{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T15:58:51Z","timestamp":1782316731403,"version":"3.54.5"},"reference-count":29,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2026,4,23]],"date-time":"2026-04-23T00:00:00Z","timestamp":1776902400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2026,4,23]],"date-time":"2026-04-23T00:00:00Z","timestamp":1776902400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62272007"],"award-info":[{"award-number":["62272007"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>In recent years, cloud-edge-end collaborative federated learning frameworks have been widely used in many scenarios and achieved good results. However, with the complexity of application requirements, the problems of device heterogeneity and data heterogeneity become more prominent. Traditional frameworks often face challenges such as uneven allocation of computational resources and inefficient training when dealing with these problems. To address this problem, this paper proposes a novel federated learning framework for multi-domain collaborative analysis of networked encrypted flows. First, we split the model training tasks, intelligently assign part of the model training tasks to terminal devices based on their performance, while the remaining model training tasks that require more computational resources are handed over to edge servers. Second, we introduce a resource scheduling scheme among edge servers to reasonably allocate model training tasks and fully utilize resources. Finally, high quality global models are obtained through a weight-enabled global model aggregation scheme. Experiments show that our proposed scheme can effectively address the impact of device heterogeneity and data heterogeneity in encrypted traffic identification in cross-domain networks, and improve the training efficiency and model performance of the overall system while ensuring data privacy and security.<\/jats:p>","DOI":"10.1186\/s42400-026-00580-9","type":"journal-article","created":{"date-parts":[[2026,4,23]],"date-time":"2026-04-23T07:01:58Z","timestamp":1776927718000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Resource-based online orchestration for multi-domain collaborative analysis of network encrypted traffic"],"prefix":"10.1186","volume":"9","author":[{"given":"Yunhua","family":"He","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhen","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bin","family":"Wu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Keshav","family":"Sood","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ke","family":"Xiao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yong","family":"Yan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Limin","family":"Sun","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,4,23]]},"reference":[{"key":"580_CR1","doi-asserted-by":"crossref","unstructured":"Abbasi M, Taherkordi A, Shahraki A (2022) Flitc: A novel federated learning-based method for IoT traffic classification. In: 2022 IEEE international conference on smart computing (SMARTCOMP), pp. 206\u2013212","DOI":"10.1109\/SMARTCOMP55677.2022.00055"},{"key":"580_CR2","doi-asserted-by":"crossref","unstructured":"Bazaraa MS, Sherali HD, Shetty CM (2006) Nonlinear programming: theory and algorithms","DOI":"10.1002\/0471787779"},{"key":"580_CR3","unstructured":"Cisco (2024) Cybersecurity Reports. https:\/\/www.cisco.com\/c\/en\/us\/products\/security\/cybersecurity-reports.html. [Online]. Accessed: 2024-08-12"},{"key":"580_CR4","unstructured":"CVX Research I (2012) CVX: matlab software for disciplined convex programming, version 2.0. https:\/\/cvxr.com\/cvx"},{"issue":"1","key":"580_CR5","first-page":"2909","volume":"17","author":"S Diamond","year":"2016","unstructured":"Diamond S, Boyd S (2016) Cvxpy: a python-embedded modeling language for convex optimization. J Mach Learn Res 17(1):2909\u20132913","journal-title":"J Mach Learn Res"},{"key":"580_CR6","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2023.109614","volume":"224","author":"Z