Thilini Dahanayaka

dblp:268/2056 · DBLP profile ↗
← Back
10ranked-venue papers
4as first author
8since 2021 · last 2026
0000-0003-2166-0828ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 8 · 4 first-author · 6 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2026 TrafficLLM: LLMs for improved open-set encrypted traffic analysis
abstract
Encrypted traffic has been known to be vulnerable to traffic analysis attacks that exploit the statistical features of encrypted traffic flows, such as packet sizes, timing, and direction, to infer information about the underlying content, which undermines the privacy guarantees of end-to-end encryption. Existing methods such as CNNs lack generalizability, requiring model changes based on the dataset. Furthermore, while state-of-the-art attacks leverage deep learning models to achieve high accuracy, most attacks work under the less realistic closed-set assumption, failing in the open-set setting. Deploying such attacks in practice requires addressing the open-set scenario, which allows the models to filter out target content from other background traffic. The effectiveness of open-set traffic classification largely relies on the model’s ability to generalize and accurately extract features from traffic traces, which are essentially sequential data. Concurrently, Large Language Models (LLM) are increasingly becoming popular in modeling sequential data beyond their typical applications in natural language processing. Inspired by this, our work introduces TrafficLLM, a novel traffic analysis attack method that leverages pre-trained LLMs, such as GPT-2 and LLaMA-2-7B, to extract features from network traffic traces with minimal fine-tuning. Using seven existing encrypted traffic datasets, we show that LLMs improve the open-set performance of traffic classification; for instance, our method, TrafficLLM outperforms ET-BERT and CNN-based approaches by 12.7 % and 13.7 % with GPT-2 feature extractor and 17.6 % and 21.5 % with LLaMA-2-7B feature extractor, respectively.
Yasod Ginige, Bhanuka Silva, Thilini Dahanayaka, Suranga Seneviratne
Comput. Networks3
2025 Demo: P4 Based In-network ML with Federated Learning to Secure and Slice IoT Networks
abstract
Recent cyberattacks have increasingly targeted distributed networking environments like IoT networks. To detect these attacks, hidden under network traffic encryption, many centralized Machine Learning (ML) based solutions have been introduced, which are not well suited for IoT networks. This work proposes PIFL a practical approach to secure IoT networks by combining federated learning, in-network ML using P4-enabled devices, software-defined networks, and binarized neural networks. PIFL detects compromised edge devices and isolates them into separate network slices based on trust parameters derived from their behavior. We demonstrate the feasibility of PIFL using an experimental testbed with three intelligent network devices and seven IoT devices implemented on Raspberry Pi devices.
Chamara Manoj Madarasingha Kattadige, Thilini Dahanayaka, Kanchana Thilakarathna, Suranga Seneviratne, Young Choon Lee, Salil S. Kanhere, Albert Y. Zomaya, Aruna Seneviratne, Phil Ridley
WoWMoM2
2023 POSTER: Performance Characterization of Binarized Neural Networks in Traffic Fingerprinting
abstract
Traffic fingerprinting allows making inferences about encrypted traffic flows through passive observation. They have been used for tasks such as network performance management and analytics and in attacker settings such as censorship and surveillance. A key challenge when implementing traffic fingerprinting in real-time settings is how the state-of-the-art traffic fingerprint models can be ported into programmable in-network computing devices with limited computing resources. Towards this, in this work, we characterize the performance of binarized traffic fingerprinting neural networks that are efficient and well-suited for in-network computing devices and propose a new data encoding method that is better suited for network traffic. Overall, we show that the proposed binary neural network with first-layer binarization and last-layer quantization reduces the performance requirement of hardware equipment while retaining the accuracies of those models of binary datasets over 70%. Furthermore, when combined with our proposed encoding algorithm, accuracies of binarized models of numeric datasets show further improvements to achieve over 65% accuracy.
Yiyan Wang, Thilini Dahanayaka, Guillaume Jourjon, Suranga Seneviratne
AsiaCCS2
2023 The Wyner Variational Autoencoder for Unsupervised Multi-Layer Wireless Fingerprinting
abstract
Wireless fingerprinting is a device identification approach which leverages hardware imperfections and wireless channel variations as unique user-centric signatures. Recent studies have also demonstrated that user behavior can be used as a signature by collecting network traffic data, e.g., packet length, without the need to decode/decrypt the payload. Inspired by these results, we propose a multi-layer fingerprinting framework that jointly combines the multi-layer signatures for improved identification performance. In contrast to previous works in the area, our multi-view learning approach is rooted in the common information framework developed by Wyner [1] and is able to exploit data with multiple forms to enable the extraction of the user-centric signatures shared among the multi-layer features without the need for labels (i.e., unsupervised learning setup). We further use variational inference to obtain a computationally efficient algorithm based on a tight surrogate bound on the loss function. Our evaluation framework is based on a dataset obtained by combining real-world video traffic with simulated physical layer characteristics. Finally, our empirical results show that our Wyner Variational Autoencoder significantly outper-forms the state-of-the-art baseline in the unsupervised wireless fingerprinting setting.
