Pith. sign in

REVIEW 4 major objections 6 minor 62 references

WFCAT: Augmenting Website Fingerprinting with Channel-wise Attention on Timing Features

T0 review · 4 major / 6 minor · reviewed 2026-08-11 · deepseek-v4-flash

Pith's one-line read The paper claims that a website fingerprinting attack built on an inter-arrival time histogram and channel-wise attention can identify Tor pages through strong defenses, reaching 59% accuracy against Surakav in closed-world tests.

desk verdict A genuinely new timing feature and a broad empirical study, but the headline Surakav number was selected by tuning G on the Surakav data—the qualitative finding likely stands, the exact 59% does not. read the letter →

arxiv 2412.11487 v1 pith:UXL2T5L5 submitted 2024-12-16 cs.CR

classification cs.CR
keywords websitefingerprintingToranonymitytrafficanalysisinter-arrivaltimehistogramchannel-wiseattentionconvolutionalneuralnetworkdefendedclassificationtimingfeatures
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper aims to show that website fingerprinting attacks on Tor can be made much stronger against modern defenses by treating packet timing as a first-class feature. It claims that existing attacks either discard fine timing detail or use raw timestamps that defenses perturb, and that a middle-granularity representation called the inter-arrival time (IAT) histogram retains enough timing structure to break defenses that delay or pad packets. On top of this representation, the paper builds a CNN, WFCAT, whose multi-scale kernels and channel-wise attention learn which timing patterns matter. If the claims hold, a local passive observer can deanonymize Tor users even when the traffic has passed through defenses such as Surakav, which was previously considered strong.

What carries the argument

The load-bearing object is the inter-arrival time (IAT) histogram, an intermediate-granularity trace representation. Given a Tor trace as an ordered sequence of cells with timestamps $t_i$ and directions $d_i$, each cell gets an inter-arrival time $\delta_i = t_i - t_{i-1}$, and the loading timeline is cut into slots of length $s$. In each slot, incoming and outgoing cells are counted separately into $G$ bins whose edges are evenly spaced on a logarithmic scale, yielding a tensor $\tilde{X}$ of shape $G\times2\times L$. The accompanying WFCAT backbone uses an Inception2d block—kernels of width 2 and heights $2k+1$ for $k=0,\dots,K-1$—to look at the in/out correlation at multiple scales, a squeeze-and-excitation block that learns a weight per feature channel through a two-layer fully connected net and sigmoid, and Inception1d blocks after reshaping; global average pooling produces the final logits. The representation is what preserves timing information that TAM-style counts discard, and the attention is what lets the model emphasise the IAT bins that survive defense noise.

What would settle it

Train WFCAT on traces from one set of Tor circuits and test it on traces for the same pages collected through different circuits and a different time window, using an independent implementation of Surakav (or the defense authors' original code) rather than the authors' reimplementation. If closed-world accuracy on these traces falls to the pre-WFCAT level (around 31% or below), the claimed 59% figure would not generalize beyond the specific collection setting.

Watch

Extended reading notes

Core claim

The paper's central claim is that packet timing leaks through defenses that are supposed to hide traffic shape, and that the leak can be harvested with the right representation and architecture. Existing attacks either use raw timestamps, which defense delays jitter, or coarse packet-count matrices (TAM), which lose the spacing between cells inside each time slot. WFCAT replaces these with an inter-arrival time (IAT) histogram: for each fixed time slot it bins the intervals between consecutive cells on a logarithmic scale, separately for outgoing and incoming cells, producing a $G \times 2 \times L$ tensor. A CNN with multi-scale Inception kernels and a squeeze-and-excitation channel-attention block then learns which IAT bins and time slots are informative. In closed-world tests on 100 monitored pages, WFCAT reaches 94.47% accuracy on undefended traces and 59.12% on Surakav-defended traces, compared with 30.92% for the RF attack and 15.04% for Tik-Tok; it also leads in open-world precision-recall against all tested defenses except the deterministic Tamaraw defense. The paper concludes that timing-sensitive defenses—padding and delaying mechanisms whose activation depends on page characteristics—inadvertently leave a recoverable fingerprint.

Load-bearing premise

The attack's reported 59% accuracy against Surakav assumes the authors' own implementation of Surakav produces traces representative of the defense, and that the attacker can train on traces drawn from the same defense and network distribution as the victim's traffic; if either condition fails, the reported accuracy does not transfer.