Diao","year":"2023","unstructured":"Diao Z, Xie G, Wang X et al (2023) EC-GCN: an encrypted traffic classification framework based on multi-scale graph convolution networks. Comput Netw 224:109614","journal-title":"Comput Netw"},{"key":"580_CR7","doi-asserted-by":"crossref","unstructured":"Draper-Gil G, Lashkari AH, Mamun MSRI, et al (2016) Characterization of encrypted and vpn traffic using time-related features. In: Proceedings of the 2nd international conference on information systems security and privacy (ICISSP), pp. 407\u2013414","DOI":"10.5220\/0005740704070414"},{"issue":"5","key":"580_CR8","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3673237","volume":"15","author":"S Fu","year":"2024","unstructured":"Fu S, Dong F, Shen D et al (2024) Design: online device selection and edge association for federated synergy learning-enabled aIoT. ACM Trans Intell Syst Tech 15(5):1\u201328","journal-title":"ACM Trans Intell Syst Tech"},{"key":"580_CR9","doi-asserted-by":"crossref","unstructured":"Grant M, Boyd S (2008) Graph implementations for nonsmooth convex programs. In: Blondel V, Boyd S, Kimura H (eds) Recent Advances in Learning and Control. Lecture Notes in Control and Information Sciences, pp 95\u2013110. Springer, Berlin. http:\/\/stanford.edu\/~boyd\/graph_dcp.html","DOI":"10.1007\/978-1-84800-155-8_7"},{"key":"580_CR10","doi-asserted-by":"publisher","unstructured":"Habibi Lashkari A, Draper Gil G, Mamun MSI, Ghorbani AA (2017)Characterization of tor traffic using time based features. In: Proceedings of the 3rd international conference on information systems security and privacy-ICISSP, pp 253\u2013262. SciTePress, Portugal. https:\/\/doi.org\/10.5220\/0006105602530262 . INSTICC","DOI":"10.5220\/0006105602530262"},{"key":"580_CR11","doi-asserted-by":"crossref","unstructured":"Han X, Xu G, Zhang M, et al (2024) DE-GNN dual embedding with graph neural network for fine-grained encrypted traffic classification. Comput Netw 245:110372","DOI":"10.1016\/j.comnet.2024.110372"},{"key":"580_CR12","doi-asserted-by":"crossref","unstructured":"Kim D-Y, Lee D-E, Kim J-W, et al (2023) Collaborative policy learning for dynamic scheduling tasks in cloud-edge-terminal IoT networks using federated reinforcement learning. IEEE Internet of Things J","DOI":"10.1109\/JIOT.2023.3327495"},{"issue":"18","key":"580_CR13","doi-asserted-by":"publisher","first-page":"17844","DOI":"10.1109\/JIOT.2022.3174567","volume":"9","author":"Z Li","year":"2022","unstructured":"Li Z, He Y, Yu H et al (2022) Data heterogeneity-robust federated learning via group client selection in industrial IoT. IEEE Internet Things J 9(18):17844\u201317857. https:\/\/doi.org\/10.1109\/JIOT.2022.3174567","journal-title":"IEEE Internet Things J"},{"issue":"24","key":"580_CR14","doi-asserted-by":"publisher","first-page":"8028","DOI":"10.3390\/s24248028","volume":"24","author":"L Li","year":"2024","unstructured":"Li L, Zhu L, Li W (2024) Cloud-edge-end collaborative federated learning: Enhancing model accuracy and privacy in non-iid environments. Sensors 24(24):8028. https:\/\/doi.org\/10.3390\/s24248028","journal-title":"Sensors"},{"key":"580_CR15","doi-asserted-by":"crossref","unstructured":"Liu Y, Wang X, Qu B et al (2024) Atvitsc: a novel encrypted traffic classification method based on deep learning. IEEE Trans Inf Forensics Secur","DOI":"10.1109\/TIFS.2024.3433446"},{"issue":"1","key":"580_CR16","doi-asserted-by":"publisher","first-page":"27","DOI":"10.3390\/electronics10010027","volume":"10","author":"H Mun","year":"2020","unstructured":"Mun H, Lee Y (2020) Internet traffic classification with federated learning. Electronics 10(1):27","journal-title":"Electronics"},{"key":"580_CR17","unstructured":"Palo Alto Networks (2024) Research Resources. https:\/\/www.paloaltonetworks.com\/resources\/research. [Online]. Accessed: 2024-08-12"},{"key":"580_CR18","doi-asserted-by":"crossref","unstructured":"Ng KW, Tian GL, Tang ML (2011) Dirichlet and related distributions: theory, methods and