Cerasuolo, Francesco (2025) Continuous and Adaptive Learning for Network Traffic Analysis in the New Internet Era. [Tesi di dottorato]

[thumbnail of _PhD_Thesis__Francesco_Cerasuolo.pdf] Documento PDF
_PhD_Thesis__Francesco_Cerasuolo.pdf

Download (8MB)
Item Type: Tesi di dottorato
Resource language: English
Title: Continuous and Adaptive Learning for Network Traffic Analysis in the New Internet Era
Creators:
Creators
Email
Cerasuolo, Francesco
francesco.cerasuolo@unina.it
Date: 10 December 2025
Number of Pages: 196
Institution: Università degli Studi di Napoli Federico II
Department: Ingegneria Elettrica e delle Tecnologie dell'Informazione
Dottorato: Ingegneria informatica ed automatica
Ciclo di dottorato: 38
Coordinatore del Corso di dottorato:
nome
email
Russo, Stefano
stefano.russo@unina.it
Tutor:
nome
email
Pescapè, Antonio
UNSPECIFIED
Date: 10 December 2025
Number of Pages: 196
Keywords: Network Traffic Classification, Incremental Learning, Federated Learning, Explainable AI, Network Intrusion Detection System
Settori scientifico-disciplinari del MIUR: Area 09 - Ingegneria industriale e dell'informazione > ING-INF/05 - Sistemi di elaborazione delle informazioni
Additional information: 38 ciclo del dottorato ITEE
Date Deposited: 10 Dec 2025 22:28
Last Modified: 02 Sep 2026 08:04
URI: https://www.fedoa.unina.it/id/eprint/15959

Collection description

In recent years, managing networks has become an increasingly critical task, mainly due to the continuous growth and evolution of network traffic. This dynamic scenario poses challenges in identifying what is flowing through the network, affecting traditional approaches—i.e., port-based, Deep Packet Inspection (DPI)—and the more recent Machine Learning (ML) and Deep Learning (DL) ones. Notably, the latter struggle when facing unseen traffic patterns, lack of transparency, and rely on a huge amount of data, whose sharing raises privacy concerns. This thesis focuses on the network traffic classification, considering two valuable domains: mobile network traffic and network attack traffic. To this aim, it introduces MEMENTO, a novel Class Incremental Learning (CIL) approach, to design (i) incremental Traffic Classifier (TC), capable of identifying new applications retaining knowledge of already known ones—differing from the ideal training-from-scratch for < 2% F1 Score in singleincrements; (ii) adaptive Network Intrusion Detection System (NIDS), able to detect zero-day attacks while preserving knowledge of known attacks and legitimate traffic—obtaining up to 95% F1 Score. In addition, this thesis leverages CIL approaches to facilitate the deployment and adaptation of traffic classifiers across different network environments, allowing models to adjust to known traffic types while accommodating new ones. Furthermore, to enable collaborative and privacy-preserving classification process, we bridge the gap between CIL and Federated Learning (FL), devising a Federated Class Incremental Learning (FCIL) procedure for MEMENTO—reaching 89% F1 Score at most in classifying attacks. Finally, to address the limitations in transparency of DL solutions, this thesis investigates the results of MEMENTO through eXplainable AI (XAI) techniques.

Downloads

Downloads per month over past year

Actions (login required)

View Item View Item