Editorial extensions

If this is right

  • If the headline result holds, the Surakav defense is not providing the security margin prior work assumed: a passive observer can identify a monitored page from defended traffic 59% of the time in a 100-page closed world.
  • Timing-sensitive defenses such as RegulaTor and Surakav leak page identity in their delay and padding schedules; defenses should be re-evaluated with IAT-based attacks rather than only direction-sequence or TAM attacks.
  • Traffic-splitting defenses like TrafficSliver remain vulnerable (over 50% closed-world accuracy and 0.59 recall), so splitting alone should not be treated as sufficient protection.
  • Noise-injection-only defenses such as FRONT and WTF-PAD cost bandwidth but give little protection: WFCAT stays near 93% closed-world accuracy against both.
  • Attackers can get strong accuracy from few labeled traces (20–30 per class on defended datasets), which makes the attack more realistic when pages change frequently.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • A natural next benchmark for WF defenses would be to report accuracy against an IAT-histogram attack in addition to TAM and direction-sequence attacks; the paper's ablations suggest defenses tuned to defeat one representation may not defeat the other.
  • The channel-attention weights could be inspected to identify which IAT bins and time slots carry the signal for a given defense, potentially revealing the exact delay or padding trigger that leaks information; this is a testable hypothesis the paper does not pursue.
  • Because WFCAT exploits timing regularity, defenses that randomize their delay schedules per page load or per circuit, rather than making delays page-dependent, may be more robust; constructing such a defense and measuring WFCAT's accuracy would be a concrete extension.
  • The IAT histogram representation is generic enough that it could be applied to other encrypted-traffic classification tasks, such as application or service identification, with the same attention mechanism; the paper only evaluates it for website fingerprinting.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 6 minor

Summary. The paper proposes WFCAT, a website fingerprinting attack on Tor that represents a trace as an inter-arrival-time (IAT) histogram over fixed time slots and classifies it with a CNN comprising Inception blocks and channel-wise attention (SEBlock). The authors report state-of-the-art closed-world accuracy against defended traces, notably 59.12% against Surakav versus 30.92% for RF and 15.04% for Tik-Tok, and they also present open-world results, bandwidth-mismatch robustness, sample-efficiency curves, and training-time comparisons. The contribution is primarily empirical: the representation and architecture are described in detail, but no code, data, or error bars are provided.

Significance. If the headline results survive independent verification, this is a meaningful advance for the WF attack literature: the paper identifies timing information as a persistent leakage source under strong reshaping defenses, and the proposed IAT histogram plus multi-scale attention CNN is a plausible mechanism for exploiting it. The evaluation is broad, covering seven defenses, closed- and open-world settings, bandwidth shifts, varying training set sizes, and an ablation study. However, the absence of released code/data/error bars, the unresolved G=4 versus G=9 conflict, and the use of a defense implementation from the authors' own group mean that the quantitative claims are not yet established at the reported precision. The paper contains no formal proofs; its contribution is empirical, which makes the reproducibility and evaluation-protocol concerns directly load-bearing. I would therefore treat the contribution as significant but conditional on a re-evaluation with a pre-specified configuration.

major comments (4)
  1. [V-B, V-H, Table II] The manuscript contains a direct contradiction on the default bin count G. Section V-B states that hyperparameters were tuned on the undefended dataset using the validation set and that 'G = 4 provides optimal performance', while Table II lists the final G as 9, and Section V-H reports experiments on the Surakav dataset showing accuracy peaking at 59% when G=9 and explicitly stating 'Based on these results, we set G = 9 as the default value.' Since Table III, the headline closed-world result, was presumably produced with G=9, the final configuration appears to have been selected using the Surakav test distribution, which is inconsistent with the tuning protocol claimed in V-B. The 59.12% figure is therefore a post-selection maximum rather than the accuracy of a pre-specified model. Please state explicitly which G was used for Table III, re-run the main comparisons with a configuration fixed before any Surakav evaluation (including the G=4 configuration from V-B), and report results for both configurations with confidence intervals.
  2. [V-A] The Surakav dataset is collected with the authors' own implementation of the defense: Section V-A states that 'Due to the absence of accurate simulation code for Surakav', the authors 'collected another dataset defended by Surakav using Gong's implementation on WFDefProxy'. Since the authors include the original Surakav and WFDefProxy authors, the attacker and the defender are evaluated within the same group's framework. This creates an insider-advantage risk: if this implementation differs from the Surakav defense as originally specified or as deployed, the reported 59.12% accuracy may not transfer to other Surakav instances. To support the central claim, the paper should provide the exact Surakav parameters and configuration used, validate the collected traces against the original Surakav paper's trace statistics, and ideally compare against an independent implementation. Releasing the collected traces and a description of the WFDefProxy Surakav module would allow the community to assess representativeness.
  3. [V-A, Table III] The evaluation methodology is underspecified regarding the relationship between the 8:1:1 split and the claimed 10-fold cross-validation. Section V-A says the dataset is divided into training, validation, and test sets with an 8:1:1 ratio and also that 10-fold cross-validation is conducted for each experiment with combined results. These are not the same protocol, and it is unclear whether hyperparameters were tuned once on a fixed validation set or per fold, and whether the reported accuracies are averages across folds or pooled over all test folds. This matters directly for the G=9 selection in V-H, because that section appears to evaluate on the Surakav test set. Please specify the exact protocol, including how the validation set was used during ASHA tuning and whether the final G and K were chosen before any test-set evaluation.
  4. [V-A, Table III] No confidence intervals or variance estimates are reported for any of the closed- or open-world numbers, despite the claim of 10-fold cross-validation. Given that the headline margin over RF on Surakav is 28.20 percentage points, even a few points of optimism would not overturn the qualitative conclusion, but the exact margin and the 'over 59%' claim are not reliable as stated. Please report the standard deviation or 95% confidence interval for each accuracy figure, and make the code and processed traces available so that the reader can reproduce the reported numbers for at least the Surakav and undefended configurations.
minor comments (6)
  1. [Abstract] The abstract says the improvement over RF and Tik-Tok is 'over 28% and 48%', but Table III shows differences of 28.20 and 44.08 percentage points; the '48%' should be '44%' or the sentence should be reworded.
  2. [V-C] The narrative alternates between 'TikTok' and 'Tik-Tok'; please use the consistent name used in the reference list and other sections.
  3. [V-C] The sentence 'However, our defense and other attacks have not compromised Tamaraw' should read 'our attack' rather than 'our defense', since WFCAT is an attack.
  4. [V-A] There is a typo: 'We have rent two servers' should be 'We have rented two servers'.
  5. [Figure 2] The figure example shows G=3 bins, while the final configuration in Table II and Section V-H uses G=9; either caption the figure as an illustrative example with G=3 or update the figure to show the default setting.
  6. [Figure 8] The two subfigures in Figure 8 lack clear axis labels and titles; the left panel varies G and the right panel varies K, but this is only apparent from the caption. Please add titles and axis labels.