applications","DOI":"10.1002\/9781119995784"},{"key":"580_CR19","unstructured":"Wu Z, Sun S, Wang Y, et al (2025) Beyond model scale limits: end-edge-cloud federated learning with self-rectified knowledge agglomeration. arXiv:2501.00693. Accepted for publication"},{"key":"580_CR20","doi-asserted-by":"crossref","unstructured":"Wu Z, Sun S, Wang Y, Liu M et al (2024) Agglomerative federated learning: empowering larger model training via end-edge-cloud collaboration. In: IEEE INFOCOM 2024-IEEE conference on computer communications, pp. 131\u2013140","DOI":"10.1109\/INFOCOM52122.2024.10621254"},{"key":"580_CR21","doi-asserted-by":"crossref","unstructured":"Yan X, He L, Xu Y, et al (2024) High-speed encrypted traffic classification by using payload features. Digital Commun. Netw","DOI":"10.1016\/j.dcan.2024.02.003"},{"key":"580_CR22","doi-asserted-by":"crossref","unstructured":"Yi C, Cai J, Zhang T, et al (2021) Workload re-allocation for edge computing with server collaboration: A cooperative queueing game approach. IEEE Trans Mob Comput 22(5):3095\u20133111","DOI":"10.1109\/TMC.2021.3128887"},{"key":"580_CR23","doi-asserted-by":"crossref","unstructured":"Yi C, Cai J, Zhu K et al (2020) A queueing game based management framework for fog computing with strategic computing speed control. IEEE Trans Mob Comput 21(5):1537\u20131551","DOI":"10.1109\/TMC.2020.3026194"},{"key":"580_CR24","doi-asserted-by":"crossref","unstructured":"Zeng Y, Wang Z, Guo X, et al (2023) Social networks based robust federated learning for encrypted traffic classification. In: ICC 2023-IEEE international conference on communications, pp 4937\u20134942","DOI":"10.1109\/ICC45041.2023.10279778"},{"key":"580_CR25","volume":"1","author":"Y Zhang","year":"2015","unstructured":"Zhang Y, Wang S, Ji G (2015) A comprehensive survey on particle swarm optimization algorithm and its applications. Math Probl Eng 1:931256","journal-title":"Math Probl Eng"},{"key":"580_CR26","doi-asserted-by":"crossref","unstructured":"Zhan M, Yang J, Jia D et al, (2025) Eapt: An encrypted traffic classification model via adversarial pre-trained transformers. Comput Netw 257:110973","DOI":"10.1016\/j.comnet.2024.110973"},{"key":"580_CR27","doi-asserted-by":"crossref","unstructured":"Zhao Y, Chen J, Wu D, et al (2019) Multi-task network anomaly detection using federated learning. In: Proceedings of the 10th international symposium on information and communication technology, pp 273\u2013279","DOI":"10.1145\/3368926.3369705"},{"key":"580_CR28","doi-asserted-by":"crossref","unstructured":"Zhao L, Ni S, Wu D et al (2023) Cloud-edge-client collaborative learning in digital twin empowered mobile networks. IEEE J Selected Areas Commun","DOI":"10.1109\/JSAC.2023.3310060"},{"key":"580_CR29","unstructured":"Zscaler (2024) ThreatLabZ Resources. https:\/\/www.zscaler.com\/resources\/threatlabz. [Online]. Accessed: 2024-08-12"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-026-00580-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-026-00580-9","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-026-00580-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,23]],"date-time":"2026-04-23T07:02:11Z","timestamp":1776927731000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s42400-026-00580-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,23]]},"references-count":29,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,12]]}},"alternative-id":["580"],"URL":"https:\/\/doi.org\/10.1186\/s42400-026-00580-9","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,4,23]]},"assertion":[{"value":"4 March 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"3 November 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"23 April 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"We declare that we have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"Not applicable.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval and consent to participate"}},{"value":"Not applicable.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent for publication"}}],"article-number":"158"}}