REVIEW 4 major objections 6 minor 62 references
WFCAT: Augmenting Website Fingerprinting with Channel-wise Attention on Timing Features
T0 review · 4 major / 6 minor · reviewed 2026-08-11 · deepseek-v4-flash
Pith's one-line read The paper claims that a website fingerprinting attack built on an inter-arrival time histogram and channel-wise attention can identify Tor pages through strong defenses, reaching 59% accuracy against Surakav in closed-world tests.
desk verdict A genuinely new timing feature and a broad empirical study, but the headline Surakav number was selected by tuning G on the Surakav data—the qualitative finding likely stands, the exact 59% does not. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is the inter-arrival time (IAT) histogram, an intermediate-granularity trace representation. Given a Tor trace as an ordered sequence of cells with timestamps $t_i$ and directions $d_i$, each cell gets an inter-arrival time $\delta_i = t_i - t_{i-1}$, and the loading timeline is cut into slots of length $s$. In each slot, incoming and outgoing cells are counted separately into $G$ bins whose edges are evenly spaced on a logarithmic scale, yielding a tensor $\tilde{X}$ of shape $G\times2\times L$. The accompanying WFCAT backbone uses an Inception2d block—kernels of width 2 and heights $2k+1$ for $k=0,\dots,K-1$—to look at the in/out correlation at multiple scales, a squeeze-and-excitation block that learns a weight per feature channel through a two-layer fully connected net and sigmoid, and Inception1d blocks after reshaping; global average pooling produces the final logits. The representation is what preserves timing information that TAM-style counts discard, and the attention is what lets the model emphasise the IAT bins that survive defense noise.
What would settle it
Train WFCAT on traces from one set of Tor circuits and test it on traces for the same pages collected through different circuits and a different time window, using an independent implementation of Surakav (or the defense authors' original code) rather than the authors' reimplementation. If closed-world accuracy on these traces falls to the pre-WFCAT level (around 31% or below), the claimed 59% figure would not generalize beyond the specific collection setting.
Extended reading notes
Core claim
The paper's central claim is that packet timing leaks through defenses that are supposed to hide traffic shape, and that the leak can be harvested with the right representation and architecture. Existing attacks either use raw timestamps, which defense delays jitter, or coarse packet-count matrices (TAM), which lose the spacing between cells inside each time slot. WFCAT replaces these with an inter-arrival time (IAT) histogram: for each fixed time slot it bins the intervals between consecutive cells on a logarithmic scale, separately for outgoing and incoming cells, producing a $G \times 2 \times L$ tensor. A CNN with multi-scale Inception kernels and a squeeze-and-excitation channel-attention block then learns which IAT bins and time slots are informative. In closed-world tests on 100 monitored pages, WFCAT reaches 94.47% accuracy on undefended traces and 59.12% on Surakav-defended traces, compared with 30.92% for the RF attack and 15.04% for Tik-Tok; it also leads in open-world precision-recall against all tested defenses except the deterministic Tamaraw defense. The paper concludes that timing-sensitive defenses—padding and delaying mechanisms whose activation depends on page characteristics—inadvertently leave a recoverable fingerprint.
Load-bearing premise
The attack's reported 59% accuracy against Surakav assumes the authors' own implementation of Surakav produces traces representative of the defense, and that the attacker can train on traces drawn from the same defense and network distribution as the victim's traffic; if either condition fails, the reported accuracy does not transfer.
Editorial extensions
If this is right
- If the headline result holds, the Surakav defense is not providing the security margin prior work assumed: a passive observer can identify a monitored page from defended traffic 59% of the time in a 100-page closed world.
- Timing-sensitive defenses such as RegulaTor and Surakav leak page identity in their delay and padding schedules; defenses should be re-evaluated with IAT-based attacks rather than only direction-sequence or TAM attacks.
- Traffic-splitting defenses like TrafficSliver remain vulnerable (over 50% closed-world accuracy and 0.59 recall), so splitting alone should not be treated as sufficient protection.
- Noise-injection-only defenses such as FRONT and WTF-PAD cost bandwidth but give little protection: WFCAT stays near 93% closed-world accuracy against both.
- Attackers can get strong accuracy from few labeled traces (20–30 per class on defended datasets), which makes the attack more realistic when pages change frequently.
Reading between the lines
- A natural next benchmark for WF defenses would be to report accuracy against an IAT-histogram attack in addition to TAM and direction-sequence attacks; the paper's ablations suggest defenses tuned to defeat one representation may not defeat the other.
- The channel-attention weights could be inspected to identify which IAT bins and time slots carry the signal for a given defense, potentially revealing the exact delay or padding trigger that leaks information; this is a testable hypothesis the paper does not pursue.
