Related Experiment Video
Updated: Jul 16, 2025

High-precision Electromagnetic Flowmeter with Empty Pipe Detection via Complex Programmable Logic Device-based Waveform Recognition
Published on: June 27, 2025
Malicious traffic detection on sampled network flow data with novelty-detection-based models
Adrián Campazas-Vega1, Ignacio Samuel Crespo-Martínez2, Ángel Manuel Guerrero-Higueras3
1Robotics Group, University of León, Campus de Vegazana s/n, 24071, León, Spain. acamv@unileon.es.
Cyber-attacks pose significant risks. This study shows novelty-detection models can effectively identify malicious network traffic even with heavily sampled flow data, achieving high accuracy and low false alarms.
Area of Science:
- Computer Science
- Cybersecurity
- Network Security
Background:
- Classical anomaly detection analyzes individual packets, which is infeasible for high-traffic routers.
- Routers use flow data for network statistics, but sampling is necessary due to computational costs, leading to information loss.
- Detecting cyber-attacks using sampled flow data remains a challenge.
Purpose of the Study:
- To demonstrate the feasibility of detecting malicious network traffic using anomaly detection on sampled flow data.
- To evaluate the performance of novelty-detection-based models on flow data with a sampling rate of 1 out of 1,000 packets.
- To assess the accuracy and false alarm rate of these models using both synthetic and real-world network data.
Main Methods:
- Utilized anomaly-detection-based models, specifically focusing on novelty detection.
- Employed synthetic sampled flow data and actual sampled flow data from the RedCAYLE network.
- Evaluated model performance based on accuracy and false alarm rates.
Main Results:
- Malicious network traffic can be successfully detected even when using flow data sampled at a rate of 1 out of 1,000 packets.
- Novelty-detection-based models achieved high accuracy in identifying malicious traffic within sampled flow data.
- The proposed approach demonstrated a low false alarm rate, indicating reliable detection.
Conclusions:
- Anomaly detection, particularly novelty detection, is effective for identifying cyber-attacks on sampled network flow data.
- The findings support the use of sampled flow data for cybersecurity threat detection in resource-constrained environments.
- This research validates that significant network security insights can be retained despite aggressive data sampling.
Related Concept Videos
Rapidly Varying Flow
Typical Model Studies
Uniform Depth Channel Flow
Uniform Depth Channel Flow: Problem Solving

