ConceptioArchivearXiv CS
arXiv CSopen access

Observing the Relationship between QoS Unpredictability, Prediction Error, and User Activity in a Remote Desktop Service

Unknown · 2026 · arxiv_cs
arXiv CS · Papers · License: Open Access · 2026
Open Source ↗Direct PDF ↓
distributedsystemsprotocols
networking, internet, protocols, distributed systems

Journal of Information Processing Vol.26 1–10 (Jan. 2018) [DOI: 10.2197/ipsjjip.26.1]

Regular Paper

Observing the Relationship between QoS Unpredictability, Prediction Error, and User Activity in a Remote Desktop Service Keisuke Ishibashi1,a) Xuliang Deng1,†1 Yoshiaki Kitaguchi2 Kenichi Nagami3 Ichiro Mizukoshi4 Akira Sato5 Daiyu Nobori6 Received: June 10, 2026, Accepted: xx xx, xxxx

arXiv:2607.28216v1 [cs.NI] 30 Jul 2026

Abstract: With the increasing need for remote work, especially since the COVID-19 era, Remote Desktop Services

(RDS) have become widely used. Because interactive RDS usage depends heavily on communication quality, some studies have investigated the relationship between QoS metrics and user activity in RDS. However, these works have been conducted in experimental environments, where the number of samples is limited and may not reflect real-world usage. Consequently, the relationship between temporal fluctuations in QoS and user activity remains underexplored. This paper investigates the relationship between QoS statistics and user activity using real-world usage logs of an RDS, Thin-Telework System. We analyze time-series data of round-trip time (RTT), the number of sent packets, and the number of received bytes per user. Notably, we find that not only the average RTT but also its temporal fluctuation (e.g., standard deviation over time) and its instantaneous deviation from the mean are significantly associated with user activity. From the users’ perspective, these features correspond to QoS unpredictability and the prediction error, respectively, and may provide insights into psychological mechanisms underlying user behavior. Keywords: Remote Desktop Service, QoS, User Activity, Unpredictability, Prediction Error

1.

Introduction

Remote work using virtual desktop solutions, such as Remote Desktop Services (RDS), Desktop as a Service (DaaS) and Virtual Desktop Infrastructure (VDI), has become widespread, especially since the COVID-19 era, because these technologies enable off-site work with relatively low security risk (Hereafter, we use the term RDS for all the above services). When employees run software on their own or company-issued PCs off-site, sensitive data may leak through cached files or local logs. In contrast, RDS transmits only graphical display frames, so the main remaining risk is eavesdropping, which can be mitigated with encrypted channels. Thanks to these advantages, the global RDS market grew to USD 27.62 billion in 2023 [1]. Despite these benefits, some users suffer degraded interactive performance and user experience, when communication quality, or Quality of Service (QoS), is low. Smooth RDS operation depends on QoS because a wide variety of tasks, document editing, slide creation, chatting, and online meetings, are streamed through the network. Tolia et al. investigated how network performance limits thin-client usability and found that latency poses 1 2 3 4 5 6 †1 a)

International Christian University Institute of Science Tokyo INTEC Inc. NTT EAST University of Tsukuba Information-Technology Promotion Agency, JAPAN Presently with Meta Platforms, Inc. [email protected]

© 2018 Information Processing Society of Japan

a greater challenge than bandwidth; users start noticing lag when round-trip time (RTT) exceeds 150 ms [2]. Taylor et al. empirically evaluated the impact of network latency and different remote-desktop delivery methods on user performance and behavior [3]. Burke & Figueroa investigated the relationship between QoS and QoE for RDS and reported that latency sensitivity is application-dependent; for example, text editing satisfaction declined sharply once latency rose above 60 ms [4]. While previous studies have clarified users’ QoE under specific QoS conditions in detail, they were all conducted in controlled experimental environments. In recent years considerable progress has been made in assessing the impact of QoS on QoE, user activity, and user engagement in real-world settings, for example in large-scale video streaming services [5], [6], [7]. By analyzing real-world usage data, these studies have revealed genuine reductions in user activity during periods of QoS degradation, effects that controlled lab experiments often fail to capture. However, owing to the distributed nature of RDS across clients and servers, measuring a large number of client–server pairs via network measurement has remained difficult. In this paper, we investigate the relationship between QoS and user communication behavior in the Thin-Telework System, an RDS relaying platform developed in 2020 to facilitate remote work during the COVID-19 era [8]. The service relays RDS traffic as depicted in Figure 1 and reached 671, 929 users by March 2026. We extracted time-series data of latency (RTT), the numbers of sent packets, and the number of received bytes

1

Journal of Information Processing Vol.26 1–10 (Jan. 2018)

2.

