PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
April 29, 2026Journal of King Saud University - Computer and Information Sciences0 citationsOpen Access

Restorable Trojan Packet: a practical neural backdoor attack against network traffic classifiers

View Full Paper
JYJiaji YuanMLMohan LiYSYanbin Sun

Key Points

  • This research aims to develop a neural backdoor attack method that effectively compromises network traffic classifiers.
  • Proposes the Restorable Trojan Packet attack method.
  • Designs an encoder-decoder network for embedding triggers in packets.
  • Uses dynamic and sample-specific triggers to bypass detection.
  • Demonstrates a high success rate in compromising packet-level network flow classifiers.
  • Maintains high levels of stealthiness while executing the attack.
  • Restores packets to their original form post-attack.

Abstract

Deep learning (DL) has found extensive applications in network traffic classification. To ensure the trustworthiness of these DL-based classifiers in real-world deployments, it is imperative to examine their susceptibility to attacks targeting AI models, similar to those encountered in other domains such as computer vision. Existing research has demonstrated that neural backdoor attacks pose a threat to DL-based network flow classifiers. However, these attack methods typically employ static trigger modes or necessitate attackers to simultaneously control both training data and the training process, imposing stringent conditions for launching these attacks in real-world scenarios. Additionally, current research overlooks the restoration process of trojan packets to their original data packets after introducing triggers. This omission poses a challenge for malicious recipients in effectively utilizing transmitted data for subsequent attack processes after receiving trojan packets. To address these issues, this paper proposes Restorable Trojan Packet, a practical packet-level network traffic neural backdoor attack method. Specifically, we design an encoder-decoder network. The encoder is employed to embed dynamic and sample-specific triggers into the payload of network packets, thereby bypassing detection by network traffic classifiers. The decoder is used to restore the packets with embedded triggers back to their original form, which allows attackers to proceed with subsequent attack steps after the reception of the trojan packets. The attacker only needs to perturb a small amount of training data, without requiring control over the entire training process, to efficiently poison the target model. Extensive experiments demonstrate that our attack method can effectively compromise packet-level network flow classifiers. The method achieves a high success rate with lower requirements on the attacker’s capabilities, all while maintaining high levels of stealthiness and robustness. Furthermore, our method accurately restores network packets to their original form.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Yuan et al. (2026) studied this question.

synapsesocial.com/papers/69f154c0879cb923c49450fehttps://doi.org/10.1007/s44443-026-00780-w
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1Enhanced Network Traffic Classification with Machine Learning Algorithms2024 · 29 citations
  2. 2Trojaning Attack on Neural Networks2018 · 1,258 citations
  3. 3Characterization of Encrypted and VPN Traffic using Time-related Features2016 · 1,133 citations
  4. 4Network Traffic Classifier With Convolutional and Recurrent Neural Networks for Internet of Things2017 · 771 citations
  5. 5Learning to Classify: A Flow-Based Relation Network for Encrypted Traffic Classification2020 · 103 citations