- Because WFCAT exploits timing regularity, defenses that randomize their delay schedules per page load or per circuit, rather than making delays page-dependent, may be more robust; constructing such a defense and measuring WFCAT's accuracy would be a concrete extension.
- The IAT histogram representation is generic enough that it could be applied to other encrypted-traffic classification tasks, such as application or service identification, with the same attention mechanism; the paper only evaluates it for website fingerprinting.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper proposes WFCAT, a website fingerprinting attack on Tor that represents a trace as an inter-arrival-time (IAT) histogram over fixed time slots and classifies it with a CNN comprising Inception blocks and channel-wise attention (SEBlock). The authors report state-of-the-art closed-world accuracy against defended traces, notably 59.12% against Surakav versus 30.92% for RF and 15.04% for Tik-Tok, and they also present open-world results, bandwidth-mismatch robustness, sample-efficiency curves, and training-time comparisons. The contribution is primarily empirical: the representation and architecture are described in detail, but no code, data, or error bars are provided.
Significance. If the headline results survive independent verification, this is a meaningful advance for the WF attack literature: the paper identifies timing information as a persistent leakage source under strong reshaping defenses, and the proposed IAT histogram plus multi-scale attention CNN is a plausible mechanism for exploiting it. The evaluation is broad, covering seven defenses, closed- and open-world settings, bandwidth shifts, varying training set sizes, and an ablation study. However, the absence of released code/data/error bars, the unresolved G=4 versus G=9 conflict, and the use of a defense implementation from the authors' own group mean that the quantitative claims are not yet established at the reported precision. The paper contains no formal proofs; its contribution is empirical, which makes the reproducibility and evaluation-protocol concerns directly load-bearing. I would therefore treat the contribution as significant but conditional on a re-evaluation with a pre-specified configuration.
major comments (4)
- [V-B, V-H, Table II] The manuscript contains a direct contradiction on the default bin count G. Section V-B states that hyperparameters were tuned on the undefended dataset using the validation set and that 'G = 4 provides optimal performance', while Table II lists the final G as 9, and Section V-H reports experiments on the Surakav dataset showing accuracy peaking at 59% when G=9 and explicitly stating 'Based on these results, we set G = 9 as the default value.' Since Table III, the headline closed-world result, was presumably produced with G=9, the final configuration appears to have been selected using the Surakav test distribution, which is inconsistent with the tuning protocol claimed in V-B. The 59.12% figure is therefore a post-selection maximum rather than the accuracy of a pre-specified model. Please state explicitly which G was used for Table III, re-run the main comparisons with a configuration fixed before any Surakav evaluation (including the G=4 configuration from V-B), and report results for both configurations with confidence intervals.
- [V-A] The Surakav dataset is collected with the authors' own implementation of the defense: Section V-A states that 'Due to the absence of accurate simulation code for Surakav', the authors 'collected another dataset defended by Surakav using Gong's implementation on WFDefProxy'. Since the authors include the original Surakav and WFDefProxy authors, the attacker and the defender are evaluated within the same group's framework. This creates an insider-advantage risk: if this implementation differs from the Surakav defense as originally specified or as deployed, the reported 59.12% accuracy may not transfer to other Surakav instances. To support the central claim, the paper should provide the exact Surakav parameters and configuration used, validate the collected traces against the original Surakav paper's trace statistics, and ideally compare against an independent implementation. Releasing the collected traces and a description of the WFDefProxy Surakav module would allow the community to assess representativeness.
- [V-A, Table III] The evaluation methodology is underspecified regarding the relationship between the 8:1:1 split and the claimed 10-fold cross-validation. Section V-A says the dataset is divided into training, validation, and test sets with an 8:1:1 ratio and also that 10-fold cross-validation is conducted for each experiment with combined results. These are not the same protocol, and it is unclear whether hyperparameters were tuned once on a fixed validation set or per fold, and whether the reported accuracies are averages across folds or pooled over all test folds. This matters directly for the G=9 selection in V-H, because that section appears to evaluate on the Surakav test set. Please specify the exact protocol, including how the validation set was used during ASHA tuning and whether the final G and K were chosen before any test-set evaluation.
- [V-A, Table III] No confidence intervals or variance estimates are reported for any of the closed- or open-world numbers, despite the claim of 10-fold cross-validation. Given that the headline margin over RF on Surakav is 28.20 percentage points, even a few points of optimism would not overturn the qualitative conclusion, but the exact margin and the 'over 59%' claim are not reliable as stated. Please report the standard deviation or 95% confidence interval for each accuracy figure, and make the code and processed traces available so that the reader can reproduce the reported numbers for at least the Surakav and undefended configurations.
minor comments (6)
- [Abstract] The abstract says the improvement over RF and Tik-Tok is 'over 28% and 48%', but Table III shows differences of 28.20 and 44.08 percentage points; the '48%' should be '44%' or the sentence should be reworded.
