Defeating DNN-Based Traffic Analysis Systems in Real-Time With Blind Adversarial Perturbations
Milad Nasr, Alireza Bahramali, Amir Houmansadr
摘要
Deep neural networks (DNNs) are commonly used for various traffic analysis problems, such as website fingerprinting and flow correlation, as they outperform traditional (e.g., statistical) techniques by large margins. However, deep neural networks are known to be vulnerable to adversarial examples: adversarial inputs to the model that get labeled incorrectly by the model due to small adversarial perturbations. In this paper, for the first time, we show that an adversary can defeat DNN-based traffic analysis techniques by applying adversarial perturbations on the patterns of live network traffic. Applying adversarial perturbations (examples) on traffic analysis classifiers faces two major challenges. First, the perturbing party (i.e., the adversary) should be able to apply the adversarial network perturbations on live traffic, with no need to buffering traffic or having some prior knowledge about upcoming network packets. We design a systematic approach to create adversarial perturbations that are independent of their target network connections, and therefore can be applied in real-time on live traffic. We therefore call such adversarial perturbations blind. Second, unlike image classification applications, perturbing traffic features is not straight-forward as this needs to be done while preserving the correctness of dependent traffic features. We address this challenge by introducing remapping functions that we use to enforce different network constraints while creating blind adversarial perturbations. Our blind adversarial perturbations algorithm is generic and can be applied on various types of traffic classifiers. We demonstrate this by implementing a Tor pluggable transport that applies adversarial perturbations on live Tor connections to defeat DNN-based website fingerprinting and flow correlation techniques, the two most-studied types of traffic analysis. We show that our blind adversarial perturbations are even transferable between different models and architectures, so they can be applied by blackbox adversaries. Finally, we show that existing countermeasures perform poorly against blind adversarial perturbations, therefore, we introduce a tailored countermeasure.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper24
- Robust Adversarial Attacks Against DNN-Based Wireless Communication SystemsAlireza Bahramali, Milad Nasr, Amir Houmansadr, Dennis Goeckel 等CCS 2021 · 被引用 80 次
- Surakav: Generating Realistic Traces for a Strong Website Fingerprinting DefenseJiajun Gong, Wuqi Zhang, Charles Zhang, Tao WangS&P 2022 · 被引用 64 次
- Realistic Website Fingerprinting By Augmenting Network TracesAlireza Bahramali, Ardavan Bozorgi, Amir HoumansadrCCS 2023 · 被引用 45 次
- Real-Time Website Fingerprinting Defense via Traffic Cluster AnonymizationMeng Shen, Kexin Ji, Jinhe Wu, Qi Li 等S&P 2024 · 被引用 26 次
- Robust and Reliable Early-Stage Website Fingerprinting Attacks via Spatial-Temporal Distribution AnalysisXinhao Deng, Qi Li, Ke XuCCS 2024 · 被引用 22 次
它引用的顶会 Paper15
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha 等S&P 2016 · 被引用 3,275 次
- Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep LearningPayap Sirinam, Mohsen Imani, Marc Juarez, Matthew WrightCCS 2018 · 被引用 632 次
- Website Fingerprinting at Internet ScaleAndriy Panchenko, Fabian Lanze, Jan Pennekamp, Thomas Engel 等NDSS 2016 · 被引用 625 次
- k-fingerprinting: A Robust Scalable Website Fingerprinting TechniqueJamie Hayes, George DanezisUSENIX Security 2016 · 被引用 474 次
相关 Paper
- Statistical Privacy for Streaming TrafficXiaokuan Zhang, Jihun Hamm, Michael K. Reiter, Yinqian ZhangNDSS 2019 · 被引用 49 次
- Trace-agnostic and Adversarial Training-resilient Website Fingerprinting DefenseLitao Qiao, Bang Wu, Heng Li, Cuiying Gao 等INFOCOM 2024 · 被引用 8 次
- Automated Website Fingerprinting through Deep LearningVera Rimmer, Davy Preuveneers, Marc Juarez, Tom van Goethem 等NDSS 2018 · 被引用 399 次
- WFGuard: an Effective Fuzzing-testing-based Traffic Morphing Defense against Website FingerprintingZhen Ling, Gui Xiao, Lan Luo, Rong Wang 等INFOCOM 2024 · 被引用 6 次
- SoK: A Critical Evaluation of Efficient Website Fingerprinting DefensesNate Mathews, James K. Holland, Se Eun Oh, Mohammad Saidur Rahman 等S&P 2023