Teng-Hui Huang, Thilini Dahanayaka, Kanchana Thilakarathna, Philip H. W. Leong, Hesham El Gamal
GLOBECOM2
2023 Robust open-set classification for encrypted traffic fingerprinting
abstract
Encrypted network traffic has been known to leak information about their underlying content through side-channel information leaks. Traffic fingerprinting attacks exploit this by using machine learning techniques to threaten user privacy by identifying user activities such as website visits, videos streamed, and messenger app activities. Although state-of-the-art traffic fingerprinting attacks have high performances, even undermining the latest defenses, most of them are developed under the closed-set assumption. To deploy them in practical situations, it is important to adapt them to the open-set scenario, which allows the attacker to identify its target content while rejecting other background traffic. At the same time, in practice, these models need to be deployed on in-networking devices such as programmable switches, which have limited memory and computation power. Model weight quantization can reduce the memory footprint of deep learning models while at the same time, allowing inference to be done as integer operations as opposed to floating point operations. Open-set classification in the domain of traffic fingerprinting has not been explored well in prior work and none of them explored the effect of quantization on the open-set performance of such models. In this work, we propose a framework for robust open-set classification of encrypted traffic based on three key ideas. First, we show that a well-regularized deep learning model improves the open-set classification and then we propose a novel open-set classification method with three variants that perform consistently over multiple datasets. Next, we show that traffic fingerprinting models can be quantized without a significant drop in both closed-set and open-set accuracy and therefore, they can be readily deployed on in-network computing devices. Finally, we show that when the above three components are combined, the resulting open-set classifier outperforms all other open-set classification methods evaluated across five datasets with a minimum and maximum increase in F1_Score of 8.9% and 77.3% respectively.
Thilini Dahanayaka, Yasod Ginige, Yi Huang 0023, Guillaume Jourjon, Suranga Seneviratne
Comput. Networks1
2022 Inline Traffic Analysis Attacks on DNS over HTTPS
abstract
Even though end-to-end encryption was introduced to Domain Name System (DNS) communications to ensure user privacy and there is an increase in adoption of DNS over HTTPS (DoH), prior research has demonstrated that encrypted DNS traffic is vulnerable to traffic analysis attacks. However, these attacks were demonstrated under strong assumptions such as handling only closed-set classification or doing only post-event analysis. In this work we demonstrate traffic analysis attacks on DoH without such strong assumptions. We first show the feasibility of website fingerprinting over DoH traffic and present an inline traffic analysis attack that achieve over 90% accuracy using DoH traces of length as short as ten packets. Next, we propose a novel open-set classification method and achieve over 75% accuracy on both closed-set and open-set samples for the open-set scenario. Finally, we demonstrate that the same attack can be performed without any knowledge on the start of the activity.
Thilini Dahanayaka, Guillaume Jourjon, Suranga Seneviratne
LCN1
2022 Dissecting traffic fingerprinting CNNs with filter activations
Thilini Dahanayaka, Guillaume Jourjon, Suranga Seneviratne
Comput. Networks1
2021 SMAUG: Streaming Media Augmentation Using CGANs as a Defence Against Video Fingerprinting
abstract
Traffic fingerprinting and developing defenses against it has always been an arms race between the attackers and the defenders. The rapid evolution of deep learning methods makes developing stronger traffic fingerprinting models much easier, while overhead, latency, and deployment constraints restrict the abilities of the defenses. As such, there is always the need of coming up with novel defenses against traffic fingerprinting. In this paper, we propose SMAUG, a novel CGAN-based (Conditional Generative Adversarial Network) defense to protect video streaming traffic against fingerprinting. We first assess the performance of various GANs in video streaming traffic synthesis using multiple GAN quality metrics and show that CGAN outperforms other types of GANs such as basic GANs and WGANs (Wasserstein GAN). Our proposed defense, SMAUG, uses CGANs to synthesize video traffic flows and use those synthesized flows to camouflage the original traffic that needs protection. We compare SMAUG with other state-of-the-art defenses - FPA and d*-private methods, as well as a kernel density estimation-based baseline and show that SMAUG provides better privacy with lower overhead and delay.
Alexander Vaskevich, Thilini Dahanayaka, Guillaume Jourjon, Suranga Seneviratne
NCA2
2020 Poster Abstract: Passive Activity Classification of Smart Homes through Wireless Packet Sniffing
abstract
Network communications, despite being encrypted, leak crucial information via side channels. WiFi networks are more prone to such side-channel attacks since any attacker within the network’s range can passively eavesdrop the channel. With the increasing number of smart home devices and sensors connecting to private WiFi networks, it is essential to understand the inadvertent information leakage through WiFi side-channels. Our work demonstrates how fine-granular information on the activities happening inside a house can be inferred by passively monitoring WiFi network traffic. In particular, we were able to correctly classify various user interactions with simple IoT devices such as smart bulbs or power sockets as well as advanced voice-based intelligent assistants.
Kwon Nung Choi, Thilini Dahanayaka, David Kennedy, Kanchana Thilakarathna, Suranga Seneviratne, Salil S. Kanhere, Prasant Mohapatra
IPSN2
2020 Understanding Traffic Fingerprinting CNNs
abstract
HTTPS encrypted traffic can leak information about underlying contents through various statistical properties of traffic flows like packet lengths and timing, opening doors to traffic fingerprinting attacks. Recently proposed traffic fingerprinting attacks leveraged Convolutional Neural Networks (CNNs) and recorded very high accuracies undermining the state-of-the-art mitigation techniques. In this paper, we methodically dissect such CNNs with the objectives of building further accurate and scalable traffic classifiers and understanding the inner workings of such CNNs to develop effective mitigation techniques. By conducting experiments with three datasets, we show that website fingerprinting CNNs focus majorly on the initial parts of traces instead of longer windows of continuous uploads or downloads. Next, we show that traffic fingerprinting CNNs exhibit transfer-learning capabilities allowing identification of new websites with fewer data. Finally, we show that traffic fingerprinting CNNs outperform RNNs because of their resilience to random shifts in data happening due to varying network conditions.
Thilini Dahanayaka, Guillaume Jourjon, Suranga Seneviratne
LCN1