Skip to main navigation Skip to search Skip to main content

Graph-Contrastive Pretraining for Payload-Free Encrypted-Traffic Intrusion Detection: Cross-Dataset OOD Transfer with Frozen Artifacts

Research output: Articlepeer-review

Abstract

Encrypted transport increasingly limits the visibility required by intrusion detection systems (IDS), motivating payload-free learning from flow statistics and protocol metadata. We introduce GCP, a graph-contrastive pretraining framework that casts flows as nodes in a sparse graph and learns transferable node embeddings via an InfoNCE-style objective with graph-specific augmentations. The learned encoder is evaluated through frozen-embedding linear probing and cross-dataset out-of-domain (OOD) transfer, within a fully scripted pipeline that freezes run manifests and artifacts to make every reported number traceable and reproducible. Experiments cover enterprise IDS and encrypted DNS/DoH traffic using CICIDS2017, UNSW-NB15, and DoH-Combined at three label granularities (L1/L2/L3), for both binary detection (y) and finer-grained targets ((Formula presented.)), aggregated over five fixed split seeds with 95% confidence intervals. Results show that GCP yields a pronounced in-domain advantage on UNSW-NB15 for y (Macro-F1 (Formula presented.)) while substantially reducing false-alarm rate (FAR (Formula presented.)) compared with strong tabular baselines. In feature-separable regimes (CICIDS2017 and DoH L1/L2), boosted-tree and supervised baselines remain difficult to surpass, but ablations confirm that graph structure alone is insufficient without contrastive pretraining. OOD transfer is strongly source–target dependent, with the most reliable transfer within closely related DoH domains, highlighting dataset shift as a first-class evaluation criterion for encrypted-traffic IDS.

Translated title of the contributionPreentrenamiento contrastivo basado en grafos para detección de intrusiones en tráfico cifrado sin cargas útiles: transferencia OOD entre conjuntos de datos con artefactos congelados
Original languageEnglish
Article number389
Pages (from-to)1-22
Number of pages22
JournalAlgorithms
Volume19
Issue number5
DOIs
Publication statusPublished - May 2026

Bibliographical note

Publisher Copyright:
© 2026 by the authors.

Fingerprint

Dive into the research topics of 'Graph-Contrastive Pretraining for Payload-Free Encrypted-Traffic Intrusion Detection: Cross-Dataset OOD Transfer with Frozen Artifacts'. Together they form a unique fingerprint.

Cite this