FINDING · DETECTION

An attacker who generates 10 defended copies of each training trace (re-sampling noise each time) improves Tik-Tok accuracy against DeTorrent from 31.9% to 48.2%, demonstrating that dataset augmentation with multiple defended samples is a practical countermeasure against randomized padding defenses including DeTorrent and FRONT.

From 2024-holland-detorrentDeTorrent: An Adversarial Padding-only Traffic Analysis Defense · §6.4 · 2024 · Proceedings on Privacy Enhancing Technologies

Implications

Tags

censors
generic
techniques
website-fingerprintml-classifier
defenses
randomization

Extracted by claude-sonnet-4-6 — review before relying.