CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◬ AI & Machine Learning Aug 06, 2026

Open-World Darknet Traffic Recognition Under Leave-One-Service-Out Evaluation

arXiv Security Archived Aug 06, 2026 ✓ Full text saved

arXiv:2608.04167v1 Announce Type: new Abstract: Darknet traffic recognition is critical for cyber threat intelligence, as anonymity networks are often used to conceal malicious activity. However, most existing studies rely on closed-world evaluation, assuming all service categories are known during training and testing, which is unrealistic in real-world environments. This paper presents an open-world darknet traffic classification framework using leave-one-service-out evaluation and uncertainty

Full text archived locally
✦ AI Summary · Claude Sonnet


    Computer Science > Cryptography and Security [Submitted on 4 Aug 2026] Open-World Darknet Traffic Recognition Under Leave-One-Service-Out Evaluation Javeriah Saleem, Rafiqul Islam, Md Zahidul Islam Darknet traffic recognition is critical for cyber threat intelligence, as anonymity networks are often used to conceal malicious activity. However, most existing studies rely on closed-world evaluation, assuming all service categories are known during training and testing, which is unrealistic in real-world environments. This paper presents an open-world darknet traffic classification framework using leave-one-service-out evaluation and uncertainty-aware classification with Random Forest and XGBoost models. Experimental results demonstrate significant performance degradation when transitioning from closed-world to open-world settings, demonstrating that closed-world evaluation substantially overestimates deployment robustness. For example, XGBoost Macro-F1 decreases from 88.8% to 46.1% in the I2P environment, while Random Forest performance drops from 87.4% to 45.7%. Although uncertainty-based rejection slightly improves robustness, strong behavioral similarity between known and unknown services leads to frequent misclassification. Semantic absorption analysis further shows that FreeNet video traffic is classified as browsing traffic with an 88.1% assignment rate, while I2P peer-to-peer traffic is absorbed into FTP-related behavior with an 83.4% assignment rate. The findings demonstrate that behavioral overlap remains a major challenge for reliable open-world darknet traffic classification. Subjects: Cryptography and Security (cs.CR) Cite as: arXiv:2608.04167 [cs.CR]   (or arXiv:2608.04167v1 [cs.CR] for this version)   https://doi.org/10.48550/arXiv.2608.04167 Focus to learn more Submission history From: Javeriah Saleem Miss [view email] [v1] Tue, 4 Aug 2026 19:24:24 UTC (820 KB) Access Paper: view license Current browse context: cs.CR < prev   |   next > new | recent | 2026-08 Change to browse by: cs References & Citations NASA ADS Google Scholar Semantic Scholar Export BibTeX Citation Bookmark Bibliographic Tools Bibliographic and Citation Tools Bibliographic Explorer Toggle Bibliographic Explorer (What is the Explorer?) Connected Papers Toggle Connected Papers (What is Connected Papers?) Litmaps Toggle Litmaps (What is Litmaps?) scite.ai Toggle scite Smart Citations (What are Smart Citations?) Code, Data, Media Demos Related Papers About arXivLabs Which authors of this paper are endorsers? | Disable MathJax (What is MathJax?)
    💬 Team Notes
    Article Info
    Source
    arXiv Security
    Category
    ◬ AI & Machine Learning
    Published
    Aug 06, 2026
    Archived
    Aug 06, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