Fig. 1

Measurement Environment

from anonymized access logs. We then examine how RTT relates to two network-level proxies for user activity: the number of sent packets, which primarily reflects user-generated input such as keystrokes and mouse movements, and the number of received bytes, which consists mainly of graphical frames returned from the office PC. While these metrics do not directly measure usability or subjective QoE, they provide large-scale, objective evidence of how QoS conditions correlate with observable user behavior—a perspective that prior laboratory studies cannot offer. In addition to examining the relationship between average RTT and user activity, we also investigate the relationship between other RTT statistics and user activity, and find that both temporal fluctuation and instantaneous deviation from the mean are associated with reduced usage. Specifically, we calculate three metrics, Exponential Moving Average (EMA), Exponential Moving Standard Deviation (EMSD), and the difference from the previous EMA value (Diff). Our main contributions are as follows: • We provide a large-scale observational analysis of QoS statistics and network-observable user activity in a realworld RDS, using logs from 19,819 users and 39,737,619 active one-minute slots. • Beyond average RTT, we examine history-aware QoS statistics, namely EMA, EMSD, and Diff, and show that temporal variability and prediction-error-like features are more strongly associated with user activity when the mean RTT is below 100 ms. • We quantify the relative importance of these features using LightGBM and SHAP values, and show that EMSD and Diff are stronger predictors of user activity than EMA. Rather than measuring subjective QoE directly, this work complements prior laboratory studies by providing large-scale observational evidence on network-observable user activity. The rest of the paper is organized as follows. Section 2 reviews related work on QoE evaluation for RDS, effect of QoS on QoE in the real world, and QoS predictability. Section 3 describes our measurement environment and dataset. Section 4 presents our analysis of QoS statistics, user activity, and their relationships. Section 5 discusses the results and their limitations. Finally, Section 6 summarizes the findings and outlines future work.

© 2018 Information Processing Society of Japan

Related Works

2.1 Effect of QoS on User Activity in the Wild Considerable progress has recently been made in studying the effect of QoS on QoE, user activity, and user engagement “in the wild,” that is, how engagement, or users’ service usage, decreases when QoS degrades [5] [6] [7] [9] [10] [11] [12]. One representative behavioral change is abandoning an application such as video streaming: users tend to stop watching when playback stalls (i.e., buffering), which is often induced by increased packet loss or network latency. For example, Dobrian et al. reported that a 1% increase in buffering ratio can reduce user engagement by more than three minutes during a 90-minute live event [6]. Beyond video streaming, numerous studies have examined web transactions. For instance, a 500 ms latency increase results in a 20% drop in traffic [13], and a 100 ms increase can cause a 7% decrease in conversion rates [14]. Thakkar et al. used a quasiexperimental approach for an online e-mail service and found that raising latency to 500 ms reduced user activity by 12%. Unfortunately, such large-scale field studies have not been conducted for RDS. Moreover, most existing works focus on average latency and neglect finer-grained statistics such as temporal deviation or trend. 2.2 QoE and User Activity in RDS In contrast, prior RDS studies have mainly relied on controlled laboratory experiments. These studies clarify latency sensitivity and subjective user perception, but they do not provide large-scale observational evidence from real-world deployments. Tolia et al. measured how network performance limits thinclient usability and showed that latency poses a greater challenge than bandwidth; users begin to notice lag when RTT exceeds approximately 150 ms [2]. Taylor et al. empirically evaluated the impact of network latency and different remote-desktop delivery methods on user performance and behavior [3]. In their experiment, thin-client users performed three tasks, document editing, photo editing and a non-interactive game, under latencies of 30, 60, 120, and 240 ms. User satisfaction for document editing dropped sharply, whereas satisfaction for photo editing and game remained moderate even at 240 ms. Burke and Figueroa further reported that latency sensitivity is application-dependent, with text editing satisfaction declining sharply once latency exceeds 60 ms [4]. Arellano-Uson et al. developed a method to estimate application-level interactive latency, which is directly correlated with users’ QoE [15], and evaluated the relationship between this latency and the network-level RTT [16] for 47 users. They concluded that, when RTT is small, it is not a good indicator of application-level latency because of the processing delay in local computers, but that once RTT exceeds 15 ms, it becomes the primary component of interactivity time. Although these studies provide detailed insights into QoE under specific QoS conditions, they were conducted in controlled laboratory environments. Consequently, the findings may not fully capture real-world usage and rely largely on questionnairebased subjective assessments. This work complements prior QoE

2

Journal of Information Processing Vol.26 1–10 (Jan. 2018)

studies by providing large-scale observational evidence of how QoS statistics relate to user activity in real-world RDS usage. 2.3 QoS Predictability Temporal trends or deviations in QoS directly influence its predictability, which in turn strongly affect user engagement and QoE. For video streaming, low jitter is essential to prevent receiverbuffer overflow or underflow, both of which cause playback stalls. In adaptive streaming, the bit-rate and buffer size are continually adjusted to QoS (e.g. latency or throughput) [17] [18] [19]; consequently, prediction errors can severely degrade QoE. Beyond application-level control, fluctuating QoS reduces predictability from the human user’s perspective and thus has psychological consequences. Sabet et al. showed that online-game players can adapt to a certain amount of delay, as long as that delay remains stable [20]. Conversely, when QoS is unpredictable, QoE declines; the same study notes that “regardless of performance, frequent delay switching annoys gamers.” In a different domain, Obafemi et al. argue that QoE models for Voice over Internet Protocol (VoIP) should incorporate jitter to one-way delay [21]. While prior work has suggested that QoS instability affects user experience across various services, a systematic, data-driven comparison of how mean latency, its variability, and instantaneous prediction error jointly predict user behavior, at scale and in real deployments, remains lacking. Motivated by these findings, we investigate how detailed QoS statistics are associated with user activity in the wild.

