The One-Page Setting: A Higher Standard for Evaluating Website Fingerprinting Defenses
Tao Wang
Abstract
To defeat Website Fingerprinting (WF) attacks that threaten privacy on anonymity technologies such as Tor, defenses have been proposed and evaluated under the multi-page setting. The multi-page setting was designed as a difficult setting for the attacker and therefore gives too much of an advantage to the defense, allowing weak defenses to show success. We argue that all WF defenses should instead be evaluated under the one-page setting so that the defender needs to meet a higher standard of success. Evaluating known WF defenses under the one-page setting, we found that Decoy, Front and Tamaraw all failed to defend against WF attacks. None of these defenses were shown to be vulnerable in previous work. In Tamaraw's case, the attacker's TPR increases 13 times from 2.9% to 37% with 4.4% FPR; he can also achieve 91% TPR and 21% FPR. We also found that these attacks were able to succeed in a wide array of newly defined WF scenarios that could not be captured by the standard laboratory scenario. In response, we create the first defense that is strong enough for the one-page setting by augmenting Tamaraw with greater randomization overhead so that its anonymity sets are more evenly dispersed.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers4
- Surakav: Generating Realistic Traces for a Strong Website Fingerprinting DefenseJiajun Gong, Wuqi Zhang, Charles Zhang, Tao WangS&P 2022 · 64 citations
- Real-Time Website Fingerprinting Defense via Traffic Cluster AnonymizationMeng Shen, Kexin Ji, Jinhe Wu, Qi Li et al.S&P 2024 · 26 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- Cease at the Ultimate Goodness: Towards Efficient Website Fingerprinting Defense via Iterative Mutual Information MinimizationRong Wang, Zhen Ling, Guangchi Liu, Shaofeng Li et al.NDSS 2026 · 3 citations
Related papers
- Zero-delay Lightweight Defenses against Website FingerprintingJiajun Gong, Tao WangUSENIX Security 2020
- Forge: A Robust Multi-tab Website Fingerprinting Attack via Blind Source SeparationYitan Huang, Wei Qiao, Ding Wang, Meng Shen et al.WWW 2026
- Walkie-Talkie: An Efficient Defense Against Passive Website Fingerprinting AttacksTao Wang, Ian GoldbergUSENIX Security 2017 · 249 citations
- Lightening the Load: A Cluster-Based Framework for A Lower-Overhead, Provable Website Fingerprinting DefenseKhashayar Khajavi, Tao WangNDSS 2026 · 1 citation
- Stop, Don't Click Here Anymore: Boosting Website Fingerprinting By Considering Sets of SubpagesAsya Mitseva, Andriy PanchenkoUSENIX Security 2024 · 18 citations
