated-orcid":false,"given":"Zhigang","family":"Lu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-9851-5548","authenticated-orcid":false,"given":"Baoxu","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"issue":"3","key":"10.1016\/j.comnet.2026.112120_bib0001","doi-asserted-by":"crossref","first-page":"1999","DOI":"10.1007\/s00500-019-04030-2","article-title":"Deep packet: a novel approach for encrypted traffic classification using deep learning","volume":"24","author":"Lotfollahi","year":"2020","journal-title":"Soft. Comput."},{"key":"10.1016\/j.comnet.2026.112120_bib0002","doi-asserted-by":"crossref","first-page":"59783","DOI":"10.1109\/ACCESS.2021.3073967","article-title":"VoIP traffic detection in tunneled and anonymous networks using deep learning","volume":"9","author":"Islam","year":"2021","journal-title":"IEEE Access"},{"key":"10.1016\/j.comnet.2026.112120_bib0003","doi-asserted-by":"crossref","first-page":"15","DOI":"10.1016\/j.jnca.2018.12.014","article-title":"A mobile malware detection method using behavior features in network traffic","volume":"133","author":"Wang","year":"2019","journal-title":"J. Netw. Comput. Appl."},{"key":"10.1016\/j.comnet.2026.112120_bib0004","unstructured":"Google, HTTPS Encryption on the Web, 2024, Accessed: January 2024. (https:\/\/transparencyreport.google.com\/https\/overview?hl=en)."},{"key":"10.1016\/j.comnet.2026.112120_bib0005","unstructured":"Zscaler, Spoiler: New ThreatLabz Report Reveals Over 85% of Attacks Are Encrypted, 2022, Accessed: December 2022. (https:\/\/www.zscaler.com\/blogs\/security-research\/2022-encrypted-attacks-report)."},{"key":"10.1016\/j.comnet.2026.112120_bib0006","series-title":"Proceedings of the ACM Turing Award Celebration Conference-China 2023","first-page":"131","article-title":"Rosetta: enabling robust tls encrypted traffic classification in diverse network environments with tcp-aware traffic augmentation","author":"Xie","year":"2023"},{"key":"10.1016\/j.comnet.2026.112120_bib0007","series-title":"Proceedings of the 2nd International Conference on Information Systems Security and Privacy (ICISSP 2016)","first-page":"407","article-title":"Characterization of encrypted and VPN traffic using time-related features","author":"Gil","year":"2016"},{"key":"10.1016\/j.comnet.2026.112120_bib0008","series-title":"Proceedings of the 2016 ACM Workshop on Artificial Intelligence and Security","first-page":"35","article-title":"Identifying encrypted malware traffic with contextual flow data","author":"Anderson","year":"2016"},{"key":"10.1016\/j.comnet.2026.112120_bib0009","series-title":"2020 ITU Kaleidoscope: Industry-Driven Digital Transformation (ITU K)","first-page":"1","article-title":"PERT: Payload encoding representation from transformer for encrypted traffic classification","author":"He","year":"2020"},{"key":"10.1016\/j.comnet.2026.112120_bib0010","series-title":"Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security","first-page":"3366","article-title":"New directions in automated traffic analysis","author":"Holland","year":"2021"},{"issue":"5","key":"10.1016\/j.comnet.2026.112120_bib0011","doi-asserted-by":"crossref","first-page":"3521","DOI":"10.1109\/TDSC.2021.3101311","article-title":"EBSNN: Extended byte segment neural network for network traffic classification","volume":"19","author":"Xiao","year":"2021","journal-title":"IEEE Trans. Depend. Secure Comput."},{"key":"10.1016\/j.comnet.2026.112120_bib0012","series-title":"Proceedings of the ACM Web Conference 2022","first-page":"633","article-title":"Et-bert: a contextualized datagram representation with pre-training transformers for encrypted traffic classification","author":"Lin","year":"2022"},{"issue":"1","key":"10.1016\/j.comnet.2026.112120_bib0013","doi-asserted-by":"crossref","first-page":"63","DOI":"10.1109\/TIFS.2017.2737970","article-title":"Robust smartphone app identification via encrypted network traffic analysis","volume":"13","author":"Taylor","year":"2017","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112120_bib0014","series-title":"IEEE INFOCOM 2019-IEEE Conference on Computer Communications","first-page":"1171","article-title":"Fs-net: a flow sequence network for encrypted traffic