3.

Measurement Environment

3.1 Thin-Telework System We utilize usage data from an actual RDS platform, the Thin-Telework System. Thin-Telework System was developed by Information-technology Promotion Agency (IPA), Japan and NTT EAST, and entered service in April, 2020 to provide easy, secure remote access during the COVID-19 era [8]. Users install server software to their office computers and register them to the Thin-Telework System in advance. When they begin remote work, they connect from their home computer to the Thin-Telework relay server via a client application or web browser. The relay server authenticates each user and forwards packets between the home and office PCs. All traffic is carried over an SSL-VPN tunnel encrypted with TLS 1.3, so users do not need to modify the office firewall to accept inbound connections while security is maintained. 3.2 Measurement We deployed a packet-capture server in front of the ThinTelework relay servers and recorded the headers of packets exchanged between the relay and office PCs, and the relay and the home computer (Fig. 1). Capture was performed with administrative permission. Packet payloads were not stored; IP addresses were anonymized and used to associate packets with individual TCP connections and to infer the user’s country of origin. We analyze one week of data collected from 11–17 December 2023.

© 2018 Information Processing Society of Japan

Fig. 2

Scatter plot of total sending bytes and receiving bytes for each client PCs. The red line shows the points where sending bytes and receiving bytes are equal. We can recognize three clusters; sending bytes larger than 106 and under the red line, receiving bytes larger than 106 and above the red line, sending bytes smaller than 106 and near the red line.

RTT was calculated between the capture server and each client PC (home PCs and office PCs). We matched the sequence numbers of packets sent from the relay servers with the acknowledgment numbers of the corresponding packets returned by the client PCs, and defined RTT as the timestamp difference between each matched pair. To avoid overestimation due to the Delayed ACK mechanism [22], packet pairs separated by more than 25 ms were discarded. Because packets from both home and office PCs traverse the capture point, we first separate the traffic into three groups: (1) office PCs (large upstream byte counts), (2) home PCs (large downstream byte counts), and (3) inactive clients (≤ 106 bytes in both directions), as illustrated by the scatter plot of sent versus received bytes in Fig. 2. The threshold of 106 bytes was chosen to exclude TCP connection setup and keep-alive traffic that does not reflect sustained RDS sessions; varying this threshold by an order of magnitude in either direction did not materially change the composition of the identified clusters. In RDS, home PCs mainly transmit user input events, whereas office PCs return screen images; therefore, home-PC flows exhibit far fewer sent than received bytes. To exclude automated or overseas usage, we restrict the dataset to home PCs located in Japan, identified via a Geo-IP service [23]. The resulting dataset contains 19, 819 unique home-PC IP addresses. There exist many QoS metrics other than RTT, the reason why we choose RTT is explained in the next subsection, as well as the rationale for using the number of packets sent and bytes received as proxies of user activity. We then aggregate the packet data into 60-second slots and compute the mean RTT within each slot. This yields an RTT time series of length 10, 080(= 60 × 24 × 7) for every user, which we use as the primary QoS indicator. For user-activity indicators, we use the number of packets sent and the number of bytes received by each home PC during the same 60-second slot. We then extract time slots that contain at least one RTT sample and a non-zero packet count. With one week of data, there are 10, 080 one-minute slots for each of the 19, 819 users, and by excluding inactive slots we obtain 39, 737, 619 active time-slot samples. This sample size is sufficient for our analysis of short time-scale phenomena at the

3

Journal of Information Processing Vol.26 1–10 (Jan. 2018)

one-minute level. On the other hand, longer time-scale effects, such as seasonal effects or long-term trends in which user context may change, are left for future work. 3.3 Metrics of User Activity and QoS 3.3.1 User Activity Metrics In the target RDS use case (the Thin-Telework System), the main purpose of use is expected to be office work. Figure 3 shows the number of unique client IP addresses that appear in each hour during the one-week measurement period. It exhibits a typical daily pattern, with a clear increase between 9 a.m. and 5 p.m. from Monday to Friday, which indicates that the system is mainly used for office work. In the office applications used on this system, users provide input via keyboard and mouse and then wait for the graphical frames returned from the office PC. Although these input and output events are not directly observed in the network, the number of packets sent and the number of bytes received can be regarded as proxies for these events. In Appendix A.1, we conduct a small experiment to confirm that the number of packets sent and the number of bytes received depends on the user activity for office applications. 3.3.2 QoS Metrics Various QoS metrics may be relevant to remote interactive applications. In this study, we focus on RTT as the primary QoS metric for analyzing user activity for the following reasons: • Previous laboratory studies have reported that latency is the primary QoS factor for such remote desktop applications [2], [3], and [4]. • RTT reflects both delay and jitter, because jitter is the temporal variation of delay and can be captured through temporal fluctuations of RTT. In our analysis, EMSD is introduced to quantify this variability. • Since the RDS sessions run over TCP, packet loss is recovered by retransmissions and mainly appears as additional delay due to the retransmission or as reduced throughput due to congestion control. In other words, the impact of moderate loss is largely reflected in the effective RTT and its variability. • The office applications considered here do not appear to be strongly throughput-sensitive, in contrast to video-streaming applications. In addition, the 99th percentile of the number of bytes received in 60 seconds is about 14 MB (see Fig. 5), which corresponds to approximately 1.8 Mbps. Because this value is significantly smaller than typical accesslink capacities today, throughput limitations are unlikely to be the primary cause of user activity degradation in our environment. However, a joint analysis of throughput and RTT for throughput-sensitive applications is an important topic for future work.

4.

Analysis Results

4.1 Basic Statistics First, we present basic traffic and QoS statistics for home PCs.

© 2018 Information Processing Society of Japan

Fig. 3

Time Series of Number of Unique IP Addresses. X-axis starts with the beginning of the measurement, period, Monday 0 a.m. December 11th, 2023.

Fig. 4

CCDF of the number of sent packets from home PC in 60 seconds

Figures 4 and 5 show the complementary cumulative distribution functions (CCDFs) for the number of packets sent and the number of bytes received per 60-second slot for all home-PC clients. Although the two CCDFs exhibit a similar shape, their x-ranges differ. Both CCDFs reveal step-like drops. For example, the CCDF of sent packets falls sharply around 12 and 60 packets, reflecting periodic keep-alive messages sent every five seconds or one second, respectively. Despite focusing on active home PCs, a considerable number of time slots contain no user operations or think time. Excluding these keep-alive periods, the number of sent packets spans 102 to 104 , whereas received-bytes counts range from 103 to 107 . Among active users, the mean and median counts of sent packets are 1, 729 and 1, 072, respectively; for received bytes they are 2, 149, 247 and 468, 423. Figure 6 depicts the CCDFs of home-PC RTT. RTT values range from 2 ms to 300 ms, and 70% of time slots fall between 10 and 100 ms. We also plot office-PC RTT, which are markedly smaller. This is because most office PCs use wired connections and are geographically close to the Tokyo relay servers, whereas home PCs are distributed nationwide and may use wireless access. The average RTTs are 25 ms for home PCs and 8 ms for office PCs. Although users perceive the sum of relay-to-home and relayto-office RTTs, the latter is relatively small and stable, we focus on the home-PC RTT as the primary QoS metric in subsequent analyses. 4.2 Relationship between RTT Statistics and User Activity 4.2.1 Association between Instantaneous RTT and User Activity We next investigate how RTT statistics are associated with user activity. Figures 7 and 8 plot scatter diagrams of RTT versus the number of packets sent, bytes received, respectively; each point

4

Journal of Information Processing Vol.26 1–10 (Jan. 2018)

CCDF of the number of received bytes by home PC in 60 seconds

Fig. 11

Median of number of sent packets for binning Exponential Moving Average (EMA)

CCDF of average RTT between relay servers and both Home and Office PC in 60 seconds

Fig. 12

Median of number of received bytes for binning Exponential Moving Average (EMA)

Fig. 13

Median of number of sent packets for binning Exponential Moving Standard Deviation (EMSD)

Fig. 5

Fig. 6

Fig. 7

Scatter plot for RTT and the number of sent packets

Fig. 8

Scatter plot for RTT and the number of received bytes

Fig. 9

Median of number of sent packets for binning RTT

Fig. 10

Median of number of received bytes for binning RTT

represents one 60-second time slot for a client. As RTT exceeds 30 ms, outliers with exceptionally high packet or byte counts dis-

© 2018 Information Processing Society of Japan

appear, and once RTT surpasses 100 ms, the majority of points with moderate activity also vanish. However, because the number of observed slots also decreases as average RTT increases, it is unclear whether this decline stems from reduced user activity or merely from fewer samples. To disentangle these factors, we group the data into 1 ms RTT bins and compute the median activity for each bin*1 . Figures 9 and 10 show the median numbers of packets sent and bytes received per bin. The previous trend, sharp drops beyond 30 ms and 100 ms, remain evident at the median level, confirming that they are not results of sample-count reduction. These findings align with earlier studies [2], [3]. There is a sharp drop below 10 ms, which we attribute to automated monitoring or keep-alive connections from within the same AS rather than genuine interactive user sessions; these slots are retained in the analysis because excluding them does not materially affect the trends observed above 10 ms. 4.2.2 Association between RTT History and User Activity Thus far, we have examined the instantaneous effect of RTT on user activity by analyzing data within the same 60 second slot. However, user behavior may also depend on preceding QoS conditions. To capture such history effects, we compute three exponentially weighted statistics for each slot: the exponential moving average (EMA, Et ), the exponential moving standard deviation (EMSD, S t ), and the one-step prediction error (Diff, Dt ). They are defined recursively as *1

We use the median to mitigate outlier effects, the mean would be influenced by rare bursts.

