Every night, millions of people settle in front of streaming platforms to watch films, series, and live events, and nearly all of that traffic is protected by SSL/TLS encryption. The encryption is designed to keep the content itself hidden from anyone who might be watching the network, from curious internet service providers to malicious eavesdroppers. But a new study published in Cluster Computing by Jan Fesl, Michal Konopa, Yelena Trofimova, Viktor Černý and colleagues at the Czech Technical University in Prague and the University of South Bohemia shows just how porous that privacy shield really is. The team has developed a dynamic, highly scalable deep-learning approach that can identify which video stream is flowing through an encrypted connection with an accuracy close to the best-known solutions, while dramatically reducing the time and computational power needed to keep the identification system up to date.
The core insight behind the research is not new. For nearly a decade, researchers have demonstrated that encrypted traffic leaks information through its side channels: packet sizes, timing patterns, and the bursty structure of adaptive video streaming all leave characteristic traces that survive encryption. Landmark work such as the 2017 study Beauty and the Burst showed that remote observers could identify encrypted video streams, and subsequent studies extended the technique to platforms like YouTube, including attacks that could name the specific title a user was watching. What has changed is the scale and the operational reality of these systems. Most published identification algorithms rely on static machine learning models, which means that whenever the pattern database is modified, for example when a new film or series is added to the catalogue, the entire model must be retrained from scratch, a process that consumes large amounts of time and computational power.
That limitation matters because streaming catalogues are anything but static. New content appears daily, encoding parameters shift, and traffic patterns evolve with every codec update and delivery-network change. A classifier trained last month may already be out of date. Fesl and his colleagues, working under the long-term VideoStream Hunter project financed by the Czech national research and education network operator CESNET, set out to build an identification system that could grow and adapt as easily as the catalogues it monitors. Their answer is a family of deep-learning models based on Siamese neural networks, an architecture originally developed for one-shot image recognition and since applied to tasks ranging from wireless signal classification to recommendation systems.
The Siamese design is what gives the new approach its scalability. Instead of learning to assign each traffic sample to one of a fixed set of classes, a Siamese network learns a similarity function: it takes two inputs, embeds each into a common representation space, and decides how similar they are. In the context of encrypted video identification, one input is a fingerprint extracted from live network traffic and the other is a reference fingerprint from the pattern database. If the network judges them similar enough, the stream is identified as the corresponding title. The crucial consequence is that adding a new video to the database does not require retraining the network at all. The model has learned what similarity looks like in general, so new fingerprints can simply be enrolled, much like adding a new face to a face-recognition gallery without teaching the system to see again.
A second pillar of the work is data. As part of their long-term research programme, the team created a new dataset containing several thousand fingerprints of real video streams captured from network traffic probes. This is a significant contribution in a field where many studies rely on laboratory recordings or public datasets that may not reflect the messiness of production networks, where adaptive bitrate switching, background traffic, and VPN tunnelling all distort the signals. The dataset builds on the group’s earlier published encrypted network video stream dataset, and it allowed the researchers to test their models under realistic conditions rather than idealised ones. The paper’s authors acknowledge the University of South Bohemia’s Faculty of Science and the Czech Technical University’s Faculty of Information Technology for providing the technical equipment for the experiments, with Tomáš Macák responsible for the experimental part.
The technical challenge the fingerprints must overcome is substantial. Modern streaming platforms deliver video using adaptive protocols such as DASH and increasingly over the QUIC transport protocol, which fragments and re-encodes content dynamically in response to network conditions. Two viewers watching the same film may produce noticeably different packet sequences depending on their bandwidth, device, and player implementation. Earlier approaches have attacked this problem with a variety of tools, including Markov probability fingerprints, differential fingerprints, low-dimensional embeddings, Levenshtein-distance clustering, and ensemble classifiers, each achieving respectable accuracy under specific assumptions. The Siamese approach differs philosophically: rather than modelling each video’s traffic pattern as a fixed signature, it learns the deeper structure that makes two traces of the same content recognisably related even when their surface features differ.
In their evaluation, the researchers report that the accuracy of their Siamese models is close to the current best-known solutions in the field, while avoiding the lengthy training process those solutions require. That trade-off is the heart of the paper’s contribution. A system that matches state-of-the-art accuracy but can absorb new fingerprints on the fly is far more practical for real-world deployment, whether by network operators monitoring traffic for capacity planning, by security teams hunting for policy violations, or by researchers studying how streaming platforms behave at scale. The dynamic, highly scalable character of the method means the pattern database can be modified without the expensive retraining cycles that have made static classifiers brittle in production environments.
