Can AI See What Is Happening Behind the Darknet?

The darknet is designed to hide identities and communications—but can AI still recognize what is happening inside its traffic? Our SafeSurf Darknet 2025 dataset explores how machine learning can detect, classify, and understand hidden network behaviors.
Like

Share this post

Choose a social network to share with, or copy the URL to share elsewhere

This is a representation of how your post may appear on social media. The actual post will vary between social networks

Beyond the Darknet: Teaching AI to Recognize Hidden Network Behavior

The darknet represents one of cybersecurity's most challenging environments. Technologies such as Tor, I2P, Freenet, ZeroNet, and VPNs provide valuable privacy and anonymity, but the same capabilities can also conceal malicious activities, command-and-control communications, and data exfiltration.

For cybersecurity researchers, this creates an important challenge:

Can we not only identify darknet traffic but also understand what is happening within it?

This question motivated our latest research.

From Detection to Understanding

Many existing darknet datasets focus primarily on a relatively simple question: Is this traffic normal or darknet?

But real-world threat intelligence requires more.

Security analysts may need to determine which anonymity technology generated the traffic and, more importantly, understand its underlying behavior. Existing datasets often lack this combination of platform diversity, detailed labeling, and behavioral information.

We therefore developed SafeSurf Darknet 2025, a new dataset designed to move darknet analysis from simple detection toward deeper traffic understanding.

Three Layers of Darknet Intelligence

What makes SafeSurf Darknet 2025 distinctive is its three-layer hierarchical structure.

Layer 1—Detection: Is the traffic normal or darknet?

Layer 2—Technology: If it is darknet traffic, does it belong to Tor, I2P, Freenet, ZeroNet, or a VPN?

Layer 3 — Behavior: What is actually happening? The dataset distinguishes browsing, FTP, video streaming, P2P sharing, email, audio streaming, chatting, and VoIP.

This means the same network traffic can progressively reveal more information—from identifying its presence to understanding its technology and behavioral characteristics.  For a deeper look at Darknet traffic, refer to Figure 1 below.

Figure 1. The three-layer SafeSurf Darknet 2025 concept: progressing from basic darknet detection to technology identification and fine-grained behavioral analysis.

Building the Dataset from Real Traffic

Rather than relying solely on previously published traffic, we constructed a controlled multi-node environment that combines physical and virtual machines.

Traffic was captured from realistic user activities across different darknet technologies using Wireshark, and CICFlowMeter transformed the captured packets into machine-learning-ready network flows.

Importantly, behaviors were intentionally generated and labeled according to their known capture sessions rather than relying on automated labeling. This allowed us to establish clearer ground truth for activities such as browsing, email, chatting, file transfer, streaming, P2P, and VoIP.

What Does SafeSurf Darknet 2025 Contain?

At the first level, the dataset contains 360,358 normal flows and 91,404 darknet flows.

Those darknet flows are further categorized across the five technologies, including 26,284 Freenet, 25,499 ZeroNet, 22,958 I2P, 12,546 Tor, and 4,117 VPN flows. The third layer then organizes them into eight behavioral categories.

Each record contains 79 flow-level statistical and temporal features, providing a rich foundation for machine learning, traffic profiling, anomaly detection, and threat-intelligence research. Figure 2 explores the SafeSurf Darknet 2025 at a Glance.

Figure 2. SafeSurf Darkby technologynet 2025 at a glance, highlighting its hierarchical labeling, multi-platform coverage, behavioral diversity, and machine-learning-ready feature set.

Can Machine Learning Actually Recognize It?

To find out, we benchmarked eight supervised machine-learning approaches.

The results were encouraging: the best models achieved 99.46% accuracy for Normal vs. Darknet detection, 96.21% for Darknet technology classification, and 84.93% for behavioral classification.

The declining accuracy across the three layers also tells an interesting story: detecting darknet traffic is easier than understanding what users are actually doing within it.

That deeper behavioral classification remains an important challenge—and an interesting direction for future cybersecurity research.

Why This Matters

Darknet technologies are inherently dual-use. They provide legitimate privacy and anonymity while also creating environments that can conceal cyber threats.

For defenders, simply knowing that darknet traffic exists may therefore not be enough. Understanding which technology is being used and what behavioral patterns are occurring could provide richer information for intrusion detection, traffic profiling, and cyber threat intelligence.

By publicly releasing SafeSurf Darknet 2025, we aim to provide researchers with a realistic foundation for developing and evaluating the next generation of intelligent darknet analysis techniques.

