Cerasuolo, Francesco (2025) Continuous and Adaptive Learning for Network Traffic Analysis in the New Internet Era. [Tesi di dottorato]

[thumbnail of _PhD_Thesis__Francesco_Cerasuolo.pdf] Documento PDF
_PhD_Thesis__Francesco_Cerasuolo.pdf
Visibile a [TBR] Amministratori dell'archivio

Download (8MB) | Richiedi una copia
Tipologia del documento: Tesi di dottorato
Lingua: English
Titolo: Continuous and Adaptive Learning for Network Traffic Analysis in the New Internet Era
Autori:
Autore
Email
Cerasuolo, Francesco
francesco.cerasuolo@unina.it
Data: 10 Dicembre 2025
Numero di pagine: 196
Istituzione: Università degli Studi di Napoli Federico II
Dipartimento: Ingegneria Elettrica e delle Tecnologie dell'Informazione
Dottorato: Ingegneria informatica ed automatica
Ciclo di dottorato: 38
Coordinatore del Corso di dottorato:
nome
email
Russo, Stefano
stefano.russo@unina.it
Tutor:
nome
email
Pescapè, Antonio
[non definito]
Data: 10 Dicembre 2025
Numero di pagine: 196
Parole chiave: Network Traffic Classification, Incremental Learning, Federated Learning, Explainable AI, Network Intrusion Detection System
Settori scientifico-disciplinari del MIUR: Area 09 - Ingegneria industriale e dell'informazione > ING-INF/05 - Sistemi di elaborazione delle informazioni
Informazioni aggiuntive: 38 ciclo del dottorato ITEE
Depositato il: 10 Dic 2025 22:28
Ultima modifica: 12 Ago 2026 05:37
URI: https://www.fedoa.unina.it/id/eprint/15959

Abstract

In recent years, managing networks has become an increasingly critical task, mainly due to the continuous growth and evolution of network traffic. This dynamic scenario poses challenges in identifying what is flowing through the network, affecting traditional approaches—i.e., port-based, Deep Packet Inspection (DPI)—and the more recent Machine Learning (ML) and Deep Learning (DL) ones. Notably, the latter struggle when facing unseen traffic patterns, lack of transparency, and rely on a huge amount of data, whose sharing raises privacy concerns. This thesis focuses on the network traffic classification, considering two valuable domains: mobile network traffic and network attack traffic. To this aim, it introduces MEMENTO, a novel Class Incremental Learning (CIL) approach, to design (i) incremental Traffic Classifier (TC), capable of identifying new applications retaining knowledge of already known ones—differing from the ideal training-from-scratch for < 2% F1 Score in singleincrements; (ii) adaptive Network Intrusion Detection System (NIDS), able to detect zero-day attacks while preserving knowledge of known attacks and legitimate traffic—obtaining up to 95% F1 Score. In addition, this thesis leverages CIL approaches to facilitate the deployment and adaptation of traffic classifiers across different network environments, allowing models to adjust to known traffic types while accommodating new ones. Furthermore, to enable collaborative and privacy-preserving classification process, we bridge the gap between CIL and Federated Learning (FL), devising a Federated Class Incremental Learning (FCIL) procedure for MEMENTO—reaching 89% F1 Score at most in classifying attacks. Finally, to address the limitations in transparency of DL solutions, this thesis investigates the results of MEMENTO through eXplainable AI (XAI) techniques.

Downloads

Downloads per month over past year

Actions (login required)

Modifica documento Modifica documento