FINDING · DETECTION

A site-only WFP encoder trained without any persona labels already encodes substantial persona information: attaching a lightweight MLP probe to its frozen representations recovers persona accuracy roughly 20–30 percentage points above a random-encoder baseline across all 10 sites (e.g., approximately 53% vs. 21% on Amazon, 49% vs. 27% on YouTube, using the same probe architecture and training budget).

From 2026-song-personafingerprint-measuring-personaPersonaFingerprint: Measuring Persona Inference on Modern Websites with LLM-Driven Browsing · §4.5, §5.7.1, Figure 4 · 2026 · arXiv preprint

Implications

Tags

censors
generic
techniques
website-fingerprintml-classifier
defenses
tor

Extracted by claude-sonnet-4-6 — review before relying.