classification","author":"Liu","year":"2019"},{"key":"10.1016\/j.comnet.2026.112120_bib0015","doi-asserted-by":"crossref","first-page":"2367","DOI":"10.1109\/TIFS.2021.3050608","article-title":"Accurate decentralized application identification via encrypted traffic analysis using graph neural networks","volume":"16","author":"Shen","year":"2021","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112120_bib0016","doi-asserted-by":"crossref","unstructured":"C. Fu, Q. Li, K. Xu, Detecting unknown encrypted malicious traffic in real time via flow interaction graph analysis, (2023). arXiv preprint arXiv: 2301.13686.","DOI":"10.14722\/ndss.2023.23080"},{"key":"10.1016\/j.comnet.2026.112120_bib0017","doi-asserted-by":"crossref","first-page":"3589","DOI":"10.1109\/TIFS.2021.3071595","article-title":"MBTree: Detecting encryption RATs communication using malicious behavior tree","volume":"16","author":"Dong","year":"2021","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112120_bib0018","series-title":"Proceedings of the 25th International Symposium on Research in Attacks, Intrusions and Defenses","first-page":"495","article-title":"Encrypted malware traffic detection via graph-based network analysis","author":"Fu","year":"2022"},{"key":"10.1016\/j.comnet.2026.112120_bib0019","doi-asserted-by":"crossref","DOI":"10.1109\/TIFS.2023.3300521","article-title":"CBSeq: A channel-level behavior sequence for encrypted malware traffic detection","author":"Cui","year":"2023","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112120_bib0020","series-title":"2018 IEEE\/ACM 26th International Symposium on Quality of Service (IWQoS)","first-page":"1","article-title":"Byte segment neural network for network traffic classification","author":"Li","year":"2018"},{"key":"10.1016\/j.comnet.2026.112120_bib0021","series-title":"Proceedings of the ACM Web Conference 2023","first-page":"2066","article-title":"Tfe-gnn: a temporal fusion encoder using graph neural networks for fine-grained encrypted traffic classification","author":"Zhang","year":"2023"},{"key":"10.1016\/j.comnet.2026.112120_bib0022","unstructured":"X. Meng, C. Lin, Y. Wang, Y. Zhang, Netgpt: generative pretrained transformer for network traffic, (2023). arXiv preprint arXiv: 2304.09513."},{"key":"10.1016\/j.comnet.2026.112120_bib0023","series-title":"2024 IEEE 32nd International Conference on Network Protocols (ICNP)","first-page":"1","article-title":"Netmamba: efficient network traffic classification via pre-training unidirectional mamba","author":"Wang","year":"2024"},{"key":"10.1016\/j.comnet.2026.112120_bib0024","unstructured":"T. Cui, X. Lin, S. Li, M. Chen, Q. Yin, Q. Li, K. Xu, Trafficllm: enhancing large language models for network traffic analysis with generic traffic representation, (2025). arXiv preprint arXiv: 2504.04222."},{"issue":"24","key":"10.1016\/j.comnet.2026.112120_bib0025","doi-asserted-by":"crossref","first-page":"7294","DOI":"10.3390\/s20247294","article-title":"Flow-data gathering using netflow sensors for fitting malicious-traffic detection models","volume":"20","author":"Campazas-Vega","year":"2020","journal-title":"Sensors"},{"key":"10.1016\/j.comnet.2026.112120_bib0026","series-title":"2021 7th International Conference on Web Research (ICWR)","first-page":"71","article-title":"Android malware detection and classification based on network traffic using deep learning","author":"Gohari","year":"2021"},{"key":"10.1016\/j.comnet.2026.112120_bib0027","doi-asserted-by":"crossref","unstructured":"Y. Mirsky, T. Doitshman, Y. Elovici, A. Shabtai, Kitsune: an ensemble of autoencoders for online network intrusion detection, (2018). arXiv preprint arXiv: 1802.09089.","DOI":"10.14722\/ndss.2018.23204"},{"key":"10.1016\/j.comnet.2026.112120_bib0028","article-title":"Feature mining for encrypted malicious traffic detection with deep learning and other machine learning algorithms","volume":"128","author":"Wang","year":"2023","journal-title":"Compute. Secur."