Skip to main navigation Skip to search Skip to main content

Enhanced Encrypted IoT Malicious Traffic Detection via Adaptive Fusion and Focal Loss: An Improved Heterogeneous Graph Approach

  • Mianzhang Luo
  • , Xiaoyi Yang
  • , Yuqing Lan*
  • *Corresponding author for this work
  • Beihang University
  • University of Science and Technology Beijing

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

The rapid proliferation of the Internet of Things (IoT) has significantly expanded the attack surface of network environments, making malicious traffic detection a critical security challenge. The widespread adoption of encryption technologies further exacerbates this challenge, as traditional plaintext feature-based detection methods are no longer effective. Although existing deep learning approaches have shown progress in encrypted traffic classification, they still face limitations in feature fusion strategies and the accurate identification of hard-to-classify samples. To address these shortcomings, this paper proposes an enhanced approach based on a dual-granularity heterogeneous graph neural network framework. Specifically, we introduce an adaptive feature fusion mechanism that dynamically adjusts feature weights and employs cross-view attention to fully exploit the complementarity of features across different granularities. Additionally, we replace the conventional cross-entropy loss with Focal Loss, enabling the model to focus more on challenging MitM (Man-in-the-Middle) samples during training. Extensive experiments conducted on the CIC-IIoT 2025 and IoT-23 datasets demonstrate that the proposed approach achieves significant improvements in both weighted average accuracy and F1 score over baseline methods. Compared to the state-of-the-art encrypted traffic classification framework, MH-Net, the F1 score improves by 11.5% on the CIC-IIoT dataset, while also significantly reducing the misclassification of MitM samples as benign traffic. These results confirm the effectiveness and superiority of the proposed method. This work provides a practical solution for encrypted traffic classification in IoT environments, enabling more accurate detection of malicious traffic and improving the security of IoT networks.

Original languageEnglish
Title of host publication2026 International Conference on Generative Artificial Intelligence and Information Security, GAIIS 2026
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages237-242
Number of pages6
ISBN (Electronic)9798331546229
DOIs
StatePublished - 2026
Event2026 International Conference on Generative Artificial Intelligence and Information Security, GAIIS 2026 - Wuhan, China
Duration: 27 Mar 202629 Mar 2026

Publication series

Name2026 International Conference on Generative Artificial Intelligence and Information Security, GAIIS 2026

Conference

Conference2026 International Conference on Generative Artificial Intelligence and Information Security, GAIIS 2026
Country/TerritoryChina
CityWuhan
Period27/03/2629/03/26

Keywords

  • encrypted traffic classification
  • feature fusion
  • focal loss
  • heterogeneous graph neural networks

Fingerprint

Dive into the research topics of 'Enhanced Encrypted IoT Malicious Traffic Detection via Adaptive Fusion and Focal Loss: An Improved Heterogeneous Graph Approach'. Together they form a unique fingerprint.

Cite this