BGA: A noise-immune neural distillation framework for malicious signature extraction in high-entropy encrypted flows

📅 2026-08-14
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the challenges of attention dilution and malicious signature extraction in high-entropy TLS 1.3 encrypted traffic by proposing BGA, a noise-resistant neural distillation framework. Integrating ANOVA-based feature decoupling with WGAN-GP for sample balancing, alongside BiLSTM and adaptive gated attention mechanisms, the method effectively suppresses encryption noise while amplifying threat signatures. Experimental results demonstrate that BGA achieves a detection accuracy exceeding 95.2% and improves recall for rare attacks by 43.2%. Furthermore, it outperforms Transformer-based models in noise robustness by 8.57% while maintaining an inference latency of only 0.282 ms. These findings confirm that BGA enables precise, real-time detection of malicious threats within high-entropy encrypted environments, offering a significant advancement over existing deep learning approaches for secure network traffic analysis.
📝 Abstract
To mitigate attention dilution in high-entropy TLS 1.3 flows, we propose BGA, a noise-immune neural distillation framework for encrypted threat intelligence.The methodology first employs Analysis of Variance (ANOVA) to decouple high-discriminatory control-plane features - specifically industrial setpoints - from stochastic cryptographic noise. To resolve the extreme class imbalance within a corpus of 86,878 flow records, a Wasserstein GAN with Gradient Penalty (WGAN-GP) module, enforcing the 1-Lipschitz constraint, is integrated to synthesize high-fidelity minority samples, elevating the detection recall of rare Malicious State Command Injections(MSCI) attacks by 43.2%. At its core, the BGA architecture integrates Bidirectional Long Short-Term Memory (BiLSTM) for temporal dependency extraction and an Adaptive Gated Multi-Head Attention mechanism. This gated unit functions as a neural filter to dynamically suppress encryption artifacts while amplifying malicious signatures. Extensive evaluations on CIC-IDS-2018 and Edge-IIoT benchmarks demonstrate a performance ceiling exceeding 95.2% across all key metrics. Furthermore, noise-injection stress tests confirm BGAs superior structural resilience with a 8.57% performance margin over vanilla Transformers, while its ultra-low inference latency of 0.2820 ms (estimated 1.6920 ms via theoretical scaling for ARM) indicates a high potential for real-time feasibility on heterogeneous industrial edge gateways, providing a promising architectural baseline for future hardware implementation.
Problem

Research questions and friction points this paper is trying to address.

Encrypted Traffic Analysis
Malicious Signature Extraction
Attention Dilution
Class Imbalance
TLS 1.3
Innovation

Methods, ideas, or system contributions that make the work stand out.

Neural Distillation
WGAN-GP
Adaptive Gated Attention
Noise Immunity
Encrypted Traffic Analysis
🔎 Similar Papers
No similar papers found.
S
Sheng Hong
School of Cyber Science and Technology, Beihang University, Beijing, 100191, China
Y
Yixuan Huang
School of Cyber Science and Technology, Beihang University, Beijing, 100191, China
Weiwei Jiang
Weiwei Jiang
Beijing University of Posts and Telecommunications
Artificial IntelligenceSignal ProcessingData AnalysisMachine LearningWireless Communication
J
Junyuan Zhang
Beijing Electronic Science and Technology Institute, Beijing, 100070, China
Jiacheng Wang
Jiacheng Wang
Nanyang Technological University
ISACGenAILow-altitude wireless networkSemantic Communications
R
Ruijian Jiao
School of Cyber Science and Technology, Beihang University, Beijing, 100191, China