A Deep Learning-Based Hybrid Architecture Using Probabilistic Spiking Neural Networks and Transformers for TOR Traffic Forensic Analysis
DOI:
https://doi.org/10.70917/ijcisim-2026-2032Keywords:
TOR Traffic Analysis, Probabilistic Spiking Neural Network (PSNN), Transformer Architecture, Deep Learning, Network Security, Temporal Feature ExtractionAbstract
With the ever-increasing traffic growth in encrypted networks, especially in anonymity-preserving networks like TOR, traffic classification becomes an important but challenging task owing to the dynamic, stochastic and obfuscated nature of the traffic. Conventional deep learning models, such as Convolutional Neural Networks (CNN) and Bidirectional Long Short-Term Memory (BiLSTM) networks, have proven successful in extracting local and temporal features, respectively; but they are still constrained in learning long-term interactions and the inherent probabilistic nature of encrypted traffic patterns. In this paper, we propose a new hybrid framework that combines a Probabilistic Spiking Neural Network (PSNN) with a Transformer to effectively classify encrypted traffic. The PSNN models temporal dynamics in a probabilistic manner via sparse spike representations, allowing robust processing of noisy and non-uniform traffic sequences. The Transformer uses self-attention to model global contextual relationships within traffic sequences, alleviating the sequential processing limitations of recurrent networks. Experiments on standard encrypted traffic datasets show that the proposed PSNN–Transformer model achieves superior classification performance compared to baseline CNN and BiLSTM models: 99.26% vs 97.41% and 98.81%, respectively. The findings underline the benefits of probabilistic feature learning and global self-attention for extracting discriminative representations