HAAD: A Heuristic Ant Algorithm for Defending Against Website Fingerprinting Attacks
Pingfan Li, Kun Xie, Ruotian Xie, Pengcheng Zhao, Jiajun He, Jigang Wen, Wei Liang, Yong Xie · Proceedings of the ACM on Networking · 2026
Website Fingerprinting (WF) attacks based on Deep Neural Networks (DNN) pose serious threats to user privacy in anonymous communication systems such as Tor. Existing defenses show limited effectiveness in black-box scenarios, facing challenges including poor perturbation transferability, lack of directional and real-time constraints, limited universality, and high overhead. To address these issues, this paper proposes HAAD (Heuristic Ant-based Adversarial Defense), a black-box defense framework based on an ant colony algorithm. HAAD generates perturbations by combining an ensemble substitute model with ant colony optimization, avoiding reliance on gradient information and enhancing transferability to unknown models. Additionally, a per-packet injection method with directional constraints is designed to achieve real-time defense without extra latency. A universal perturbation algorithm is introduced, optimizing perturbations for diverse traffic scenarios via a scoring mechanism, effectively reducing communication overhead. Experimental results show that under various adversarial attack models, HAAD achieves a Defense Success Rate (DSR) exceeding 90% while requiring only 30 injected dummy packets—incurring minimal overhead. When deployed on a P4 switch, the maximum end-to-end latency is only 200 nanoseconds. We further implement HAAD in the Tor pt-plugin, where the full-page load median latency is merely 0.02 seconds. These results highlight HAAD's strong defensive capability and practical applicability.