AppSniffer: Towards Robust Mobile App Fingerprinting Against VPN
Sanghak Oh, Minwook Lee, Hyunwoo Lee, Elisa Bertino, Hyoungshick Kim
Abstract
Application fingerprinting is a useful data analysis technique for network administrators, marketing agencies, and security analysts. For example, an administrator can adopt application fingerprinting techniques to determine whether a user’s network access is allowed. Several mobile application fingerprinting techniques (e.g., FlowPrint, AppScanner, and ET-BERT) were recently introduced to identify applications using the characteristics of network traffic. However, we find that the performance of the existing mobile application fingerprinting systems significantly degrades when a virtual private network (VPN) is used. To address such a shortcoming, we propose a framework dubbed AppSniffer that uses a two-stage classification process for mobile app fingerprinting. In the first stage, we distinguish VPN traffic from normal traffic; in the second stage, we use the optimal model for each traffic type. Specifically, we propose a stacked ensemble model using Light Gradient Boosting Machine (LightGBM) and a FastAI library-based neural network model to identify applications’ traffic when a VPN is used. To show the feasibility of AppSniffer, we evaluate the detection accuracy of AppSniffer for 150 popularly used Android apps. Our experimental results show that AppSniffer effectively identifies mobile applications over VPNs with F1-scores between 84.66% and 95.49% across four different VPN protocols. In contrast, the best state-of-the-art method (i.e., AppScanner) demonstrates significantly lower F1-scores between 25.63% and 47.56% in the same settings. Overall, when normal traffic and VPN traffic are mixed, AppSniffer achieves an F1-score of 90.63%, which is significantly better than AppScanner that shows an F1-score of 70.36%.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers4
- Towards Context-Aware Traffic Classification via Time-Wavelet Fusion NetworkZiming Zhao, Zhuoxue Song, Xiaofei Xie, Zhaoxuan Li et al.KDD 2025 · 5 citations
- Defending against Traffic Analysis Attacks with Flexible In-Network ObfuscationGuorui Xie, Qing Li, Zhenning Shi, Gianni Antichi et al.NSDI 2026 · 2 citations
- Time Tells All: Deanonymization of Blockchain RPC Users with Zero Transaction FeeShan Wang, Ming Yang, Yu Liu, Yue Zhang et al.CCS 2025
- SoK: Decoding the Enigma of Encrypted Network Traffic ClassifiersNimesha Wickramasinghe, Arash Shaghaghi, Gene Tsudik, Sanjay K. JhaS&P 2025
Builds on5
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- WireGuard: Next Generation Kernel Network TunnelJason A. DonenfeldNDSS 2017 · 259 citations
- TLS 1.3 in Practice: How TLS 1.3 Contributes to the InternetHyunwoo Lee, Doowon Kim, Yonghwi KwonWWW 2021 · 47 citations
- Programmable In-Network Security for Context-aware BYOD PoliciesQiao Kang, Lei Xue, Adam Morrison, Yuxin Tang et al.USENIX Security 2020
- OpenVPN is Open to VPN FingerprintingDiwen Xue, Reethika Ramesh, Arham Jain, Michalis Kallitsis et al.USENIX Security 2022
Related papers
- FlowPrint: Semi-Supervised Mobile-App Fingerprinting on Encrypted Network TrafficThijs van Ede, Riccardo Bortolameotti, Andrea Continella, Jingjing Ren et al.NDSS 2020
- Practical VPN Fingerprinting using Coarse Inference of Field Specifications in Data ChannelsTaewook Kim, Jinhwan Kim, Sangmin Lee, Yeongpil ChoINFOCOM 2026
- DecETT: Accurate App Fingerprinting Under Encrypted Tunnels via Dual Decouple-based Semantic EnhancementZheyuan Gu, Chang Liu, Xiyuan Zhang, Chen Yang et al.WWW 2025 · 2 citations
- Identifying VPN Servers through Graph-Represented BehaviorsChenxu Wang, Jiangyi Yin, Zhao Li, Hongbo Xu et al.WWW 2024 · 6 citations
- Packet-Level Open-World App Fingerprinting on Wireless TrafficJianfeng Li, Shuohan Wu, Hao Zhou, Xiapu Luo et al.NDSS 2022
