Cerasuolo, Francesco (2025) Continuous and Adaptive Learning for Network Traffic Analysis in the New Internet Era. [Tesi di dottorato]
|
Documento PDF
_PhD_Thesis__Francesco_Cerasuolo.pdf Visibile a [TBR] Amministratori dell'archivio Download (8MB) | Richiedi una copia |
| Tipologia del documento: | Tesi di dottorato |
|---|---|
| Lingua: | English |
| Titolo: | Continuous and Adaptive Learning for Network Traffic Analysis in the New Internet Era |
| Autori: | Autore Email Cerasuolo, Francesco francesco.cerasuolo@unina.it |
| Data: | 10 Dicembre 2025 |
| Numero di pagine: | 196 |
| Istituzione: | Università degli Studi di Napoli Federico II |
| Dipartimento: | Ingegneria Elettrica e delle Tecnologie dell'Informazione |
| Dottorato: | Ingegneria informatica ed automatica |
| Ciclo di dottorato: | 38 |
| Coordinatore del Corso di dottorato: | nome email Russo, Stefano stefano.russo@unina.it |
| Tutor: | nome email Pescapè, Antonio [non definito] |
| Data: | 10 Dicembre 2025 |
| Numero di pagine: | 196 |
| Parole chiave: | Network Traffic Classification, Incremental Learning, Federated Learning, Explainable AI, Network Intrusion Detection System |
| Settori scientifico-disciplinari del MIUR: | Area 09 - Ingegneria industriale e dell'informazione > ING-INF/05 - Sistemi di elaborazione delle informazioni |
| Informazioni aggiuntive: | 38 ciclo del dottorato ITEE |
| Depositato il: | 10 Dic 2025 22:28 |
| Ultima modifica: | 12 Ago 2026 05:37 |
| URI: | https://www.fedoa.unina.it/id/eprint/15959 |
Abstract
In recent years, managing networks has become an increasingly critical task, mainly due to the continuous growth and evolution of network traffic. This dynamic scenario poses challenges in identifying what is flowing through the network, affecting traditional approaches—i.e., port-based, Deep Packet Inspection (DPI)—and the more recent Machine Learning (ML) and Deep Learning (DL) ones. Notably, the latter struggle when facing unseen traffic patterns, lack of transparency, and rely on a huge amount of data, whose sharing raises privacy concerns. This thesis focuses on the network traffic classification, considering two valuable domains: mobile network traffic and network attack traffic. To this aim, it introduces MEMENTO, a novel Class Incremental Learning (CIL) approach, to design (i) incremental Traffic Classifier (TC), capable of identifying new applications retaining knowledge of already known ones—differing from the ideal training-from-scratch for < 2% F1 Score in singleincrements; (ii) adaptive Network Intrusion Detection System (NIDS), able to detect zero-day attacks while preserving knowledge of known attacks and legitimate traffic—obtaining up to 95% F1 Score. In addition, this thesis leverages CIL approaches to facilitate the deployment and adaptation of traffic classifiers across different network environments, allowing models to adjust to known traffic types while accommodating new ones. Furthermore, to enable collaborative and privacy-preserving classification process, we bridge the gap between CIL and Federated Learning (FL), devising a Federated Class Incremental Learning (FCIL) procedure for MEMENTO—reaching 89% F1 Score at most in classifying attacks. Finally, to address the limitations in transparency of DL solutions, this thesis investigates the results of MEMENTO through eXplainable AI (XAI) techniques.
Downloads
Downloads per month over past year
Actions (login required)
![]() |
Modifica documento |


