TY - GEN
T1 - Enhanced Encrypted IoT Malicious Traffic Detection via Adaptive Fusion and Focal Loss
T2 - 2026 International Conference on Generative Artificial Intelligence and Information Security, GAIIS 2026
AU - Luo, Mianzhang
AU - Yang, Xiaoyi
AU - Lan, Yuqing
N1 - Publisher Copyright:
© 2026 IEEE.
PY - 2026
Y1 - 2026
N2 - The rapid proliferation of the Internet of Things (IoT) has significantly expanded the attack surface of network environments, making malicious traffic detection a critical security challenge. The widespread adoption of encryption technologies further exacerbates this challenge, as traditional plaintext feature-based detection methods are no longer effective. Although existing deep learning approaches have shown progress in encrypted traffic classification, they still face limitations in feature fusion strategies and the accurate identification of hard-to-classify samples. To address these shortcomings, this paper proposes an enhanced approach based on a dual-granularity heterogeneous graph neural network framework. Specifically, we introduce an adaptive feature fusion mechanism that dynamically adjusts feature weights and employs cross-view attention to fully exploit the complementarity of features across different granularities. Additionally, we replace the conventional cross-entropy loss with Focal Loss, enabling the model to focus more on challenging MitM (Man-in-the-Middle) samples during training. Extensive experiments conducted on the CIC-IIoT 2025 and IoT-23 datasets demonstrate that the proposed approach achieves significant improvements in both weighted average accuracy and F1 score over baseline methods. Compared to the state-of-the-art encrypted traffic classification framework, MH-Net, the F1 score improves by 11.5% on the CIC-IIoT dataset, while also significantly reducing the misclassification of MitM samples as benign traffic. These results confirm the effectiveness and superiority of the proposed method. This work provides a practical solution for encrypted traffic classification in IoT environments, enabling more accurate detection of malicious traffic and improving the security of IoT networks.
AB - The rapid proliferation of the Internet of Things (IoT) has significantly expanded the attack surface of network environments, making malicious traffic detection a critical security challenge. The widespread adoption of encryption technologies further exacerbates this challenge, as traditional plaintext feature-based detection methods are no longer effective. Although existing deep learning approaches have shown progress in encrypted traffic classification, they still face limitations in feature fusion strategies and the accurate identification of hard-to-classify samples. To address these shortcomings, this paper proposes an enhanced approach based on a dual-granularity heterogeneous graph neural network framework. Specifically, we introduce an adaptive feature fusion mechanism that dynamically adjusts feature weights and employs cross-view attention to fully exploit the complementarity of features across different granularities. Additionally, we replace the conventional cross-entropy loss with Focal Loss, enabling the model to focus more on challenging MitM (Man-in-the-Middle) samples during training. Extensive experiments conducted on the CIC-IIoT 2025 and IoT-23 datasets demonstrate that the proposed approach achieves significant improvements in both weighted average accuracy and F1 score over baseline methods. Compared to the state-of-the-art encrypted traffic classification framework, MH-Net, the F1 score improves by 11.5% on the CIC-IIoT dataset, while also significantly reducing the misclassification of MitM samples as benign traffic. These results confirm the effectiveness and superiority of the proposed method. This work provides a practical solution for encrypted traffic classification in IoT environments, enabling more accurate detection of malicious traffic and improving the security of IoT networks.
KW - encrypted traffic classification
KW - feature fusion
KW - focal loss
KW - heterogeneous graph neural networks
UR - https://www.scopus.com/pages/publications/105041624226
U2 - 10.1109/GAIIS69281.2026.11519230
DO - 10.1109/GAIIS69281.2026.11519230
M3 - 会议稿件
AN - SCOPUS:105041624226
T3 - 2026 International Conference on Generative Artificial Intelligence and Information Security, GAIIS 2026
SP - 237
EP - 242
BT - 2026 International Conference on Generative Artificial Intelligence and Information Security, GAIIS 2026
PB - Institute of Electrical and Electronics Engineers Inc.
Y2 - 27 March 2026 through 29 March 2026
ER -