Open-World Darknet Traffic Recognition Under Leave-One-Service-Out Evaluation
arXiv SecurityArchived Aug 06, 2026✓ Full text saved
arXiv:2608.04167v1 Announce Type: new Abstract: Darknet traffic recognition is critical for cyber threat intelligence, as anonymity networks are often used to conceal malicious activity. However, most existing studies rely on closed-world evaluation, assuming all service categories are known during training and testing, which is unrealistic in real-world environments. This paper presents an open-world darknet traffic classification framework using leave-one-service-out evaluation and uncertainty
Full text archived locally
✦ AI Summary· Claude Sonnet
Computer Science > Cryptography and Security
[Submitted on 4 Aug 2026]
Open-World Darknet Traffic Recognition Under Leave-One-Service-Out Evaluation
Javeriah Saleem, Rafiqul Islam, Md Zahidul Islam
Darknet traffic recognition is critical for cyber threat intelligence, as anonymity networks are often used to conceal malicious activity. However, most existing studies rely on closed-world evaluation, assuming all service categories are known during training and testing, which is unrealistic in real-world environments. This paper presents an open-world darknet traffic classification framework using leave-one-service-out evaluation and uncertainty-aware classification with Random Forest and XGBoost models. Experimental results demonstrate significant performance degradation when transitioning from closed-world to open-world settings, demonstrating that closed-world evaluation substantially overestimates deployment robustness. For example, XGBoost Macro-F1 decreases from 88.8% to 46.1% in the I2P environment, while Random Forest performance drops from 87.4% to 45.7%. Although uncertainty-based rejection slightly improves robustness, strong behavioral similarity between known and unknown services leads to frequent misclassification. Semantic absorption analysis further shows that FreeNet video traffic is classified as browsing traffic with an 88.1% assignment rate, while I2P peer-to-peer traffic is absorbed into FTP-related behavior with an 83.4% assignment rate. The findings demonstrate that behavioral overlap remains a major challenge for reliable open-world darknet traffic classification.
Subjects: Cryptography and Security (cs.CR)
Cite as: arXiv:2608.04167 [cs.CR]
(or arXiv:2608.04167v1 [cs.CR] for this version)
https://doi.org/10.48550/arXiv.2608.04167
Focus to learn more
Submission history
From: Javeriah Saleem Miss [view email]
[v1] Tue, 4 Aug 2026 19:24:24 UTC (820 KB)
Access Paper:
view license
Current browse context:
cs.CR
< prev | next >
new | recent | 2026-08
Change to browse by:
cs
References & Citations
NASA ADS
Google Scholar
Semantic Scholar
Export BibTeX Citation
Bookmark
Bibliographic Tools
Bibliographic and Citation Tools
Bibliographic Explorer Toggle
Bibliographic Explorer (What is the Explorer?)
Connected Papers Toggle
Connected Papers (What is Connected Papers?)
Litmaps Toggle
Litmaps (What is Litmaps?)
scite.ai Toggle
scite Smart Citations (What are Smart Citations?)
Code, Data, Media
Demos
Related Papers
About arXivLabs
Which authors of this paper are endorsers? | Disable MathJax (What is MathJax?)