- [V-C] The narrative alternates between 'TikTok' and 'Tik-Tok'; please use the consistent name used in the reference list and other sections.
- [V-C] The sentence 'However, our defense and other attacks have not compromised Tamaraw' should read 'our attack' rather than 'our defense', since WFCAT is an attack.
- [V-A] There is a typo: 'We have rent two servers' should be 'We have rented two servers'.
- [Figure 2] The figure example shows G=3 bins, while the final configuration in Table II and Section V-H uses G=9; either caption the figure as an illustrative example with G=3 or update the figure to show the default setting.
- [Figure 8] The two subfigures in Figure 8 lack clear axis labels and titles; the left panel varies G and the right panel varies K, but this is only apparent from the caption. Please add titles and axis labels.
Circularity Check
Headline Surakav accuracy is selected on the Surakav test set, not a fixed-configuration prediction.
-
fitted input called prediction
[Section V-B (hyperparameter tuning) vs. Section V-H (ablation), Table II and Figure 8]
"As shown in Figure 8, the accuracy of WFCAT increases significantly from 49% to 58% as G increases from 2 to 4. Beyond this point, the accuracy fluctuates slightly around 58%, peaking at 59% when G = 9. Based on these results, we set G = 9 as the default value."
This makes the headline Surakav result an in-sample selection rather than an out-of-sample prediction. Section V-B states that hyperparameters were tuned on the undefended dataset and that 'G = 4 provides optimal performance,' yet Table II lists G = 9 as final. Section V-H then re-selects G by observing accuracy on the Surakav dataset, choosing the value that peaks at 59%. Because the 59.12% accuracy reported in Table III is obtained with exactly that chosen configuration, the claimed margin over RF (30.92%) and Tik-Tok (15.04%) is partly an artifact of maximizing the evaluation metric on the same test distribution.
full rationale
The core derivation is not circular: the IAT histogram is defined by equations (3)-(5) from raw trace timestamps and directions, and the Inception/SEBlock CNN backbone is specified independently of any accuracy target. The clear circularity is at the evaluation boundary. Section V-B says the model was tuned on the undefended validation set with G=4 optimal, but Section V-H searches G on the Surakav dataset, peaks at 59% when G=9, and then sets G=9 as default; the reported 59.12% Surakav accuracy is therefore the result of model selection on the Surakav test distribution. This is a form of fitted input called prediction and inflates the headline margin over prior attacks. The authors' use of their own Surakav implementation and WFDefProxy framework is an additional external-validity risk, but by itself it is not a derivation-level circularity. The absence of released code or data prevents readers from verifying which configuration produced the main table.
Assumptions & free parameters
free parameters (5)
- Time slot duration s =
44 ms
- Trace length L =
1800
- Bin number G =
9
- Inception kernel count K =
4
- SE reduction ratio r =
16
assumptions (5)
- domain assumption The attacker observes the full ordered sequence of Tor cells with timestamps and directions between client and entry node.
- domain assumption The attacker knows the defense and can train on traces generated under the same defense distribution as the victim.
- domain assumption Inter-arrival times of cells carry page-dependent information that survives Surakav, RegulaTor, FRONT, and related defenses.
- domain assumption Logarithmic binning of IAT values is the right invariance to absorb Tor circuit latency noise.
- domain assumption The Surakav dataset collected with Gong's implementation faithfully represents the Surakav defense.
Cite this review
Pith. "Pith review of WFCAT: Augmenting Website Fingerprinting with Channel-wise Attention on Timing Features." pith.science (2026). https://pith.science/paper/UXL2T5L5
@misc{pith2026241211487,
author = {Pith},
title = {Pith review of: WFCAT: Augmenting Website Fingerprinting with Channel-wise Attention on Timing Features},
year = {2026},
howpublished = {\url{https://pith.science/paper/UXL2T5L5}},
note = {Machine review of arXiv:2412.11487}
}
read the original abstract
Website Fingerprinting (WF) aims to deanonymize users on the Tor network by analyzing encrypted network traffic. Recent deep-learning-based attacks show high accuracy on undefended traces. However, they struggle against modern defenses that use tactics like injecting dummy packets and delaying real packets, which significantly degrade classification performance. Our analysis reveals that current attacks inadequately leverage the timing information inherent in traffic traces, which persists as a source of leakage even under robust defenses. Addressing this shortfall, we introduce a novel feature representation named the Inter-Arrival Time (IAT) histogram, which quantifies the frequencies of packet inter-arrival times across predetermined time slots. Complementing this feature, we propose a new CNN-based attack, WFCAT, enhanced with two innovative architectural blocks designed to optimally extract and utilize timing information. Our approach uses kernels of varying sizes to capture multi-scale features, which are then integrated using a weighted sum across all feature channels to enhance the model's efficacy in identifying temporal patterns. Our experiments validate that WFCAT substantially outperforms existing methods on defended traces in both closed- and open-world scenarios. Notably, WFCAT achieves over 59% accuracy against Surakav, a recently developed robust defense, marking an improvement of over 28% and 48% against the state-of-the-art attacks RF and Tik-Tok, respectively, in the closed-world scenario.
