FINDING · EVALUATION

In open-world evaluation against 40 unseen background websites, models trained with Human+Claude traces suffer only 2–3% accuracy degradation versus 5–8% for Human-only training. This demonstrates that LLM-augmented data provides behavioral regularization that reduces false positives on background traffic, sustaining closed-world accuracy under realistic adversarial conditions.

From 2026-song-redefining-website-fingerprintingRedefining Website Fingerprinting Attacks with Multi-Agent LLMs · §5.5 / Figure 7 · 2026 · PoPETs 2026

Implications

Tags

censors
generic
techniques
website-fingerprintml-classifier

Extracted by claude-sonnet-4-6 — review before relying.