{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T09:39:00Z","timestamp":1781257140167,"version":"3.54.1"},"reference-count":35,"publisher":"MDPI AG","issue":"14","license":[{"start":{"date-parts":[[2022,7,13]],"date-time":"2022-07-13T00:00:00Z","timestamp":1657670400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61602491"],"award-info":[{"award-number":["61602491"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Most machine learning algorithms only have a good recognition rate on balanced datasets. However, in the field of malicious traffic identification, benign traffic on the network is far greater than malicious traffic, and the network traffic dataset is imbalanced, which makes the algorithm have a low identification rate for small categories of malicious traffic samples. This paper presents a traffic sample synthesizing model named Conditional Tabular Traffic Generative Adversarial Network (CTTGAN), which uses a Conditional Tabular Generative Adversarial Network (CTGAN) algorithm to expand the small category traffic samples and balance the dataset in order to improve the malicious traffic identification rate. The CTTGAN model expands and recognizes feature data, which meets the requirements of a machine learning algorithm for training and prediction data. The contributions of this paper are as follows: first, the small category samples are expanded and the traffic dataset is balanced; second, the storage cost and computational complexity are reduced compared to models using image data; third, discrete variables and continuous variables in traffic feature data are processed at the same time, and the data distribution is described well. The experimental results show that the recognition rate of the expanded samples is more than 0.99 in MLP, KNN and SVM algorithms. In addition, the recognition rate of the proposed CTTGAN model is better than the oversampling and undersampling schemes.<\/jats:p>","DOI":"10.3390\/s22145243","type":"journal-article","created":{"date-parts":[[2022,7,14]],"date-time":"2022-07-14T00:12:40Z","timestamp":1657757560000},"page":"5243","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":22,"title":["CTTGAN: Traffic Data Synthesizing Scheme Based on Conditional GAN"],"prefix":"10.3390","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1170-7127","authenticated-orcid":false,"given":"Jiayu","family":"Wang","sequence":"first","affiliation":[{"name":"College of Electronic Engineering, National University of Defense Technology, Hefei 230037, China"},{"name":"Anhui Province Key Laboratory of Cyberspace Security Situation Awareness and Evaluation, Hefei 230037, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6388-1720","authenticated-orcid":false,"given":"Xuehu","family":"Yan","sequence":"additional","affiliation":[{"name":"College of Electronic Engineering, National University of Defense Technology, Hefei 230037, China"},{"name":"Anhui Province Key Laboratory of Cyberspace Security Situation Awareness and Evaluation, Hefei 230037, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lintao","family":"Liu","sequence":"additional","affiliation":[{"name":"College of Electronic Engineering, National University of Defense Technology, Hefei 230037, China"},{"name":"Anhui Province Key Laboratory of Cyberspace Security Situation Awareness and Evaluation, Hefei 230037, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7390-3647","authenticated-orcid":false,"given":"Longlong","family":"Li","sequence":"additional","affiliation":[{"name":"College of Electronic Engineering, National University of Defense Technology, Hefei 230037, China"},{"name":"Anhui Province Key Laboratory of Cyberspace Security Situation Awareness and Evaluation, Hefei 230037, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9778-7783","authenticated-orcid":false,"given":"Yongqiang","family":"Yu","sequence":"additional","affiliation":[{"name":"College of Electronic Engineering, National University of Defense Technology, Hefei 230037, China"},{"name":"Anhui Province Key Laboratory of Cyberspace Security Situation Awareness and Evaluation, Hefei 230037, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,7,13]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"1257","DOI":"10.1109\/TNET.2014.2320577","article-title":"Robust Network Traffic Classification","volume":"23","author":"Zhang","year":"2015","journal-title":"IEEE\/ACM Trans. Netw."