Industrial Control System (ICS) network traffic classification is crucial for network security and management but remains challenging due to the imbalanced nature of traffic data, privacy constraints, and the lack of labeled samples. Existing solutions primarily rely on supervised learning methods that require extensive labeled data, limiting their generalization in real-world industrial environments. To address this, we propose PHierT, a Privacy-Preserving Hierarchical Transformer Model that learns hierarchical representations from unlabeled ICS network traffic while ensuring privacy protection by excluding payload data. PHierT pre-trains a deep contextualized traffic representation model on large-scale unlabeled data and fine-tunes it with a small number of labeled samples. By leveraging hierarchical traffic encoding and a novel Masked Packet Prediction (MPP) task, our model achieves stateof-the-art performance across multiple ICS network traffic classification tasks. Experimental results on four real-world datasets demonstrate that PHierT generally outperforms existing methods, achieving a 29.17% improvement in F1-score for intrusion detection on CIC_MODBUS and a 3.25% increase on 2017QUT_DNP3. Notably, our approach effectively preserves industrial privacy while enhancing classification performance, providing new insights into encrypted ICS traffic analysis and generalizable representation learning.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

PHierT: A Privacy-Preserving Hierarchical Transformer Model for ICS Network Traffic Classification

  • Shengquan Chen,
  • Qilei Yin,
  • Jiaxing Song

摘要

Industrial Control System (ICS) network traffic classification is crucial for network security and management but remains challenging due to the imbalanced nature of traffic data, privacy constraints, and the lack of labeled samples. Existing solutions primarily rely on supervised learning methods that require extensive labeled data, limiting their generalization in real-world industrial environments. To address this, we propose PHierT, a Privacy-Preserving Hierarchical Transformer Model that learns hierarchical representations from unlabeled ICS network traffic while ensuring privacy protection by excluding payload data. PHierT pre-trains a deep contextualized traffic representation model on large-scale unlabeled data and fine-tunes it with a small number of labeled samples. By leveraging hierarchical traffic encoding and a novel Masked Packet Prediction (MPP) task, our model achieves stateof-the-art performance across multiple ICS network traffic classification tasks. Experimental results on four real-world datasets demonstrate that PHierT generally outperforms existing methods, achieving a 29.17% improvement in F1-score for intrusion detection on CIC_MODBUS and a 3.25% increase on 2017QUT_DNP3. Notably, our approach effectively preserves industrial privacy while enhancing classification performance, providing new insights into encrypted ICS traffic analysis and generalizable representation learning.