5

Journal of Information Processing Vol.26 1–10 (Jan. 2018)

Table 1

Fig. 14

Median of number of received bytes for binning Exponential Moving Standard Deviation (EMSD)

Fig. 15

Median of number of sent packets for binning Difference with Exponential Moving Average (Diff)

Fig. 16

Median of number of received bytes for binning Difference with Exponential Moving Average (Diff)

Et = αRt + (1 − α)Et−1 p S t := Vt

(1)

Vt := α(Rt − Et )2 + (1 − α)Vt−1

(2)

Dt = Rt − Et−1 ,

(3)

where Rt is the mean RTT in slot t. To capture short-term QoS history and to examine the effect of the smoothing factor, we use α = 0.8, 0.9, 0.95, and confirm that our main observations are robust across these values. In the literature, EMA is used to model human expectation for continuous stimuli [25]; accordingly, we interpret EMA as the user’s RTT expectation or prediction, EMSD as RTT instability or unpredictability, and Diff as the instantaneous prediction error. Figures 11, 12, 13, 14, 15, and 16 plot the medians of packets sent and bytes received against binned EMA, EMSD, and Diff (bin width = 1 ms). The EMA curves resemble those for the raw RTT mean, whereas both EMSD and Diff exhibit distinct patterns: (i) as EMSD increases up to around 20 ms, activity drops rapidly and then plateaus; (ii) as Diff increases beyond approximately 20 ms, activity again drops rapidly. Interestingly, values below about −2 ms are also associated with reduced activity. One possible explanation is that users prefer stable latency and do not immediately take advantage of sudden improvements; alternatively, large negative Diff may correspond to transitions from previously poor conditions, where user activity has already been discouraged. In contrast, a Diff of about −1 ms indicates a small improvement with tolerable latency variability, and user activity

© 2018 Information Processing Society of Japan

SHAP

Feature

RFI (Sent Packets)

RFI (Received Bytes)

EMA EMSD Diff

21.0% 31.8% 47.2%

23.5% 41.9% 33.4%

remains high. The above observations are common for all αs. Hereafter, we select α = 0.9 as the representative value because it corresponds to an effective memory window of approximately 10 slots (10 minutes), which aligns with plausible timescales of user adaptation to network conditions in interactive desktop tasks. To explore joint effects, we generate heat-maps of EMSD versus Diff for several EMA ranges (we use 20 ms bin for EMA in these heat-maps). Figure 17 shows heat-maps of time-slot counts. Note that the colors are drawn on a logarithmic scale. For heat maps with EMA smaller than 100 ms, there is a vertical stripe at EMSD < 10 ms and a horizontal stripe in the middle of the heat map, consistent with the marginal plots. Additional heat maps for sent packets and received bytes are shown in Figs. 18 and 19, respectively; cells with fewer than 100 samples are omitted to avoid sparse artifacts. The high-activity region—concentrated at low EMSD and near-zero Diff—is most clearly visible in the EMA = [0, 20] and [20, 40] panels, where the bright zone collapses sharply as EMSD exceeds approximately 10 ms or the absolute values of Diff exceed approximately 5 ms. This confirms that, at low mean latency, temporal stability rather than the mean level itself is the dominant correlate of user activity. As EMA increases, the horizontal stripes tilt upward, indicating that larger absolute Diff is tolerated when the baseline RTT is high, mirroring the asymmetry observed in Fig. 15. Taken together, these results suggest that, once mean latency is below 100 ms, its variability (EMSD) and prediction error (Diff) show stronger association with user activity, consistent with psychological and reinforcement-learning studies that emphasize prediction error as a primary driver of human response [26]. 4.2.3 Significance of RTT-derived Features To quantify the observations in the previous section, we evaluate the relative importance of the three RTT-derived features, EMA, EMSD, and Diff, in predicting user activity. We train a LightGBM regressor [27] to predict the numbers of packets and bytes, and compute SHAP (SHapley Additive exPlanations) values [28] for each feature. The SHAP value ϕ(i j) of feature j in sample i is defined as

ϕ(i j) := 

X (|N| − |S | − 1)!|S |! × |N|! S ⊂F\{ j}

 E[ f (X)|XS = xS , X j = x j ] − E[ f (X)|XS = xS ] ,

(4)

where N is the full feature set and f (·) is the prediction function (the LightGBM regressor). Because SHAP values are computed for each sample, we summarize them by the Relative Feature Importance (RFI): P ( j) i |ϕ | R j := P P i (k) k i |ϕi |

(5)

6

Journal of Information Processing Vol.26 1–10 (Jan. 2018)

Fig. 17

Heat-maps for the number of time slot counts for each EMSD and Diff bins, conditioning by EMA. Colors are drawn in log scale.

Fig. 18

Heat-maps for the number of sent packets for each EMSD and Diff bins, conditioning by EMA

Table 1 lists the results. Surprisingly, EMA has the lowest RFI. More precisely, Diff shows a higher importance score for sent packets, whereas EMSD shows a higher importance score for received bytes. One possible explanation is that the number of packets sent mainly reflects user input behavior and may be more sensitive to short-term deviations in RTT, which are captured by Diff. In contrast, the number of bytes received reflects a combination of user input and application-side responses (for example, screen updates), which may depend more on longer time-scale variability, as captured by EMSD.

5.

Discussion and Limitations

5.1 Activity Proxy and Its Limitations We use the number of sent packets and the number of received bytes as coarse, network-level proxies for user activity, as user activity cannot be measured through encrypted network data. These metrics reflect a combination of application type and usage patterns rather than direct observations of user actions.