},{"key":"ref_2","unstructured":"Park, J.S., Yoon, S.H., and Kim, M.S. (2013, January 25\u201327). Performance improvement of payload signature-based traffic classification system using application traffic temporal locality. Proceedings of the 2013 15th Asia-Pacific Network Operations and Management Symposium (APNOMS), Hiroshima, Japan."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Lee, S.H., Park, J.S., Yoon, S.H., and Kim, M.S. (2015, January 19\u201321). High performance payload signature-based Internet traffic classification system. Proceedings of the 2015 17th Asia-Pacific Network Operations and Management Symposium (APNOMS), Busan, Korea.","DOI":"10.1109\/APNOMS.2015.7275374"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"de Lucia, M.J., and Cotton, C. (2019, January 12\u201314). Detection of Encrypted Malicious Network Traffic using Machine Learning. Proceedings of the MILCOM 2019\u20142019 IEEE Military Communications Conference (MILCOM), Norfolk, VA, USA.","DOI":"10.1109\/MILCOM47813.2019.9020856"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"130","DOI":"10.1016\/j.eswa.2019.01.064","article-title":"Feature Analysis of Encrypted Malicious Traffic","volume":"125","author":"Shekhawat","year":"2019","journal-title":"Expert Syst. Appl."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Ma, R., and Qin, S. (2017, January 13\u201316). Identification of unknown protocol traffic based on deep learning. Proceedings of the 2017 3rd IEEE International Conference on Computer and Communications (ICCC), Chengdu, China.","DOI":"10.1109\/CompComm.2017.8322732"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Liu, Z., Li, S., Zhang, Y., Yun, X., and Cheng, Z. (2020, January 7\u201310). Efficient Malware Originated Traffic Classification by Using Generative Adversarial Networks. Proceedings of the 2020 IEEE Symposium on Computers and Communications (ISCC), Rennes, France.","DOI":"10.1109\/ISCC50000.2020.9219561"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Dong, S., Xia, Y., and Peng, T. (2021). Traffic identification model based on generative adversarial deep convolutional network. Ann. Telecommun.","DOI":"10.1007\/s12243-021-00876-6"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"6659022","DOI":"10.1155\/2021\/6659022","article-title":"Deep-Feature-Based Autoencoder Network for Few-Shot Malicious Traffic Detection","volume":"2021","author":"He","year":"2021","journal-title":"Secur. Commun. Netw."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"107049","DOI":"10.1016\/j.comnet.2019.107049","article-title":"HELAD: A novel network anomaly detection model based on heterogeneous ensemble learning","volume":"169","author":"Zhong","year":"2019","journal-title":"Comput. Netw."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"661","DOI":"10.1109\/TNSM.2021.3112283","article-title":"A Cost-Sensitive Deep Learning-Based Approach for Network Traffic Classification","volume":"19","author":"Telikani","year":"2022","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"923","DOI":"10.1002\/int.22230","article-title":"A Self-Adaptive Synthetic Over-Sampling Technique for Imbalanced Classification","volume":"35","author":"Gu","year":"2019","journal-title":"Int. J. Intell. Syst."},{"key":"ref_13","first-page":"4707","article-title":"Trainable Undersampling for Class-Imbalance Learning","volume":"33","author":"Peng","year":"2019","journal-title":"Proc. AAAI Conf. Artif. Intell."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"321","DOI":"10.1613\/jair.953","article-title":"SMOTE: Synthetic Minority Over-sampling Technique","volume":"16","author":"Chawla","year":"2002","journal-title":"J. Artif. Intell. Res."},{"key":"ref_15","first-page":"109","article-title":"P2P Traffic Identification Based Over-Sampling Technique","volume":"30","author":"Qian","year":"2014","journal-title":"Telecommun. Sci."},{"key":"ref_16","unstructured":"Yan, B.H., Han, G.D., Huang, Y.J., and Yu, X.L. (2017). DPCS2017+41+A Novel traffic Classification Method Based on Imbalanced Data. J. Comput. Appl."},{"key":"ref_17","first-page":"1","article-title":"Generative Adversarial Nets","volume":"27","author":"Goodfellow","year":"2014","journal-title":"Neural Inf. Process. Syst."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Vu, L., Bui, C.T., and Nguyen, Q.U. (2017, January 7\u20138). A Deep Learning Based Method for Handling Imbalanced Problem in Network Traffic Classification. Proceedings of the Eighth International Symposium on Information & Communication Technology, Nha Trang, Vietnam.","DOI":"10.1145\/3155133.3155175"},{"key":"ref_19","unstructured":"Odena, A., Olah, C., and Shlens, J. (2016, January 20\u201322). Conditional Image Synthesis With Auxiliary Classifier GANs. Proceedings of the International Conference on Machine Learning, New York, NY, USA."