Abstract
Encrypted transport increasingly limits the visibility required by intrusion detection systems (IDS), motivating payload-free learning from flow statistics and protocol metadata. We introduce GCP, a graph-contrastive pretraining framework that casts flows as nodes in a sparse graph and learns transferable node embeddings via an InfoNCE-style objective with graph-specific augmentations. The learned encoder is evaluated through frozen-embedding linear probing and cross-dataset out-of-domain (OOD) transfer, within a fully scripted pipeline that freezes run manifests and artifacts to make every reported number traceable and reproducible. Experiments cover enterprise IDS and encrypted DNS/DoH traffic using CICIDS2017, UNSW-NB15, and DoH-Combined at three label granularities (L1/L2/L3), for both binary detection (y) and finer-grained targets ((Formula presented.)), aggregated over five fixed split seeds with 95% confidence intervals. Results show that GCP yields a pronounced in-domain advantage on UNSW-NB15 for y (Macro-F1 (Formula presented.)) while substantially reducing false-alarm rate (FAR (Formula presented.)) compared with strong tabular baselines. In feature-separable regimes (CICIDS2017 and DoH L1/L2), boosted-tree and supervised baselines remain difficult to surpass, but ablations confirm that graph structure alone is insufficient without contrastive pretraining. OOD transfer is strongly source–target dependent, with the most reliable transfer within closely related DoH domains, highlighting dataset shift as a first-class evaluation criterion for encrypted-traffic IDS.
| Translated title of the contribution | Preentrenamiento contrastivo basado en grafos para detección de intrusiones en tráfico cifrado sin cargas útiles: transferencia OOD entre conjuntos de datos con artefactos congelados |
|---|---|
| Original language | English |
| Article number | 389 |
| Pages (from-to) | 1-22 |
| Number of pages | 22 |
| Journal | Algorithms |
| Volume | 19 |
| Issue number | 5 |
| DOIs | |
| Publication status | Published - May 2026 |
Bibliographical note
Publisher Copyright:© 2026 by the authors.
Fingerprint
Dive into the research topics of 'Graph-Contrastive Pretraining for Payload-Free Encrypted-Traffic Intrusion Detection: Cross-Dataset OOD Transfer with Frozen Artifacts'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver