FINDING · DETECTION
An uncertainty-aware filtering (UF) mechanism quantifies per-token reliability via Shannon entropy of the cross-modal header–payload attention matrix, finding that encrypted payloads still contain low-entropy tokens with stable cross-modal alignment that serve as reliable classification anchors — demonstrating that nominally randomized byte streams retain exploitable low-entropy structure.
From 2026-he-trafficmoe-heterogeneity-aware-mixture — TrafficMoE: Heterogeneity-aware Mixture of Experts for Encrypted Traffic Classification · §III-D · 2026 · arXiv preprint
Implications
- Payload randomization that achieves high aggregate entropy is insufficient; censors can train models to identify residual low-entropy tokens (protocol-aligned or structure-preserving regions) and weight classification on those anchors.
- Circumvention protocols should target uniform entropy at the byte-chunk or stride level, not just overall payload entropy, to eliminate per-token reliability signals.
Tags
Extracted by claude-sonnet-4-6 — review before relying.