ENGINEERING Information Technology & Electronic Engineering  2026 Vol.27 No.8 P.1-18

http://doi.org/10.1631/ENG.ITEE.2026.0095


Representation levels and objective consistency of network traffic generation: a survey


Author(s):  Biying WANG, Baosheng WANG, Shuang ZHAO, Jinshu SU, Shuhui CHEN, Minxin WANG, Zhengpeng LI, Ziling WEI

Affiliation(s):  1. College of Computer Science and Technology, National University of Defense Technology, Changsha 410073, China more

Corresponding email(s):   weiziling@nudt.edu.cn

Key Words:  Network traffic generation, Traffic representation levels, Task consistency, Protocol consistency


Biying WANG, Baosheng WANG, Shuang ZHAO, Jinshu SU, Shuhui CHEN, Minxin WANG, Zhengpeng LI, Ziling WEI. Representation levels and objective consistency of network traffic generation: a survey[J]. Journal of Zhejiang University Science C, 2026, 27(8): 1-18.

@article{title="Representation levels and objective consistency of network traffic generation: a survey",
author="Biying WANG, Baosheng WANG, Shuang ZHAO, Jinshu SU, Shuhui CHEN, Minxin WANG, Zhengpeng LI, Ziling WEI",
journal="Journal of Zhejiang University Science C",
volume="27",
number="8",
pages="1-18",
year="2026",
publisher="Zhejiang University Press & Springer",
doi="10.1631/ENG.ITEE.2026.0095"
}

%0 Journal Article
%T Representation levels and objective consistency of network traffic generation: a survey
%A Biying WANG
%A Baosheng WANG
%A Shuang ZHAO
%A Jinshu SU
%A Shuhui CHEN
%A Minxin WANG
%A Zhengpeng LI
%A Ziling WEI
%J Frontiers of Information Technology & Electronic Engineering
%V 27
%N 8
%P 1-18
%@ 1869-1951
%D 2026
%I Zhejiang University Press & Springer
%DOI 10.1631/ENG.ITEE.2026.0095

TY - JOUR
T1 - Representation levels and objective consistency of network traffic generation: a survey
A1 - Biying WANG
A1 - Baosheng WANG
A1 - Shuang ZHAO
A1 - Jinshu SU
A1 - Shuhui CHEN
A1 - Minxin WANG
A1 - Zhengpeng LI
A1 - Ziling WEI
J0 - Frontiers of Information Technology & Electronic Engineering
VL - 27
IS - 8
SP - 1
EP - 18
%@ 1869-1951
Y1 - 2026
PB - Zhejiang University Press & Springer
ER -
DOI - 10.1631/ENG.ITEE.2026.0095


Abstract: 
Network traffic research relies on large-scale, high-quality traffic data. However, obtaining such data remains difficult because of privacy constraints, collection costs, class imbalance, and continuous updates. These challenges have increased researchers’ interest in traffic generation. Although many generation methods have been proposed, existing studies and surveys often overlook two key questions: what form of traffic is generated and what practical objectives it can support. Based on 113 candidate records published from 2019 to 2026, this survey provides a detailed analysis of 39 representative network traffic generation studies through the lenses of representation levels and objective consistency. We organize existing methods into four representation levels and analyze how generated data relate to usage scenarios. We find that many methods preserve information that is useful for downstream tasks such as classification and intrusion detection, but task usefulness does not guarantee replayability or usability in real network environments. High-level representations are easier to model, yet they often discard protocol semantics, packet dependencies, and communication logic. We therefore distinguish task consistency from protocol consistency and show that the latter remains underexplored. We further summarize evaluation practices, discuss level-specific metrics, and highlight future directions including controllable generation, protocol-aware state-consistent synthesis, and engineering-oriented evaluation.

