{"title":"Enhancing encrypted HTTPS traffic classification based on stacked deep ensembles models.","authors":"Ahmed M Elshewey, Ahmed M Osman","doi":"10.1038/s41598-025-21261-6","DOIUrl":null,"url":null,"abstract":"<p><p>The classification of encrypted HTTPS traffic is a critical task for network management and security, where traditional port or payload-based methods are ineffective due to encryption and evolving traffic patterns. This study addresses the challenge using the public Kaggle dataset (145,671 flows, 88 features, six traffic categories: Download, Live Video, Music, Player, Upload, Website). An automated preprocessing pipeline is developed to detect the label column, normalize classes, perform a stratified 70/15/15 split into training, validation, and testing sets, and apply imbalance-aware weighting. Multiple deep learning architectures are benchmarked, including DNN, CNN, RNN, LSTM, and GRU, capturing different spatial and temporal patterns of traffic features. Experimental results show that CNN achieved the strongest single-model performance (Accuracy 0.9934, F1_macro 0.9912, ROC-AUC_macro 0.9999). To further improve robustness, a stacked ensemble meta-learner based on multinomial logistic regression was trained on model outputs, achieving state-of-the-art performance with Accuracy 0.9949, Precision_macro 0.9923, Recall_macro 0.9941, F1_macro 0.9932, and ROC-AUC_macro 0.9998. The framework also outputs confusion matrices, ROC curves, and learning curves for interpretability. To ensure reproducibility and practical use, the full codebase is publicly available on GitHub, providing researchers and practitioners with a deployment-ready pipeline for encrypted traffic analytics where ensemble learning surpasses individual models.</p>","PeriodicalId":21811,"journal":{"name":"Scientific Reports","volume":"15 1","pages":"35230"},"PeriodicalIF":3.9000,"publicationDate":"2025-10-09","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Scientific Reports","FirstCategoryId":"103","ListUrlMain":"https://doi.org/10.1038/s41598-025-21261-6","RegionNum":2,"RegionCategory":"综合性期刊","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"MULTIDISCIPLINARY SCIENCES","Score":null,"Total":0}
引用次数: 0
Abstract
The classification of encrypted HTTPS traffic is a critical task for network management and security, where traditional port or payload-based methods are ineffective due to encryption and evolving traffic patterns. This study addresses the challenge using the public Kaggle dataset (145,671 flows, 88 features, six traffic categories: Download, Live Video, Music, Player, Upload, Website). An automated preprocessing pipeline is developed to detect the label column, normalize classes, perform a stratified 70/15/15 split into training, validation, and testing sets, and apply imbalance-aware weighting. Multiple deep learning architectures are benchmarked, including DNN, CNN, RNN, LSTM, and GRU, capturing different spatial and temporal patterns of traffic features. Experimental results show that CNN achieved the strongest single-model performance (Accuracy 0.9934, F1_macro 0.9912, ROC-AUC_macro 0.9999). To further improve robustness, a stacked ensemble meta-learner based on multinomial logistic regression was trained on model outputs, achieving state-of-the-art performance with Accuracy 0.9949, Precision_macro 0.9923, Recall_macro 0.9941, F1_macro 0.9932, and ROC-AUC_macro 0.9998. The framework also outputs confusion matrices, ROC curves, and learning curves for interpretability. To ensure reproducibility and practical use, the full codebase is publicly available on GitHub, providing researchers and practitioners with a deployment-ready pipeline for encrypted traffic analytics where ensemble learning surpasses individual models.
期刊介绍:
We publish original research from all areas of the natural sciences, psychology, medicine and engineering. You can learn more about what we publish by browsing our specific scientific subject areas below or explore Scientific Reports by browsing all articles and collections.
Scientific Reports has a 2-year impact factor: 4.380 (2021), and is the 6th most-cited journal in the world, with more than 540,000 citations in 2020 (Clarivate Analytics, 2021).
•Engineering
Engineering covers all aspects of engineering, technology, and applied science. It plays a crucial role in the development of technologies to address some of the world''s biggest challenges, helping to save lives and improve the way we live.
•Physical sciences
Physical sciences are those academic disciplines that aim to uncover the underlying laws of nature — often written in the language of mathematics. It is a collective term for areas of study including astronomy, chemistry, materials science and physics.
•Earth and environmental sciences
Earth and environmental sciences cover all aspects of Earth and planetary science and broadly encompass solid Earth processes, surface and atmospheric dynamics, Earth system history, climate and climate change, marine and freshwater systems, and ecology. It also considers the interactions between humans and these systems.
•Biological sciences
Biological sciences encompass all the divisions of natural sciences examining various aspects of vital processes. The concept includes anatomy, physiology, cell biology, biochemistry and biophysics, and covers all organisms from microorganisms, animals to plants.
•Health sciences
The health sciences study health, disease and healthcare. This field of study aims to develop knowledge, interventions and technology for use in healthcare to improve the treatment of patients.