Open Access
ARTICLE
DVG-GNN: Dual-View Graph Representation Learning for Encrypted Traffic Classification
1 Intelligent Perception and Instrumentation College, Zhongyuan University of Technology, Zhengzhou, China
2 School of Computer Science, Zhongyuan University of Technology, Zhengzhou, China
3 School of Software, Henan University of Engineering, Zhengzhou, China
4 School of Software, Zhongyuan University of Technology, Zhengzhou, China
5 School of Mathematical Sciences, Shenzhen University, Shenzhen, China
6 Guangdong Provincial Key Laboratory of Intelligent Information Processing, Shenzhen University, Shenzhen, China
* Corresponding Author: Yu Wang. Email:
Computers, Materials & Continua 2026, 89(1), 28 https://doi.org/10.32604/cmc.2026.083419
Received 03 April 2026; Accepted 17 June 2026; Issue published 13 August 2026
Abstract
The rapid proliferation of encrypted communication technologies, such as TLS, VPNs, and Tor, has significantly limited the effectiveness of traditional traffic classification methods that rely on port numbers or deep packet inspection. While handcrafted statistical features provide partial solutions, they often lack robustness and generalization in complex traffic scenarios. Although deep learning models such as CNNs and RNNs can capture local and sequential patterns, they typically overlook higher-order structural dependencies among bytes. To address these challenges, we propose DVG-GNN, a Dual-View Graph representation learning framework for encrypted traffic classification. The framework decomposes each packet into header and payload views, leveraging distinct byte embeddings and multi-scale one-dimensional convolutions to extract fine-grained contextual features. View-specific graphs are constructed using Pointwise Mutual Information (PMI) to model byte-level relationships, and a GraphSAGE-based encoder with attention pooling is employed to learn global structural representations. A gated fusion mechanism further integrates the dual-view features to enhance discriminative capability. Extensive experiments on ISCX-VPN2016, ISCX-Tor2016, and USTC-TFC2016 demonstrate that the proposed method consistently outperforms state-of-the-art approaches across multiple evaluation metrics, validating its effectiveness and generalization ability in diverse encrypted traffic classification tasks.Keywords
Cite This Article
Copyright © 2026 The Author(s). Published by Tech Science Press.This work is licensed under a Creative Commons Attribution 4.0 International License , which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.


Submit a Paper
Propose a Special lssue
View Full Text
Download PDF
Downloads
Citation Tools