Figures
Figures from the paper (4 more)
Reference graph
Works this paper leans on
-
[1]
Fingerprinting Attack on Tor Anonymity Using Deep Learning
Kota Abe and Shigeki Goto. Fingerprinting Attack on Tor Anonymity Using Deep Learning. Proceedings of the 10th Asia-Pacific Advanced Network, pages 15–20, 2016
work page 2016
-
[2]
DFD: Adversarial Learning-based Ap- proach to Defend Against Website Fingerprinting
Ahmed Abusnaina, Rhongho Jang, Aminollah Khormali, DaeHun Nyang, and David Mohaisen. DFD: Adversarial Learning-based Ap- proach to Defend Against Website Fingerprinting. In The 39th IEEE Conference on Computer Communications , pages 2459–2468. IEEE, 2020
work page 2020
-
[3]
Realistic Website Fingerprinting By Augmenting Network Traces
Alireza Bahramali, Ardavan Bozorgi, and Amir Houmansadr. Realistic Website Fingerprinting By Augmenting Network Traces. In Proceedings of the 30th ACM SIGSAC Conference on Computer and Communications Security, pages 1035–1049. ACM, 2023
work page 2023
-
[4]
Var-CNN: A Data-Efficient Website Fingerprinting Attack Based on Deep Learning
Sanjit Bhat, David Lu, Albert Kwon, and Srinivas Devadas. Var-CNN: A Data-Efficient Website Fingerprinting Attack Based on Deep Learning. Proceedings on Privacy Enhancing Technologies, pages 292–310, 2019
work page 2019
-
[5]
CS-BuFLO: A Congestion Sensitive Website Fingerprinting Defense
Xiang Cai, Rishab Nithyanand, and Rob Johnson. CS-BuFLO: A Congestion Sensitive Website Fingerprinting Defense. In Proceedings of the 13th Workshop on Privacy in the Electronic Society , pages 121–130. ACM, 2014
work page 2014
-
[6]
A Systematic Approach to Developing and Evaluating Website Fingerprinting Defenses
Xiang Cai, Rishab Nithyanand, Tao Wang, Rob Johnson, and Ian Gold- berg. A Systematic Approach to Developing and Evaluating Website Fingerprinting Defenses. In Proceedings of the 21st ACM SIGSAC Conference on Computer and Communications Security, pages 227–238. ACM, 2014
work page 2014
-
[7]
Touching From a Distance: Website Fingerprinting Attacks and Defenses
Xiang Cai, Xin Cheng Zhang, Brijesh Joshi, and Rob Johnson. Touching From a Distance: Website Fingerprinting Attacks and Defenses. In Proceedings of the 19th ACM SIGSAC Conference on Computer and Communications Security, pages 605–616. ACM, 2012
work page 2012
-
[8]
Towards Evaluating the Robustness of Neural Networks
Nicholas Carlini and David Wagner. Towards Evaluating the Robustness of Neural Networks. In IEEE Symposium on Security and Privacy, pages 39–57. IEEE Computer Society, 2017
work page 2017
Show all 62 references
-
[9]
Website Finger- printing Defenses at the Application Layer
Giovanni Cherubin, Jamie Hayes, and Marc Ju ´arez. Website Finger- printing Defenses at the Application Layer. Proceedings on Privacy Enhancing Technologies, pages 186–203, 2017
2017
-
[10]
Robust and Reliable Early-Stage Web- site Fingerprinting Attacks via Spatial-Temporal Distribution Analysis
Xinhao Deng, Qi Li, and Ke Xu. Robust and Reliable Early-Stage Web- site Fingerprinting Attacks via Spatial-Temporal Distribution Analysis. In Proceedings of the 31st on ACM SIGSAC Conference on Computer and Communications Security , pages 1997–2011. ACM, 2024
1997
-
[11]
Robust Multi-tab Website Fingerprinting Attacks in the Wild
Xinhao Deng, Qilei Yin, Zhuotao Liu, Xiyuan Zhao, Qi Li, Mingwei Xu, Ke Xu, and Jianping Wu. Robust Multi-tab Website Fingerprinting Attacks in the Wild. In IEEE Symposium on Security and Privacy, pages 1005–1022. IEEE, 2023
2023
-
[12]
Syverson
Roger Dingledine, Nick Mathewson, and Paul F. Syverson. Tor: The Second-Generation Onion Router. In Proceedings of the 13th USENIX Security Symposium, pages 303–320. USENIX Association, 2004. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY , VOL. *, NO. *, DECEMBER 2024 12
2004
-
[13]
Dyer, Scott E
Kevin P. Dyer, Scott E. Coull, Thomas Ristenpart, and Thomas Shrimp- ton. Peek-a-Boo, I Still See You: Why Efficient Traffic Analysis Countermeasures Fail. In IEEE Symposium on Security and Privacy , pages 332–346. IEEE Computer Society, 2012
2012
-
[14]
Zero-delay Lightweight Defenses against Website Fingerprinting
Jiajun Gong and Tao Wang. Zero-delay Lightweight Defenses against Website Fingerprinting. In Proceedings of the 29th USENIX Security Symposium, pages 717–734. USENIX Association, 2020
2020
-
[15]
Surakav: Generating Realistic Traces for a Strong Website Fingerprinting Defense
Jiajun Gong, Wuqi Zhang, Charles Zhang, and Tao Wang. Surakav: Generating Realistic Traces for a Strong Website Fingerprinting Defense. In IEEE Symposium on Security and Privacy , pages 1525–1525. IEEE, 2022
2022
-
[16]
WFDefProxy: Real World Implementation and Evaluation of Website Fingerprinting Defenses
Jiajun Gong, Wuqi Zhang, Charles Zhang, and Tao Wang. WFDefProxy: Real World Implementation and Evaluation of Website Fingerprinting Defenses. IEEE Transactions on Information Forensics and Security , pages 1357–1371, 2024
2024
-
[17]
Goodfellow, Jonathon Shlens, and Christian Szegedy
Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. Explaining and Harnessing Adversarial Examples. In Proceedings of the 3rd International Conference on Learning Representations , 2015
2015
-
[18]
BAPM: Block Attention Profiling Model for Multi-tab Website Fingerprinting Attacks on Tor
Zhong Guan, Gang Xiong, Gaopeng Gou, Zhen Li, Mingxin Cui, and Chang Liu. BAPM: Block Attention Profiling Model for Multi-tab Website Fingerprinting Attacks on Tor. In Proceedings of the 37th Annual Computer Security Applications Conference , pages 248–259. ACM, 2021
2021
-
[19]
k-fingerprinting: A Robust Scalable Website Fingerprinting Technique
Jamie Hayes and George Danezis. k-fingerprinting: A Robust Scalable Website Fingerprinting Technique. In Proceedings of the 25th USENIX Security Symposium, pages 1187–1203. USENIX Association, 2016
2016
-
[20]
Gaussian Error Linear Units (GELUs)
Dan Hendrycks and Kevin Gimpel. Gaussian Error Linear Units (GELUs). arXiv preprint arXiv:1606.08415 , 2016
2016 arXiv
-
[21]
Protecting against Website Fingerprinting with Multihoming
S ´ebastien Henri, Gines Garcia-Aviles, Pablo Serrano, Albert Banchs, and Patrick Thiran. Protecting against Website Fingerprinting with Multihoming. Proceedings on Privacy Enhancing Technologies , pages 89–110, 2020
2020
-
[22]
Holland and Nicholas Hopper
James K. Holland and Nicholas Hopper. RegulaTor: A Straightforward Website Fingerprinting Defense. Proceedings on Privacy Enhancing Technologies, pages 344–362, 2022
2022
-
[23]
Squeeze-and-Excitation Networks
Jie Hu, Li Shen, and Gang Sun. Squeeze-and-Excitation Networks. In IEEE Conference on Computer Vision and Pattern Recognition , pages 7132–7141. IEEE Computer Society, 2018
2018
-
[24]
Batch Normalization: Accelerating Deep Network Training by Reducing Internal Covariate Shift
Sergey Ioffe and Christian Szegedy. Batch Normalization: Accelerating Deep Network Training by Reducing Internal Covariate Shift. In Proceedings of the 32nd International Conference on International Conference on Machine Learning , page 448–456. JMLR, 2015
2015
-
[25]
RUDOLF: An Efficient and Adaptive Defense Approach Against Website Fingerprinting Attacks Based on Soft Actor-Critic Algorithm
Meiyi Jiang, Baojiang Cui, Junsong Fu, Tao Wang, Lu Yao, and Bharat K Bhargava. RUDOLF: An Efficient and Adaptive Defense Approach Against Website Fingerprinting Attacks Based on Soft Actor-Critic Algorithm. IEEE Transactions on Information Forensics and Security , 2024
2024
-
[26]
Transformer- based Model for Multi-tab Website Fingerprinting Attack
Zhaoxin Jin, Tianbo Lu, Shuang Luo, and Jiaze Shang. Transformer- based Model for Multi-tab Website Fingerprinting Attack. In Pro- ceedings of the 30th ACM SIGSAC Conference on Computer and Communications Security, pages 1050–1064. ACM, 2023
2023
-
[27]
Toward an Efficient Website Fingerprinting Defense
Marc Ju ´arez, Mohsen Imani, Mike Perry, Claudia D ´ıaz, and Matthew Wright. Toward an Efficient Website Fingerprinting Defense. In European Symposium on Research in Computer Security , pages 27–46. Springer, 2016
2016
-
[28]
TrafficSliver: Fighting Website Fingerprinting Attacks with Traffic Splitting
Wladimir De la Cadena, Asya Mitseva, Jens Hiller, Jan Pennekamp, Sebastian Reuter, Julian Filter, Thomas Engel, Klaus Wehrle, and Andriy Panchenko. TrafficSliver: Fighting Website Fingerprinting Attacks with Traffic Splitting. In Proceedings of the 27th ACM SIGSAC Conference o...
