arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

变色龙:通过多对多流量变形抵御Tor网站指纹识别的鲁棒防御

Chameleon: Robust Defense Against Tor Website Fingerprinting via Many-to-Many Traffic Morphing

Yuwen Cui, Kai Wei, Kehan Shen, Ning Wang, Zhuo Lu, Yao Liu, Guangjing Wang

arXiv 2608.20160首次发表:更新:

AI 中文总结

Chameleon是一种基于多对多流量变形的Tor网站指纹鲁棒防御,可降低多种攻击的准确率,同时减少带宽和时间开销,在实际部署中表现优异。

AI 中文摘要

网站指纹(WF)攻击可通过利用侧信道特征从加密的Tor流量中推断用户的浏览活动。尽管已提出多种WF防御方法,但我们发现大多数现有防御会产生可学习的网页轨迹映射特征。我们进一步表明,对抗训练的鲁棒性并不必然意味着对基于防御感知自动编码器(DAAE)的攻击的鲁棒性。为解决这些局限性,我们提出了Chameleon(变色龙),一种基于多对多随机流量变形的鲁棒WF防御。Chameleon选择具有高类内多样性和低类间差异的变形候选对象,将每个网页轨迹随机映射到多个候选对象,并允许不同网页共享变形目标,从而增加对抗不确定性。针对实际Tor部署,Chameleon引入了基于基数前缀树(radix-trie)的同步机制,使可插拔传输(PT)端点能够使用数据包方向前缀识别一致的变形轨迹,同时结合轨迹变异和归一化前缀匹配以降低开销。我们在封闭世界和开放世界设置下,针对三个公共数据集上的六种最先进防御和五种WF攻击对Chameleon进行评估。与Adaptive Tamaraw相比,Chameleon将基于对抗训练的攻击准确率降低了多达36.74%,同时分别降低了34.12%的带宽开销和60.38%的时间开销。在GTT23数据集上针对基于DAAE的RF攻击,Chameleon将攻击性能限制在35.19%的F1分数,而Adaptive Tamaraw仅将其限制在88.22%的F1分数。在真实世界的PT网桥评估中,Chameleon大幅降低了强WF攻击的有效性,同时仅产生16.25%的时间开销。

英文摘要

Website fingerprinting (WF) attacks can infer users' browsing activities from encrypted Tor traffic by exploiting side-channel features. Although many WF defenses have been proposed, we find that most existing defenses create learnable web trace mapping features. We further show that robustness against adversarial training does not necessarily imply robustness against defense-aware autoencoder (DAAE)-based attacks. To address these limitations, we present Chameleon, a robust WF defense based on many-to-many randomized traffic morphing. Chameleon selects morphing candidates with high intra-class diversity and low inter-class disparity. Chameleon randomly maps each webpage trace to multiple candidates, and allows different webpages to share morphing targets, thereby increasing adversarial uncertainty. For practical Tor deployment, Chameleon introduces a radix-trie-based synchronization mechanism that enables pluggable transport (PT) endpoints to identify consistent morphing traces using packet-direction prefixes, together with trace mutation and normalized prefix matching to reduce overhead. We evaluate Chameleon against six state-of-the-art defenses and five WF attacks on three public datasets in closed- and open-world settings. Compared with Adaptive Tamaraw, Chameleon reduces adversarial-training-based attack accuracy by up to 36.74% while reducing bandwidth and time overhead by 34.12% and 60.38%, respectively. Under DAAE-based RF attacks on GTT23, Chameleon limits attack performance to 35.19% F1-score while Adaptive Tamaraw only limits it to 88.22% F1-score. In the real-world PT bridge evaluation, Chameleon substantially reduces the effectiveness of strong WF attacks while incurring only 16.25% time overhead.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