Contrastive Sequence Learning for DoH Tunnel Detection and Fine-Grained Traffic Classification

DNS over HTTPS (DoH) protects name-resolution traffic but can also conceal command-and-control and data-exfiltration channels. Detection is challenging because benign and malicious flows share similar statistics, packet relationships span long sequences, and labeled malicious examples are scarce. We present the Contrastive Learning–Transformer–Bidirectional Gated Recurrent Unit–Attention model (CL–TBiGRU–Attention). The model combines contrastive pretraining with global and bidirectional temporal modeling. We evaluate binary DoH/non-DoH detection, tunneling-tool classification on two datasets, and malware-family classification. Across these four tasks, accuracy ranges from 94.91% to 99.98%, and the F1-score ranges from 95.02% to 99.98%. The model outperforms the listed neural baselines in binary detection and all listed methods in the three fine-grained tasks. On malware-family classification, it reaches 97.00% accuracy and 97.01% F1-score, with most residual confusion occurring between Sisron and Zloader. These results show the value of contrastive sequence modeling for coarse- and fine-grained DoH traffic analysis on the evaluated benchmarks.

Authors

Institutions

Publication Details

Journal
Computers
Published
2026-09-14
DOI
https://doi.org/10.3390/computers15090617
Primary Topic
Internet Traffic Analysis and Secure E-voting
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Contrastive Sequence Learning for DoH Tunnel Detection and Fine-Grained Traffic Classification

Jun Yin, Peng Zhang, Yanlei Liu, Yi Gu et al.
Computers
Internet Traffic Analysis and Secure E-voting
article

Contrastive Sequence Learning for DoH Tunnel Detection and Fine-Grained Traffic Classification

Jun Yin, Peng Zhang, Yanlei Liu, Yi Gu, Tongjie Wei, Peng Wang
article en

Abstract

DNS over HTTPS (DoH) protects name-resolution traffic but can also conceal command-and-control and data-exfiltration channels. Detection is challenging because benign and malicious flows share similar statistics, packet relationships span long sequences, and labeled malicious examples are scarce. We present the Contrastive Learning–Transformer–Bidirectional Gated Recurrent Unit–Attention model (CL–TBiGRU–Attention). The model combines contrastive pretraining with global and bidirectional temporal modeling. We evaluate binary DoH/non-DoH detection, tunneling-tool classification on two datasets, and malware-family classification. Across these four tasks, accuracy ranges from 94.91% to 99.98%, and the F1-score ranges from 95.02% to 99.98%. The model outperforms the listed neural baselines in binary detection and all listed methods in the three fine-grained tasks. On malware-family classification, it reaches 97.00% accuracy and 97.01% F1-score, with most residual confusion occurring between Sisron and Zloader. These results show the value of contrastive sequence modeling for coarse- and fine-grained DoH traffic analysis on the evaluated benchmarks.

ComputersVol. 15(9)
Nanjing University of Science and Technology (CN), Inner Mongolia Electric Power (China) (CN)
Peace, Justice and strong institutions
Openalex Percentile: Top 8%
Internet Traffic Analysis and Secure E-voting
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Contrastive Sequence Learning for DoH Tunnel Detection and Fine-Grained Traffic Classification — Jun Yin, Peng Zhang, et al. · Computers (2026) | TGRS Research Map | TGRS