MARATTO

article · Computers

Unsupervised TTL-Based Deep Learning for Anomaly Detection in SIM-Tagged Network Traffic

2026Open accessIbn Tofail University

Abstract

The rise of SIM cloning, identity spoofing, and covert manipulation in mobile and IoT networks has created an urgent need for continuous post-registration verification. This work introduces an unsupervised deep learning framework for detecting behavioral anomalies in SIM-tagged network flows by modeling the intrinsic structure of benign behavioral descriptors (TTL, timing drift, payload statistics). A Temporal Deep Autoencoder (TDAE) combining Conv1D layers and an LSTM encoder is trained exclusively on normal traffic and used to identify deviations through reconstruction error, enabling one-class (label-free) training. For deployment, alarms are set using an unsupervised quantile threshold τα calibrated on benign traffic with a false-alarm budget; τ* is reported only as a diagnostic reference for model comparison. To ensure realism, a large-scale corpus of 3.6 million SIM-tagged flows was constructed by enriching public IoT traffic with pseudo-operator identifiers (synthetic SIM tags derived from device identifiers) and controlled anomaly injections. Cross-domain experiment transfer under SIM-grouped protocol: Training on clean Cassavia-like traffic and testing on attack-rich Guarascio-like flows yields a PR-AUC of 0.93 for the proposed Conv-LSTM Temporal Deep Autoencoder, outperforming Dense Autoencoder, Isolation Forest, One-Class SVM, and LOF baselines. Conversely, the reverse direction collapses to PR-AUC ≈0.5, confirming the absence of data leakage and the validity of one-class behavioral learning. Sensitivity analysis shows that performance is stable around the unsupervised quantile operating point. Overall, the proposed framework provides a lightweight, interpretable, and data-efficient behavioral verification layer for detecting cloned or unauthorized SIM activity, complementing existing registration mechanisms in next-generation telecom and IoT ecosystems.

Research topics

  • Internet Traffic Analysis and Secure E-voting
  • Network Security and Intrusion Detection
  • Anomaly Detection Techniques and Applications

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.3390/computers15020107

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.