FINDING · DETECTION

In open-world evaluation, an average of 34.4% of traffic from unseen personas is misattributed to a specific canonical persona (MisAttr@OW), and misattributions concentrate heavily: on average 58.7% of misattributed windows fall into just the top-3 canonical personas, rising to 66.8% and 69.3% on Bilibili and Zhihu respectively. The classifier correctly rejects unseen personas as OW with an average F1 of only 65.6%.

From 2026-song-personafingerprint-measuring-personaPersonaFingerprint: Measuring Persona Inference on Modern Websites with LLM-Driven Browsing · §5.4, Table 2 · 2026 · arXiv preprint

Implications

Tags

censors
generic
techniques
website-fingerprintml-classifier
defenses
tor

Extracted by claude-sonnet-4-6 — review before relying.