© 2018 Information Processing Society of Japan

That said, these proxies have several limitations that should be kept in mind when interpreting the results. First, they do not directly distinguish between user think time and active input periods. Second, they depend on application-specific behaviors such as batching, compression, and rendering mechanisms. As a result, the same level of user activity may produce different traffic patterns across applications. If application types or contexts could be inferred, a more finegrained analysis of user activity would be possible. In particular, separating user think time from active interaction periods would provide deeper insights into user behavior. 5.2 QoS Metrics RTT is estimated from seq/ack matching and is therefore only available during bidirectional packet exchanges. In low-activity slots, fewer matched pairs may be available, potentially introducing a selection bias toward slots with higher activity levels. This may cause the observed RTT distributions in low-activity regimes

7

Journal of Information Processing Vol.26 1–10 (Jan. 2018)

Fig. 19

Heat-maps for the number of received bytes for each EMSD and Diff bins, conditioning by EMA

of-day effects—for example, in the early morning both RTT and user activity tend to be low. If such a factor affects QoS and user activity in the same direction, QoS degradation could spuriously appear to cause reduced user activity. We have not yet identified specific confounders of this kind; investigating them is left for future work.

Fig. 20

Possible causal relations between QoS and packet/byte counts

to be less reliable. 5.3 Observation Period The dataset covers only one week in mid-December. Although this is sufficient for analyzing short-term relationships at the oneminute time scale, it does not capture longer-term variations such as seasonal effects, holiday schedules, or period-specific work patterns. Accordingly, the generality of the results beyond the observed week remains to be validated using longer-term measurements. 5.4 Causality and Confounders We have confirmed correlations between QoS statistics and packet/byte counts, which we treat as network-observable proxies for user activity. The associations between EMSD, Diff, and user activity are consistent and robust across values of α, suggesting that these statistics may serve as useful signals of changes in user activity. Nevertheless, correlation does not imply causation, and several alternative explanations warrant consideration. Figure 20 summarizes the possible relationships, which we discuss in turn. (a) Confounding factors. A common factor may influence both QoS and user activity (and hence the packet/byte counts). Candidates include application type, user context, and time-

© 2018 Information Processing Society of Japan

(b) Reverse causality. Rather than QoS degradation reducing user activity, increased packet and byte counts—driven by higher user activity or a change of application—could congest the network and thereby degrade QoS. This would induce a negative correlation from user activity to QoS. Because such reverse causality opposes the positive association we observe, its presence would imply that the true effect from QoS to user activity is even stronger than the observed correlation suggests. However, the average bit rate is low (see below), so network-level congestion of this kind appears unlikely in our environment. (c) Intermediate factors. RTT can also affect packet/byte counts through TCP congestion-avoidance algorithms. As discussed in section 3.3.2 the average bit rate for an RDS session (about 1.8 Mbps) is significantly smaller than typical available bandwidth today; we therefore expect that TCP congestion avoidance does not constrain the sending rate, even in a high-RTT environment. A joint analysis of throughput and RTT for throughput-sensitive applications nonetheless remains important future work. In summary, the observed relationships should be interpreted as correlations between QoS statistics and network-observable user activity. A more rigorous causal analysis, using application-level measurements or controlled experiments, is left for future work.

6.

Conclusion

We analyzed one week of real-world RDS logs and examined how RTT is associated with user activity. Beyond the mean latency, we introduced two history-aware features, EMSD and

8

Journal of Information Processing Vol.26 1–10 (Jan. 2018)

Diff, and found that both are strongly correlated with user activity when the mean RTT is below 100 ms. In practice, once the average latency is kept within an acceptable range, monitoring latency stability through EMSD and Diff may offer more informative signals of user experience changes than monitoring mean latency alone. From the users’ perspective, fluctuation represents difficulty in predicting QoS, whereas deviation represents prediction error of QoS. These findings highlight the importance of interpreting QoS statistics through a psychological lens. We believe that our results can inform more efficient network and application control; if these correlations reflect causal effects, operators should prioritize predictability and minimize fluctuations once the average latency is within an acceptable range. To our knowledge, this is the first large-scale RDS study that links sub-100 ms temporal QoS statistics to observed user communication behavior. Acknowledgments This research was supported by a grant from the Telecommunications Advancement Foundation.

[15]

[16]

[17] [18] [19]

[20]

[21] [22]

References [1]

[2] [3]

[4] [5]

[6] [7] [8] [9]

[10]

[11]

[12]

[13] [14]

