With the rapid proliferation of encrypted network traffic, traditional signature-based and port-based detection methods have become ineffective against encrypted protocols such as HTTPS, TLS, and VPN. Deep learning models have achieved remarkable success in encrypted traffic classification due to their ability to learn complex hierarchical representations. However, these models suffer from a lack of transparency, as their decision-making processes remain largely opaque, limiting their reliability and applicability in critical cybersecurity environments. Explainable Artificial Intelligence (XAI) has emerged as a powerful solution to address this interpretability challenge. By integrating techniques such as feature attribution, visualization, surrogate modeling, and counterfactual reasoning, XAI enables human-understandable explanations for deep learning predictions. This paper provides a comprehensive review of recent advances (2023-2025) in XAI-based encrypted traffic detection. The review systematically analyzes representative approaches-SHAP, LIME, attention visualization, counterfactual explanation, and GNNExplainer-across different model architectures (CNN, Transformer, and GNN). A comparative analysis of ten contemporary studies reveals that XAI not only enhances the interpretability and reliability of deep models but also improves anomaly detection and policy optimization in encrypted networks. Finally, we discuss open challenges including real-time interpretability, lightweight deployment, cross-model fusion, and human-AI collaborative security analysis.
Paper
Full text
Explainable Ai for Encrypted Traffic Detection: a Comprehensive Survey
Semantic Scholar · 2025
Abstract
With the rapid proliferation of encrypted network traffic, traditional signature-based and port-based detection methods have become ineffective against encrypted protocols such as HTTPS, TLS, and VPN. Deep learning models have achieved remarkable success in encrypted traffic classification due to their ability to learn complex hierarchical representations. However, these models suffer from a lack of transparency, as their decision-making processes remain largely opaque, limiting their reliability and applicability in critical cybersecurity environments. Explainable Artificial Intelligence (XAI) has emerged as a powerful solution to address this interpretability challenge. By integrating techniques such as feature attribution, visualization, surrogate modeling, and counterfactual reasoning, XAI enables human-understandable explanations for deep learning predictions. This paper provides a comprehensive review of recent advances (2023-2025) in XAI-based encrypted traffic detection. The review systematically analyzes representative approaches-SHAP, LIME, attention visualization, counterfactual explanation, and GNNExplainer-across different model architectures (CNN, Transformer, and GNN). A comparative analysis of ten contemporary studies reveals that XAI not only enhances the interpretability and reliability of deep models but also improves anomaly detection and policy optimization in encrypted networks. Finally, we discuss open challenges including real-time interpretability, lightweight deployment, cross-model fusion, and human-AI collaborative security analysis.