Lune

NSDI2026Top-tier venue

Defending against Traffic Analysis Attacks with Flexible In-Network Obfuscation

Guorui Xie, Qing Li, Zhenning Shi, Gianni Antichi, Yijia Zhu, Kejun Li, Changxing Weng, Sebastiano Miano, Yong Jiang, Mingwei Xu

2026Year
2Citations

Abstract

Traffic analysis attacks can exploit side channels in encrypted traffic (e.g., packet sizes) to infer user activities. Existing defenses provide weak protection, impose excessive bandwidth overhead, or require hard-to-deploy coordination. We present Securitas, a novel network traffic obfuscation framework that protects from side-channel attacks using a learning-guided mix of packet fragmentation and insertion. We implemented Securitas on a number of different data planes: Tofino switch, AMD/Xilinx FPGA, eBPF, and BMv2. Experiments show that Securitas reduces attack accuracy by up to 95.89%, while consuming 42.69× less bandwidth than prior defenses. Realworld Internet tests confirm minimal performance impact, e.g., adding 0.15s to the web page load.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

Builds on8

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines