{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,29]],"date-time":"2026-07-29T15:14:15Z","timestamp":1785338055513,"version":"3.55.0"},"reference-count":31,"publisher":"MDPI AG","issue":"2","license":[{"start":{"date-parts":[[2022,2,21]],"date-time":"2022-02-21T00:00:00Z","timestamp":1645401600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100000266","name":"Engineering and Physical Sciences Research Council","doi-asserted-by":"publisher","award":["EP\/W00366X\/1"],"award-info":[{"award-number":["EP\/W00366X\/1"]}],"id":[{"id":"10.13039\/501100000266","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>In this study, a simple yet effective framework is proposed to characterize fine-grained in-app user activities performed on mobile applications using a convolutional neural network (CNN). The proposed framework uses a time window-based approach to split the activity\u2019s encrypted traffic flow into segments, so that in-app activities can be identified just by observing only a part of the activity-related encrypted traffic. In this study, matrices were constructed for each encrypted traffic flow segment. These matrices acted as input into the CNN model, allowing it to learn to differentiate previously trained (known) and previously untrained (unknown) in-app activities as well as the known in-app activity type. The proposed method extracts and selects salient features for encrypted traffic classification. This is the first-known approach proposing to filter unknown traffic with an average accuracy of 88%. Once the unknown traffic is filtered, the classification accuracy of our model would be 92%.<\/jats:p>","DOI":"10.3390\/fi14020067","type":"journal-article","created":{"date-parts":[[2022,2,21]],"date-time":"2022-02-21T20:24:21Z","timestamp":1645475061000},"page":"67","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":10,"title":["CNN for User Activity Detection Using Encrypted In-App Mobile Data"],"prefix":"10.3390","volume":"14","author":[{"given":"Madushi H.","family":"Pathmaperuma","sequence":"first","affiliation":[{"name":"Institute for Digital Technologies, Loughborough University London, London E20 3BS, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yogachandran","family":"Rahulamathavan","sequence":"additional","affiliation":[{"name":"Institute for Digital Technologies, Loughborough University London, London E20 3BS, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1465-6495","authenticated-orcid":false,"given":"Safak","family":"Dogan","sequence":"additional","affiliation":[{"name":"Institute for Digital Technologies, Loughborough University London, London E20 3BS, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ahmet","family":"Kondoz","sequence":"additional","affiliation":[{"name":"Institute for Digital Technologies, Loughborough University London, London E20 3BS, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,2,21]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"76","DOI":"10.1109\/MCOM.2019.1800819","article-title":"Deep learning for encrypted traffic classification: An overview","volume":"57","author":"Rezaei","year":"2019","journal-title":"IEEE Commun. Mag."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Taylor, V.F., Spolaor, R., Conti, M., and Martinovic, I. (2016, January 21\u201324). Appscanner: Automatic fingerprinting of smartphone apps from encrypted network traffic. Proceedings of the 2016 IEEE European Symposium on Security and Privacy (EuroS&P), Saarbruecken, Germany.","DOI":"10.1109\/EuroSP.2016.40"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Wang, Q., Yahyavi, A., Kemme, B., and He, W. (2015, January 28\u201330). I know what you did on your smartphone: Inferring app usage over encrypted data traffic. Proceedings of the 2015 IEEE Conference on Communications and Network Security (CNS), Florence, Italy.","DOI":"10.1109\/CNS.2015.7346855"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Pathmaperuma, M.H., Rahulamathavan, Y., Dogan, S., and Kondoz, A.M. (2020). In-app activity recognition from Wi-Fi encrypted traffic. Science and Information Conference, Springer.","DOI":"10.1007\/978-3-030-52249-0_46"},{"key":"ref_5","unstructured":"Saltaformaggio, B., Choi, H., Johnson, K., Kwon, Y., Zhang, Q., Zhang, X., Xu, D., and Qian, J. (2016, January 8\u20139). Eavesdropping on fine-grained user activities within smartphone apps over encrypted network traffic. Proceedings of the 10th USENIX Workshop on Offensive Technologies (WOOT 16), Austin, TX, USA."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Zhou, H., Wang, Y., Lei, X., and Liu, Y. (2017, January 15\u201318). A method of improved CNN traffic classification. Proceedings of the 2017 13th International Conference on Computational Intelligence and Security (CIS), Hong Kong, China.","DOI":"10.1109\/CIS.2017.00046"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Shapira, T., and Shavitt, Y. (May, January 29). Flowpic: Encrypted internet traffic classification is as easy as image recognition. Proceedings of the IEEE INFOCOM 2019-IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS), Paris, France.","DOI":"10.1109\/INFCOMW.2019.8845315"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Ma, X., Dai, Z., He, Z., Ma, J., Wang, Y., and Wang, Y. (2017). Learning traffic as images: A deep convolutional neural network for large-scale transportation network speed prediction. Sensors, 17.","DOI":"10.3390\/s17040818"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"114","DOI":"10.1109\/TIFS.2015.2478741","article-title":"Analyzing android encrypted network traffic to identify user actions","volume":"11","author":"Conti","year":"2015","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"63","DOI":"10.1109\/TIFS.2017.2737970","article-title":"Robust smartphone app identification via encrypted network traffic analysis","volume":"13","author":"Taylor","year":"2017","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"1257","DOI":"10.1109\/TNET.2014.2320577","article-title":"Robust network traffic classification","volume":"23","author":"Zhang","year":"2014","journal-title":"IEEE\/ACM Trans. Netw."