},{"key":"ref_20","unstructured":"Arjovsky, M., Chintala, S., and Bottou, L. (2017). Wasserstein GAN. arXiv."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"83","DOI":"10.1016\/j.ins.2018.04.092","article-title":"Zero-day malware detection using transferred generative adversarial networks based on deep autoencoders","volume":"460","author":"Kim","year":"2018","journal-title":"Inf. Sci."},{"key":"ref_22","unstructured":"Lin, Z., Shi, Y., and Xue, Z. (2018). IDSGAN: Generative Adversarial Networks for Attack Generation against Intrusion Detection. arXiv."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Lee, R. (2020). Expansion of Cyber Attack Data from Unbalanced Datasets Using Generative Adversarial Networks. Software Engineering Research, Management and Applications, Springer.","DOI":"10.1007\/978-3-030-24344-9"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Shahriar, M.H., Haque, N.I., Rahman, M.A., and Alonso, J.M. (2020, January 13\u201317). G-IDS: Generative Adversarial Networks Assisted Intrusion Detection System. Proceedings of the 2020 IEEE 44th Annual Computers, Software, and Applications Conference (COMPSAC), Madrid, Spain.","DOI":"10.1109\/COMPSAC48688.2020.0-218"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"102177","DOI":"10.1016\/j.adhoc.2020.102177","article-title":"IGAN-IDS: An Imbalanced Generative Adversarial Network towards Intrusion Detection System in Ad-hoc Networks","volume":"105","author":"Huang","year":"2020","journal-title":"Ad Hoc Netw."},{"key":"ref_26","unstructured":"Wallach, H., Larochelle, H., Beygelzimer, A., d\u2019Alch\u00e9-Buc, F., Fox, E., and Garnett, R. (2019). Modeling Tabular data using Conditional GAN. Advances in Neural Information Processing Systems, Curran Associates, Inc."},{"key":"ref_27","unstructured":"Huang, H., Yu, P.S., and Wang, C. (2018). An Introduction to Image Synthesis with Generative Adversarial Nets. arXiv."},{"key":"ref_28","unstructured":"Jhamtani, H., and Berg-Kirkpatrick, T. (2019, January 15). Modeling Self-Repetition in Music Generation using Generative Adversarial Networks. Proceedings of the Machine Learning for Music Discovery Workshop, ICML, Long Beach, CA, USA."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Rajeswar, S., Subramanian, S., Dutil, F., Pal, C., and Courville, A. (2017). Adversarial Generation of Natural Language. arXiv.","DOI":"10.18653\/v1\/W17-2629"},{"key":"ref_30","unstructured":"Mirza, M., and Osindero, S. (2014). Conditional Generative Adversarial Nets. Comput. Sci., 2672\u20132680."},{"key":"ref_31","unstructured":"Yahi, A., Vanguri, R., Elhadad, N., and Tatonetti, N.P. (2017). Generative Adversarial Networks for Electronic Health Records: A Framework for Exploring and Evaluating Methods for Predicting Drug-Induced Laboratory Test Trajectories. arXiv."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Yu, L., Zhang, W., Wang, J., and Yong, Y. (2016, January 12\u201317). SeqGAN: Sequence Generative Adversarial Nets with Policy Gradient. Proceedings of the AAAI Conference on Artificial Intelligence, Phoenix, AZ, USA.","DOI":"10.1609\/aaai.v31i1.10804"},{"key":"ref_33","unstructured":"Choi, E., Biswal, S., Malin, B., Duke, J., and Sun, J. (2017, January 18\u201319). Generating Multi-label Discrete Patient Records using Generative Adversarial Networks. Proceedings of the Machine Learning for Healthcare Conference, Boston, MA, USA."},{"key":"ref_34","unstructured":"Lederrey, G., Hillel, T., and Bierlaire, M. (2022). DATGAN: Integrating expert knowledge into deep learning for synthetic tabular data. arXiv."},{"key":"ref_35","unstructured":"Drummond, C., and Holte, R. (2003, January 21). C4.5, Class Imbalance, and Cost Sensitivity: Why Under-Sampling beats Over-Sampling. Proceedings of the Workshop on Learning from Imbalanced Datasets II, Washington, DC, USA."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/14\/5243\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T23:49:41Z","timestamp":1760140181000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/14\/5243"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,7,13]]},"references-count":35,"journal-issue":{"issue":"14","published-online":{"date-parts":[[2022,7]]}},"alternative-id":["s22145243"],"URL":"https:\/\/doi.org\/10.3390\/s22145243","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,7,13]]}}}