1971
-
[29]
Minipatch: Un- dermining DNN-based Website Fingerprinting with Adversarial Patches
Ding Li, Yuefei Zhu, Minghao Chen, and Jue Wang. Minipatch: Un- dermining DNN-based Website Fingerprinting with Adversarial Patches. IEEE Transactions on Information Forensics and Security , pages 2437– 2451, 2022
2022
-
[30]
A System for Massively Parallel Hyperparameter Tuning
Liam Li, Kevin Jamieson, Afshin Rostamizadeh, Ekaterina Gonina, Jonathan Ben-Tzur, Moritz Hardt, Benjamin Recht, and Ameet Tal- walkar. A System for Massively Parallel Hyperparameter Tuning. Proceedings of Machine Learning and Systems , pages 230–246, 2020
2020
-
[31]
A Large-scale Multiple-objective Method for Black-box Attack against Object Detection
Siyuan Liang, Longkang Li, Yanbo Fan, Xiaojun Jia, Jingzhi Li, Baoyuan Wu, and Xiaochun Cao. A Large-scale Multiple-objective Method for Black-box Attack against Object Detection. In European Conference on Computer Vision , 2022
2022
-
[32]
Efficient Adversarial Attacks for Visual Object Tracking
Siyuan Liang, Xingxing Wei, Siyuan Yao, and Xiaochun Cao. Efficient Adversarial Attacks for Visual Object Tracking. In Computer Vision– ECCV 2020: 16th European Conference, Glasgow, UK, August 23–28, 2020, Proceedings, Part XXVI 16 , 2020
2020
-
[33]
Parallel Rectangle Flip Attack: A Query-based Black-box Attack against Object Detection
Siyuan Liang, Baoyuan Wu, Yanbo Fan, Xingxing Wei, and Xiaochun Cao. Parallel Rectangle Flip Attack: A Query-based Black-box Attack against Object Detection. arXiv preprint arXiv:2201.08970 , 2022
2022 arXiv
-
[34]
Towards an Efficient Defense against Deep Learning based Website Fingerprinting
Zhen Ling, Gui Xiao, Wenjia Wu, Xiaodan Gu, Ming Yang, and Xinwen Fu. Towards an Efficient Defense against Deep Learning based Website Fingerprinting. In The 41st IEEE Conference on Computer Communications, pages 310–319. IEEE, 2022
2022
-
[35]
AdvTraffic: Obfuscating Encrypted Traffic with Adversarial Examples
Hao Liu, Jimmy Dani, Hongkai Yu, Wenhai Sun, and Boyang Wang. AdvTraffic: Obfuscating Encrypted Traffic with Adversarial Examples. In The 30th IEEE/ACM International Symposium on Quality of Service , pages 1–10. IEEE, 2022
2022
-
[36]
DynaFlow: An Efficient Website Fingerprinting Defense Based on Dynamically- Adjusting Flows
David Lu, Sanjit Bhat, Albert Kwon, and Srinivas Devadas. DynaFlow: An Efficient Website Fingerprinting Defense Based on Dynamically- Adjusting Flows. In Proceedings of the 17th Workshop on Privacy in the Electronic Society , pages 109–113. ACM, 2018
2018
-
[37]
Xiapu Luo, Peng Zhou, Edmond W. W. Chan, Wenke Lee, Rocky K. C. Chang, and Roberto Perdisci. HTTPOS: Sealing Information Leaks with Browser-side Obfuscation of Encrypted Flows. In Proceedings of the 18th Network and Distributed System Security Symposium . The Internet Society, 2011
2011
-
[38]
SoK: A Critical Evaluation of Efficient Website Fingerprinting Defenses
Nate Mathews, James K Holland, Se Eun Oh, Mohammad Saidur Rahman, Nicholas Hopper, and Matthew Wright. SoK: A Critical Evaluation of Efficient Website Fingerprinting Defenses. In IEEE Symposium on Security and Privacy , pages 344–361. IEEE, 2022
2022
-
[39]
Defeating DNN- Based Traffic Analysis Systems in Real-Time With Blind Adversarial Perturbations
Milad Nasr, Alireza Bahramali, and Amir Houmansadr. Defeating DNN- Based Traffic Analysis Systems in Real-Time With Blind Adversarial Perturbations. In Proceedings of the 30th USENIX Security Symposium , pages 2705–2722. USENIX Association, 2021
2021
-
[40]
Glove: A Bespoke Website Fingerprinting Defense
