arrow
Return

Enhancing encrypted HTTPS traffic classification based on stacked deep ensembles models

delete2025-10-09
delete0
delete
OA
AI
A
Ahmed M. Elshewey
A
Ahmed M. Osman *
DOI:10.1038/s41598-025-21261-6delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The classification of encrypted HTTPS traffic is a critical task for network management and security, where traditional port or payload-based methods are ineffective due to encryption and evolving traffic patterns. This study addresses the challenge using the public Kaggle dataset (145,671 flows, 88 features, six traffic categories: Download, Live Video, Music, Player, Upload, Website). An automated preprocessing pipeline is developed to detect the label column, normalize classes, perform a stratified 70/15/15 split into training, validation, and testing sets, and apply imbalance-aware weighting. Multiple deep learning architectures are benchmarked, including DNN, CNN, RNN, LSTM, and GRU, capturing different spatial and temporal patterns of traffic features. Experimental results show that CNN achieved the strongest single-model performance (Accuracy 0.9934, F1_macro 0.9912, ROC-AUC_macro 0.9999). To further improve robustness, a stacked ensemble meta-learner based on multinomial logistic regression was trained on model outputs, achieving state-of-the-art performance with Accuracy 0.9949, Precision_macro 0.9923, Recall_macro 0.9941, F1_macro 0.9932, and ROC-AUC_macro 0.9998. The framework also outputs confusion matrices, ROC curves, and learning curves for interpretability. To ensure reproducibility and practical use, the full codebase is publicly available on GitHub, providing researchers and practitioners with a deployment-ready pipeline for encrypted traffic analytics where ensemble learning surpasses individual models.
Keywords:
HTTPS traffic classification
Encrypted traffic
Network security
Network traffic classification
Deep learning
Ensemble learning
Cyber security
CNN
DNN

Journal

Scientific Reports cover
Scientific Reports
IF:
3.9
Papers:
28.0W
Citations:
83.5W

Organization

F
Faculty of Computers and Information
Scholars:
108
Papers: 74
Citations: 0
Cited Papers

Cited Papers

Deep learning for encrypted traffic classification in the face of data drift: An empirical study
err2023-04-01
err0
PREAI
errNavid Malekghaini; Elham Akbari; Mohammad A. Salahuddin; Noura Limam; Raouf Boutaba; Bertrand Mathieu; Stephanie Moteau; Stephane Tuffin
errShare
errSave
DDoS classification of network traffic in software defined networking SDN using a hybrid convolutional and gated recurrent neural network
err2025-08-09
err0
errOAAI
errAhmed M. Elshewey; Safia Abbas; Ahmed M. Osman; Eman Abdullah Aldakheel; Yasser Fouad
errShare
errSave
High-speed encrypted traffic classification by using payload features
err2024-02-01
err0
errOAAI
errXinge Yan; Liukun He; Yifan Xu; Jiuxin Cao; Liangmin Wang; Guyang Xie
errShare
errSave
Hierarchical Perception for Encrypted Traffic Classification via Class Incremental Learning
err2025-02-01
err0
PREAI
errLi, Zhiyuan; Bu, Lingbin; Wang, Yifan; Ma, Qiming; Tan, Lin; Bu, Fanliang
errShare
errSave
Combine intra- and inter-flow: A multimodal encrypted traffic classification model driven by diverse features
err
IF0
err2024-05-01
err0
PREAI
errXiangbin Wang; Qingjun Yuan; Yongjuan Wang; Gaopeng Gou; Chunxiang Gu; Gang Yu; Gang Xiong
errShare
errSave
Network traffic classification based on federated semi-supervised learning
err2024-04-01
err8
errOAAI
errWang, Zixuan; Li, Zeyi; Fu, Mengyi; Ye, Yingchun; Wang, Pan
errShare
errSave
researcher View more