首次系统评估网页指纹攻击在真实环境下的表现,发现多数攻击在复杂场景中失效。
Beyond a Single Perspective: Towards a Realistic Evaluation of Website Fingerprinting Attacks
- 构建多维度真实场景测试框架,涵盖防御、流量漂移等六类挑战
- 实验显示多数攻击在组合环境下准确率从90%以上降至不足60%
- 为开发更实用的攻击方法提供关键评估标准,适合安全研究者参考
网页指纹(WF)攻击通过分析加密流量中的模式,推断用户访问的网站,严重威胁匿名通信系统。尽管近期技术在受控环境中准确率超过90%,但多数研究局限于单一场景,忽视了真实环境的复杂性。本文首次对现有WF攻击在多样化真实条件下的表现进行系统性全面评估,包括防御机制、流量漂移、多标签浏览、早期检测、开放世界设置及少样本场景。实验结果表明,许多在孤立环境中表现优异的攻击在面对其他条件时性能显著下降。由于现实环境常同时存在多种挑战,当前的WF攻击难以直接应用。本研究揭示了现有攻击的局限性,并提出多维评估框架,为发展更鲁棒、更实用的攻击方法提供关键洞见。
原文摘要 · Abstract (English)
Website Fingerprinting (WF) attacks exploit patterns in encrypted traffic to infer the websites visited by users, posing a serious threat to anonymous communication systems. Although recent WF techniques achieve over 90% accuracy in controlled experimental settings, most studies remain confined to single scenarios, overlooking the complexity of real-world environments. This paper presents the first systematic and comprehensive evaluation of existing WF attacks under diverse realistic conditions, including defense mechanisms, traffic drift, multi-tab browsing, early-stage detection, open-world settings, and few-shot scenarios. Experimental results show that many WF techniques with strong performance in isolated settings degrade significantly when facing other conditions. Since real-world environments often combine multiple challenges, current WF attacks are difficult to apply directly in practice. This study highlights the limitations of WF attacks and introduces a multidimensional evaluation framework, offering critical insights for developing more robust and practical WF attacks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。