AI Chat Paper
Note: Please note that the following content is generated by AMiner AI. SciOpen does not take any responsibility related to this content.
{{lang === 'zh_CN' ? '文章概述' : 'Summary'}}
{{lang === 'en_US' ? '中' : 'Eng'}}
Chat more with AI
PDF (4.7 MB)
Collect
Submit Manuscript AI Chat Paper
Show Outline
Outline
Show full outline
Hide outline
Outline
Show full outline
Hide outline
Article | Open Access

LLM-Driven Cross-Flow Modeling for Network Attack Traffic Detection

Aoran Huang1,2( )Sinuo Zhang1,2Haoxiang Zhu1,2Xiaojing Fan1,2Huachun Zhou1,2( )
School of Electronic and Information Engineering, Beijing Jiaotong University, Beijing, China
National Engineering Research Center for Advanced Network Technologies, Beijing Jiaotong University, Beijing, China
Show Author Information

Abstract

In Future Mobile Internet and convergence application scenarios, existing network attack traffic detection methods are insufficient in characterizing cross-flow correlations and structural dependencies during the attack process, and therefore still have limited generalization ability in complex scenarios and unknown attack identification tasks. To address this issue, this paper proposes a cross-flow modeling large language model framework, which extends the traditional detection paradigm based on single-flow features to joint modeling oriented toward cross-flow context and relational structure. Specifically, this paper constructs cross-flow context through flow sorting, grouping, and cross-group sampling, and combines an inter-flow relation matrix with a dual-branch embedding mechanism to achieve structured representation and relation-aware modeling of network traffic; at the model level, by removing the causal mask and introducing a relation-aware bias into bidirectional self-attention, the representation capability of the large language model for complex attack behaviors and potential inter-flow dependencies is enhanced. Experimental results show that the proposed method overall outperforms traditional machine learning and deep learning baseline models, and demonstrates better stability and accuracy in tasks such as fine-grained classification, unknown attack identification, and cross-scenario generalization. Ablation experiments further verify the effectiveness of the proposed cross-flow context construction, dual-branch embedding, and relation-aware LLM adaptation, demonstrating that each component contributes to the overall detection performance and generalization ability. Our work shows that, after targeted structural adaptation, large language models can effectively serve non-text security tasks such as network traffic analysis, thereby supporting AI-driven security modeling for Future Mobile Internet environments.

References

【1】
【1】
 
 
Computer Modeling in Engineering & Sciences
Article number: 50

{{item.num}}

Comments on this article

Go to comment

< Back to all reports

Review Status: {{reviewData.commendedNum}} Commended , {{reviewData.revisionRequiredNum}} Revision Required , {{reviewData.notCommendedNum}} Not Commended Under Peer Review

Review Comment

Close
Close
Cite this article:
Huang A, Zhang S, Zhu H, et al. LLM-Driven Cross-Flow Modeling for Network Attack Traffic Detection. Computer Modeling in Engineering & Sciences, 2026, 148(1): 50. https://doi.org/10.32604/cmes.2026.083972

6

Views

0

Downloads

0

Crossref

0

Web of Science

0

Scopus

Received: 14 April 2026
Accepted: 05 June 2026
Published: 27 July 2026
© The Author 2026.

This work is licensed under a Creative Commons Attribution 4.0 International License, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.