FINDING · DETECTION

Joint multi-task training with a combined loss L_joint = L_site + λ·L_pers shows that increasing λ from 0 to 2 raises mixed-site persona accuracy from approximately 45% to approximately 80% while website accuracy declines only from approximately 90% to approximately 75%, demonstrating a wide regime where an attacker can gain strong persona inference at modest cost to existing WFP capability.

From 2026-song-personafingerprint-measuring-personaPersonaFingerprint: Measuring Persona Inference on Modern Websites with LLM-Driven Browsing · §4.4, §5.7.2, Figure 5 · 2026 · arXiv preprint

Implications

Tags

censors
generic
techniques
website-fingerprintml-classifiertraffic-shape
defenses
tor

Extracted by claude-sonnet-4-6 — review before relying.