Pith. sign in

REVIEW 3 cited by

TrafficLLM: Enhancing Large Language Models for Network Traffic Analysis with Generic Traffic Representation

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2504.04222 v2 pith:JVM6B76Z submitted 2025-04-05 cs.LG cs.AIcs.CR

classification cs.LGcs.AIcs.CR
keywords traffictrafficllmanalysisdetectiongeneralizationperformanceacrossnetwork
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Machine learning (ML) powered network traffic analysis has been widely used for the purpose of threat detection. Unfortunately, their generalization across different tasks and unseen data is very limited. Large language models (LLMs), known for their strong generalization capabilities, have shown promising performance in various domains. However, their application to the traffic analysis domain is limited due to significantly different characteristics of network traffic. To address the issue, in this paper, we propose TrafficLLM, which introduces a dual-stage fine-tuning framework to learn generic traffic representation from heterogeneous raw traffic data. The framework uses traffic-domain tokenization, dual-stage tuning pipeline, and extensible adaptation to help LLM release generalization ability on dynamic traffic analysis tasks, such that it enables traffic detection and traffic generation across a wide range of downstream tasks. We evaluate TrafficLLM across 10 distinct scenarios and 229 types of traffic. TrafficLLM achieves F1-scores of 0.9875 and 0.9483, with up to 80.12% and 33.92% better performance than existing detection and generation methods. It also shows strong generalization on unseen traffic with an 18.6% performance improvement. We further evaluate TrafficLLM in real-world scenarios. The results confirm that TrafficLLM is easy to scale and achieves accurate detection performance on enterprise traffic.

Discussion (0). Sign in to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. X-PRINT:Platform-Agnostic and Scalable Fine-Grained Encrypted Traffic Fingerprinting

    cs.CR 2025-08 conditional novelty 6.0 of 10

    X-PRINT shows that backend URI invocation sequences, inferred from encrypted traffic side channels, can serve as platform-agnostic fingerprints for fine-grained app behavior identification.

  2. TeleMath: A Benchmark for Large Language Models in Telecom Mathematical Problem Solving

    cs.AI 2025-06 conditional novelty 6.0 of 10

    TeleMath introduces 500 numerical telecom math problems and shows reasoning-optimized LLMs outperform larger general-purpose models on them.

  3. Identifying the Threshold Chain Length for Stress Overshoot in Ring-Linear Polymer Blends under Uniaxial Elongation: The Role of Multiple Threading

    cond-mat.soft 2026-03 unverdicted novelty 5.0 of 10

    In 1:1 ring-linear blends, stress overshoot under uniaxial elongation appears only above a threading threshold Z≈4, driven by multiple linear chains piercing each ring.

Pith tools