Rishab Nithyanand, Xiang Cai, and Rob Johnson. Glove: A Bespoke Website Fingerprinting Defense. In Proceedings of the 13th Workshop on Privacy in the Electronic Society , pages 131–134. ACM, 2014
2014
-
[41]
GANDaLF: GAN for Data-Limited Fingerprinting
Se Eun Oh, Nate Mathews, Mohammad Saidur Rahman, Matthew Wright, and Nicholas Hopper. GANDaLF: GAN for Data-Limited Fingerprinting. Proceedings on Privacy Enhancing Technologies , pages 305–322, 2021
2021
-
[42]
Website Fingerprinting at Internet Scale
Andriy Panchenko, Fabian Lanze, Jan Pennekamp, Thomas Engel, An- dreas Zinnen, Martin Henze, and Klaus Wehrle. Website Fingerprinting at Internet Scale. In Proceedings of the 23rd Network and Distributed System Security Symposium . The Internet Society, 2016
2016
-
[43]
Website Fingerprinting in Onion Routing Based Anonymization Networks
Andriy Panchenko, Lukas Niessen, Andreas Zinnen, and Thomas En- gel. Website Fingerprinting in Onion Routing Based Anonymization Networks. In Proceedings of the 10th Workshop on Privacy in the Electronic Society, pages 103–114. ACM, 2011
2011
-
[44]
Tranco: A Research-Oriented Top Sites Ranking Hardened Against Manipulation
Victor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Ma- ciej Korczynski, and Wouter Joosen. Tranco: A Research-Oriented Top Sites Ranking Hardened Against Manipulation. In Proceedings of the 26th Annual Network and Distributed System Security Symposium . The Internet ...
2019
-
[45]
Proposal 329: Traffic Splitting
The Tor Project. Proposal 329: Traffic Splitting. The Tor Project Proposals, 2023. Accessed: 2024-08-30
2023
-
[46]
Towards effective and efficient padding machines for tor
Tobias Pulls. Towards effective and efficient padding machines for tor. CoRR, abs/2011.13471, 2020
2011 arXiv
-
[47]
Mockingbird: Defending Against Deep-Learning- Based Website Fingerprinting Attacks With Adversarial Traces
Mohammad Saidur Rahman, Mohsen Imani, Nate Mathews, and Matthew Wright. Mockingbird: Defending Against Deep-Learning- Based Website Fingerprinting Attacks With Adversarial Traces. IEEE Transactions on Information Forensics and Security , pages 1594–1609, 2020
2020
-
[48]
Tik-Tok: The Utility of Packet Timing in Website Fingerprinting Attacks
Mohammad Saidur Rahman, Payap Sirinam, Nate Mathews, Kan- tha Girish Gangadhara, and Matthew Wright. Tik-Tok: The Utility of Packet Timing in Website Fingerprinting Attacks. Proceedings on Privacy Enhancing Technologies, pages 5–24, 2020
2020
-
[49]
Automated Website Fingerprinting through Deep Learning
Vera Rimmer, Davy Preuveneers, Marc Ju ´arez, Tom van Goethem, and Wouter Joosen. Automated Website Fingerprinting through Deep Learning. In Proceedings of the 25th Network and Distributed System Security Symposium. The Internet Society, 2018
2018
-
[50]
AW A: Adversarial Website Adaptation
Amir Mahdi Sadeghzadeh, Behrad Tajali, and Rasool Jalili. AW A: Adversarial Website Adaptation. IEEE Transactions on Information Forensics and Security, pages 3109–3122, 2021
2021
-
[51]
Patch-based Defenses against Web Fingerprinting Attacks
Shawn Shan, Arjun Nitin Bhagoji, Haitao Zheng, and Ben Y Zhao. Patch-based Defenses against Web Fingerprinting Attacks. In Proceed- ings of the 14th ACM Workshop on Artificial Intelligence and Security , pages 97–109, 2021
2021
-
[52]
Subverting Website Fingerprinting Defenses with Robust Traffic Rep- resentation
Meng Shen, Kexin Ji, Zhenbo Gao, Qi Li, Liehuang Zhu, and Ke Xu. Subverting Website Fingerprinting Defenses with Robust Traffic Rep- resentation. In Joseph A. Calandrino and Carmela Troncoso, editors, Proceedings of the 32nd USENIX Security Symposium , pages 607–624. USENIX As...
