Lightening the Load: A Cluster-Based Framework for A Lower-Overhead, Provable Website Fingerprinting Defense
Khashayar Khajavi, Tao Wang
Abstract
Website fingerprinting (WF) attacks remain a significant threat to encrypted traffic, prompting the development of a wide range of defenses. Among these, two prominent classes are regularization-based defenses, which shape traffic using fixed padding rules, and supersequence-based approaches, which conceal traces among predefined patterns. In this work, we present a unified framework for designing an adaptive WF defense that combines the effectiveness of regularization with the provable security of supersequence-style grouping. The scheme first extracts behavioural patterns from traces and clusters them into -diverse anonymity sets; an early-time-series classifier (adapted from ECDIRE) then switches from a conservative global set of regularization parameters to the lighter, set-specific parameters. We instantiate the design as emphAdaptive Tamaraw, a variant of Tamaraw that assigns padding parameters on a per-cluster basis while retaining its original information-theoretic guarantee. Comprehensive experiments on public real-world datasets confirm the benefits. By tuning , operators can trade privacy for efficiency: in its high-privacy mode, Adaptive Tamaraw pushes the bound on any attacker's accuracy below textbf30%, whereas in efficiency-centred settings it cuts total overhead by textbf99 percentage points compared with classic Tamaraw.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers1
Ask how each one uses itBuilds on12
- Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep LearningPayap Sirinam, Mohsen Imani, Marc Juarez, Matthew WrightCCS 2018 · 632 citations
- Website Fingerprinting at Internet ScaleAndriy Panchenko, Fabian Lanze, Jan Pennekamp, Thomas Engel et al.NDSS 2016 · 625 citations
- k-fingerprinting: A Robust Scalable Website Fingerprinting TechniqueJamie Hayes, George DanezisUSENIX Security 2016 · 474 citations
- Automated Website Fingerprinting through Deep LearningVera Rimmer, Davy Preuveneers, Marc Juarez, Tom van Goethem et al.NDSS 2018 · 399 citations
- Walkie-Talkie: An Efficient Defense Against Passive Website Fingerprinting AttacksTao Wang, Ian GoldbergUSENIX Security 2017 · 249 citations
Related papers
- Zero-delay Lightweight Defenses against Website FingerprintingJiajun Gong, Tao WangUSENIX Security 2020
- Surakav: Generating Realistic Traces for a Strong Website Fingerprinting DefenseJiajun Gong, Wuqi Zhang, Charles Zhang, Tao WangS&P 2022 · 64 citations
- The One-Page Setting: A Higher Standard for Evaluating Website Fingerprinting DefensesTao WangCCS 2021 · 16 citations
- Understanding the Privacy-Preserving Potential of HTTP/2 Against Webpage FingerprintingBogdan Constantin Cebere, Prateek Kumar, Sylvain Chatel, Wouter Lueks et al.CCS 2026
- TrafficSliver: Fighting Website Fingerprinting Attacks with Traffic SplittingWladimir De la Cadena, Asya Mitseva, Jens Hiller, Jan Pennekamp et al.CCS 2020 · 110 citations