The implications cut in two directions, and both deserve attention. On one side, the work is a pointed reminder that encryption alone does not guarantee viewing privacy. An observer positioned anywhere along the path between a viewer and a streaming server, at an ISP, a corporate gateway, or a public Wi-Fi access point, can in principle determine what that viewer is watching without ever breaking the encryption itself. This is a classic side-channel attack, and the growing sophistication of the techniques, documented across a series of surveys and studies of encrypted traffic analysis, means that the gap between what encryption promises and what it delivers for metadata privacy continues to widen. Countermeasures such as traffic padding, obfuscation, and constant-rate transmission exist, but they carry real costs in bandwidth and efficiency, which is why platforms have been slow to adopt them.
On the other side, the same technology has legitimate and valuable uses. Network operators need to understand traffic composition to provision capacity and diagnose quality-of-service problems, and encrypted traffic increasingly blindsides those tools. Content-delivery networks and regulators may need to verify that licensed content is being delivered as contracted. The Siamese architecture’s ability to scale gracefully makes such applications more feasible, because the identification system can track a catalogue of thousands of titles without collapsing under the weight of its own retraining schedule. The research also connects to a broader trend in machine learning, where metric-learning approaches that compare examples directly are displacing fixed-class classifiers in domains where the set of categories is large, open-ended, and constantly changing.
For the field of encrypted traffic analysis, the study signals a shift in what matters most. The question is no longer only whether encrypted video can be identified, which has been answered affirmatively many times over, but whether identification systems can keep pace with the real world’s churn. By pairing a large, realistic dataset of several thousand real-stream fingerprints with an architecture that treats identification as similarity comparison rather than classification, the Czech team has moved the state of the art closer to operational reality. As streaming continues to dominate global internet traffic and encryption becomes ever more universal, the contest between the metadata we inevitably leak and the tools that can exploit it is only going to intensify, and this work shows that the tools are getting faster, more flexible, and harder to outgrow.
Subject of Research: Identification of encrypted network video streams using Siamese neural networks
Article Title: Dynamic highly-scalable approach for encrypted network videostream identification
Article References: Dynamic highly-scalable approach for encrypted network videostream identification. (n.d.). https://doi.org/10.1007/s10586-026-06584-x
Image Credits: AI Generated
DOI: 10.1007/s10586-026-06584-x
Keywords: encrypted traffic analysis, video stream identification, Siamese neural networks, deep learning, network privacy, side-channel attacks, SSL/TLS, streaming platforms, traffic fingerprints, machine learning, network security, dataset
Cite Scienmag News
APA
MLA
Chicago
Cassandra Pierce. (September 30, 2026). Siamese Neural Networks Expose What You Watch, Even Behind Encryption. Scienmag. https://scienmag.com/siamese-neural-networks-expose-what-you-watch-even-behind-encryption/
Cassandra Pierce. “Siamese Neural Networks Expose What You Watch, Even Behind Encryption.” Scienmag, 30 September 2026, https://scienmag.com/siamese-neural-networks-expose-what-you-watch-even-behind-encryption/. Accessed 30 September 2026.
Cassandra Pierce. “Siamese Neural Networks Expose What You Watch, Even Behind Encryption.” Scienmag. September 30, 2026. https://scienmag.com/siamese-neural-networks-expose-what-you-watch-even-behind-encryption/
Copy citation
Download RIS
Tags: advanced machine learning techniques for traffic fingerprintingcybersecurity challenges in encrypted content deliverydatasetdeep learningdeep learning for encrypted traffic classificationencrypted traffic analysisEncrypted video stream identificationMachine learningmitigating privacy risks in online streamingnetwork privacynetwork securitynetwork traffic analysis using deep neural networksprivacy implications of encrypted streaming servicesprivacy vulnerabilities in SSL/TLS encrypted streamingscalable real-time video stream identificationSiamese neural networksSiamese neural networks for traffic analysisside-channel attacksside-channel information leakage in encrypted video streamsSSL/TLSstreaming platformstraffic fingerprintsvideo stream identificationvideo stream recognition behind encryption