2023
-
[53]
Real-Time Website Fingerprinting Defense via Traffic Cluster Anonymization
Meng Shen, Kexin Ji, Jinhe Wu, Qi Li, Xiangdong Kong, Ke Xu, and Liehuang Zhu. Real-Time Website Fingerprinting Defense via Traffic Cluster Anonymization. In IEEE Symposium on Security and Privacy , pages 263–263. IEEE, 2024
2024
-
[54]
Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep Learning
Payap Sirinam, Mohsen Imani, Marc Ju ´arez, and Matthew Wright. Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep Learning. In Proceedings of the 25th ACM SIGSAC Conference on Computer and Communications Security , pages 1928–
1928
-
[55]
Triplet Fingerprinting: More Practical and Portable Website Fingerprinting with N-shot Learning
Payap Sirinam, Nate Mathews, Mohammad Saidur Rahman, and Matthew Wright. Triplet Fingerprinting: More Practical and Portable Website Fingerprinting with N-shot Learning. In Proceedings of the 26th ACM SIGSAC Conference on Computer and Communications Security , pages 1131–1148....
2019
-
[56]
Reed, Dragomir Anguelov, Dumitru Erhan, Vincent Vanhoucke, and Andrew Rabinovich
Christian Szegedy, Wei Liu, Yangqing Jia, Pierre Sermanet, Scott E. Reed, Dragomir Anguelov, Dumitru Erhan, Vincent Vanhoucke, and Andrew Rabinovich. Going Deeper with Convolutions. In IEEE Conference on Computer Vision and Pattern Recognition , pages 1–9. IEEE Computer Society, 2015
2015
-
[57]
High Precision Open-World Website Fingerprinting
Tao Wang. High Precision Open-World Website Fingerprinting. In IEEE Symposium on Security and Privacy , pages 152–167. IEEE, 2020
2020
-
[58]
Effective Attacks and Provable Defenses for Website Fin- gerprinting
Tao Wang, Xiang Cai, Rishab Nithyanand, Rob Johnson, and Ian Goldberg. Effective Attacks and Provable Defenses for Website Fin- gerprinting. In Proceedings of the 23rd USENIX Security Symposium , pages 143–157. USENIX Association, 2014
2014
-
[59]
Improved Website Fingerprinting on Tor
Tao Wang and Ian Goldberg. Improved Website Fingerprinting on Tor. In Proceedings of the 12th Workshop on Privacy in the Electronic Society , pages 201–212. ACM, 2013
2013
-
[60]
Walkie-Talkie: An Efficient Defense Against Passive Website Fingerprinting Attacks
Tao Wang and Ian Goldberg. Walkie-Talkie: An Efficient Defense Against Passive Website Fingerprinting Attacks. In Proceedings of the 26th USENIX Security Symposium , pages 1375–1390. USENIX Association, 2017
2017
-
[61]
Rosetta: Enabling Robust TLS Encrypted Traffic Classification in Diverse Network Environments with TCP-Aware Traffic Augmentation
Renjie Xie, Jiahao Cao, Enhuan Dong, Mingwei Xu, Kun Sun, Qi Li, Licheng Shen, and Menghao Zhang. Rosetta: Enabling Robust TLS Encrypted Traffic Classification in Diverse Network Environments with TCP-Aware Traffic Augmentation. In Proceedings of the 32nd USENIX Security Sympo...
2023
-
[62]
Contrastive Fingerprinting: A Novel Website Fingerprinting Attack over Few-shot Traces
Yi Xie, Jiahao Feng, Wenju Huang, Yixi Zhang, Xueliang Sun, Xiaochou Chen, and Xiapu Luo. Contrastive Fingerprinting: A Novel Website Fingerprinting Attack over Few-shot Traces. In Tat-Seng Chua, Chong- Wah Ngo, Ravi Kumar, Hady W. Lauw, and Roy Ka-Wei Lee, editors, Proceeding...
2024
Reviewed August 11, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.