网络流量生成的表示层级与目标一致性综述

王碧莹1,王宝生1,赵双1,2,苏金树1,3,陈曙晖1,王敏欣1,李正芃1,魏子令11
1国防科技大学计算机学院,中国长沙市,410073
2湖南警察学院信息技术(网监)系,中国长沙市,410138
3军事科学院,中国北京市,100091
摘要:网络流量研究依赖于大规模、高质量的流量数据。然而,由于隐私限制、采集成本、类别不平衡以及数据持续更新等原因,获取此类数据仍然十分困难。这些挑战增加了研究人员对流量生成的关注。尽管目前已提出许多生成方法,现有研究和综述往往忽略了两个关键问题:生成何种形式的流量以及它能支持哪些实际目标。基于2019年至2026年间发表的113份候选记录,本综述从表示层级和目标一致性两个视角,对其中39项代表性网络流量生成研究进行详细分析。我们将现有方法归纳为4个表示层级,并分析了生成数据与使用场景间的关系。我们发现,许多方法保留了有利于分类和入侵检测等下游任务的信息,但任务有用性并不能保证其在真实网络环境中的可重放性或可用性。高层表示虽然更容易建模,但往往会丢弃协议语义、数据包依赖关系和通信逻辑。因此,我们区分了任务一致性与协议一致性,并指出后者目前仍缺乏足够探索。我们进一步总结了评估实践,讨论了各层级特有的评估指标,指明了未来研究方向,包括可控流量生成、协议感知的状态一致合成以及面向工程的评估方法。

关键词:网络流量生成;流量表示层级;任务一致性;协议一致性

Darkslateblue:Affiliate; Royal Blue:Author; Turquoise:Article

Reference

[1]Adeleke OA, Bastin N, Gurkan D, 2023. Network traffic generation: a survey and methodology. ACM Comput Surv, 55(2):28.

[2]Alsaedi A, Moustafa N, Tari Z, et al., 2020. TON_IoT telemetry dataset: a new generation dataset of IoT and IIoT for data-driven intrusion detection systems. IEEE Access, 8:165130-165150.

[3]Cai SH, Zhao XY, Chen JF, et al., 2025. CT-SSSA: malicious traffic augmentation based on classifier TransGAN and spatial-channel synergistic self-attention. Knowl-Based Syst, 329:114285.

[4]Carillo R, Cerasuolo F, Bovenzi G, et al., 2025. Explainable federated class incremental learning for encrypted network traffic classification. Comput Netw, 269:111448.

[5]Chai HY, Jiang T, Yu L, 2024. Diffusion model-based mobile traffic generation with open data for network planning and optimization. Proc 30th Conf on Knowledge Discovery and Data Mining, p.4828-4838.

[6]Chai HY, Qi XQ, Li Y, 2025a. Spatio-temporal knowledge driven diffusion model for mobile traffic generation. IEEE Trans Mob Comput, 24(6):4939-4956.

[7]Chai HY, Zhang SY, Qi XQ, et al., 2025b. UoMo: a universal model of mobile traffic forecasting for wireless network optimization. Proc 31st Conf on Knowledge Discovery and Data Mining V.2, p.4308-4319.

[8]Charlier J, Singh A, Ormazabal G, et al., 2019. SynGAN: towards generating synthetic network attacks using GANs.

[9]Chawla NV, Bowyer KW, Hall LO, et al., 2002. SMOTE: synthetic minority over-sampling technique. J Artif Intell Res, 16(1):321-357.

[10]Chen YC, 2017. A tutorial on kernel density estimation and recent advances. Biostat Epidemiol, 1(1):161-187.

[11]Cheng A, 2019. PAC-GAN: packet generation of network traffic using generative adversarial networks. IEEE 10th Annual Information Technology, Electronics and Mobile Communication Conf, p.728-734.

[12]Chu A, Jiang X, Liu SN, et al., 2024. Feasibility of state space models for network traffic generation. Proc SIGCOMM Workshop on Networks for AI Computing, p.9-17.

[13]Chu A, Jiang X, Liu SN, et al., 2026. NetSSM: multi-flow and state-aware network trace generation using state-space models. Proc ACM Netw, 4(CoNEXT1):6.

[14]Delgado-Soto JA, de Vergara JEL, González I, et al., 2025. GPT on the wire: towards realistic network traffic conversations generated with large language models. Comput Netw, 265:111308.

