Lune

CCS2026顶会

Understanding the Privacy-Preserving Potential of HTTP/2 Against Webpage Fingerprinting

Bogdan Constantin Cebere, Prateek Kumar, Sylvain Chatel, Wouter Lueks, Christian Rossow

2026年份

摘要

Website fingerprinting (WF) attacks can infer which webpage a user visits from encrypted HTTPS traffic alone, compromising privacy even without decryption. WF defenses commonly shape traffic through noise, padding, delays, or flow splitting -yet they are most often studied from the perspective of encapsulating protocols like Tor or VPN rather than at the application layer (HTTP).

In this work, we focus on application-layer defenses enabled by the most widely deployed version of HTTP -HTTP/2. We demonstrate how known defenses can be emulated through HTTP/2 features at the client side (HTTPOS, LLaMA, FRONT, Tamaraw) and the server side (ALPaCA, Tamaraw). We further show that HTTP/2 features -such as proactive resource suggestion, multiplexing, and flow control -offer untapped potential for lightweight yet effective defenses deployable at both endpoints.

We evaluate these defenses using a unified blueprint that calibrates defense parameters per dataset, then combines practical attacks, information-theoretic leakage estimates, and overhead measurements. For each defense, this framework identifies the strongest hyperparameter-tuned fingerprinting model and estimates the residual uncertainty induced by the defense using two information-theoretic leakage estimators -all while accounting for the defense's privacy-overhead trade-offs.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper24

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