MTC-Kansformer: Malware Traffic Classification by Kansformer with Self-Superivised Learning

Haohua Wang, Maode Ma, Hui Wang, Yufeng Zhou, Chenjun He, Yingjuan Shi · 2025

Malware Traffic Classification (MTC) is a key area of research in cybersecurity. Accurate and efficient classification is vital for defending against malware. Many methods use supervised learning, especially Convolutional Neural Networks (CNNs), to train feature extractors. However, obtaining a large number of labeled samples is costly, and relying solely on CNNs may limit the local receptive fields, compromising the retention of key features. Additionally, existing Transformer backbone networks have quadratic computational complexity. This paper proposes the MTC-Kansformer, a traffic classification model that addresses these issues and improves classification accuracy and efficiency. The model integrates a self-supervised learning framework with a Kansformer. The Kansformer encoder replaces the traditional Multi-Layer Perceptron (MLP) layer with fasterKAN, enhancing the representation and interpretability of nonlinear features. Initially, the raw traffic is converted into gray images. Then, the Kansformer self-supervised model is used to extract key features from randomly masked images, and the prediction module is employed to predict the masked images. Finally, the encoder is finetuned using a downstream malware dataset to perform effective malware traffic classification tasks. Experimental results show that the MTC-Kansformer outperforms existing models, achieving a classification accuracy of$\mathbf{9 8. 7 8 \%}$on the USTC-TFC2016 dataset, surpassing existing models.

Read the paper · More papers on PaperTik