Circularity Check

1 steps flagged · score 6.0 of 10

Headline Surakav accuracy is selected on the Surakav test set, not a fixed-configuration prediction.

  1. fitted input called prediction [Section V-B (hyperparameter tuning) vs. Section V-H (ablation), Table II and Figure 8]
    "As shown in Figure 8, the accuracy of WFCAT increases significantly from 49% to 58% as G increases from 2 to 4. Beyond this point, the accuracy fluctuates slightly around 58%, peaking at 59% when G = 9. Based on these results, we set G = 9 as the default value."

    This makes the headline Surakav result an in-sample selection rather than an out-of-sample prediction. Section V-B states that hyperparameters were tuned on the undefended dataset and that 'G = 4 provides optimal performance,' yet Table II lists G = 9 as final. Section V-H then re-selects G by observing accuracy on the Surakav dataset, choosing the value that peaks at 59%. Because the 59.12% accuracy reported in Table III is obtained with exactly that chosen configuration, the claimed margin over RF (30.92%) and Tik-Tok (15.04%) is partly an artifact of maximizing the evaluation metric on the same test distribution.

full rationale

The core derivation is not circular: the IAT histogram is defined by equations (3)-(5) from raw trace timestamps and directions, and the Inception/SEBlock CNN backbone is specified independently of any accuracy target. The clear circularity is at the evaluation boundary. Section V-B says the model was tuned on the undefended validation set with G=4 optimal, but Section V-H searches G on the Surakav dataset, peaks at 59% when G=9, and then sets G=9 as default; the reported 59.12% Surakav accuracy is therefore the result of model selection on the Surakav test distribution. This is a form of fitted input called prediction and inflates the headline margin over prior attacks. The authors' use of their own Surakav implementation and WFDefProxy framework is an additional external-validity risk, but by itself it is not a derivation-level circularity. The absence of released code or data prevents readers from verifying which configuration produced the main table.

Assumptions & free parameters 5 free parameters · 5 assumptions · 0 invented entities

WFCAT introduces no new physical or conceptual entities; it introduces a feature representation and a network architecture. The central claim depends on five tuned hyperparameters (s, L, G, K, r) and on the domain assumption that timing patterns persist under the tested defenses.

free parameters (5)
  • Time slot duration s = 44 ms
    Tuned between 22 and 330 ms on the undefended validation set; controls the time granularity of the IAT histogram (Section V-B).
  • Trace length L = 1800
    Tuned from 500 to 3000; considers the first 80 seconds of a trace at 44 ms slots.
  • Bin number G = 9
    Tuned in [2,10] on the Surakav dataset (Figure 8, Section V-H); Section V-B says 4 while Table II and Section V-H say 9, an internal inconsistency.
  • Inception kernel count K = 4
    Tuned on the Surakav dataset (Figure 8); determines multi-scale kernels in the Inception2d and Inception1d blocks.
  • SE reduction ratio r = 16
    Hand-chosen in the Squeeze-and-Excitation block to reduce the channel dimension (Section IV-C).
assumptions (5)
  • domain assumption The attacker observes the full ordered sequence of Tor cells with timestamps and directions between client and entry node.
    Section II threat model; this is the standard WF setting and is needed for the IAT histogram input.
  • domain assumption The attacker knows the defense and can train on traces generated under the same defense distribution as the victim.
    Section II states adversarial training with known defense; all reported numbers rely on matching train and test defense distributions.
  • domain assumption Inter-arrival times of cells carry page-dependent information that survives Surakav, RegulaTor, FRONT, and related defenses.
    Section IV-A presents this as the motivating observation for the IAT histogram; if the timing leakage is not general, the central performance claim fails.
  • domain assumption Logarithmic binning of IAT values is the right invariance to absorb Tor circuit latency noise.
    Section IV-B states that Tor latency applies a multiplicative random effect, so exponential bins are used; this is asserted, not derived.
  • domain assumption The Surakav dataset collected with Gong's implementation faithfully represents the Surakav defense.
    Section V-A; the headline result depends on this implementation, whose code is not independently released or verified.

how reviews work

0 comments
Cite this review

Pith. "Pith review of WFCAT: Augmenting Website Fingerprinting with Channel-wise Attention on Timing Features." pith.science (2026). https://pith.science/paper/UXL2T5L5

