Chameleon: Robust Defense Against Tor Website Fingerprinting via Many-to-Many Traffic Morphing

📅 2026-08-20
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文提出Chameleon,一种基于多对多随机流量变形的防御方法,以解决Tor网站指纹攻击问题,通过增加对手不确定性来提高防御效果。
📝 Abstract
Website fingerprinting (WF) attacks can infer users' browsing activities from encrypted Tor traffic by exploiting side-channel features. Although many WF defenses have been proposed, we find that most existing defenses create learnable web trace mapping features. We further show that robustness against adversarial training does not necessarily imply robustness against defense-aware autoencoder (DAAE)-based attacks. To address these limitations, we present Chameleon, a robust WF defense based on many-to-many randomized traffic morphing. Chameleon selects morphing candidates with high intra-class diversity and low inter-class disparity. Chameleon randomly maps each webpage trace to multiple candidates, and allows different webpages to share morphing targets, thereby increasing adversarial uncertainty. For practical Tor deployment, Chameleon introduces a radix-trie-based synchronization mechanism that enables pluggable transport (PT) endpoints to identify consistent morphing traces using packet-direction prefixes, together with trace mutation and normalized prefix matching to reduce overhead. We evaluate Chameleon against six state-of-the-art defenses and five WF attacks on three public datasets in closed- and open-world settings. Compared with Adaptive Tamaraw, Chameleon reduces adversarial-training-based attack accuracy by up to 36.74% while reducing bandwidth and time overhead by 34.12% and 60.38%, respectively. Under DAAE-based RF attacks on GTT23, Chameleon limits attack performance to 35.19% F1-score while Adaptive Tamaraw only limits it to 88.22% F1-score. In the real-world PT bridge evaluation, Chameleon substantially reduces the effectiveness of strong WF attacks while incurring only 16.25% time overhead.
Problem

Research questions and friction points this paper is trying to address.

Website Fingerprinting
Tor Traffic
Side-Channel Features
Adversarial Training
Defense-Aware Autoencoder
Innovation

Methods, ideas, or system contributions that make the work stand out.

many-to-many traffic morphing
intra-class diversity
inter-class disparity
radix-trie-based synchronization mechanism
pluggable transport (PT)
🔎 Similar Papers
No similar papers found.
Y
Yuwen Cui
Bellini College of Artificial Intelligence, Cybersecurity and Computing, University of South Florida
Kai Wei
Kai Wei
Amazon
Computational social scienceNLPSLU
K
Kehan Shen
Bellini College of Artificial Intelligence, Cybersecurity and Computing, University of South Florida
Ning Wang
Ning Wang
University of South Florida
Trustworthy machine learningdifferential privacyadversarial machine learning
Zhuo Lu
Zhuo Lu
University of South Florida
Wireless Mobile SecurityData and AI SecurityIoT Security
Yao Liu
Yao Liu
Professor of Computer Science, University of South Florida
Computer and Network Security
G
Guangjing Wang
Bellini College of Artificial Intelligence, Cybersecurity and Computing, University of South Florida