Multiscale fingerprinting for robust website fingerprinting attack

Jiadong Shi, Wenjin Wang, Qiang Zhou, Liangmin Wang · The Computer Journal · 2025

Abstract Website fingerprinting (WF) attacks based on deep neural networks can effectively identify the target website. Recently, WF defence methods with trace adversarial examples (DTAE) can reduce classification accuracy of existing deep WF attacks from over 98% to approximately 50%. To overcome the vulnerability of deep WF attacks in classifying traces defended by adversarial examples, we propose a novel WF attack method specially designed for DTAE, called multiscale fingerprinting (MF). Specifically, MF slices each trace with different time slots to build a multi-channel matrix as the model input, and utilizes a multiscale convolutional neural network to extract the real trace patterns, which are changed and complicated by DTAE. Furthermore, we evaluate the performance of MF in closed- and open-world scenarios on the public dataset. In the closed-world scenario, MF achieves superior performance on DTAE methods, exhibiting an improvement of 12.32% over the state-of-the-art DTAE. In the open-world scenario, MF attains better performance on defended traces on Recall and Precision metrics, which demonstrates the enhanced robustness compared to existing deep WF attacks.

Read the paper · More papers on PaperTik