Our new X account is live! Follow @wizwand_team for updates
WorkDL logo mark

MalMoE: Mixture-of-Experts Enhanced Encrypted Malicious Traffic Detection Under Graph Drift

About

Encryption has been commonly used in network traffic to secure transmission, but it also brings challenges for malicious traffic detection, due to the invisibility of the packet payload. Graph-based methods are emerging as promising solutions by leveraging multi-host interactions to promote detection accuracy. But most of them face a critical problem: Graph Drift, where the flow statistics or topological information of a graph change over time. To overcome these drawbacks, we propose a graph-assisted encrypted traffic detection system, MalMoE, which applies Mixture of Experts (MoE) to select the best expert model for drift-aware classification. Particularly, we design 1-hop-GNN-like expert models that handle different graph drifts by analyzing graphs with different features. Then, the redesigned gate model conducts expert selection according to the actual drift. MalMoE is trained with a stable two-stage training strategy with data augmentation, which effectively guides the gate on how to perform routing. Experiments on open-source, synthetic, and real-world datasets show that MalMoE can perform precise and real-time detection.

Yunpeng Tan, Qingyang Li, Mingxin Yang, Yannan Hu, Lei Zhang, Xinggong Zhang• 2026

Related benchmarks

TaskDatasetResultRank
Malicious Traffic DetectionCIC-IDS without drift 2018
Accuracy99.7
5
Malicious Traffic DetectionCIC-IDS 2018 (with drift)
Accuracy99.93
5
Malicious Traffic DetectionToN-IoT with drift
ACC90.11
5
Malicious Traffic DetectionBoT-IoT without drift
Accuracy99.77
5
Malicious Traffic DetectionBoT-IoT with drift
Accuracy99.47
5
Malicious Traffic DetectionUNSW-NB15 (without drift)
Accuracy99.67
5
Malicious Traffic DetectionUNSW-NB15 (with drift)
Accuracy0.9964
5
Malicious Traffic DetectionSynthetic (without drift)
Accuracy98.8
5
Malicious Traffic DetectionSynthetic (with drift)
ACC93.76
5
Malicious Traffic DetectionOverall Performance without drift
ACC97.16
5
Showing 10 of 12 rows

Other info

Follow for update