USENIX Security2023Top-tier venue
Subverting Website Fingerprinting Defenses with Robust Traffic Representation
Meng Shen, Kexin Ji, Zhenbo Gao, Qi Li, Liehuang Zhu, Ke Xu
Abstract
Anonymity networks, e.g., Tor, are vulnerable to various website fingerprinting (WF) attacks, which allows attackers to perceive user privacy on these networks. However, the defenses developed recently can effectively interfere with WF attacks, e.g., by simply injecting dummy packets. In this paper, we propose a novel WF attack called Robust Fingerprinting (RF), which enables an attacker to fingerprint the Tor traffic under various defenses. Specifically, we develop a robust traffic representation method that generates Traffic Aggregation Matrix (TAM) to fully capture key informative features leaked from Tor traces. By utilizing TAM, an attacker can train a CNN-based classifier that learns common high-level traffic features uncovered by different defenses. We conduct extensive experiments with public real-world datasets to compare RF with state-of-the-art (SOTA) WF attacks. The closed- and open-world evaluation results demonstrate that RF significantly outperforms the SOTA attacks. In particular, RF can effectively fingerprint Tor traffic under the SOTA defenses with an average accuracy improvement of 8.9% over the best existing attack (i.e., Tik-Tok).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 885a7ff3-f68c-49a7-a78f-e82ce8978ff4Cited by top-tier papers21
- Point Cloud Analysis for ML-Based Malicious Traffic Detection: Reducing Majorities of False Positive AlarmsChuanpu Fu, Qi Li, Ke Xu, Jianping WuCCS 2023 · 30 citations
- Real-Time Website Fingerprinting Defense via Traffic Cluster AnonymizationMeng Shen, Kexin Ji, Jinhe Wu, Qi Li et al.S&P 2024 · 26 citations
- Robust and Reliable Early-Stage Website Fingerprinting Attacks via Spatial-Temporal Distribution AnalysisXinhao Deng, Qi Li, Ke XuCCS 2024 · 22 citations
- Stop, Don't Click Here Anymore: Boosting Website Fingerprinting By Considering Sets of SubpagesAsya Mitseva, Andriy PanchenkoUSENIX Security 2024 · 18 citations
- Detecting Tunneled Flooding Traffic via Deep Semantic Analysis of Packet Length PatternsChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2024 · 13 citations
Builds on15
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha et al.S&P 2016 · 3,275 citations
- Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep LearningPayap Sirinam, Mohsen Imani, Marc Juarez, Matthew WrightCCS 2018 · 632 citations
- Website Fingerprinting at Internet ScaleAndriy Panchenko, Fabian Lanze, Jan Pennekamp, Thomas Engel et al.NDSS 2016 · 625 citations
- k-fingerprinting: A Robust Scalable Website Fingerprinting TechniqueJamie Hayes, George DanezisUSENIX Security 2016 · 474 citations
- Automated Website Fingerprinting through Deep LearningVera Rimmer, Davy Preuveneers, Marc Juarez, Tom van Goethem et al.NDSS 2018 · 399 citations
Related papers
- Swallow: A Transfer-Robust Website Fingerprinting Attack via Consistent Feature LearningMeng Shen, Jinhe Wu, Junyu Ai, Qi Li et al.CCS 2025 · 1 citation
- RoFiRe: Robust Website Fingerprinting on Real-World Tor Traffic via Improved Augmentation and NormalizationHaeseung Jeon, Sujin Kim, Nate Mathews, Hosung Kang et al.WWW 2026
- Trace-agnostic and Adversarial Training-resilient Website Fingerprinting DefenseLitao Qiao, Bang Wu, Heng Li, Cuiying Gao et al.INFOCOM 2024 · 8 citations
- Transformer-based Model for Multi-tab Website Fingerprinting AttackZhaoxin Jin, Tianbo Lu, Shuang Luo, Jiaze ShangCCS 2023 · 30 citations
- WFGuard: an Effective Fuzzing-testing-based Traffic Morphing Defense against Website FingerprintingZhen Ling, Gui Xiao, Lan Luo, Rong Wang et al.INFOCOM 2024 · 6 citations
