[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-117820-en":3,"doc-seo-117820-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},117820,549758146520,"Patrick","https://ap-avatar.wpscdn.com/avatar/80002397d8c0411e94?_k=1775819394049821470",8,"Research & Report","Darknet traffic classification and adversarial attacks using machine learning","The anonymous nature of darknets enables illegal activities, motivating automated detection of darknet traffic using machine learning and deep learning. This research improves darknet traffic detection by evaluating a broad set of ML/DL methods for both traffic classification and underlying application-type classification. Using the CIC-Darknet2020 dataset (Tor and VPN, plus clearnet sessions), results show a Random Forest model outperforms prior state-of-the-art approaches. Robustness is tested via adversarial obfuscation of application classes, demonstrating degradations and discussing defenses.","San Jose State University  \nSJSU ScholarWorks  \nFaculty Research, Scholarly, and Creative Activity  \n4-1-2023  \nDarknet traffic classification and adversarial attacks using machine learning  \nNhien Rust-Nguyen  \nSan Jose State University  \nShruti Sharma  \nSan Jose State University  \nMark Stamp  \nSan Jose State University, [mark.stamp@sjsu.edu](mark.stamp@sjsu.edu)  \nFollow this and additional works at: [https://scholarworks.sjsu.edu/faculty_rsca](https://scholarworks.sjsu.edu/faculty_rsca)  \nRecommended Citation  \nNhien Rust-Nguyen, Shruti Sharma, and Mark Stamp. \"Darknet traffic classification and adversarial attacks using machine learning\" Computers and Security (2023) . [https://doi.org/10.1016/](https://doi.org/10.1016/)  \nj.cose.2023.103098  \nThis Article is brought to you for free and open access by SJSU ScholarWorks. It has been accepted for inclusion in Faculty Research, Scholarly, and Creative Activity by an authorized administrator of SJSU ScholarWorks. For more information, please contact [scholarworks@sjsu.edu](scholarworks@sjsu.edu).  \nComputers & Security 127 (2023) 103098  \nContents lists available at ScienceDirect  \nComputers & Security  \njournal [homepage: www.elsevier.com/locate/cose](homepage: www.elsevier.com/locate/cose)  \n| Darknet traﬃc classiﬁcation and adversarial attacks using machine\u003Cbr>learning\u003Cbr>Nhien Rust-Nguyen, Shruti Sharma, Mark Stamp∗ Department of Computer Science, San Jose State University, United States |  |  |\n| --- | --- | --- |\n| a r t i c l e i n f o | a b s t r a c t\u003Cbr>The anonymous nature of darknets is commonly exploited for illegal activities. Previous research has employed machine learning and deep learning techniques to automate the detection of darknet traﬃc in an attempt to block these criminal activities. This research aims to improve darknet traﬃc detection by assessing a wide variety of machine learning and deep learning techniques for the classiﬁcation of such trafﬁc and for classiﬁcation of the underlying application types. We ﬁnd that a Random Forest model outperforms other state-of-the-art machine learning techniques used in prior work with the CIC-Darknet2020 dataset. To evaluate the robustness of our Random Forest classiﬁer, we obfuscate select application type classes to simulate realistic adversarial attack scenarios. We demonstrate that our best-performing classiﬁer can be degraded by such attacks, and we consider ways to effectively deal with such adversarial attacks.\u003Cbr>© 2023 The Author(s). Published by Elsevier Ltd.\u003Cbr>This is an open access article under the CC BY license ([http://creativecommons.org/licenses/by/4.0/](http://creativecommons.org/licenses/by/4.0/)) |  |\n| Article history:\u003Cbr>Received 12 June 2022\u003Cbr>Revised 22 October 2022\u003Cbr>Accepted 9 January 2023\u003Cbr>Available online 14 January 2023 |  |  |\n| Keywords:\u003Cbr>Darknet\u003Cbr>Classiﬁcation\u003Cbr>Adversarial attacks\u003Cbr>Convolutional neural network Auxiliary-Classiﬁer generative adversarial network\u003Cbr>Random forest |  |  |\n\n1. Introduction  \nMost of us are familiar with the Internet and the World Wide Web (WWW, or web). We regularly access both using web browsers or other networked applications to share information publicly, guided by search engine indexing of the Domain Name System (DNS) over globally bridged Internet Protocol (IP) networks. This publicly accessible and indexed address space is known asthe surface web or clearnet. In contrast, the WWW address space which is not indexed by search engines but still publicly accessible is known as the deep web. Private networks within the deep web or networks comprised of unallocated address space are known as darknets and collectively termed the dark web. Fig. 1 illustrates the relationship between these layers of the Internet.  \nThe dark web is reached by an overlay network requiring special software, user authorization, or non-standard communication protocols (Demertzis et al. ). Many darknets afford users anonymity during communication and thus facilitate","cbCailp8DAo1KlDe","https://ap.wps.com/l/cbCailp8DAo1KlDe","pdf",2685991,1,17,"English","en",105,"# Introduction\n## Dark web and darknet background\n## CIC-Darknet2020 dataset and research goal\n## Machine learning and deep learning approaches\n## Data augmentation for class imbalance\n# Adversarial robustness evaluation","[{\"question\":\"What problem does the research address in darknet monitoring?\",\"answer\":\"It targets automated classification of darknet traffic and the underlying application types to help identify and inhibit criminal activities enabled by darknet anonymity.\"},{\"question\":\"Which model performs best for traffic and application-type classification?\",\"answer\":\"The Random Forest model outperforms other state-of-the-art machine learning techniques evaluated on the CIC-Darknet2020 dataset.\"},{\"question\":\"How is robustness to adversarial attacks evaluated?\",\"answer\":\"The approach obfuscates select application type classes to simulate realistic adversarial attack scenarios and measures how the best classifier degrades under those manipulations.\"}]","Darknet traffic classification and adversarial attacks using machine learning | PDF",1785679774,43,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"darknet-traffic-classification-and-adversarial-attacks-using-machine-learning","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/darknet-traffic-classification-and-adversarial-attacks-using-machine-learning/117820/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-02",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does the research address in darknet monitoring?","Question",{"text":75,"@type":76},"It targets automated classification of darknet traffic and the underlying application types to help identify and inhibit criminal activities enabled by darknet anonymity.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"Which model performs best for traffic and application-type classification?",{"text":80,"@type":76},"The Random Forest model outperforms other state-of-the-art machine learning techniques evaluated on the CIC-Darknet2020 dataset.",{"name":82,"@type":73,"acceptedAnswer":83},"How is robustness to adversarial attacks evaluated?",{"text":84,"@type":76},"The approach obfuscates select application type classes to simulate realistic adversarial attack scenarios and measures how the best classifier degrades under those manipulations.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]