IP Library › Granted Patent US 12,651,159
Granted Patent B2
US 12,651,159 · App. 17/788,999 · Granted Jun 9, 2026

Computer-implemented method for accelerating convergence in the training of generative adversarial networks (GAN) to generate synthetic network traffic, and computer programs of same

Inventors: Alberto Mozo Velasco (Madrid, ES); Sandra Gomez Canaval (Madrid, ES); Antonio Pastor Perales (Madrid, ES); Diego R. Lopez (Madrid, ES); Edgar Talavera Munoz (Madrid, ES)
Assignee: Telefonica, S.A.
G06N3/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,651,159
App. No.
17/788,999
Granted
Jun 9, 2026
Kind
B2
Abstract

Proposed are a computer-implemented method for accelerating convergence in the training of generative adversarial networks (GAN) to generate synthetic network traffic, and computer programs of same. The method allows the GAN network to ensure that the training converges in a limited time period less than the standard training period of existing GAN networks. The method allows results to be obtained in different use scenarios related to the generation and processing of network traffic data according to objectives such as the creations of arbitrary amounts of simulated data (a) with characteristics (statistics) similar to real datasets obtained from real network traffic, but (b) without including any part of any real dataset; diversity in the type of data to be created: IP traffic, network attacks, etc.; and the detection of changes in the network traffic patterns analysed and generated.

Claims (50)

1 . A computer-implemented method for accelerating convergence in the training of generative adversarial networks (GAN) to generate synthetic network traffic, wherein the method comprises:

receiving, in a generator of a GAN, identifiers of at least one class of network traffic;

generating, by the generator, using a random vector, synthetic network traffic elements of the at least one class of network traffic associated with each of the identifiers received and generating a dataset of synthetic network traffic;

training a discriminator of the GAN based on a dataset of real network traffic, the dataset of synthetic network traffic, and a first ratio of elements of dataset of real network traffic to elements of the dataset of synthetic network traffic,

wherein the first ratio is such that the elements of the dataset of synthetic network traffic represent a smaller percentage of a total number of elements than that of the elements of the dataset of real network traffic,

wherein each element of the dataset of real network traffic is associated by a class of traffic to which a respective element belongs and each element of the dataset of synthetic network traffic is provided to the discriminator identified as synthetic traffic, and

wherein the training process for the discriminator comprises adjusting internal parameters of the discriminator;

training the generator by generating new synthetic network traffic based on the dataset of real network traffic, the dataset of synthetic network traffic, and a second ratio of the elements of the dataset of real network traffic to the elements of the dataset of synthetic network traffic, the second ratio being different than the first ratio,

wherein, during the training of the generator, each element of the dataset of synthetic network traffic is provided to the discriminator,

wherein a total set of elements provided to the discriminator when the generator is training is greater, by a predetermined ratio, than the total set of elements provided to the discriminator when the discriminator is training,

wherein during the training process for the generator, the discriminator does not modify the internal parameters of the discriminator, and

wherein the training process for the generator comprises adjusting internal parameters of the generator, the adjusting being performed based on a probability of the discriminator classifying an element of the dataset of synthetic network traffic as real traffic; and

comparing statistical distributions of the dataset of real network traffic and of the dataset of synthetic network traffic, wherein the comparing comprises:

generating statistical data of the dataset of real network traffic for each set of elements of the same class of traffic;

repeating the generating of the dataset of synthetic network traffic having a first size using the internal parameters of the generator, wherein a difference between the first size and a size of the dataset of real network traffic is within a threshold;

generating statistical data of the dataset of synthetic network traffic for each set of elements of a same class of traffic;

comparing the statistical data of the dataset of real network traffic with the statistical data of the dataset of synthetic network traffic for each class of network traffic;

based on the difference of the statistical data of the dataset of real network traffic with the statistical data of the dataset of synthetic network traffic being less than a predetermined threshold for each class of traffic, concluding GAN training; and

based on the difference of the statistical data of the dataset of real network traffic with the statistical data of the dataset of synthetic network traffic not being less than the threshold for each class of traffic, continuing GAN training.

2 . The method according to claim 1 , wherein the predetermined threshold is specific for each class of traffic.

3 . The method according to claim 1 , wherein the predetermined threshold is the same for all classes of traffic.

4 . The method according to claim 1 , which further comprises performing a detection of a divergence of the GAN based on a first difference between the statistical data of the dataset of real network traffic and the statistical data of the dataset of synthetic network traffic being greater than a previous difference for at least one class of traffic,

wherein when the first difference is greater than the previous difference, restarting the training of the GAN based on revised internal parameters of the generator and revised internal parameters of the discriminator.

5 . The method according to claim 4 , wherein a percentage of elements of the dataset of synthetic network traffic out of the total number of elements is different than a previous percentage prior to restarting, and

wherein a third ratio of the total number of elements provided to the discriminator during the training of the generator and the total number of elements provided to the discriminator during the training of the discriminator has a different value after the restarting than prior to the restarting.

6 . The method according to claim 1 , wherein statistical data comprises the mean or standard deviation of at least one characteristic parameter of network traffic elements.

7 . The method according to claim 1 , wherein a percentage of elements of the dataset of synthetic network traffic out of the total number of elements is between 1% and 20%.