[15]Dowoo B, Jung Y, Choi C, 2019. PcapGAN: packet capture file generator by style-based generative adversarial networks. 18th IEEE Int Conf on Machine Learning and Applications, p.1149-1154.

[16]Draper-Gil G, Lashkari AH, Mamun MSI, et al., 2016. Characterization of encrypted and VPN traffic using time-related features. Proc 2nd Int Conf on Information Systems Security and Privacy, p.407-414.

[17]Du LF, He JJ, Li T, et al., 2023. DBWE-Corbat: background network traffic generation using dynamic word embedding and contrastive learning for cyber range. Comput Secur, 129:103202.

[18]Fernandes DAB, Neto M, Soares LFB, et al., 2015. On the self-similarity of traffic generated by network traffic simulators. In: Obaidat MS, Nicopolitidis P, Zarai F (Eds.), Modeling and Simulation of Computer Networks and Systems. Morgan Kaufmann, Waltham, p.285-311.

[19]Goodfellow IJ, Pouget-Abadie J, Mirza M, et al., 2014. Generative adversarial networks. Proc 28th Int Conf on Neural Information Processing Systems, p.2672-2680. https://dl.acm.org/doi/10.5555/2969033.2969125

[20]Ho J, Jain A, Abbeel P, 2020. Denoising diffusion probabilistic models. Proc 34th Int Conf on Neural Information Processing Systems, Article 574. https://dl.acm.org/doi/abs/10.5555/3495724.3496298

[21]Hochreiter S, Schmidhuber J, 1997. Long short-term memory. Neur Comput, 9(8):1735-1780.

[22]Huang YZ, Li XH, Geng JX, et al., 2026. TrafficT5: multi-stage self-correcting framework for traffic generation. Comput Netw, 274:111858.

[23]Hui SD, Wang HD, Wang ZH, et al., 2022. Knowledge enhanced GAN for IoT traffic generation. Proc ACM Web Conf, p.3336-3346.

[24]Jablaoui R, Liouane N, 2026. GA-CNN-BiGRU-IDS: a robust framework for intrusion detection system based on GA for data augmentation and hybrid CNN-BiGRU model for spatiotemporal feature extraction. Comput Electr Eng, 130:110900.

[25]Jiang X, Liu SN, Gember-Jacobson A, et al., 2024. NetDiffusion: network data augmentation through protocol-constrained traffic generation. Proc ACM Meas Anal Comput Syst, 8(1):11.

[26]Jonath KK, Naz A, Zhang SG, 2026. GMM-cGAN: mitigating data scarcity and label noise for robust encrypted malicious traffic classification. Comput Netw, 274:111823.

[27]Kattadige C, Muramudalige SR, Choi KN, et al., 2021. VideoTrain: a generative adversarial framework for synthetic video traffic generation. IEEE 22nd Int Symp on a World of Wireless, Mobile and Multimedia Networks, p.209-218.

[28]Kennedy J, Eberhart R, 1995. Particle swarm optimization. Proc Int Conf on Neural Networks, p.1942-1948.

[29]Kholgh DK, Kostakos P, 2023. PAC-GPT: a novel approach to generating synthetic network traffic with GPT-3. IEEE Access, 11:114936-114951.

[30]Kingma DP, Welling M, 2014. Auto-encoding variational Bayes.

[31]Koroniotis N, Moustafa N, Sitnikova E, et al., 2019. Towards the development of realistic botnet dataset in the Internet of Things for network forensic analytics: Bot-IoT dataset. Future Gener Comput Syst, 100:779-796.

[32]Li J, Li X, 2022. 5G network traffic prediction based on EEMD-GAN. Proc 7th Int Conf on Cyber Security and Information Engineering, p.408-412.

[33]Li T, Hui SD, Zhang SY, et al., 2024. Mobile user traffic generation via multi-scale hierarchical GAN. ACM Trans Knowl Discov Data, 18(8):189.