@misc{pith2026241211487,
  author       = {Pith},
  title        = {Pith review of: WFCAT: Augmenting Website Fingerprinting with Channel-wise Attention on Timing Features},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/UXL2T5L5}},
  note         = {Machine review of arXiv:2412.11487}
}
read the original abstract

Website Fingerprinting (WF) aims to deanonymize users on the Tor network by analyzing encrypted network traffic. Recent deep-learning-based attacks show high accuracy on undefended traces. However, they struggle against modern defenses that use tactics like injecting dummy packets and delaying real packets, which significantly degrade classification performance. Our analysis reveals that current attacks inadequately leverage the timing information inherent in traffic traces, which persists as a source of leakage even under robust defenses. Addressing this shortfall, we introduce a novel feature representation named the Inter-Arrival Time (IAT) histogram, which quantifies the frequencies of packet inter-arrival times across predetermined time slots. Complementing this feature, we propose a new CNN-based attack, WFCAT, enhanced with two innovative architectural blocks designed to optimally extract and utilize timing information. Our approach uses kernels of varying sizes to capture multi-scale features, which are then integrated using a weighted sum across all feature channels to enhance the model's efficacy in identifying temporal patterns. Our experiments validate that WFCAT substantially outperforms existing methods on defended traces in both closed- and open-world scenarios. Notably, WFCAT achieves over 59% accuracy against Surakav, a recently developed robust defense, marking an improvement of over 28% and 48% against the state-of-the-art attacks RF and Tik-Tok, respectively, in the closed-world scenario.

Figures

Figures reproduced from arXiv: 2412.11487 by the authors.

Figure 1
Figure 1. WF attack model. carried by different types of packets while being more robust against perturbations compared to raw timestamps. • Alongside our proposed trace representation, we intro￾duce a novel CNN block. We employ multiple kernels of different sizes to capture features at various scales and then fuse all the features using different weights learned during the training process. This approach ensures that highly … view at source ↗
Figure 2
Figure 2. Visualization of IAT histogram computation. In this [PITH_FULL_IMAGE:figures/full_fig_p004_2.png] view at source ↗
Figure 3
Figure 3. WFCAT model’s architecture. *The first Conv2d and all Conv1d blocks are our proposed new blocks. bG = +∞. After the computation for L time slots, we get a matrix of shape G×2×L as our feature representation. The hyperparameter L is the total number of time slots considered for a trace, while the hyperparameter G is the number of bins to gather the IAT values in each time slot. We chose logarithmic bins for construct… view at source ↗
Figures from the paper (4 more)
Figure 4
Figure 4. Figure 4: Illustration of the first Conv2d block: utilizing multiple [PITH_FULL_IMAGE:figures/full_fig_p005_4.png]
Figure 6
Figure 6. Figure 6: Attack performance with different number of train [PITH_FULL_IMAGE:figures/full_fig_p009_6.png]
Figure 5
Figure 5. Figure 5: Attack performance against various defenses in the [PITH_FULL_IMAGE:figures/full_fig_p009_5.png]
Figure 7
Figure 7. Figure 7: Training time of attacks on the open-world undefended [PITH_FULL_IMAGE:figures/full_fig_p010_7.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

62 extracted references · 60 canonical work pages

  1. [1]

    Fingerprinting Attack on Tor Anonymity Using Deep Learning

    Kota Abe and Shigeki Goto. Fingerprinting Attack on Tor Anonymity Using Deep Learning. Proceedings of the 10th Asia-Pacific Advanced Network, pages 15–20, 2016

  2. [2]

    DFD: Adversarial Learning-based Ap- proach to Defend Against Website Fingerprinting

    Ahmed Abusnaina, Rhongho Jang, Aminollah Khormali, DaeHun Nyang, and David Mohaisen. DFD: Adversarial Learning-based Ap- proach to Defend Against Website Fingerprinting. In The 39th IEEE Conference on Computer Communications , pages 2459–2468. IEEE, 2020

  3. [3]

    Realistic Website Fingerprinting By Augmenting Network Traces

    Alireza Bahramali, Ardavan Bozorgi, and Amir Houmansadr. Realistic Website Fingerprinting By Augmenting Network Traces. In Proceedings of the 30th ACM SIGSAC Conference on Computer and Communications Security, pages 1035–1049. ACM, 2023

  4. [4]

    Var-CNN: A Data-Efficient Website Fingerprinting Attack Based on Deep Learning

    Sanjit Bhat, David Lu, Albert Kwon, and Srinivas Devadas. Var-CNN: A Data-Efficient Website Fingerprinting Attack Based on Deep Learning. Proceedings on Privacy Enhancing Technologies, pages 292–310, 2019

  5. [5]

    CS-BuFLO: A Congestion Sensitive Website Fingerprinting Defense

    Xiang Cai, Rishab Nithyanand, and Rob Johnson. CS-BuFLO: A Congestion Sensitive Website Fingerprinting Defense. In Proceedings of the 13th Workshop on Privacy in the Electronic Society , pages 121–130. ACM, 2014

  6. [6]

