FINDING · DETECTION

Training WFP classifiers with LLM multi-agent simulated traces boosts cross-user accuracy to the 80% range (TikTok: 50.3%→84.9%, NetCLR: 53.6%→77.3%) compared to under 15% for models trained on scripted-only traffic. ClaudeOnly training outperforms ScriptedOnly baselines by approximately 3× on held-out human traces, using only 20% of the data volume, at a cost of roughly $10/GB versus $35/GB for human collection.

From 2026-song-redefining-website-fingerprintingRedefining Website Fingerprinting Attacks with Multi-Agent LLMs · §5.4 / Figure 6 · 2026 · PoPETs 2026

Implications

Tags

censors
generic
techniques
website-fingerprintml-classifiertraffic-shape

Extracted by claude-sonnet-4-6 — review before relying.