自适应流量伪装:针对物联网指纹识别的因果与资源感知防御
Adaptive Traffic Camouflage: Causal and Resource-Aware Defense Against IoT Fingerprinting
浏览论文内容
中文总结 AI 辅助
针对物联网流量形态指纹识别,提出一种因果且资源感知的自适应流量伪装控制器,在预算约束下选择变换,显著降低指纹识别性能,同时控制带宽和延迟开销。
中文摘要 AI 辅助
加密技术隐藏了物联网的有效载荷,但流量形态仍可通过数据包大小、时序、方向和分包方式揭示设备身份。我们提出了自适应流量伪装,这是一种因果的、泄漏感知的控制器,无需运行时设备标签即可表征流量形态泄漏,并根据前一窗口的上下文为下一个流量窗口选择预算可行的变换。该控制器在填充、分包、时序和复合变换之间进行选择,或在无需伪装时保持流量不变。我们在CIC-IoT-2022、IoT Sentinel和UNSW数据集上,使用经典和基于序列的指纹识别模型,在干净训练、防御感知和增量暴露设置下,以固定、随机和均值带宽匹配的基线进行评估。在Balanced配置下,伪装使平均Macro-F1相对于干净流量降低了13.2%至23.3%,平均带宽开销为4.88%至7.47%,最大增加延迟为0.64毫秒。在更大的Privacy配置下,降低幅度增至28.0%至43.5%。防御感知训练在CIC-IoT-2022和UNSW上恢复了攻击者的大部分性能损失,而IoT Sentinel仍保持显著的隐私差距。非因果的同窗口参考相比前一窗口控制仅提供适度的额外收益,而元数据丰富的攻击者在目标流量形态表面之外仍然有效。这些结果表明,在明确的通信约束下,因果且资源感知的伪装可以降低物联网流量形态的可指纹性,而保护的持续性取决于防御分布被学习的难易程度。
英文摘要
Encryption hides IoT payloads, but traffic shape can still reveal device identity through packet sizes, timing, direction, and packetization. We present Adaptive Traffic Camouflage, a causal, leakage-aware controller that characterizes traffic-shape leakage without runtime device labels and selects a budget-feasible transformation for the next traffic window from previous-window context. The controller chooses among padding, packet splitting, timing, and composite transformations, or leaves traffic unchanged when camouflage is unnecessary. We evaluate the design on CIC-IoT-2022, IoT Sentinel, and UNSW using classical and sequence-based fingerprinting models under clean-trained, defense-aware, and incremental-exposure settings, with fixed, random, and mean-bandwidth-matched baselines. Under the Balanced profile, camouflage reduces mean Macro-F1 by 13.2-23.3% relative to clean traffic with 4.88-7.47% average bandwidth overhead and at most 0.64 ms added latency. Under the larger Privacy profile, the reduction increases to 28.0-43.5%. Defense-aware training recovers much of the lost attacker performance on CIC-IoT-2022 and UNSW, while IoT Sentinel retains a substantial privacy gap. A non-causal same-window reference provides only modest additional benefit over previous-window control, and metadata-rich attackers remain effective outside the targeted traffic-shape surface. These results show that causal, resource-aware camouflage can reduce IoT traffic-shape fingerprintability under explicit communication constraints, while the persistence of protection depends on how readily the defended distribution can be learned.
发表机构
- University of Notre Dame(圣母大学)
- Microsoft Research(微软研究院)
机构由 AI 辅助整理,请以论文原文为准。