IoT-TSO: An Unsupervised Method for Classifying Malicious IoT Traffic via Tensor Self-Optimization
Fengyuan Nie, Weiwei Liu, Guangjie Liu, Bo Gao, Jianan Huang, Chau Yuen · IEEE Transactions on Network Science and Engineering · 2025
Machine learning-based network traffic classification is crucial for ensuring communication security in Internet of Things (IoT), particularly with unsupervised methods. This approach is valued for its low dependency on manually labeled samples, which is beneficial in scenarios where collecting sufficiently diverse malicious traffic samples is challenging. However, most existing unsupervised methods heavily rely on expert knowledge to extract shallow traffic features for constructing representations, limiting the effective utilization of deep features associated with malicious traffic. Moreover, incomplete traffic data resulting from various efficient but unreliable network transmission protocols in IoT scenarios significantly impact traffic classification performance. In this paper, we propose an unsupervised method for classifying malicious IoT traffic using tensor self-optimization (IoT-TSO). First, packet-wise representations are extracted and constructed into a high-order traffic tensor. Then, tensor singular value decomposition (t-SVD) is employed to achieve tensor self-completion optimization (SCO) and self-expressive optimization (SEO) strategies, transforming the traffic tensor into an optimized form for clustering. SCO leverages the spatio-temporal correlations among packets to recover missing packet representations, while SEO explores the intrinsic relationships between different traffic flows to further enhance classification performance. Typical IoT traffic datasets are used to benchmark the proposed method, with experimental results demonstrating its superior performance over state-of-the-art unsupervised approaches.