Hardware & Software IT Services, “Device as a Service (DaaS) Market Size, Share & Industry Analysis,” Fortune Buisiness Inside, https://www.fortunebusinessinsights.com/device-as -a-service-market-108000. [Online, accessed 8-June-2026] N. Tolia, D. G. Andersen, and M. Satyanarayanan, “Quantifying interactive user experience on thin clients,” IEEE Computer, vol. 39, no. 3, pp. 46–52, Mar. 2006. B. Taylor, Y. Abe, A. K. Dey, and M. Satyanarayanan, “Virtual machines for remote computing: Measuring the user experience,” Carnegie Mellon University Technical Report CMU-CS-15-101, Pittsburgh, PA, Jan. 2015. A. Burke and M. Figueroa, “Latency perception in cloud-based workspaces and environments,” SMPTE Motion Imaging Journal, vol. 130, no. 7, pp. 31–38, Aug. 2021. C. Moldovan, F. Wamser, T. Hoßfeld, “User Behavior and Engagement of a Mobile Video Streaming User from Crowdsourced Measurements,” in Proc. 2019 Eleventh International Conference on Quality of Multimedia Experience (QoMEX), June 2019. F. Dobrian, et al., “Understanding the Impact of Video Quality on User Engagement,” ACM SIGCOMM Computer Communication Review, Vol. 41, Issue 4, August 2011. S. S. Krishnan and R. K. Sitaraman, “Video Stream Quality Impacts Viewer Behavior,” in Proc. ACM Internet Measurement Conference (IMC), November 2012. NTT EAST–IPA, “Thin Telework System”, https://telework.cyber.ipa.go.jp/news/. [Online, accessed 8-June-2026] D. Raca, D. Leahy, C. J. Sreenan, and J. J. Quinlan, “Incorporating prediction into adaptive streaming algorithms: A QoE perspective,” in Proc. ACM Workshop on Network and Operating Systems Support for Digital Audio and Video (NOSSDAV ’18), Amsterdam, Netherlands, June 2018, pp. 19–24. E. Plakia, G. Mylonas, and P. Papadimitriou, “Should I stay or should I go: Analysis of the impact of application QoS on user engagement in YouTube,” ACM Trans. Multimedia Comput. Commun. Appl., vol. 16, no. 3, pp. 1–21, Aug. 2020. H. Koto, N. Fukumoto, S. Niida, H. Yokota, S. Arakawa, and M. Murata, “Users Reaction to Network Quality During Web Browsing on Smartphones,” in Proc. 26th International Teletraffic Congress (ITC), September 2014. N. Poggi, D. Carrera, R. Gavalda, and E. Ayguade, “Non-intrusive Estimation of QoS Degradation Impact on E-Commerce User Satisfaction,” in Proc. IEEE 10th International Symposium on Network Computing and Applications, August 2011. G. Linden. Geeking with greg. http://glinden.blogspot.com/ 2006/11/marissa-mayer-at-web-20.html, 2021. [Online, accessed 8-June-2026]. R. Morton and T. Barth. Akamai Online Retail Performance Report: Milliseconds Are Critical, https://www.ir.akamai.com/ news-releases/news-release-details/

© 2018 Information Processing Society of Japan

[23] [24] [25]

[26] [27] [28]

akamai-online-retail-performance -report-milliseconds-are Apr. 2017. [Online, accessed 8-June2026]. J. Arellano-Uson, E. Magana, D. Morato et al., “Protocolagnostic method for monitoring interactivity time in remote desktop services,” Multimed Tools Appl 80, 19107–19135 (2021). https://doi.org/10.1007/s11042-021-10708-3 J. Arellano-Uson, E. Magana, D. Morato and M. Izal, “Evaluation of RTT as an Estimation of Interactivity Time for QoE Evaluation in Remote Desktop Environments,” 2023 33rd International Telecommunication Networks and Applications Conference, Melbourne, Australia, 2023, pp. 240-245, doi: 10.1109/ITNAC59571.2023.10368539. T. Stockhammer, “Dynamic adaptive streaming over HTTP,” in Proc. ACM Conference on Multimedia Systems (MMSys), February 2011. T. Kimura, T. Kimura, A. Matsumoto, and K. Yamagishi, “Balancing Quality of Experience and Traffic Volume in Adaptive Video Streaming,” IEEE Access 9, pp. 15530 - 15547, 2021. M. Seufert, S. Egger, M. Slanina, T. Zinner, T. Hoßfeld, and P. T.GiaAuthors, “A Survey on Quality of Experience of HTTP Adaptive Streaming,” IEEE Communications Surveys & Tutorials, Vol. 17, issue 1, January 2015. S. Sabet, S. Schmid, and A. El Saddik, “Quantifying the impact of network delay switching on QoE in online multiplayer games,” in Proc. IEEE Global Communications Conference (GLOBECOM 2022), Rio de Janeiro, Brazil, Dec. 2022, pp. 3041–3046. A. Obafemi, A. L. Mohammed, and S. Misra, “Impact of jitter playout buffer on E-model in VoIP,” in Proc. 10th Int. Conf. on Networks (ICN 2011), St. Maarten, Netherlands Antilles, Jan. 2011, pp. 135–140. R. Braden, “Requirements for Internet Hosts – Communication Layers”, STD 3, RFC 1122, October 1989. MAXMIND, “GeoLite Databases and Web Services,” https://dev. maxmind.com/geoip/geolite2-free-geolocation-data/ J. A. Nieh, S. J. Yang, and N. Novik, “Measuring Thin-Client Performance Using Slow-Motion Benchmarking,” ACM Transactions on Computer Systems, Vol. 21, No. 1, Feb. 2003, pp. 87—115. A. C. Smit, E. Schat, E. Ceulemans, “The Exponentially Weighted Moving Average Procedure for Detecting Changes in Intensive Longitudinal Data in Psychological Research in Real-Time: A Tutorial Showcasing Potential Applications,” Assessment 30, pp. 1354–1368, 2023. W. Schultz, P. Dayan, and P. R. Montague, “A Neural Substrate of Prediction and Reward,” Science, vol. 275, no. 5306, pp. 1593–1599, Mar. 1997. lightgbm.LGBMRegressor, https://lightgbm.readthedocs. io/en/latest/pythonapi/lightgbm.LGBMRegressor.html [Online; accessed 8-June-2026]. S. Lundberg, and S.-I. Lee, “A Unified Approach to Interpreting Model Predictions,” Proceedings of the 31st International Conference on Neural Information Processing Systems (NIPS’17), pp. 4768 – 4777, 2017.