},{"key":"10.1016\/j.comnet.2026.112120_bib0029","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2021.107974","article-title":"TSCRNN: a novel classification scheme of encrypted traffic based on flow spatiotemporal features for efficient management of IIoT","volume":"190","author":"Lin","year":"2021","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112120_bib0030","series-title":"2021 IEEE 23rd Int Conf on High Performance Computing & Communications; 7th Int Conf on Data Science & Systems; 19th Int Conf on Smart City; 7th Int Conf on Dependability in Sensor, Cloud & Big Data Systems & Application (HPCC\/DSS\/SmartCity\/DependSys)","first-page":"478","article-title":"Memg: mobile encrypted traffic classification with markov chains and graph neural network","author":"Cai","year":"2021"},{"key":"10.1016\/j.comnet.2026.112120_bib0031","doi-asserted-by":"crossref","first-page":"2166","DOI":"10.1109\/TIFS.2022.3179955","article-title":"Seeing traffic paths: encrypted traffic classification with path signature features","volume":"17","author":"Xu","year":"2022","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.comnet.2026.112120_bib0032","series-title":"Proceedings of the 37th Annual Computer Security Applications Conference","first-page":"1025","article-title":"Mappgraph: mobile-app classification on encrypted network traffic using deep graph convolution neural networks","author":"Pham","year":"2021"},{"issue":"1","key":"10.1016\/j.comnet.2026.112120_bib0033","doi-asserted-by":"crossref","first-page":"29","DOI":"10.1186\/s42400-022-00131-y","article-title":"Subspace clustering via graph auto-encoder network for unknown encrypted traffic recognition","volume":"5","author":"Yang","year":"2022","journal-title":"Cybersecurity"},{"key":"10.1016\/j.comnet.2026.112120_bib0034","series-title":"2022 IEEE\/ACM 30th International Symposium on Quality of Service (IWQoS)","article-title":"Flow sequence-based anonymity network traffic identification with residual graph convolutional networks","author":"Zhao","year":"2022"},{"key":"10.1016\/j.comnet.2026.112120_bib0035","doi-asserted-by":"crossref","DOI":"10.1016\/j.ins.2023.119229","article-title":"Graph based encrypted malicious traffic detection with hybrid analysis of multi-view features","volume":"644","author":"Hong","year":"2023","journal-title":"Inf. Sci."},{"key":"10.1016\/j.comnet.2026.112120_bib0036","series-title":"2020 IEEE 39th International Performance Computing and Communications Conference (IPCCC)","first-page":"1","article-title":"An encrypted traffic classification method combining graph convolutional network and autoencoder","author":"Sun","year":"2020"},{"key":"10.1016\/j.comnet.2026.112120_bib0037","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2023.109614","article-title":"EC-GCN: A encrypted traffic classification framework based on multi-scale graph convolution networks","volume":"224","author":"Diao","year":"2023","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112120_bib0038","series-title":"Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security","first-page":"3431","article-title":"Realtime robust malicious traffic detection via frequency domain analysis","author":"Fu","year":"2021"},{"key":"10.1016\/j.comnet.2026.112120_bib0039","series-title":"Network and Distributed System Security Symposium (NDSS)","article-title":"Flowprint: semi-supervised mobile-app fingerprinting on encrypted network traffic","volume":"27","author":"Van Ede","year":"2020"},{"key":"10.1016\/j.comnet.2026.112120_bib0040","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"5420","article-title":"Yet another traffic classifier: a masked autoencoder based traffic transformer with multi-level flow representation","volume":"37","author":"Zhao","year":"2023"},{"key":"10.1016\/j.comnet.2026.112120_bib0041","series-title":"Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses","first-page":"297","article-title":"Flow-mae: leveraging masked autoencoder for accurate, efficient and robust malicious traffic classification","author":"Hang","year":"2023"},{"key":"10.1016\/j.comnet.2026.112120_bib0042","series-title":"2025 IEEE Symposium on Security and Privacy (SP)","first-page":"1844","article-title":"Trafficformer: an efficient pre-trained model for traffic data","author":"Zhou","year":"2025"},{"key":"10.1016\/j.comnet.2026.112120_bib0043","first-page":"108","article-title":"Toward generating a new intrusion detection dataset and intrusion traffic