PST: a More Practical Adversarial Learning-based Defense Against Website Fingerprinting

被引:1
|
作者
Jiang, Minghao [1 ,2 ]
Wang, Yong [3 ]
Gou, Gaopeng [1 ,2 ]
Cai, Wei [1 ,2 ]
Xiong, Gang [1 ,2 ]
Shi, Junzheng [1 ,2 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
[2] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing, Peoples R China
[3] Coordinat Ctr China, Natl Comp Network Emergency Response Tech Team, Hong Kong, Peoples R China
关键词
Anonymity Communication; Privacy; Website Fingerprinting attack and defense; Deep Learning; Adversarial Machine Learning;
D O I
10.1109/GLOBECOM42002.2020.9322307
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
To prevent serious privacy leakage from website fingerprinting (WF) attacks, many traditional or adversarial WF defenses have been released. However, traditional WF defenses such as Walkie-Talkie (W-T) still generate patterns that might be captured by the deep learning (DL) based WF attacks, which are not effective. Adversarial perturbation based WF defenses better confuse WF attacks, but their requirements for the entire original traffic trace and perturbating any points including historical packets or cells of the network traffic are not practical. To deal with the effectiveness and practicality issues of existing defenses, we proposed a novel WF defense in this paper. called PST. Given a few past bursts of a trace as input, PST Predicts subsequent fuzzy bursts with a neural network, then Searches small but effective adversarial perturbation directions based on observed and predicted bursts, and finally Transfers the perturbation directions to the remaining bursts. Our experimental results over a public closed-world dataset demonstrate that PST can successfully break the network traffic pattern and achieve a high evasion rate of 87.6%, beating W-T by more than 31.59% at the same bandwidth overhead, with only observing 10 transferred bursts. Moreover, our defense adapts to WF attacks dynamically, which could be retrained or updated.
引用
收藏
页数:6
相关论文
共 50 条
  • [11] A Study on Adversarial Sample Resistance and Defense Mechanism for Multimodal Learning-Based Phishing Website Detection
    Duy, Phan The
    Minh, Vo Quang
    Dang, Bui Tan Hai
    Son, Ngo Duc Hoang
    Quyen, Nguyen Huu
    Pham, Van-Hau
    IEEE ACCESS, 2024, 12 : 137805 - 137824
  • [12] Towards a Practical Defense Against Adversarial Attacks on Deep Learning-Based Malware Detectors via Randomized Smoothing
    Gibert, Daniel
    Zizzo, Giulio
    Le, Quan
    COMPUTER SECURITY. ESORICS 2023 INTERNATIONAL WORKSHOPS, CPS4CIP, PT II, 2024, 14399 : 683 - 699
  • [13] ENSEMBLE ADVERSARIAL TRAINING BASED DEFENSE AGAINST ADVERSARIAL ATTACKS FOR MACHINE LEARNING-BASED INTRUSION DETECTION SYSTEM
    Haroon, M. S.
    Ali, H. M.
    NEURAL NETWORK WORLD, 2023, 33 (05) : 317 - 336
  • [14] Assured Deep Learning: Practical Defense Against Adversarial Attacks
    Rouhani, Bita Darvish
    Samragh, Mohammad
    Javaheripi, Mojan
    Javidi, Tara
    Koushanfar, Farinaz
    2018 IEEE/ACM INTERNATIONAL CONFERENCE ON COMPUTER-AIDED DESIGN (ICCAD) DIGEST OF TECHNICAL PAPERS, 2018,
  • [15] Tail Time Defense Against Website Fingerprinting Attacks
    Liang, Jingyuan
    Yu, Chansu
    Suh, Kyoungwon
    Han, Hyoil
    IEEE ACCESS, 2022, 10 : 18516 - 18525
  • [16] Cache Shaping: An Effective Defense Against Cache-Based Website Fingerprinting
    Li, Haipeng
    Niu, Nan
    Wang, Boyang
    CODASPY'22: PROCEEDINGS OF THE TWELVETH ACM CONFERENCE ON DATA AND APPLICATION SECURITY AND PRIVACY, 2022, : 252 - 263
  • [17] Generating practical adversarial examples against learning-based network intrusion detection systems
    Kumar, Vivek
    Kumar, Kamal
    Singh, Maheep
    ANNALS OF TELECOMMUNICATIONS, 2025, 80 (3-4) : 209 - 226
  • [18] WF-GAN: Fighting Back Against Website Fingerprinting Attack Using Adversarial Learning
    Hou, Chengshang
    Gou, Gaopeng
    Shi, Junzheng
    Fu, Peipei
    Xiong, Gang
    2020 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (ISCC), 2020, : 261 - 267
  • [19] Trace-agnostic and Adversarial Training-resilient Website Fingerprinting Defense
    Qiao, Litao
    Wu, Bang
    Li, Heng
    Gao, Cuiying
    Yuan, Wei
    Luo, Xiapu
    IEEE INFOCOM 2024-IEEE CONFERENCE ON COMPUTER COMMUNICATIONS, 2024, : 211 - 220
  • [20] Adversarial Attacks Against Deep Learning-Based Network Intrusion Detection Systems and Defense Mechanisms
    Zhang, Chaoyun
    Costa-Perez, Xavier
    Patras, Paul
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2022, 30 (03) : 1294 - 1311