FINDING · EVALUATION
In open-world evaluation against 40 unseen background websites, models trained with Human+Claude traces suffer only 2–3% accuracy degradation versus 5–8% for Human-only training. This demonstrates that LLM-augmented data provides behavioral regularization that reduces false positives on background traffic, sustaining closed-world accuracy under realistic adversarial conditions.
From 2026-song-redefining-website-fingerprinting — Redefining Website Fingerprinting Attacks with Multi-Agent LLMs · §5.5 / Figure 7 · 2026 · PoPETs 2026
Implications
- Circumvention traffic defenses must be validated in open-world settings with large background populations — a 2–3% attacker degradation in open-world is insufficient protection compared to the 5–8% that was previously assumed.
- WFP defenses that generate cover traffic mimicking monitored-site patterns may inadvertently help LLM-trained attackers by reducing the background-class diversity.
Tags
Extracted by claude-sonnet-4-6 — review before relying.