characterization","volume":"1","author":"Sharafaldin","year":"2018","journal-title":"ICISSp"},{"key":"10.1016\/j.comnet.2026.112120_bib0044","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2023.109652","article-title":"GLADS: A global-local attention data selection model for multimodal multitask encrypted traffic classification of IoT","volume":"225","author":"Dai","year":"2023","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112120_bib0045","doi-asserted-by":"crossref","first-page":"156","DOI":"10.1016\/j.cose.2018.12.012","article-title":"Flow-based network traffic generation using generative adversarial networks","volume":"82","author":"Ring","year":"2019","journal-title":"Comput. Secur."},{"key":"10.1016\/j.comnet.2026.112120_bib0046","doi-asserted-by":"crossref","first-page":"64","DOI":"10.1016\/j.phycom.2015.10.006","article-title":"A survey on 5G: the next generation of mobile communication","volume":"18","author":"Panwar","year":"2016","journal-title":"Phys. Commun."},{"key":"10.1016\/j.comnet.2026.112120_bib0047","doi-asserted-by":"crossref","first-page":"779","DOI":"10.1016\/j.future.2019.05.041","article-title":"Towards the development of realistic botnet dataset in the internet of things for network forensic analytics: bot-iot dataset","volume":"100","author":"Koroniotis","year":"2019","journal-title":"Fut. Gener. Comput. Syst."},{"key":"10.1016\/j.comnet.2026.112120_bib0048","doi-asserted-by":"crossref","first-page":"75","DOI":"10.1016\/j.comnet.2014.11.001","article-title":"Independent comparison of popular DPI tools for traffic classification","volume":"76","author":"Bujlow","year":"2015","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112120_bib0049","unstructured":"WIDE, MAWI Working Group Traffic Archive, Accessed: January 2021. (http:\/\/mawi.wide.ad.jp\/mawi\/)."},{"issue":"13","key":"10.1016\/j.comnet.2026.112120_bib0050","doi-asserted-by":"crossref","first-page":"5941","DOI":"10.3390\/s23135941","article-title":"CICIoT2023: a real-time dataset and benchmark for large-scale attacks in IoT environment","volume":"23","author":"Neto","year":"2023","journal-title":"Sensors"},{"key":"10.1016\/j.comnet.2026.112120_bib0051","series-title":"Proceedings of the 2nd International Conference on Information Systems Security and Privacy (ICISSP)","first-page":"407","article-title":"Characterization of encrypted and vpn traffic using time-related","author":"Draper-Gil","year":"2016"},{"key":"10.1016\/j.comnet.2026.112120_bib0052","series-title":"International Conference on Information Systems Security and Privacy","first-page":"253","article-title":"Characterization of tor traffic using time based features","volume":"2","author":"Lashkari","year":"2017"},{"key":"10.1016\/j.comnet.2026.112120_bib0053","series-title":"2018 International Carnahan Conference on Security Technology (ICCST)","first-page":"1","article-title":"Toward developing a systematic approach to generate benchmark android malware datasets and classification","author":"Lashkari","year":"2018"},{"key":"10.1016\/j.comnet.2026.112120_bib0054","series-title":"Proceedings of the 6th International COnference","first-page":"1","article-title":"MAWILab: Combining diverse anomaly detectors for automated anomaly labeling and performance benchmarking","author":"Fontugne","year":"2010"}],"container-title":["Computer Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1389128626001325?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1389128626001325?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T06:21:55Z","timestamp":1777616515000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S1389128626001325"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4]]},"references-count":54,"alternative-id":["S1389128626001325"],"URL":"https:\/\/doi.org\/10.1016\/j.comnet.2026.112120","relation":{},"ISSN":["1389-1286"],"issn-type":[{"value":"1389-1286","type":"print"}],"subject":[],"published":{"date-parts":[[2026,4]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"GranulNet: A unified framework for traffic identification using multi-grained feature fusion","name":"articletitle","label":"Article Title"},{"value":"Computer Networks","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.comnet.2026.112120","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"112120"}}