    A Systematic Approach to Developing and Evaluating Website Fingerprinting Defenses

    Xiang Cai, Rishab Nithyanand, Tao Wang, Rob Johnson, and Ian Gold- berg. A Systematic Approach to Developing and Evaluating Website Fingerprinting Defenses. In Proceedings of the 21st ACM SIGSAC Conference on Computer and Communications Security, pages 227–238. ACM, 2014

  7. [7]

    Touching From a Distance: Website Fingerprinting Attacks and Defenses

    Xiang Cai, Xin Cheng Zhang, Brijesh Joshi, and Rob Johnson. Touching From a Distance: Website Fingerprinting Attacks and Defenses. In Proceedings of the 19th ACM SIGSAC Conference on Computer and Communications Security, pages 605–616. ACM, 2012

  8. [8]

    Towards Evaluating the Robustness of Neural Networks

    Nicholas Carlini and David Wagner. Towards Evaluating the Robustness of Neural Networks. In IEEE Symposium on Security and Privacy, pages 39–57. IEEE Computer Society, 2017

Show all 62 references
  1. [9]

    Website Finger- printing Defenses at the Application Layer

    Giovanni Cherubin, Jamie Hayes, and Marc Ju ´arez. Website Finger- printing Defenses at the Application Layer. Proceedings on Privacy Enhancing Technologies, pages 186–203, 2017

  2. [10]

    Robust and Reliable Early-Stage Web- site Fingerprinting Attacks via Spatial-Temporal Distribution Analysis

    Xinhao Deng, Qi Li, and Ke Xu. Robust and Reliable Early-Stage Web- site Fingerprinting Attacks via Spatial-Temporal Distribution Analysis. In Proceedings of the 31st on ACM SIGSAC Conference on Computer and Communications Security , pages 1997–2011. ACM, 2024

  3. [11]

    Robust Multi-tab Website Fingerprinting Attacks in the Wild

    Xinhao Deng, Qilei Yin, Zhuotao Liu, Xiyuan Zhao, Qi Li, Mingwei Xu, Ke Xu, and Jianping Wu. Robust Multi-tab Website Fingerprinting Attacks in the Wild. In IEEE Symposium on Security and Privacy, pages 1005–1022. IEEE, 2023

  4. [12]

    Syverson

    Roger Dingledine, Nick Mathewson, and Paul F. Syverson. Tor: The Second-Generation Onion Router. In Proceedings of the 13th USENIX Security Symposium, pages 303–320. USENIX Association, 2004. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY , VOL. *, NO. *, DECEMBER 2024 12

  5. [13]

    Dyer, Scott E

    Kevin P. Dyer, Scott E. Coull, Thomas Ristenpart, and Thomas Shrimp- ton. Peek-a-Boo, I Still See You: Why Efficient Traffic Analysis Countermeasures Fail. In IEEE Symposium on Security and Privacy , pages 332–346. IEEE Computer Society, 2012

  6. [14]

    Zero-delay Lightweight Defenses against Website Fingerprinting

    Jiajun Gong and Tao Wang. Zero-delay Lightweight Defenses against Website Fingerprinting. In Proceedings of the 29th USENIX Security Symposium, pages 717–734. USENIX Association, 2020

  7. [15]

    Surakav: Generating Realistic Traces for a Strong Website Fingerprinting Defense

    Jiajun Gong, Wuqi Zhang, Charles Zhang, and Tao Wang. Surakav: Generating Realistic Traces for a Strong Website Fingerprinting Defense. In IEEE Symposium on Security and Privacy , pages 1525–1525. IEEE, 2022

  8. [16]

    WFDefProxy: Real World Implementation and Evaluation of Website Fingerprinting Defenses

    Jiajun Gong, Wuqi Zhang, Charles Zhang, and Tao Wang. WFDefProxy: Real World Implementation and Evaluation of Website Fingerprinting Defenses. IEEE Transactions on Information Forensics and Security , pages 1357–1371, 2024

  9. [17]

    Goodfellow, Jonathon Shlens, and Christian Szegedy

    Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. Explaining and Harnessing Adversarial Examples. In Proceedings of the 3rd International Conference on Learning Representations , 2015

  10. [18]

    BAPM: Block Attention Profiling Model for Multi-tab Website Fingerprinting Attacks on Tor

    Zhong Guan, Gang Xiong, Gaopeng Gou, Zhen Li, Mingxin Cui, and Chang Liu. BAPM: Block Attention Profiling Model for Multi-tab Website Fingerprinting Attacks on Tor. In Proceedings of the 37th Annual Computer Security Applications Conference , pages 248–259. ACM, 2021

  11. [19]

    k-fingerprinting: A Robust Scalable Website Fingerprinting Technique

    Jamie Hayes and George Danezis. k-fingerprinting: A Robust Scalable Website Fingerprinting Technique. In Proceedings of the 25th USENIX Security Symposium, pages 1187–1203. USENIX Association, 2016

  12. [20]

    Gaussian Error Linear Units (GELUs)

    Dan Hendrycks and Kevin Gimpel. Gaussian Error Linear Units (GELUs). arXiv preprint arXiv:1606.08415 , 2016

  13. [21]

