ADEFTOR: Adaptive Adversarial Example Generation for Website Fingerprinting Defense in Tor
Krishan Pal Singh, Emmanuel S. Pilli, Vijay Laxmi, Kashish Yusuf, Meenal Yadav · IEEE Transactions on Networking · 2025
Website Fingerprinting (WF) attacks significantly endanger user privacy in Anonymous Communication Networks, such as Tor, by allowing adversaries to infer the user’s browsing activity. Contemporary research has demonstrated that WF attacks using Deep Learning techniques transcend conventional rule-based defenses. Deep Learning models, in particular, have achieved remarkable accuracy in identifying websites visited through Tor, exhibiting the elevated threat posed by advanced WF attacks. This paper presents a novel WF defense mechanism, ADEFTOR, incorporating incremental distance reduction and universal distortion for individual sites. This approach involves selecting random target traces and progressively decreasing the distance between the modified examples and these targets. It also generates a universal distortion applicable across different user sessions and traffic types, allowing perturbations to blend into real-time network traffic seamlessly. ADEFTOR is evaluated against DL-based attacks using a public Tor traffic dataset. Experimental results demonstrate that ADEFTOR reduces the accuracy of the top-1 attack from 98% to between 29% and 39% and the accuracy of the top-2 to 47%. ADEFTOR reduces the bandwidth overhead of Full-Duplex and Half-Duplex to 45% and 60%, respectively. ADEFTOR presents a promising solution for improving privacy in the Tor networks by addressing WF attacks, effectively degrading the accuracy of sophisticated classifiers.