Final Thoughts

The darknet is designed to hide communication, but hidden does not necessarily mean invisible.

With SafeSurf Darknet 2025, we move beyond simply asking “Is this darknet traffic?” toward a more challenging question:

“What is happening inside it?”

We hope this dataset helps researchers develop more intelligent, behavior-aware, and practical cybersecurity solutions for understanding encrypted and anonymized network environments.

Published article:
SafeSurf Darknet 2025: A Novel Dataset for Darknet Traffic Detection and Analysis
Cluster Computing, Springer Nature -  https://doi.org/10.1007/s10586-025-05868-y

Please sign in or register for FREE

If you are a registered user on Research Communities by Springer Nature, please sign in

Follow the Topic

Mobile and Network Security
Mathematics and Computing > Computer Science > Data and Information Security > Mobile and Network Security
Artificial Intelligence
Mathematics and Computing > Computer Science > Artificial Intelligence
Principles and Models of Security
Mathematics and Computing > Computer Science > Data and Information Security > Principles and Models of Security
Crime Control and Security
Humanities and Social Sciences > Society > Criminology > Crime Control and Security
Data and Information Security
Mathematics and Computing > Computer Science > Data and Information Security

Related Collections

With Collections, you can get published faster and increase your visibility.

Dialog Agents Between Promise and Reality: Linguistic, Cognitive, and Societal Perspectives on Conversational AI

Large Language Models (LLMs) are now widely deployed as conversational agents in healthcare, education, customer service, and personal companionship. These systems are frequently described, by both developers, media, and users alike, as "intelligent," "empathetic," or even "understanding." Yet the gap between what these agents appear to do and what they actually do remains poorly examined in public discourse and, in many cases, in the research literature itself. This special issue takes that gap as its starting point.

This collection brings together researchers from linguistics, cognitive science, philosophy of mind, AI ethics, and machine learning to interrogate the assumptions, capabilities, and societal consequences of contemporary dialog agents. Rather than treating LLM-based conversational systems as a technical achievement to be optimized, this special issue asks what these systems mean for how we understand language, cognition, social interaction, and the boundaries of machine capability.

This collection builds on the intellectual community developed through the LaCATODA (Language and Computing – Advanced Topics on Our Digital Assistance) workshop series, which has explored the intersection of computational methods and human communicative phenomena, such as humor, emotion, cognition, and cultural context, for several years. This collection is grounded in the editorial team’s combined expertise in natural language processing, affect analysis, computational humor, cross-cultural communication, and machine ethics, which are areas that sit precisely at the boundary between technical AI research and the broader humanistic and social inquiry that defines Cluster Computing.

Topics of interest include, but are not limited to:

• Critical analysis of claims about "intelligence," "empathy," or "understanding" in dialog agents, including philosophical, linguistic, and empirical challenges to such claims.

• Cross-cultural and cross-linguistic studies of conversational AI, how humor, politeness, emotional expression, sarcasm, and metaphor are (mis)handled across languages and cultural contexts.

• The role of common sense reasoning, cognitive architectures, and neuro-symbolic methods in making dialog agents more transparent and accountable, rather than merely more fluent.

• Societal impact studies examining user trust, emotional dependency, manipulation, and informed consent in human-agent interaction.

• Ethical frameworks and governance proposals for conversational AI deployed in healthcare, education, companionship, and other sensitive social contexts.

• Affect detection and generation in dialog systems, critical evaluation of what these systems actually capture versus what they claim to capture, and the risks of simulated empathy.

• Participatory and community-based approaches to dialog agent design that center the perspectives of marginalized or underrepresented user groups.

Authors should prepare their manuscript according to the Instructions for Authors available from the Journal’s submission guidelines: https://link.springer.com/journal/10586/submission-guidelines. Submitted papers should present original, unpublished work, relevant to one of the topics of the special issue. All submitted papers will be evaluated on the basis of relevance, significance of contribution, technical quality, scholarship, and quality of presentation by at least two independent reviewers. It is the policy of the journal that no submission, or substantially overlapping submission, be published or be under review at another journal or conference at any time during the review process.

The papers will undergo the standard, rigorous journal review process and be accepted only if well-suited to the topic of this special issue and meeting the scientific level of the journal. Final decisions on all papers are made by the Editor in Chief.

Publishing Model: Hybrid

Deadline: Mar 31, 2027