{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,3]],"date-time":"2026-05-03T11:04:30Z","timestamp":1777806270829,"version":"3.51.4"},"reference-count":37,"publisher":"SAGE Publications","issue":"3","license":[{"start":{"date-parts":[[2025,3,28]],"date-time":"2025-03-28T00:00:00Z","timestamp":1743120000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Journal of Computer Security"],"published-print":{"date-parts":[[2025,5]]},"abstract":"<jats:p>The widespread use of encryption protocols and increasing privacy demands have significantly increased encrypted traffic, creating new challenges for network monitoring and threat detection. Current methods struggle with diverse scenarios and distinguish between subtle traffic patterns within webpages of the same application. To address these challenges, we introduce ANT-ET, an end-to-end multimodal framework designed for fine-grained encrypted webpage traffic fingerprinting. ANT-ET leverages a transformer to model payload semantics and constructs a traffic interaction graph to capture both temporal and spatial characteristics of packet interactions. Additionally, ANT-ET incorporates a gradient reversal layer to improve generalization by facilitating domain-invariant feature learning across related webpages. Experimental results demonstrate ANT-ET\u2019s superior performance compared to various baseline models, which were evaluated using a proprietary encrypted webpage traffic dataset and three public datasets. Ablation studies confirm the effectiveness of different framework components, while sensitivity and complexity analyses further validate ANT-ET\u2019s robustness and flexibility.<\/jats:p>","DOI":"10.1177\/0926227x251325484","type":"journal-article","created":{"date-parts":[[2025,3,29]],"date-time":"2025-03-29T04:02:05Z","timestamp":1743220925000},"page":"163-179","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":0,"title":["ANT-ET: An end-to-end multimodal framework for fine-grained encrypted traffic fingerprinting"],"prefix":"10.1177","volume":"33","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-2569-4803","authenticated-orcid":false,"given":"He","family":"Kong","sequence":"first","affiliation":[{"name":"State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"},{"name":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5498-3474","authenticated-orcid":false,"given":"Liqun","family":"Yang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Technology, Beihang University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6648-324X","authenticated-orcid":false,"given":"Jingguo","family":"Ge","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"},{"name":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3470-7963","authenticated-orcid":false,"given":"Tong","family":"Li","sequence":"additional","affiliation":[{"name":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-2385-082X","authenticated-orcid":false,"given":"Hui","family":"Li","sequence":"additional","affiliation":[{"name":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","published-online":{"date-parts":[[2025,3,28]]},"reference":[{"key":"e_1_3_3_2_2","unstructured":"Let\u2019s encrypt stats\u2013letsencrypt.org https:\/\/letsencrypt.org\/stats\/#percent-pageloads (accessed 1 November 2024)."},{"key":"e_1_3_3_3_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPDS.2011.262"},{"key":"e_1_3_3_4_2","doi-asserted-by":"publisher","DOI":"10.1088\/1742-6596\/983\/1\/012060"},{"key":"e_1_3_3_5_2","doi-asserted-by":"publisher","DOI":"10.1145\/3457904"},{"key":"e_1_3_3_6_2","doi-asserted-by":"crossref","unstructured":"Lin X Xiong G Gou G et al. ET-BERT: A contextualized datagram representation with pre-training transformers for encrypted traffic classification. In: WWW' 22: The ACM Web Conference 2022 Virtual Event Lyon France April 25\u201329 2022 2022 pp. 633\u2013642. ACM.","DOI":"10.1145\/3485447.3512217"},{"key":"e_1_3_3_7_2","doi-asserted-by":"crossref","unstructured":"Zhang H Yu L Xiao X et al. TFE-GNN: A temporal fusion encoder using graph neural networks for fine-grained encrypted traffic classification. In: Proceedings of the ACM Web Conference 2023 WWW 2023 Austin TX USA 30 April 2023\u20134 May 2023 2023 pp. 2066\u20132075. ACM.","DOI":"10.1145\/3543507.3583227"},{"key":"e_1_3_3_8_2","doi-asserted-by":"crossref","unstructured":"Pang B Fu Y Ren S et al. A multi-modal approach for context-aware network traffic classification. In: IEEE International Conference on Acoustics Speech and Signal Processing ICASSP 2023 Rhodes Island Greece June 4\u201310 2023 2023 pp. 1\u20135. IEEE.","DOI":"10.1109\/ICASSP49357.2023.10095124"},{"key":"e_1_3_3_9_2","doi-asserted-by":"crossref","unstructured":"Panchenko A Lanze F Pennekamp J et al.