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Draper-Gil, G., Lashkari, A.H., Mamun, M.S.I., and Ghorbani, A.A. (2016, January 19). Characterization of encrypted and vpn traffic using time-related. Proceedings of the 2nd International Conference on Information Systems Security and Privacy (ICISSP), Fredericton, NB, Canada.","DOI":"10.5220\/0005740704070414"},{"key":"ref_13","unstructured":"Wang, W., Zhu, M., Zeng, X., Ye, X., and Sheng, Y. (2017, January 11\u201313). Malware traffic classification using convolutional neural network for representation learning. Proceedings of the 2017 International Conference on Information Networking (ICOIN), Da Nang, Vietnam."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Tang, T.A., Mhamdi, L., McLernon, D., Zaidi, S.A.R., and Ghogho, M. (2016, January 26\u201329). Deep learning approach for network intrusion detection in software defined networking. Proceedings of the 2016 International Conference on Wireless Networks and Mobile Communications (WINCOM), Fez, Morocco.","DOI":"10.1109\/WINCOM.2016.7777224"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Niyaz, Q., Sun, W., and Javaid, A.Y. (2016). A deep learning based DDoS detection system in software-defined networking (SDN). arXiv.","DOI":"10.4108\/eai.28-12-2017.153515"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Mirsky, Y., Doitshman, T., Elovici, Y., and Shabtai, A. (2018). Kitsune: An ensemble of autoencoders for online network intrusion detection. arXiv.","DOI":"10.14722\/ndss.2018.23204"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"41","DOI":"10.1109\/TETCI.2017.2772792","article-title":"A deep learning approach to network intrusion detection","volume":"2","author":"Shone","year":"2018","journal-title":"IEEE Trans. Emerg. Top. Comput. Intell."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Wang, W., Zhu, M., Wang, J., Zeng, X., and Yang, Z. (2017, January 22\u201324). End-to-end encrypted traffic classification with one-dimensional convolution neural networks. Proceedings of the 2017 IEEE International Conference on Intelligence and Security Informatics (ISI), Beijing, China.","DOI":"10.1109\/ISI.2017.8004872"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"18042","DOI":"10.1109\/ACCESS.2017.2747560","article-title":"Network traffic classifier with convolutional and recurrent neural networks for Internet of Things","volume":"5","author":"Carro","year":"2017","journal-title":"IEEE Access"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Aceto, G., Ciuonzo, D., Montieri, A., and Pescap\u00e8, A. (2019). MIMETIC: Mobile encrypted traffic classification using multimodal deep learning. Comput. Netw., 165.","DOI":"10.1016\/j.comnet.2019.106944"},{"key":"ref_21","first-page":"1","article-title":"The applications of deep learning on traffic identification","volume":"24","author":"Wang","year":"2015","journal-title":"BlackHat USA"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"1999","DOI":"10.1007\/s00500-019-04030-2","article-title":"Deep packet: A novel approach for encrypted traffic classification using deep learning","volume":"24","author":"Lotfollahi","year":"2020","journal-title":"Soft Comput."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Tavakoli, N. (2020, January 13\u201317). Seq2image: Sequence analysis using visualization and deep convolutional neural network. Proceedings of the 2020 IEEE 44th Annual Computers, Software, and Applications Conference (COMPSAC), Madrid, Spain.","DOI":"10.1109\/COMPSAC48688.2020.00-71"},{"key":"ref_24","first-page":"2056","article-title":"A study of analyzing network traffic as images in real-time","volume":"Volome 3","author":"Kim","year":"2005","journal-title":"Proceedings of the IEEE 24th Annual Joint Conference of the IEEE Computer and Communications Societies"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"1942","DOI":"10.1109\/JSAC.2006.877215","article-title":"Image-based anomaly detection technique: Algorithm, implementation and effectiveness","volume":"24","author":"Kim","year":"2006","journal-title":"IEEE J. Sel. Areas Commun."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"168","DOI":"10.1109\/ICC.2005.1494341","article-title":"Modeling network traffic as images","volume":"Volume 1","author":"Kim","year":"2005","journal-title":"Proceedings of the IEEE International Conference on Communications, 2005, ICC 2005"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"He, Y., and Li, W. (2020, January 27\u201330). Image-based encrypted traffic classification with convolution neural networks. Proceedings of the 2020 IEEE Fifth International Conference on Data Science in Cyberspace (DSC), Hong Kong, China.","DOI":"10.1109\/DSC50466.2020.00048"},{"key":"ref_28","unstructured":"(2021, July 11). Aircrack-ng. Available online: https:\/\/www.aircrack-ng.org\/."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Taheri, S., Salem, M., and Yuan, J.S. (2018). Leveraging image representation of network traffic data and transfer learning in botnet detection. Big Data Cogn. Comput., 2.","DOI":"10.3390\/bdcc2040037"},{"key":"ref_30","unstructured":"(2021, July 15). Sklearn.preprocessing. StandardScaler. Available online: https:\/\/scikit-learn.org\/stable\/modules\/generated\/sklearn.preprocessing.StandardScaler.html?highlight=standardscaler#sklearn.preprocessing.StandardScaler."},{"key":"ref_31","first-page":"865","article-title":"Traffic flow prediction with big data: A deep learning approach","volume":"16","author":"Lv","year":"2014","journal-title":"IEEE Trans. Intell. Transp. Syst."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/14\/2\/67\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T22:24:17Z","timestamp":1760135057000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/14\/2\/67"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,2,21]]},"references-count":31,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2022,2]]}},"alternative-id":["fi14020067"],"URL":"https:\/\/doi.org\/10.3390\/fi14020067","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,2,21]]}}}