Can AI See What Is Happening Behind the Darknet?

The darknet is designed to hide identities and communications—but can AI still recognize what is happening inside its traffic? Our SafeSurf Darknet 2025 dataset explores how machine learning can detect, classify, and understand hidden network behaviors.

Beyond the Darknet: Teaching AI to Recognize Hidden Network Behavior

The darknet represents one of cybersecurity's most challenging environments. Technologies such as Tor, I2P, Freenet, ZeroNet, and VPNs provide valuable privacy and anonymity, but the same capabilities can also conceal malicious activities, command-and-control communications, and data exfiltration.

For cybersecurity researchers, this creates an important challenge:

Can we not only identify darknet traffic but also understand what is happening within it?

This question motivated our latest research.

From Detection to Understanding

Many existing darknet datasets focus primarily on a relatively simple question: Is this traffic normal or darknet?

But real-world threat intelligence requires more.

Security analysts may need to determine which anonymity technology generated the traffic and, more importantly, understand its underlying behavior. Existing datasets often lack this combination of platform diversity, detailed labeling, and behavioral information.

We therefore developed SafeSurf Darknet 2025, a new dataset designed to move darknet analysis from simple detection toward deeper traffic understanding.

Three Layers of Darknet Intelligence

What makes SafeSurf Darknet 2025 distinctive is its three-layer hierarchical structure.

Layer 1—Detection: Is the traffic normal or darknet?

Layer 2—Technology: If it is darknet traffic, does it belong to Tor, I2P, Freenet, ZeroNet, or a VPN?

Layer 3 — Behavior: What is actually happening? The dataset distinguishes browsing, FTP, video streaming, P2P sharing, email, audio streaming, chatting, and VoIP.

This means the same network traffic can progressively reveal more information—from identifying its presence to understanding its technology and behavioral characteristics.  For a deeper look at Darknet traffic, refer to Figure 1 below.

Figure 1. The three-layer SafeSurf Darknet 2025 concept: progressing from basic darknet detection to technology identification and fine-grained behavioral analysis.

Building the Dataset from Real Traffic

Rather than relying solely on previously published traffic, we constructed a controlled multi-node environment that combines physical and virtual machines.

Traffic was captured from realistic user activities across different darknet technologies using Wireshark, and CICFlowMeter transformed the captured packets into machine-learning-ready network flows.

Importantly, behaviors were intentionally generated and labeled according to their known capture sessions rather than relying on automated labeling. This allowed us to establish clearer ground truth for activities such as browsing, email, chatting, file transfer, streaming, P2P, and VoIP.

What Does SafeSurf Darknet 2025 Contain?

At the first level, the dataset contains 360,358 normal flows and 91,404 darknet flows.

Those darknet flows are further categorized across the five technologies, including 26,284 Freenet, 25,499 ZeroNet, 22,958 I2P, 12,546 Tor, and 4,117 VPN flows. The third layer then organizes them into eight behavioral categories.

Each record contains 79 flow-level statistical and temporal features, providing a rich foundation for machine learning, traffic profiling, anomaly detection, and threat-intelligence research. Figure 2 explores the SafeSurf Darknet 2025 at a Glance.

Figure 2. SafeSurf Darkby technologynet 2025 at a glance, highlighting its hierarchical labeling, multi-platform coverage, behavioral diversity, and machine-learning-ready feature set.

Can Machine Learning Actually Recognize It?

To find out, we benchmarked eight supervised machine-learning approaches.

The results were encouraging: the best models achieved 99.46% accuracy for Normal vs. Darknet detection, 96.21% for Darknet technology classification, and 84.93% for behavioral classification.

The declining accuracy across the three layers also tells an interesting story: detecting darknet traffic is easier than understanding what users are actually doing within it.

That deeper behavioral classification remains an important challenge—and an interesting direction for future cybersecurity research.

Why This Matters

Darknet technologies are inherently dual-use. They provide legitimate privacy and anonymity while also creating environments that can conceal cyber threats.

For defenders, simply knowing that darknet traffic exists may therefore not be enough. Understanding which technology is being used and what behavioral patterns are occurring could provide richer information for intrusion detection, traffic profiling, and cyber threat intelligence.

By publicly releasing SafeSurf Darknet 2025, we aim to provide researchers with a realistic foundation for developing and evaluating the next generation of intelligent darknet analysis techniques.

Final Thoughts

The darknet is designed to hide communication, but hidden does not necessarily mean invisible.

With SafeSurf Darknet 2025, we move beyond simply asking “Is this darknet traffic?” toward a more challenging question:

“What is happening inside it?”

We hope this dataset helps researchers develop more intelligent, behavior-aware, and practical cybersecurity solutions for understanding encrypted and anonymized network environments.

Published article:
SafeSurf Darknet 2025: A Novel Dataset for Darknet Traffic Detection and Analysis
Cluster Computing, Springer Nature -  https://doi.org/10.1007/s10586-025-05868-y