    Protecting against Website Fingerprinting with Multihoming

    S ´ebastien Henri, Gines Garcia-Aviles, Pablo Serrano, Albert Banchs, and Patrick Thiran. Protecting against Website Fingerprinting with Multihoming. Proceedings on Privacy Enhancing Technologies , pages 89–110, 2020

  14. [22]

    Holland and Nicholas Hopper

    James K. Holland and Nicholas Hopper. RegulaTor: A Straightforward Website Fingerprinting Defense. Proceedings on Privacy Enhancing Technologies, pages 344–362, 2022

  15. [23]

    Squeeze-and-Excitation Networks

    Jie Hu, Li Shen, and Gang Sun. Squeeze-and-Excitation Networks. In IEEE Conference on Computer Vision and Pattern Recognition , pages 7132–7141. IEEE Computer Society, 2018

  16. [24]

    Batch Normalization: Accelerating Deep Network Training by Reducing Internal Covariate Shift

    Sergey Ioffe and Christian Szegedy. Batch Normalization: Accelerating Deep Network Training by Reducing Internal Covariate Shift. In Proceedings of the 32nd International Conference on International Conference on Machine Learning , page 448–456. JMLR, 2015

  17. [25]

    RUDOLF: An Efficient and Adaptive Defense Approach Against Website Fingerprinting Attacks Based on Soft Actor-Critic Algorithm

    Meiyi Jiang, Baojiang Cui, Junsong Fu, Tao Wang, Lu Yao, and Bharat K Bhargava. RUDOLF: An Efficient and Adaptive Defense Approach Against Website Fingerprinting Attacks Based on Soft Actor-Critic Algorithm. IEEE Transactions on Information Forensics and Security , 2024

  18. [26]

    Transformer- based Model for Multi-tab Website Fingerprinting Attack

    Zhaoxin Jin, Tianbo Lu, Shuang Luo, and Jiaze Shang. Transformer- based Model for Multi-tab Website Fingerprinting Attack. In Pro- ceedings of the 30th ACM SIGSAC Conference on Computer and Communications Security, pages 1050–1064. ACM, 2023

  19. [27]

    Toward an Efficient Website Fingerprinting Defense

    Marc Ju ´arez, Mohsen Imani, Mike Perry, Claudia D ´ıaz, and Matthew Wright. Toward an Efficient Website Fingerprinting Defense. In European Symposium on Research in Computer Security , pages 27–46. Springer, 2016

  20. [28]

    TrafficSliver: Fighting Website Fingerprinting Attacks with Traffic Splitting

    Wladimir De la Cadena, Asya Mitseva, Jens Hiller, Jan Pennekamp, Sebastian Reuter, Julian Filter, Thomas Engel, Klaus Wehrle, and Andriy Panchenko. TrafficSliver: Fighting Website Fingerprinting Attacks with Traffic Splitting. In Proceedings of the 27th ACM SIGSAC Conference o...

  21. [29]

    Minipatch: Un- dermining DNN-based Website Fingerprinting with Adversarial Patches

    Ding Li, Yuefei Zhu, Minghao Chen, and Jue Wang. Minipatch: Un- dermining DNN-based Website Fingerprinting with Adversarial Patches. IEEE Transactions on Information Forensics and Security , pages 2437– 2451, 2022

  22. [30]

    A System for Massively Parallel Hyperparameter Tuning

    Liam Li, Kevin Jamieson, Afshin Rostamizadeh, Ekaterina Gonina, Jonathan Ben-Tzur, Moritz Hardt, Benjamin Recht, and Ameet Tal- walkar. A System for Massively Parallel Hyperparameter Tuning. Proceedings of Machine Learning and Systems , pages 230–246, 2020

  23. [31]

    A Large-scale Multiple-objective Method for Black-box Attack against Object Detection

    Siyuan Liang, Longkang Li, Yanbo Fan, Xiaojun Jia, Jingzhi Li, Baoyuan Wu, and Xiaochun Cao. A Large-scale Multiple-objective Method for Black-box Attack against Object Detection. In European Conference on Computer Vision , 2022

  24. [32]

    Efficient Adversarial Attacks for Visual Object Tracking

    Siyuan Liang, Xingxing Wei, Siyuan Yao, and Xiaochun Cao. Efficient Adversarial Attacks for Visual Object Tracking. In Computer Vision– ECCV 2020: 16th European Conference, Glasgow, UK, August 23–28, 2020, Proceedings, Part XXVI 16 , 2020

  25. [33]

    Parallel Rectangle Flip Attack: A Query-based Black-box Attack against Object Detection

    Siyuan Liang, Baoyuan Wu, Yanbo Fan, Xingxing Wei, and Xiaochun Cao. Parallel Rectangle Flip Attack: A Query-based Black-box Attack against Object Detection. arXiv preprint arXiv:2201.08970 , 2022

  26. [34]

    Towards an Efficient Defense against Deep Learning based Website Fingerprinting

    Zhen Ling, Gui Xiao, Wenjia Wu, Xiaodan Gu, Ming Yang, and Xinwen Fu. Towards an Efficient Defense against Deep Learning based Website Fingerprinting. In The 41st IEEE Conference on Computer Communications, pages 310–319. IEEE, 2022

  27. [35]

