信息网络安全 ›› 2026, Vol. 26 ›› Issue (6): 913-924.doi: 10.3969/j.issn.1671-1122.2026.06.006

• 学术研究 • 上一篇    下一篇

基于迁移学习与改进OpenMax算法的开集射频指纹识别研究

张三1,2(), 马宇航1, 周世良1, 丁倩文1, 周曼丽1   

  1. 1 西安邮电大学自动化学院西安 710121
    2 上海人工智能实验室上海 200232
  • 收稿日期:2026-01-10 出版日期:2026-06-10 发布日期:2026-07-27
  • 作者简介:张三(1983—),男,河南,副教授,博士,主要研究方向为网络安全、图像分析与处理|马宇航(2000—),男,陕西,硕士研究生,主要研究方向为网络安全态势感知|周世良(2001—),男,宁夏,硕士研究生,主要研究方向为网络安全态势感知|丁倩文(2000—),女,河南,硕士研究生,主要研究方向为网络安全态势感知、水下图像增强|周曼丽(2001—),女,陕西,硕士研究生,主要研究方向为网络安全态势感知、水下图像增强
  • 基金资助:
    国家科技创新2030-“新一代人工智能”重大项目(2022ZD0160404);网络空间安全教育部重点实验室课题(KLCS20240102)

The Network Traffic Classification Method Based on the MoE

ZHANG San1,2(), MA Yuhang1, ZHOU Shiliang1, DING Qianwen1, ZHOU Manli1   

  1. 1 School of Automation, Xi’an University of Posts and Telecommunications, Xi’an 710121, China
    2 Shanghai Artificial Intelligence Laboratory, Shanghai 200232, China
  • Received:2026-01-10 Online:2026-06-10 Published:2026-07-27

摘要:

网络流量分类是网络安全管理不可或缺的基础支撑技术之一,具有至关重要的理论价值与现实意义。针对现有分类方法在动态网络安全环境中特征依赖性高、分类精度低和准确率不足等问题,文章提出一种基于双路径门控混合专家系统(MoE)的网络流量分类方法,通过动态门控网络自适应激活不同专家网络,实现了对网络异构流量的准确高效分类。该方法在CIC-IDS2017数据集上的实验结果表明,相较于现有网络流量分类方法,模型效果在各个方面都有巨大提升,达到了99%的准确率,误报率也极低,验证了模型的鲁棒性和准确性,该方法为复杂动态网络环境中的流量分类提供了一种轻量化、自适应的解决方法。

关键词: 网络流量分类, 混合专家系统, 双路径门控网络, 异构流量

Abstract:

Network traffic classification, as an indispensable fundamental supporting technology for network security management, holds significant theoretical value and practical significance. This work addresses the issues of high feature dependence and low classification accuracy of existing classification methods in dynamic network security environments, and proposes a network traffic classification method based on the mixture of experts (MoE) model. Through a high-order, context-aware gating mechanism, the architecture selectively orchestrated the transient engagement of specialized expert sub-networks, thereby endowing the system with adaptive, precision-tuned representational capacity, and this method achieved efficient classification of heterogeneous traffic. Experimental results on the CIC-IDS2017 benchmark dataset indicate that compared with existing network traffic classification methods, the method has achieved a significant improvement in all aspects, with an accuracy rate of 99% and an extremely low false alarm rate, verifying the robustness and accuracy of the method. Also, the work provides a lightweight and adaptive solution for traffic classification in dynamic network environments.

Key words: network traffic classification, mixture of experts, dual path network, heterogeneous traffic

中图分类号: