Chameleon Holds Tor Fingerprinting Attacks to 35.19% F1 Where the Prior Best Defense Allowed 88.22%
Most Tor website-fingerprinting defenses inadvertently create learnable trace-mapping features, and the authors show that surviving adversarial training does not imply surviving defense-aware autoencoder attacks. Chameleon uses many-to-many randomized traffic morphing, selecting candidates with high intra-class diversity and low inter-class disparity, mapping each page trace to multiple candidates and letting different pages share morphing targets to raise adversarial uncertainty. Against Adaptive Tamaraw it cuts adversarial-training attack accuracy by up to 36.74% while also reducing bandwidth and time overhead by 34.12% and 60.38%, and under DAAE-based RF attacks on GTT23 it limits attackers to 35.19% F1 where Adaptive Tamaraw allowed 88.22%.
↳ Follow the thread