    AdvTraffic: Obfuscating Encrypted Traffic with Adversarial Examples

    Hao Liu, Jimmy Dani, Hongkai Yu, Wenhai Sun, and Boyang Wang. AdvTraffic: Obfuscating Encrypted Traffic with Adversarial Examples. In The 30th IEEE/ACM International Symposium on Quality of Service , pages 1–10. IEEE, 2022

  28. [36]

    DynaFlow: An Efficient Website Fingerprinting Defense Based on Dynamically- Adjusting Flows

    David Lu, Sanjit Bhat, Albert Kwon, and Srinivas Devadas. DynaFlow: An Efficient Website Fingerprinting Defense Based on Dynamically- Adjusting Flows. In Proceedings of the 17th Workshop on Privacy in the Electronic Society , pages 109–113. ACM, 2018

  29. [37]

    Xiapu Luo, Peng Zhou, Edmond W. W. Chan, Wenke Lee, Rocky K. C. Chang, and Roberto Perdisci. HTTPOS: Sealing Information Leaks with Browser-side Obfuscation of Encrypted Flows. In Proceedings of the 18th Network and Distributed System Security Symposium . The Internet Society, 2011

  30. [38]

    SoK: A Critical Evaluation of Efficient Website Fingerprinting Defenses

    Nate Mathews, James K Holland, Se Eun Oh, Mohammad Saidur Rahman, Nicholas Hopper, and Matthew Wright. SoK: A Critical Evaluation of Efficient Website Fingerprinting Defenses. In IEEE Symposium on Security and Privacy , pages 344–361. IEEE, 2022

  31. [39]

    Defeating DNN- Based Traffic Analysis Systems in Real-Time With Blind Adversarial Perturbations

    Milad Nasr, Alireza Bahramali, and Amir Houmansadr. Defeating DNN- Based Traffic Analysis Systems in Real-Time With Blind Adversarial Perturbations. In Proceedings of the 30th USENIX Security Symposium , pages 2705–2722. USENIX Association, 2021

  32. [40]

    Glove: A Bespoke Website Fingerprinting Defense

    Rishab Nithyanand, Xiang Cai, and Rob Johnson. Glove: A Bespoke Website Fingerprinting Defense. In Proceedings of the 13th Workshop on Privacy in the Electronic Society , pages 131–134. ACM, 2014

  33. [41]

    GANDaLF: GAN for Data-Limited Fingerprinting

    Se Eun Oh, Nate Mathews, Mohammad Saidur Rahman, Matthew Wright, and Nicholas Hopper. GANDaLF: GAN for Data-Limited Fingerprinting. Proceedings on Privacy Enhancing Technologies , pages 305–322, 2021

  34. [42]

    Website Fingerprinting at Internet Scale

    Andriy Panchenko, Fabian Lanze, Jan Pennekamp, Thomas Engel, An- dreas Zinnen, Martin Henze, and Klaus Wehrle. Website Fingerprinting at Internet Scale. In Proceedings of the 23rd Network and Distributed System Security Symposium . The Internet Society, 2016

  35. [43]

    Website Fingerprinting in Onion Routing Based Anonymization Networks

    Andriy Panchenko, Lukas Niessen, Andreas Zinnen, and Thomas En- gel. Website Fingerprinting in Onion Routing Based Anonymization Networks. In Proceedings of the 10th Workshop on Privacy in the Electronic Society, pages 103–114. ACM, 2011

  36. [44]

    Tranco: A Research-Oriented Top Sites Ranking Hardened Against Manipulation

    Victor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Ma- ciej Korczynski, and Wouter Joosen. Tranco: A Research-Oriented Top Sites Ranking Hardened Against Manipulation. In Proceedings of the 26th Annual Network and Distributed System Security Symposium . The Internet ...

  37. [45]

    Proposal 329: Traffic Splitting

    The Tor Project. Proposal 329: Traffic Splitting. The Tor Project Proposals, 2023. Accessed: 2024-08-30

  38. [46]

    Towards effective and efficient padding machines for tor

    Tobias Pulls. Towards effective and efficient padding machines for tor. CoRR, abs/2011.13471, 2020

  39. [47]

    Mockingbird: Defending Against Deep-Learning- Based Website Fingerprinting Attacks With Adversarial Traces

    Mohammad Saidur Rahman, Mohsen Imani, Nate Mathews, and Matthew Wright. Mockingbird: Defending Against Deep-Learning- Based Website Fingerprinting Attacks With Adversarial Traces. IEEE Transactions on Information Forensics and Security , pages 1594–1609, 2020

  40. [48]

    Tik-Tok: The Utility of Packet Timing in Website Fingerprinting Attacks

    Mohammad Saidur Rahman, Payap Sirinam, Nate Mathews, Kan- tha Girish Gangadhara, and Matthew Wright. Tik-Tok: The Utility of Packet Timing in Website Fingerprinting Attacks. Proceedings on Privacy Enhancing Technologies, pages 5–24, 2020

  41. [49]

    Automated Website Fingerprinting through Deep Learning

    Vera Rimmer, Davy Preuveneers, Marc Ju ´arez, Tom van Goethem, and Wouter Joosen. Automated Website Fingerprinting through Deep Learning. In Proceedings of the 25th Network and Distributed System Security Symposium. The Internet Society, 2018

