FINDING · DEFENSE
Ephemeral blocking defenses reduce DF accuracy from 89.0% (undefended) to 10.2% and RF from 90.1% to 14.7% with standard 30-epoch training, at 97.5% bandwidth and 68.4% delay overhead; under infinite training, DF rises to only 29.2% and RF to 24.3%, still far below undefended baselines of 92.7% and 94.7%. Defenses are tunable at deployment time by adjusting Maybenot framework-wide limits, enabling overhead-vs-protection trade-offs without redeployment.
From 2026-pulls-ephemeral-network-layer-fingerprinting — Ephemeral Network-Layer Fingerprinting Defenses · §5.2, §5.3, Table 1, Table 2 · 2026 · PoPETs 2026
Implications
- Design traffic-analysis defenses with blocking (active delay injection), not just padding — only defenses that combine bandwidth and delay overhead remain effective under infinite-training adaptive adversaries.
- Expose per-connection tunable overhead limits (Maybenot-style) so that the overhead-vs-protection trade-off can be adjusted at runtime without redeploying or retraining defense logic.
Tags
Extracted by claude-sonnet-4-6 — review before relying.