Time will Tell: Large-scale De-anonymization of Hidden I2P Services via Live Behavior Alignment
Hongze Wang, Zhen Ling, Xiangyu Xu, Yumingzhi Pan, Guangchi Liu, Junzhou Luo, Xinwen Fu
Abstract
I2P (Invisible Internet Project) is a popular anonymous communication network. While existing de-anonymization methods for I2P focus on identifying potential traffic patterns of target hidden services among extensive network traffic, they often fail to scale effectively across the large and diverse I2P network, which consists of numerous routers. In this paper, we introduce I2PERCEPTION a low-cost approach revealing the IP addresses of I2P hidden services. In I2PERCEPTION, attackers deploy floodfill routers to passively monitor I2P routers and collect their RouterInfo . We analyze the router information publication mechanism to accurately identify routers' join (i.e. on) and leave (i.e. off) behaviors, enabling fine-grained live behavior inference across the I2P network. Active probing is used to obtain the live behavior (i.e., on-off patterns) of a target hidden service hosted on one of the I2P routers. By correlating the live behaviors of the target hidden service and I2P routers over time, we narrow down the set of routers matching the hidden service's behavior, revealing the hidden service's true network identity for de-anonymization. Through the deployment of only 15 floodfill routers over the course of eight months, we validate the precision and effectiveness of our approach with extensive real-world experiments. Our results show that I2PERCEPTION successfully de-anonymizes all controlled hidden services.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 951041ab-698a-4e5d-8052-3b87d609f991Builds on7
- DeepCorr: Strong Flow Correlation Attacks on Tor Using Deep LearningMilad Nasr, Alireza Bahramali, Amir HoumansadrCCS 2018 · 187 citations
- Measuring and Mitigating AS-level Adversaries Against TorRishab Nithyanand, Oleksii Starov, Phillipa Gill, Adva Zair et al.NDSS 2016 · 79 citations
- Counter-RAPTOR: Safeguarding Tor Against Active Routing AttacksYixin Sun, Anne Edmundson, Nick Feamster, Mung Chiang et al.S&P 2017 · 60 citations
- DeepCoFFEA: Improved Flow Correlation Attacks on Tor via Metric Learning and AmplificationSe Eun Oh, Taiji Yang, Nate Mathews, James K. Holland et al.S&P 2022 · 60 citations
- Point Break: A Study of Bandwidth Denial-of-Service Attacks against TorRob Jansen, Tavish Vaidya, Micah SherrUSENIX Security 2019 · 49 citations
Related papers
- Do Not Trust What They Tell: Exposing Malicious Accomplices in Tor via Anomalous Circuit DetectionYixuan Yao, Ming Yang, Zixia Liu, Kai Dong et al.WWW 2025 · 2 citations
- Large-scale Evaluation of Malicious Tor Hidden Service Directory DiscoveryChunmian Wang, Zhen Ling, Wenjia Wu, Qi Chen et al.INFOCOM 2022 · 10 citations
- Your Outer Appearance Mirrors Your Inner Self: Exploiting Unobservable Node Internals to Deanonymize Uploaders in FreenetYonghuan Xu, Ming Yang, Shan Wang, Xiaodan Gu et al.INFOCOM 2026
- How Do Tor Users Interact With Onion Services?Philipp Winter, Anne Edmundson, Laura M. Roberts, Agnieszka Dutkowska-Zuk et al.USENIX Security 2018 · 42 citations
- Flow Correlation Attacks on Tor Onion Service Sessions with Sliding Subset SumDaniela Lopes, Jin-Dong Dong, Pedro Medeiros, Daniel Castro et al.NDSS 2024