  42. [50]

    AW A: Adversarial Website Adaptation

    Amir Mahdi Sadeghzadeh, Behrad Tajali, and Rasool Jalili. AW A: Adversarial Website Adaptation. IEEE Transactions on Information Forensics and Security, pages 3109–3122, 2021

  43. [51]

    Patch-based Defenses against Web Fingerprinting Attacks

    Shawn Shan, Arjun Nitin Bhagoji, Haitao Zheng, and Ben Y Zhao. Patch-based Defenses against Web Fingerprinting Attacks. In Proceed- ings of the 14th ACM Workshop on Artificial Intelligence and Security , pages 97–109, 2021

  44. [52]

    Subverting Website Fingerprinting Defenses with Robust Traffic Rep- resentation

    Meng Shen, Kexin Ji, Zhenbo Gao, Qi Li, Liehuang Zhu, and Ke Xu. Subverting Website Fingerprinting Defenses with Robust Traffic Rep- resentation. In Joseph A. Calandrino and Carmela Troncoso, editors, Proceedings of the 32nd USENIX Security Symposium , pages 607–624. USENIX As...

  45. [53]

    Real-Time Website Fingerprinting Defense via Traffic Cluster Anonymization

    Meng Shen, Kexin Ji, Jinhe Wu, Qi Li, Xiangdong Kong, Ke Xu, and Liehuang Zhu. Real-Time Website Fingerprinting Defense via Traffic Cluster Anonymization. In IEEE Symposium on Security and Privacy , pages 263–263. IEEE, 2024

  46. [54]

    Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep Learning

    Payap Sirinam, Mohsen Imani, Marc Ju ´arez, and Matthew Wright. Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep Learning. In Proceedings of the 25th ACM SIGSAC Conference on Computer and Communications Security , pages 1928–

  47. [55]

    Triplet Fingerprinting: More Practical and Portable Website Fingerprinting with N-shot Learning

    Payap Sirinam, Nate Mathews, Mohammad Saidur Rahman, and Matthew Wright. Triplet Fingerprinting: More Practical and Portable Website Fingerprinting with N-shot Learning. In Proceedings of the 26th ACM SIGSAC Conference on Computer and Communications Security , pages 1131–1148....

  48. [56]

    Reed, Dragomir Anguelov, Dumitru Erhan, Vincent Vanhoucke, and Andrew Rabinovich

    Christian Szegedy, Wei Liu, Yangqing Jia, Pierre Sermanet, Scott E. Reed, Dragomir Anguelov, Dumitru Erhan, Vincent Vanhoucke, and Andrew Rabinovich. Going Deeper with Convolutions. In IEEE Conference on Computer Vision and Pattern Recognition , pages 1–9. IEEE Computer Society, 2015

  49. [57]

    High Precision Open-World Website Fingerprinting

    Tao Wang. High Precision Open-World Website Fingerprinting. In IEEE Symposium on Security and Privacy , pages 152–167. IEEE, 2020

  50. [58]

    Effective Attacks and Provable Defenses for Website Fin- gerprinting

    Tao Wang, Xiang Cai, Rishab Nithyanand, Rob Johnson, and Ian Goldberg. Effective Attacks and Provable Defenses for Website Fin- gerprinting. In Proceedings of the 23rd USENIX Security Symposium , pages 143–157. USENIX Association, 2014

  51. [59]

    Improved Website Fingerprinting on Tor

    Tao Wang and Ian Goldberg. Improved Website Fingerprinting on Tor. In Proceedings of the 12th Workshop on Privacy in the Electronic Society , pages 201–212. ACM, 2013

  52. [60]

    Walkie-Talkie: An Efficient Defense Against Passive Website Fingerprinting Attacks

    Tao Wang and Ian Goldberg. Walkie-Talkie: An Efficient Defense Against Passive Website Fingerprinting Attacks. In Proceedings of the 26th USENIX Security Symposium , pages 1375–1390. USENIX Association, 2017

  53. [61]

    Rosetta: Enabling Robust TLS Encrypted Traffic Classification in Diverse Network Environments with TCP-Aware Traffic Augmentation

    Renjie Xie, Jiahao Cao, Enhuan Dong, Mingwei Xu, Kun Sun, Qi Li, Licheng Shen, and Menghao Zhang. Rosetta: Enabling Robust TLS Encrypted Traffic Classification in Diverse Network Environments with TCP-Aware Traffic Augmentation. In Proceedings of the 32nd USENIX Security Sympo...

  54. [62]

    Contrastive Fingerprinting: A Novel Website Fingerprinting Attack over Few-shot Traces

    Yi Xie, Jiahao Feng, Wenju Huang, Yixi Zhang, Xueliang Sun, Xiaochou Chen, and Xiapu Luo. Contrastive Fingerprinting: A Novel Website Fingerprinting Attack over Few-shot Traces. In Tat-Seng Chua, Chong- Wah Ngo, Ravi Kumar, Hady W. Lauw, and Roy Ka-Wei Lee, editors, Proceeding...

Pith tools

Reviewed August 11, 2026 · model on record in the stance chip above.