[34]Lin ZN, Jain A, Wang C, et al., 2020. Using GANs for sharing networked time series data: challenges, initial promise, and open questions. Proc ACM Int Measurement Conf, p.464-483.

[35]Manocchio LD, Layeghy S, Portmann M, 2021. FlowGAN - synthetic network flow generation using generative adversarial networks. IEEE 24th Int Conf on Computational Science and Engineering, p.168-176.

[36]Meddahi A, Drira H, Meddahi A, 2021. SIP-GAN: generative adversarial networks for SIP traffic generation. Int Symp on Networks, Computers and Communications, p.1-6.

[37]Meslet-Millet F, Mouysset S, Chaput E, 2022. NeCSTGen: an approach for realistic network traffic generation using deep learning. IEEE Global Communications Conf, p.3108-3113.

[38]Meta AI, 2024. Llama3/MODEL_CARD.md. https://github.com/meta-llama/llama3/blob/main/MODEL_CARD.md [Accessed on May 25, 2026].

[39]Moustafa N, Slay J, 2015. UNSW-NB15: a comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). Military Communications and Information Systems Conf, p.1-6.

[40]Mozo A, González-Prieto Á, Pastor A, et al., 2022. Synthetic flow-based cryptomining attack generation through generative adversarial networks. Sci Rep, 12(1):2091.

[41]Nukavarapu SK, Ayyat M, Nadeem T, 2022. MirageNet - towards a GAN-based framework for synthetic network traffic generation. IEEE Global Communications Conf, p.3089-3095.

[42]Oh S, Oh MJ, Im JK, et al., 2025. Spatio-temporal data augmentation method for network traffic prediction. IEEE Access, 13:138686-138698.

[43]Poisson M, Carnier RM, Fukuda K, 2024. GothX: a generator of customizable, legitimate and malicious IoT network traffic. Proc 17th Cyber Security Experimentation and Test Workshop, p.65-73.

[44]Qi XQ, Chai HY, Yu L, et al., 2024. Regional features conditioned diffusion models for 5G network traffic generation. Proc 32nd ACM Int Conf on Advances in Geographic Information Systems, p.396-409.

[45]Ring M, Schlör D, Landes D, et al., 2019. Flow-based network traffic generation using generative adversarial networks. Comput Secur, 82:156-172.

[46]Shafi M, Lashkari AH, Roudsari AH, 2025. NTLFlowLyzer: towards generating an intrusion detection dataset and intruders behavior profiling through network and transport layers traffic analysis and pattern extraction. Comput Secur, 148:104160.

[47]Shahid MR, Blanc G, Jmila H, et al., 2020. Generative deep learning for Internet of Things network traffic generation. IEEE 25th Pacific Rim Int Symp on Dependable Computing, p.70-79.

[48]Shapira T, Shavitt Y, 2021. FlowPic: a generic representation for encrypted traffic classification and applications identification. IEEE Trans Netw Serv Manage, 18(2):1218-1232.

[49]Sharafaldin I, Habibi Lashkari A, Ghorbani AA, 2018. Toward generating a new intrusion detection dataset and intrusion traffic characterization. Proc 4th Int Conf on Information Systems Security and Privacy, p.108-116.

[50]Sharafaldin I, Lashkari AH, Hakak S, et al., 2019. Developing realistic distributed denial of service (DDoS) attack dataset and taxonomy. Int Carnahan Conf on Security Technology, p.1-8.

[51]Shawkat M, Badawi M, El-ghamrawy S, et al., 2022. An optimized FP-growth algorithm for discovery of association rules. J Supercomput, 78:5479-5506.

[52]Shin CY, Choi YS, Kim MS, 2025. Data augmentation-based enhancement for efficient network traffic classification. IEEE Access, 13:6006-6028.

[53]Sivaroopan N, Bandara D, Madarasingha C, et al., 2024. NetDiffus: network traffic generation by diffusion models through time-series imaging. Comput Netw, 251:110616.

[54]Sivaroopan N, Silva K, Madarasingha C, et al., 2026. A comprehensive survey on synthetic network traffic generation. IEEE Commun Surv Tutor, 28:5949-5983.

[55]Soper J, Xu Y, Foo E, et al., 2024. Improved packet-level synthetic network traffic generation. IEEE 23rd Int Conf on Trust, Security and Privacy in Computing and Communications, p.1928-1934.

[56]Sun DY, Chen JQ, Gong C, et al., 2024. NetDPSyn: synthesizing network traces under differential privacy. Proc ACM on Internet Measurement Conf, p.545-554.

[57]Sun PS, Yun XC, Li SH, et al., 2025. AdvTG: an adversarial traffic generation framework to deceive DL-based malicious traffic detection models. Proc ACM on Web Conf, p.3147-3159.

[58]Tavallaee M, Bagheri E, Lu W, et al., 2009. A detailed analysis of the KDD CUP 99 data set. IEEE Symp on Computational Intelligence for Security and Defense Applications, p.1-6.

[59]Wang BY, Wang BS, Wei ZL, et al., 2025. MFSI: multi-flow based service identification for encrypted network traffic. Comput Netw, 265:111283.

[60]Wang MX, Yang N, Forcade-Perkins NJ, et al., 2024. ProGen: projection-based adversarial attack generation against network intrusion detection. IEEE Trans Inform Forensics Secur, 19:5476-5491.

[61]Yang LM, Wang YJ, Liu L, et al., 2025. unFlowS: an unsupervised construction scheme of flow spectrum for network traffic detection. IEEE Trans Inform Forensics Secur, 20:3330-3345.

[62]Yin YC, Lin Z, Jin M, et al., 2022. Practical GAN-based synthetic IP header trace generation using NetShare. Proc ACM SIGCOMM Conf, p.458-472.

[63]Zhang HZ, 2024. TransFlowGAN: generation and balancing of network traffic data. Proc Asia Pacific Conf on Computing Technologies, Communications and Networking, p.51-59.

[64]Zhang JH, Tang JQ, Zhang X, et al., 2015. A survey of network traffic generation. 3rd Int Conf on Cyberspace Technology, p.1-6.

[65]Zhang S, Azizi S, Joshi A, et al., 2025. Towards behavior grammar-driven IoT network traffic generation using MUD specifications. Proc 7th Joint Workshop on CPS & IoT Security and Privacy, p.98-104.

[66]Zhang SY, Li T, Jin DP, et al., 2024. NetDiff: a service-guided hierarchical diffusion model for network flow trace generation. Proc ACM Netw, 2(CoNEXT3):16.

[67]Zhu XF, Shu NN, Zheng BW, et al., 2022. A method to generate a ground truth distributed network traffic dataset. Proc 3rd Int Conf on Control, Robotics and Intelligent System, p.219-224.

[68]Zion Y, Aharon P, Dubin R, et al., 2025. Enhancing encrypted Internet traffic classification through advanced data augmentation techniques. IEEE Int Conf on Communications, p.1-6.

Open peer comments: Debate/Discuss/Question/Opinion

<1>

Please provide your name, email address and a comment





Full Text:   <5>

Summary:  <14>

CLC number: TP393

On-line Access: 2026-06-02

Received: 2026-04-05

Revision Accepted: 2026-07-10

Crosschecked: 2026-08-03

Cited: 0

Clicked: 24

Citations:  Bibtex RefMan EndNote GB/T7714

 ORCID:

Biying WANG

0009-0005-0635-498X

Baosheng WANG

0009-0008-0583-6399

Shuang ZHAO

0000-0002-3423-8805

Jinshu SU

0000-0001-9273-616X

Shuhui CHEN

0000-0001-7413-8174

Minxin WANG

0009-0006-0743-9624

Zhengpeng LI

0009-0007-4146-9138

Ziling WEI

0000-0002-7858-1445

Journal of Zhejiang University-SCIENCE, 38 Zheda Road, Hangzhou 310027, China
Tel: +86-571-87952783; E-mail: cjzhang@zju.edu.cn
Copyright © 2000 - 2026 Journal of Zhejiang University-SCIENCE