Appendix A.1

User Activity and Packet/Byte Count

To validate that the traffic metrics we observe in the logs are informative proxies for office-work activity levels, rather than, for example, background system traffic, we conducted a controlled traffic measurement experiment in which we ran office applications (Google Docs and Google Slides) via the Thin-Telework System and measured the generated traffic (the numbers of packets sent and received, and the numbers of bytes sent and received). For comparison, we also ran a YouTube video-watching session. For Google Docs and Slides, we prepared two conditions with high and low activity levels. Table A·1 summarizes the results. We observe that these traffic statistics depend on both the application and the activity level [24]. Traffic generated by Google Docs and Slides falls within the range observed in our measurement data (Figs. 4 and 5). Note that it is biased toward the upper part of the distribution because our experiment did not include user think time and involved only continuous interaction. In contrast, traffic generated by YouTube far exceeds this range.

9

Journal of Information Processing Vol.26 1–10 (Jan. 2018)

Table A·1

Traffic Statistics Per 60 Seconds for Different Applications and Activity Levels

User Activity Slide (High) Slide (Low) Docs (High) Docs (Low) Youtube

# of Packet Sent

# of Packet Received

# of Bytes Sent

# of Bytes Received

3,241 2,047 2,058 1,047 30 K

2,700 1,777 3,043 1,098 77 K

299 K 184 K 176 K 92 K 2,384 K

1,351 K 734 K 2,525 K 359 K 101,716 K

Keisuke ISHIBASHI received the B.S. and M.S. degrees in mathematics from Tohoku University, in 1993 and 1995, respectively, and the Ph.D. degree in information science and technology from The University of Tokyo, in 2005. From 1995 to 2018, he was with Nippon Telegraph and Telephone (NTT) Laboratories, where he was involved in research on the measurement and analysis of internet traffic and performance. He is currently a Professor of Information Science with International Christian University, Japan. He is a member of IEICE, IEEE, and the Information Processing Society of Japan (IPSJ).

Xuliang DENG received the B.A. degree in information science from International Christian University, Japan, in 2023, and the M.S. degree in information networking from Carnegie Mellon University in 2024. He has professional experience as a software engineer in both Japan and the U.S. He is currently a software engineer in industry.

Yoshiaki KITAGUCHI received the B.S. and M.S. degrees in Physics from Niigata University, Japan in 1995 and 1997, respectively. He joined INTEC Inc. as a Researcher in 1997. He received the Ph.D. degree in Information Systems Engineering from The University of Electro-Communications, Japan in 2005. From 2009 to 2016, he was an Assistant Professor at the Information Media Center, at Kanazawa University, Japan. He is currently an Associate Professor at the Global Scientific Information and Computing Center, Tokyo Institute of Technology, Japan since 2017. He has been engaged in the research and development of IPv6. He is a member of the IEEE Communications Society, ACM, IEICE, and Information Processing Society of Japan (IPSJ). © 2018 Information Processing Society of Japan

Kenichi NAGAMI received the M.S degree in 1992, the Ph.D. in 2001, both from Tokyo Institute of Technology, Japan. In 1992, he joined Research and Development Center, Toshiba Corporation where he focused on communication systems. Since 2002, he has been with INTEC NetCore, and currently works in the Research and Development Department at INTEC.

Ichiro MIZUKOSHI received his B.S. degree in Mathematics from Waseda University, Japan, in 1986, and his M.S. degree in Management Science from Tsukuba University, Japan, in 1992. He has worked on various online services and Internet Service Providers (ISPs). In 1997, he joined NTT (Nippon Telegraph and Telephone Corporation), and since 2006, he has been working at NTT East. He is a member of the Information Processing Society of Japan (IPSJ).

Akira SATO received his Ph.D. from University of Tsukuba in 1998. He is an associate professor in Department of Information Engineering, Academic Computing and Communications Center at University of Tsukuba. His current research interest is an operation of academic networks. He is a member of the Information Processing Society of Japan (IPSJ).

Daiyu NOBORI is a software engineer and an entrepreneur. His development and research interests include systems software such as Virtual Private Network (VPN), distributed systems, and security. He entered University of Tsukuba in 2003 and started up a company, SoftEther Corporation in 2004. He acquired a Ph.D. degree at the Department of Computer Science, University of Tsukuba in 2017. He has been an visiting professor at University of Tsukuba since April 2022. He has developed SoftEther VPN, a cross-platform multi-protocol VPN program, made it public for free, and opened its source code in 2014.

10

Record · ID 414064 · SHA-256 a140bca6e71bd7ca
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.