TrafficT5: Multi-stage self-correcting framework for traffic generation
Yizhao Huang, Xiaohui Li, Jiaxuan Geng, Xiaolan Zhu · Computer Networks · 2025
The generation of high-fidelity, controllable malicious network traffic is essential for simulating realistic cyberattacks, evaluating defense mechanisms, and enhancing intrusion detection systems (IDS). However, existing approaches often suffer from low protocol fidelity, limited structural control, and poor adaptability, reducing their effectiveness in practical cybersecurity applications. We introduce TrafficT5, a three-stage, self-correcting framework that turns natural-language intents into executable PCAPs. It (i) predicts flow-level features, (ii) generates byte-aligned hex under a fixed 00–FF vocabulary, and (iii) invokes a repair module that deterministically enforces protocol invariants and performs detector-guided, iterative byte-level correction trained with multi-task objectives. The result is traffic that is both semantically coherent and protocol-compliant. Extensive evaluations on five network datasets demonstrate that TrafficT5 achieves an average Bad Packet Rate (BPR) of only 0.32%, significantly outperforming existing methods. Furthermore, synthetic malicious flows generated by TrafficT5 are reliably detected as threats by mainstream IDSs, and augmenting datasets with these flows improves F1 detection scores by over 5% under low-resource conditions.