Flow Correlation Attacks on Tor Onion Service Sessions with Sliding Subset Sum
Daniela Lopes, Jin-Dong Dong, Pedro Medeiros, Daniel Castro, Diogo Barradas, Bernardo Portela, João Vinagre, Bernardo Ferreira, Nicolas Christin, Nuno Santos
Abstract
—Tor is one of the most popular anonymity networks in use today. Its ability to defend against flow correlation attacks is essential for providing strong anonymity guarantees. However, the feasibility of flow correlation attacks against Tor onion services (formerly known as “hidden services”) has remained an open challenge. In this paper, we present an effective flow correlation attack that can deanonymize onion service sessions in the Tor network. Our attack is based on a novel distributed technique named Sliding Subset Sum (SUMo), which can be deployed by a group of colluding ISPs worldwide in a federated fashion. These ISPs collect Tor traffic at multiple vantage points in the network, and analyze it through a pipelined architecture based on machine learning classifiers and a novel similarity function based on the classic subset sum decision problem. These classifiers enable SUMo to deanonymize onion service sessions effectively and efficiently. We also analyze possible countermeasures that the Tor community can adopt to hinder the efficacy of these attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8d3dcfc8-4266-4fb8-8b09-6689dd9e9975Cited by top-tier papers3
- Time will Tell: Large-scale De-anonymization of Hidden I2P Services via Live Behavior AlignmentHongze Wang, Zhen Ling, Xiangyu Xu, Yumingzhi Pan et al.NDSS 2026 · 1 citation
- Time Tells All: Deanonymization of Blockchain RPC Users with Zero Transaction FeeShan Wang, Ming Yang, Yu Liu, Yue Zhang et al.CCS 2025
- MUFFLER: Secure Tor Traffic Obfuscation with Dynamic Connection Shuffling and SplittingMinjae Seo, Myoungsung You, Jaehan Kim, Taejune Park et al.INFOCOM 2025
Builds on17
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep LearningPayap Sirinam, Mohsen Imani, Marc Juarez, Matthew WrightCCS 2018 · 632 citations
- k-fingerprinting: A Robust Scalable Website Fingerprinting TechniqueJamie Hayes, George DanezisUSENIX Security 2016 · 474 citations
- DeepCorr: Strong Flow Correlation Attacks on Tor Using Deep LearningMilad Nasr, Alireza Bahramali, Amir HoumansadrCCS 2018 · 187 citations
- Measuring and Mitigating AS-level Adversaries Against TorRishab Nithyanand, Oleksii Starov, Phillipa Gill, Adva Zair et al.NDSS 2016 · 79 citations
Related papers
- DeepCoFFEA: Improved Flow Correlation Attacks on Tor via Metric Learning and AmplificationSe Eun Oh, Taiji Yang, Nate Mathews, James K. Holland et al.S&P 2022 · 60 citations
- MirageFlow: A New Bandwidth Inflation Attack on TorChristoph Sendner, Jasper Stang, Alexandra Dmitrienko, Raveen Wijewickrama et al.NDSS 2024
- The Effect of DNS on Tor's AnonymityBenjamin Greschbach, Tobias Pulls, Laura M. Roberts, Philipp Winter et al.NDSS 2017 · 51 citations
- Large-scale Evaluation of Malicious Tor Hidden Service Directory DiscoveryChunmian Wang, Zhen Ling, Wenjia Wu, Qi Chen et al.INFOCOM 2022 · 10 citations
- Do Not Trust What They Tell: Exposing Malicious Accomplices in Tor via Anomalous Circuit DetectionYixuan Yao, Ming Yang, Zixia Liu, Kai Dong et al.WWW 2025 · 2 citations