\u00a0Website fingerprinting at internet scale. In: 23rd Annual Network and Distributed System Security Symposium NDSS 2016 San Diego California USA February 21\u201324 2016 2016 pp. 23477. The Internet Society.","DOI":"10.14722\/ndss.2016.23477"},{"key":"e_1_3_3_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3046876"},{"key":"e_1_3_3_11_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2021.01.021"},{"key":"e_1_3_3_12_2","doi-asserted-by":"crossref","unstructured":"Kong H Li T Ge J et al. A novel method with transformers for fine-grained encrypted traffic classification. In: IEEE International Conference on High Performance Computing & Communications Data Science & Systems Smart City & Dependability in Sensor Cloud & Big Data Systems & Application HPCC\/DSS\/SmartCity\/DependSys 2023 Melbourne Australia December 17\u201321 2023 2023 pp. 74\u201381. IEEE.","DOI":"10.1109\/HPCC-DSS-SmartCity-DependSys60770.2023.00020"},{"key":"e_1_3_3_13_2","doi-asserted-by":"crossref","unstructured":"He HY Yang ZG Chen XN. PERT: Payload encoding representation from transformer for encrypted traffic classification. In: 2020 ITU Kaleidoscope: Industry-Driven Digital Transformation Kaleidoscope Ha Noi Vietnam December 7\u201311 2020 2020 pp. 1\u20138. IEEE.","DOI":"10.23919\/ITUK50268.2020.9303204"},{"key":"e_1_3_3_14_2","unstructured":"Devlin J Chang M-W Lee K et al. Bert: Pre-training of deep bidirectional transformers for language understanding. arXiv preprint arXiv:1810.04805 2018."},{"key":"e_1_3_3_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3050608"},{"key":"e_1_3_3_16_2","article-title":"Attention is all you need","author":"Vaswani A","unstructured":"Vaswani A, Shazeer N, Parmar N, et al. Attention is all you need. In: Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems 2017, December 4\u20139, 2017, Long Beach, CA, USA, 2017, 2017, pp. 5998\u20136008.","journal-title":"Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems 2017, December 4\u20139, 2017, Long Beach, CA, USA, 2017,"},{"key":"e_1_3_3_17_2","unstructured":"Ganin Y Lempitsky V. Unsupervised domain adaptation by backpropagation. In: Proceedings of the 32nd International Conference on Machine Learning ICML 2015 Lille France 6\u201311 July 2015 Volume 37 of JMLR Workshop and Conference Proceedings 2015 pp. 1180\u20131189. JMLR.org."},{"key":"e_1_3_3_18_2","doi-asserted-by":"crossref","unstructured":"Draper-Gil G Lashkari AH Mamun MSI et al. Characterization of encrypted and VPN traffic using time-related. In: Proceedings of the 2nd International Conference on Information Systems Security and Privacy ICISSP 2016 Rome Italy February 19\u201321 2016 2016 pp. 407\u2013414. SciTePress.","DOI":"10.5220\/0005740704070414"},{"key":"e_1_3_3_19_2","doi-asserted-by":"crossref","unstructured":"Wang W Zhu M Zeng X et al. Malware traffic classification using convolutional neural network for representation learning. In: 2017 International Conference on Information Networking ICOIN 2017 Da Nang Vietnam January 11\u201313 2017 2017 pp. 712\u2013717. IEEE.","DOI":"10.1109\/ICOIN.2017.7899588"},{"key":"e_1_3_3_20_2","doi-asserted-by":"crossref","unstructured":"Ding S Xu Y Xu H et al. A multimodal deep fusion network for mobile traffic classification. In: Wireless Algorithms Systems and Applications - 17th International Conference WASA 2022 Dalian China November 24\u201326 2022 Proceedings Part II Volume 13472 of Lecture Notes in Computer Science 2022 pp. 384\u2013392. Springer.","DOI":"10.1007\/978-3-031-19214-2_32"},{"key":"e_1_3_3_21_2","doi-asserted-by":"crossref","unstructured":"Li R Xiao X Ni S et al. Byte segment neural network for network traffic classification. In: 26th IEEE\/ACM International Symposium on Quality of Service IWQoS 2018 Banff AB Canada June 4\u20136 2018 2018 \u00a0pp. 1\u201310. IEEE.","DOI":"10.1109\/IWQoS.2018.8624128"},{"key":"e_1_3_3_22_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2737970"},{"key":"e_1_3_3_23_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00500-019-04030-2"},{"key":"e_1_3_3_24_2","doi-asserted-by":"crossref","unstructured":"Liu C He L Xiong G et al. FS-Net: A flow sequence network for encrypted traffic classification. In: 2019 IEEE Conference on Computer Communications INFOCOM 2019 Paris France April 29\u2013May 2 2019 2019 pp. 1171\u20131179. IEEE.","DOI":"10.1109\/INFOCOM.2019.8737507"},{"key":"e_1_3_3_25_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2016.10.031"},{"key":"e_1_3_3_26_2","unstructured":"Kingma DP Ba J. Adam: A method for stochastic optimization. arXiv preprint arXiv:1412.6980 2014."},{"key":"e_1_3_3_27_2","unstructured":"GitHub \u2013 dmlc\/dgl: Python package built to ease deep learning on graph on top of existing DL frameworks.\u2013github.com https:\/\/github.com\/dmlc\/dgl (accessed 1 November 2024)."},{"key":"e_1_3_3_28_2","doi-asserted-by":"crossref","unstructured":"Al-Naami K Chandra S Mustafa A et al. Adaptive encrypted traffic fingerprinting with bi-directional dependence. In: Proceedings of the 32nd Annual Conference on Computer Security Applica- tions ACSAC 2016 Los Angeles CA USA December 5\u20139 2016 2016 pp. 177\u2013188. ACM.","DOI":"10.1145\/2991079.2991123"},{"key":"e_1_3_3_29_2","doi-asserted-by":"crossref","unstructured":"Van Ede T Bortolameotti R Continella A et al. Flowprint: Semi-supervised mobile-app fingerprinting on encrypted network traffic. In: 27th Annual Network and Distributed System Security Symposium NDSS 2020 San Diego California USA February 23\u201326 2020 \u00a02020. The Internet Society.","DOI":"10.14722\/ndss.2020.24412"},{"key":"e_1_3_3_30_2","doi-asserted-by":"crossref","unstructured":"Pham T-D Ho T-L Truong-Huu T et al. Mappgraph: Mobile-app classification on encrypted network traffic using deep graph convolution neural networks. In: ACSAC \u201921: Annual Computer Security Applications Conference Virtual Event USA December 6\u201310 2021 2021 pp. 1025\u20131038. ACM.","DOI":"10.1145\/3485832.3485925"},{"key":"e_1_3_3_31_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2020.107258"},{"key":"e_1_3_3_32_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2021.107974"},{"key":"e_1_3_3_33_2","doi-asserted-by":"crossref","unstructured":"Anderson B McGrew D. Identifying encrypted malware traffic with contextual flow data. In: Proceedings of the 2016 ACM Workshop on Artificial Intelligence and Security AISec@CCS 2016 Vienna Austria October 28 2016 2016 pp. 35\u201346. ACM.","DOI":"10.1145\/2996758.2996768"},{"key":"e_1_3_3_34_2","doi-asserted-by":"crossref","unstructured":"Anderson B McGrew D. Machine learning for encrypted malware traffic classification: Accounting for noisy labels and non-stationarity. In: Proceedings of the 23rd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining Halifax NS Canada August 13\u201317 2017 2017 pp. 1723\u20131732. ACM.","DOI":"10.1145\/3097983.3098163"},{"key":"e_1_3_3_35_2","doi-asserted-by":"crossref","unstructured":"M\u00fchlhauser M Prid\u00f6hl H Herrmann D. How private is android\u2019s private DNS setting? Identifying apps by encrypted DNS traffic. In: ARES 2021: The 16th International Conference on Availability Reliability and Security Vienna Austria August 17\u201320 2021 2021 pp. 14:1\u201314:10. ACM.","DOI":"10.1145\/3465481.3465764"},{"key":"e_1_3_3_36_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11280-021-00940-0"},{"key":"e_1_3_3_37_2","doi-asserted-by":"crossref","unstructured":"Wang W Zhu M Wang J et al. End-to-end encrypted traffic classification with one-dimensional convolution neural networks. In: 2017 IEEE International Conference on Intelligence and Security Informatics ISI 2017 Beijing China July 22\u201324 2017 2017 pp. 43\u201348. IEEE.","DOI":"10.1109\/ISI.2017.8004872"},{"key":"e_1_3_3_38_2","doi-asserted-by":"crossref","unstructured":"Zheng J Li D. GCN-TC: Combining trace graph with statistical features for network traffic classification. In: 2019 IEEE International Conference on Communications ICC 2019 Shanghai China May 20\u201324 2019 2019 pp. 1\u20136. IEEE.","DOI":"10.1109\/ICC.2019.8761115"}],"container-title":["Journal of Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/0926227X251325484","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.1177\/0926227X251325484","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/0926227X251325484","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T20:45:53Z","timestamp":1777495553000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.1177\/0926227X251325484"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,3,28]]},"references-count":37,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2025,5]]}},"alternative-id":["10.1177\/0926227X251325484"],"URL":"https:\/\/doi.org\/10.1177\/0926227x251325484","relation":{},"ISSN":["0926-227X","1875-8924"],"issn-type":[{"value":"0926-227X","type":"print"},{"value":"1875-8924","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,3,28]]}}}