Lune

CCS2026Top-tier venue

Understanding the Privacy-Preserving Potential of HTTP/2 Against Webpage Fingerprinting

Bogdan Constantin Cebere, Prateek Kumar, Sylvain Chatel, Wouter Lueks, Christian Rossow

2026Year

Abstract

Website fingerprinting (WF) attacks can infer which webpage a user visits from encrypted HTTPS traffic alone, compromising privacy even without decryption. WF defenses commonly shape traffic through noise, padding, delays, or flow splitting -yet they are most often studied from the perspective of encapsulating protocols like Tor or VPN rather than at the application layer (HTTP).

In this work, we focus on application-layer defenses enabled by the most widely deployed version of HTTP -HTTP/2. We demonstrate how known defenses can be emulated through HTTP/2 features at the client side (HTTPOS, LLaMA, FRONT, Tamaraw) and the server side (ALPaCA, Tamaraw). We further show that HTTP/2 features -such as proactive resource suggestion, multiplexing, and flow control -offer untapped potential for lightweight yet effective defenses deployable at both endpoints.

We evaluate these defenses using a unified blueprint that calibrates defense parameters per dataset, then combines practical attacks, information-theoretic leakage estimates, and overhead measurements. For each defense, this framework identifies the strongest hyperparameter-tuned fingerprinting model and estimates the residual uncertainty induced by the defense using two information-theoretic leakage estimators -all while accounting for the defense's privacy-overhead trade-offs.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 33a9fb1a-edd9-4f5c-bee8-a7e95c4363d7

Builds on24

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines