FINDING · EVALUATION

ML-based VPN classifiers report FPRs of 1.4–5.5%, all exceeding the GFW's estimated practical threshold of 0.6%, while the simple RFC-heuristic approach achieves 0.11%; this indicates that real-world censors are more likely to adopt lightweight heuristic detectors than opaque ML pipelines.

From 2024-hanlon-detectingDetecting VPN Traffic through Encapsulated TCP Behavior · §4.2 Overall Classifier Results · 2024 · Free and Open Communications on the Internet

Implications

Tags

censors
cn
techniques
ml-classifiertraffic-shape

Extracted by claude-sonnet-4-6 — review before relying.