跳到主要导航 跳到搜索 跳到主要内容

TrapFlow: Controllable Website Fingerprinting Defense via Dynamic Backdoor Learning

  • Siyuan Liang
  • , Jiajun Gong*
  • , Tianmeng Fang
  • , Aishan Liu
  • , Tao Wang
  • , Xiaochun Cao
  • , Dacheng Tao
  • , Ee Chien Chang*
  • *此作品的通讯作者
  • National University of Singapore
  • Peng Cheng Laboratory
  • Simon Fraser University
  • Sun Yat-Sen University
  • Nanyang Technological University

科研成果: 期刊稿件文章同行评审

摘要

Website fingerprinting (WF) attacks, which covertly monitor user communications to identify the web pages they visit, pose a serious threat to user privacy. Existing WF defenses attempt to reduce attack accuracy by disrupting traffic patterns, but attackers can retrain their models to adapt, making these defenses ineffective. Meanwhile, their high overhead limits deployability. To overcome these limitations, we introduce a novel controllable website fingerprinting defense called TrapFlow based on backdoor learning. TrapFlow exploits the tendency of neural networks to memorize subtle patterns by injecting crafted trigger sequences into targeted website traffic, causing the attacker’s model to build incorrect associations during training. If the attacker attempts to adapt by training on such noisy data, TrapFlow ensures that the model internalizes the trigger as a dominant feature, leading to widespread misclassification across unrelated websites. Conversely, if the attacker ignores these patterns and trains only on clean data, the trigger behaves as an adversarial patch at inference time, causing model misclassification. To achieve this dual effect, we optimize the trigger using the Fast Levenshtein-like distance to maximize both its learnability and distinctiveness from normal traffic. Experiments show that TrapFlow significantly reduces the accuracy of the RF attack from 99% to 6% with 74% data overhead. This compares favorably against two SOTA defenses: FRONT reduces accuracy by only 2% at a similar overhead, while Palette achieves 32% accuracy, but with 48% more overhead. We further validate the practicality of our method in a real Tor network environment.

源语言英语
页(从-至)2610-2625
页数16
期刊IEEE Transactions on Information Forensics and Security
21
DOI
出版状态已出版 - 2026

学术指纹

探究 'TrapFlow: Controllable Website Fingerprinting Defense via Dynamic Backdoor Learning' 的科研主题。它们共同构成独一无二的学术指纹。

引用此