BGA: Neural Distillation Framework for Malicious Signature Extraction in Encrypted Flows
A new research paper on arXiv (ID: 2608.14126) proposes BGA, a noise-immune neural distillation framework designed to extract malicious signatures from high-entropy encrypted network flows, specifically targeting TLS 1.3 traffic. The framework addresses the challenge of attention dilution in such flows by using Analysis of Variance (ANOVA) to separate high-discriminatory control-plane features, such as industrial setpoints, from stochastic cryptographic noise. To tackle extreme class imbalance in a dataset of 86,878 flow records, the method integrates a Wasserstein GAN with Gradient Penalty (WGAN-GP) to synthesize high-fidelity minority samples, improving detection recall for rare Malicious State Command Injections (MSCI) attacks by 43.2%. The core architecture combines Bidirectional Long Short-Term Memory (BiLSTM) networks for temporal dependency extraction with an Adaptive Gated Multi-Head Attention mechanism, which acts as a neural filter to dynamically suppress encryption artifacts. The paper is categorized as a cross-announcement and is available at the provided arXiv URL.
Key facts
- BGA is a noise-immune neural distillation framework for encrypted threat intelligence.
- It targets high-entropy TLS 1.3 flows.
- Uses ANOVA to decouple control-plane features from cryptographic noise.
- Integrates WGAN-GP to handle class imbalance in 86,878 flow records.
- Improves detection recall of MSCI attacks by 43.2%.
- Core architecture includes BiLSTM and Adaptive Gated Multi-Head Attention.
- Paper ID: arXiv:2608.14126v1.
- Announcement type: cross.
Entities
Institutions
- arXiv