8 . The method according to claim 1 , wherein the predetermined ratio is in the range of 10-100.

9 . The method according to claim 1 , wherein the random vector has a uniform distribution with a support of [−1, 1] d .

10 . The method according to claim 1 , wherein the random vector has a multivariate normal distribution.

11 . The method according to claim 1 , wherein network traffic comprises network traffic of at least one of the following types: web, video, and traffic coming from a cloud storage service.

12 . A non-transitory computer readable medium storing instructions, that when executed, cause at least one processor to:

receive, in a generator of a GAN, identifiers of at least one class of network traffic;

generate, by the generator, using a random vector, synthetic network traffic elements of the at least one class of network traffic associated with each of the identifiers received and generating a dataset of synthetic network traffic;

train a discriminator of the GAN based on a dataset of real network traffic, the dataset of synthetic network traffic, and a first ratio of elements of dataset of real network traffic to elements of the dataset of synthetic network traffic,

wherein the first ratio is such that the elements of the dataset of synthetic network traffic represent a smaller percentage of a total number of elements than that of the elements of the dataset of real network traffic,

wherein each element of the dataset of real network traffic is associated by a class of traffic to which a respective element belongs and each element of the dataset of synthetic network traffic is provided to the discriminator identified as synthetic traffic, and

wherein the training process for the discriminator comprises adjusting internal parameters of the discriminator;

train the generator by generating new synthetic network traffic based on the dataset of real network traffic, the dataset of synthetic network traffic, and a second ratio of the elements of the dataset of real network traffic to the elements of the dataset of synthetic network traffic, the second ratio being different than the first ratio,

wherein, during the training of the generator, each element of the dataset of synthetic network traffic is provided to the discriminator,

wherein a total set of elements provided to the discriminator when the generator is training is greater, by a predetermined ratio, than the total set of elements provided to the discriminator when the discriminator is training,

wherein during the training process for the generator, the discriminator does not modify the internal parameters of the discriminator, and

wherein the training process for the generator comprises adjusting internal parameters of the generator, the adjusting being performed based on a probability of the discriminator classifying an element of the dataset of synthetic network traffic as real traffic; and

compare statistical distributions of the dataset of real network traffic and of the dataset of synthetic network traffic, wherein the comparing comprises:

generate statistical data of the dataset of real network traffic for each set of elements of the same class of traffic;

repeat the generating of the dataset of synthetic network traffic having a first size using the internal parameters of the generator, wherein a difference between the first size and a size of the dataset of real network traffic is within a threshold;

generate statistical data of the dataset of synthetic network traffic for each set of elements of a same class of traffic;

compare the statistical data of the dataset of real network traffic with the statistical data of the dataset of synthetic network traffic for each class of network traffic;

based on the difference of the statistical data of the dataset of real network traffic with the statistical data of the dataset of synthetic network traffic being less than a predetermined threshold for each class of traffic, conclude GAN training; and

based on the difference of the statistical data of the dataset of real network traffic with the statistical data of the dataset of synthetic network traffic not being less than the threshold for each class of traffic, continue GAN training.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2026
From: MOZO VELASCO, ALBERTO; GÓMEZ CANAVAL, SANDRA; PASTOR PERALES, ANTONIO AGUSTÍN; LOPEZ, DIEGO R.; TALAVERA MUÑOZ, EDGAR
To: TELEFONICA, S.A.
Reel/Frame 074544/0746 →
Continuity (1)
Related Publication 20230049479A1 · Feb 16, 2023
References Cited (11)
US 20190122120A1 · Wu · 2019 [cited by examiner]
US 20190190815A1 · Thubert · 2019 [cited by examiner]
US 20200090002A1 · Zhu · 2020 [cited by examiner]
US 20200097554A1 · Rezagholizadeh · 2020 [cited by examiner]
Heusel, M., Ramsauer, H., Unterthiner, T., Nessler, B., & Hochreiter, S. (Dec. 2017). Gans trained by a two time-scale update rule converge to a local nash equilibrium. Advances in neural information processing systems,… [cited by examiner]
He, H., Wang, H., Lee, G. H., & Tian, Y. (Jul. 2018). Bayesian modelling and monte carlo inference for GAN. In International Conference on Learning Representations (vol. 3, p. 4). (Year: 2018). [cited by examiner]
Ring, M., Schlör, D., Landes, D., & Hotho, A. (Jan. 2019). Flow-based network traffic generation using generative adversarial networks. Computers & Security, 82, 156-172. (Year: 2019). [cited by examiner]
Markus Ring, et al . . . “Flow-based network traffic generation using Generative Adversarial Networks”, Computers and Security, May 1, 2019, pp. 156-172, vol. 82. [cited by applicant]
Charu C. Aggarwal. Neural Networks and Deep Learning, [textbook]. Dec. 31, 2018, Springer, Cham, Switzerland, ISBN 978-3-319-94463-0. [cited by applicant]
Martin Heusel, et al . . . “GANs Trained by a Two Time-Scale Update Rule Converge to a Local Nash Equilibrium”, Advances In Neural Information Processing Systems, 31st Conference on Neural Information Processing Systems… [cited by applicant]
International Search Report for PCT/ES2019/070883 dated Jul. 28, 2020 [PCT/ISA/210]. [cited by applicant]